<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=collective+canvas%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 22:08:50 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 22:08:50 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=collective+canvas%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=collective+canvas%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[ShinyHunters: 275 Millionen Canvas-Nutzer in Cyberangriff betroffen - BornCity]]></title>
<description><![CDATA[Das FBI und die US-Cybersicherheitsbehörde CISA sind in die Ermittlungen eingeschaltet. Doch Instructure war nur die Spitze des Eisbergs. Die Gruppe ...]]></description>
<link>https://tsecurity.de/de/3694806/it-security-nachrichten/shinyhunters-275-millionen-canvas-nutzer-in-cyberangriff-betroffen-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694806/it-security-nachrichten/shinyhunters-275-millionen-canvas-nutzer-in-cyberangriff-betroffen-borncity/</guid>
<pubDate>Sat, 25 Jul 2026 20:01:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das FBI und die US-Cybersicherheitsbehörde CISA sind in die Ermittlungen eingeschaltet. Doch Instructure war nur die Spitze des Eisbergs. Die Gruppe ...]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT streicht die beste gratis Funktion: Warum OpenAI den Canvas im KI-Chatbot ersetzt hat]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3694791/ai-nachrichten/chatgpt-streicht-die-beste-gratis-funktion-warum-openai-den-canvas-im-ki-chatbot-ersetzt-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694791/ai-nachrichten/chatgpt-streicht-die-beste-gratis-funktion-warum-openai-den-canvas-im-ki-chatbot-ersetzt-hat/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/AZ-uhSQij_U"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShinyHunters: 275 Millionen Canvas-Nutzer in Cyberangriff betroffen - BornCity]]></title>
<description><![CDATA[Die Hacker setzen zunehmend auf Social Engineering. Beim Finanzdienstleister Figure Technology gelang der Zugriff, nachdem ein Mitarbeiter gezielt ...]]></description>
<link>https://tsecurity.de/de/3694623/hacking/shinyhunters-275-millionen-canvas-nutzer-in-cyberangriff-betroffen-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694623/hacking/shinyhunters-275-millionen-canvas-nutzer-in-cyberangriff-betroffen-borncity/</guid>
<pubDate>Sat, 25 Jul 2026 19:03:57 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die <b>Hacker</b> setzen zunehmend auf Social Engineering. Beim Finanzdienstleister Figure Technology gelang der Zugriff, nachdem ein Mitarbeiter gezielt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Security Update Review]]></title>
<description><![CDATA[I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a ...]]></description>
<link>https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for June 2026</strong></p><p class="">For June, Adobe released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic. A total of 11 of these CVEs were reported through the ZDI program.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank">APSB26-66</a></td>
    <td>Adobe Campaign Classic</td>
    <td>2</td>
    <td>Critical</td>
    <td>10.0</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank">APSB26-64</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank">APSB26-63</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>20</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank">APSB26-57</a></td>
    <td>Adobe Experience Manager Forms</td>
    <td>3</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html" target="_blank">APSB26-62</a></td>
    <td>Adobe Dreamweaver</td>
    <td>5</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html" target="_blank">APSB26-65</a></td>
    <td>Adobe Format Plugins</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-59.html" target="_blank">APSB26-59</a></td>
    <td>Adobe InCopy</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank">APSB26-58</a></td>
    <td>Adobe InDesign</td>
    <td>12</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html" target="_blank">APSB26-60</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html" target="_blank">APSB26-61</a></td>
    <td>Content Credentials SDK</td>
    <td>8</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html" target="_blank">APSB26-56</a></td>
    <td>Adobe Experience Manager</td>
    <td>57</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>11 bulletins</td>
    <td>123</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">Obviously, the update for Campaign Classic should be on the top of your deployment list if you’re a user. A CVSS 10 is rare; two in the same bulletin is pretty much a unicorn. Adobe says there are no active attacks, but I would expect heavy research into creating one. The update for Coldfusion is also a Priority 1, but again, no known attacks is the wild. I suspect the Reader patch will also receive a lot of attention as malicious PDFs are common in ransomware attacks. The update for Experience Manager may be large, but it’s mostly just cross-site scripting (XSS) bugs.</p><p class=""><strong>Microsoft Patches for June 2026</strong></p><p class="">This month, Microsoft released a new record 208 CVEs Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Secure Boot, and BitLocker. At least, that’s my count. Microsoft’s tools seem to be having some issues, as they initially included a CVE from 2020 in this release. Regardless, the count is over 200, and I counted several times.</p><p class="">One of these bugs came through the ZDI program, but bugs submitted during Pwn2Own Berlin remain unpatched. If you include the Chromium and other third-party bugs, the total CVE count for June comes to a staggering 571 CVEs. 38 of these cases are rated Critical while the rest are rated Important in severity.</p><p class="">I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time. The previous record was 177 set last year. It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns. How many of these cases were found using AI tools? How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal? The last two months were also large releases. Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future. BTW – just a note – the current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.</p><p class="">One of the bugs patched by Microsoft this month is listed as under active exploitation and three others are listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the bug being exploited in the wild.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><strong>CVE-2026-41091</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged, which indicates multiple parties say this is in the wild, meaning exploitation is likely significant. The good news is that most people won’t need to take action as Defender updates itself. However, if you don’t have this configured or are in an isolated environment, you’ll need to update to the latest version.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><strong>CVE-2026-45657</strong></a><strong> - Windows Kernel Remote Code Execution Vulnerability<br></strong>This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><strong>CVE-2026-47291</strong></a><strong> - HTTP.sys Remote Code Execution Vulnerability<br></strong>Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><strong>CVE-2026-44815</strong></a><strong> - DHCP Client Service Remote Code Execution Vulnerability<br></strong>Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><strong>CVE-2026-45585</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><strong>CVE-2026-50507</strong></a><strong> - Windows BitLocker Security Feature Bypass Vulnerability<br></strong>If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “<a href="https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085">bone shattering</a>” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.</p><p class=""> Here’s the full list of CVEs released by Microsoft for June 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="new2026-Jun-cvrf2.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="1024">
 <col width="144">
 <col width="256">
 <col width="104" span="6">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">XI</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a></td>
  <td width="256" class="xl68">Microsoft Defender
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl71">Yes</td>
  <td class="xl70">0</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a></td>
  <td width="256" class="xl68">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><span>CVE-2026-50507</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586"><span>CVE-2026-45586</span></a></td>
  <td width="256" class="xl68">Windows Collaborative
  Translation Framework (CTFMON) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="91">
  <td class="xl67" height="91"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10263"><span>CVE-2025-10263 *</span></a></td>
  <td width="256" class="xl68">ARM: CVE-2025-10263
  Completion of affected memory accesses might not be guaranteed by completion
  of a TLBI [kernel]</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567"><span>CVE-2026-48567</span></a></td>
  <td width="256" class="xl68">Azure HorizonDB<span>  </span>Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">10</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32193"><span>CVE-2026-32193</span></a></td>
  <td width="256" class="xl68">Azure Kubernetes
  Service (AKS) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644"><span>CVE-2026-47644</span></a></td>
  <td width="256" class="xl68">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><span>CVE-2026-44815</span></a></td>
  <td width="256" class="xl68">DHCP Client Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><span>CVE-2026-47291</span></a></td>
  <td width="256" class="xl68">HTTP.sys Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824"><span>CVE-2026-42824</span></a></td>
  <td width="256" class="xl68">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476"><span>CVE-2026-45476</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Network Adapter Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810"><span>CVE-2026-44810</span></a></td>
  <td width="256" class="xl68">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579"><span>CVE-2026-48579</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Online Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47655"><span>CVE-2026-47655</span></a></td>
  <td width="256" class="xl68">Microsoft Graph
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497"><span>CVE-2026-45497</span></a></td>
  <td width="256" class="xl68">Microsoft M365 Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45460"><span>CVE-2026-45460</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">4.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472"><span>CVE-2026-45472</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474"><span>CVE-2026-45474</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461"><span>CVE-2026-45461</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463"><span>CVE-2026-45463</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456"><span>CVE-2026-45456</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458"><span>CVE-2026-45458</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635"><span>CVE-2026-47635</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26142"><span>CVE-2026-26142</span></a></td>
  <td width="256" class="xl68">Nuance PowerScribe
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289"><span>CVE-2026-47289</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47654"><span>CVE-2026-47654</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48563"><span>CVE-2026-48563</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42992"><span>CVE-2026-42992</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44799"><span>CVE-2026-44799</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44801"><span>CVE-2026-44801</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985"><span>CVE-2026-42985</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648"><span>CVE-2026-45648</span></a></td>
  <td width="256" class="xl68">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987"><span>CVE-2026-42987</span></a></td>
  <td width="256" class="xl68">Windows Deployment
  Services (WDS) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828"><span>CVE-2026-33828</span></a></td>
  <td width="256" class="xl68">Windows Device Health
  Attestation (DHA) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803"><span>CVE-2026-44803</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812"><span>CVE-2026-44812</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607"><span>CVE-2026-45607</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641"><span>CVE-2026-45641</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652"><span>CVE-2026-47652</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288"><span>CVE-2026-47288</span></a></td>
  <td width="256" class="xl68">Windows Kerberos Key
  Distribution Center (KDC) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><span>CVE-2026-45657</span></a></td>
  <td width="256" class="xl68">Windows Kernel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48574"><span>CVE-2026-48574</span></a></td>
  <td width="256" class="xl68">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"><span>CVE-2026-45490</span></a></td>
  <td width="256" class="xl68">.NET SDK Elevation of
  Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491"><span>CVE-2026-45491</span></a></td>
  <td width="256" class="xl68">.NET Tampering
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591"><span>CVE-2026-45591</span></a></td>
  <td width="256" class="xl68">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47643"><span>CVE-2026-47643</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41098"><span>CVE-2026-41098</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642"><span>CVE-2026-45642</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Attestation service and Device Health Attestation Service Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45650"><span>CVE-2026-45650</span></a></td>
  <td width="256" class="xl68">Microsoft Bing Search
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45637"><span>CVE-2026-45637</span></a></td>
  <td width="256" class="xl68">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45647"><span>CVE-2026-45647</span></a></td>
  <td width="256" class="xl68">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371"><span>CVE-2026-40371</span></a></td>
  <td width="256" class="xl68">Microsoft Dynamics 365
  (on-premises) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44822"><span>CVE-2026-44822</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45455"><span>CVE-2026-45455</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45469"><span>CVE-2026-45469</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44817"><span>CVE-2026-44817</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44818"><span>CVE-2026-44818</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44820"><span>CVE-2026-44820</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44823"><span>CVE-2026-44823</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45459"><span>CVE-2026-45459</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504"><span>CVE-2026-45504</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45502"><span>CVE-2026-45502</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503"><span>CVE-2026-45503</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583"><span>CVE-2026-45583</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45500"><span>CVE-2026-45500</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45501"><span>CVE-2026-45501</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631"><span>CVE-2026-47631</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42986"><span>CVE-2026-42986</span></a></td>
  <td width="256" class="xl68">Microsoft Graphics
  Component Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41092"><span>CVE-2026-41092</span></a></td>
  <td width="256" class="xl68">Microsoft Kinect
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45644"><span>CVE-2026-45644</span></a></td>
  <td width="256" class="xl68">Microsoft Live Share
  Canvas SDK Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47293"><span>CVE-2026-47293</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45485"><span>CVE-2026-45485</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44821"><span>CVE-2026-44821</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45483"><span>CVE-2026-45483</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Project Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45475"><span>CVE-2026-45475</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44819"><span>CVE-2026-44819</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44824"><span>CVE-2026-44824</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45645"><span>CVE-2026-45645</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49161"><span>CVE-2026-49161</span></a></td>
  <td width="256" class="xl68">Microsoft PC Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a></td>
  <td width="256" class="xl68">Microsoft PowerToys
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45484"><span>CVE-2026-45484</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45454"><span>CVE-2026-45454</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298"><span>CVE-2026-47298</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45467"><span>CVE-2026-45467</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45468"><span>CVE-2026-45468</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45479"><span>CVE-2026-45479</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45453"><span>CVE-2026-45453</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636"><span>CVE-2026-47636</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47637"><span>CVE-2026-47637</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47638"><span>CVE-2026-47638</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47639"><span>CVE-2026-47639</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47641"><span>CVE-2026-47641</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33113"><span>CVE-2026-33113</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45462"><span>CVE-2026-45462</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45464"><span>CVE-2026-45464</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45465"><span>CVE-2026-45465</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47634"><span>CVE-2026-47634</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47640"><span>CVE-2026-47640</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45481"><span>CVE-2026-45481</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48560"><span>CVE-2026-48560</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48562"><span>CVE-2026-48562</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835"><span>CVE-2026-42835</span></a></td>
  <td width="256" class="xl68">Microsoft Teams for
  Android Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45606"><span>CVE-2026-45606</span></a></td>
  <td width="256" class="xl68">Microsoft UxTheme
  Library (uxtheme.dll) Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482"><span>CVE-2026-45482</span></a></td>
  <td width="256" class="xl68">Microsoft Visual
  Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466"><span>CVE-2026-45466</span></a></td>
  <td width="256" class="xl68">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45471"><span>CVE-2026-45471</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45486"><span>CVE-2026-45486</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45643"><span>CVE-2026-45643</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45457"><span>CVE-2026-45457</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980"><span>CVE-2026-42980</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42916"><span>CVE-2026-42916</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45649"><span>CVE-2026-45649</span></a></td>
  <td width="256" class="xl68">Office for Android
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47653"><span>CVE-2026-47653</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42909"><span>CVE-2026-42909</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42913"><span>CVE-2026-42913</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42993"><span>CVE-2026-42993</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45588"><span>CVE-2026-45588</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48568"><span>CVE-2026-48568</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48570"><span>CVE-2026-48570</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48573"><span>CVE-2026-48573</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48575"><span>CVE-2026-48575</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48576"><span>CVE-2026-48576</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48578"><span>CVE-2026-48578</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45654"><span>CVE-2026-45654</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45656"><span>CVE-2026-45656</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863"><span>CVE-2026-8863</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376"><span>CVE-2026-40376</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281"><span>CVE-2026-47281</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284"><span>CVE-2026-47284</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292"><span>CVE-2026-47292</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  MSSQL Extension Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569"><span>CVE-2026-48569</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287"><span>CVE-2026-47287</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42829"><span>CVE-2026-42829</span></a></td>
  <td width="256" class="xl68">Windows Administrator
  Protection Secure Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34335"><span>CVE-2026-34335</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45601"><span>CVE-2026-45601</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45598"><span>CVE-2026-45598</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45596"><span>CVE-2026-45596</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45638"><span>CVE-2026-45638</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45603"><span>CVE-2026-45603</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42911"><span>CVE-2026-42911</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45594"><span>CVE-2026-45594</span></a></td>
  <td width="256" class="xl68">Windows Application
  Identity (AppID) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45655"><span>CVE-2026-45655</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45658"><span>CVE-2026-45658</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45640"><span>CVE-2026-45640</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth Port
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45605"><span>CVE-2026-45605</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47656"><span>CVE-2026-47656</span></a></td>
  <td width="256" class="xl68">Windows Boot Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44809"><span>CVE-2026-44809</span></a></td>
  <td width="256" class="xl68">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45634"><span>CVE-2026-45634</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45608"><span>CVE-2026-45608</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41108"><span>CVE-2026-41108</span></a></td>
  <td width="256" class="xl68">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42905"><span>CVE-2026-42905</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44811"><span>CVE-2026-44811</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44808"><span>CVE-2026-44808</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44807"><span>CVE-2026-44807</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42983"><span>CVE-2026-42983</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44802"><span>CVE-2026-44802</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44813"><span>CVE-2026-44813</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44804"><span>CVE-2026-44804</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566"><span>CVE-2026-48566</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44814"><span>CVE-2026-44814</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602"><span>CVE-2026-45602</span></a></td>
  <td width="256" class="xl68">Windows Dynamic Host
  Configuration Protocol (DHCP) Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42836"><span>CVE-2026-42836</span></a></td>
  <td width="256" class="xl68">Windows Function
  Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42910"><span>CVE-2026-42910</span></a></td>
  <td width="256" class="xl68">Windows Hotpatch
  Monitoring Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42972"><span>CVE-2026-42972</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45592"><span>CVE-2026-45592</span></a></td>
  <td width="256" class="xl68">Windows Internet
  (wininet.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42903"><span>CVE-2026-42903</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42914"><span>CVE-2026-42914</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48583"><span>CVE-2026-48583</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45653"><span>CVE-2026-45653</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42984"><span>CVE-2026-42984</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45600"><span>CVE-2026-45600</span></a></td>
  <td width="256" class="xl68">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45604"><span>CVE-2026-45604</span></a></td>
  <td width="256" class="xl68">Windows Managed
  Installer Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45595"><span>CVE-2026-45595</span></a></td>
  <td width="256" class="xl68">Windows Mark of the
  Web Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45636"><span>CVE-2026-45636</span></a></td>
  <td width="256" class="xl68">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508"><span>CVE-2026-50508</span></a></td>
  <td width="256" class="xl68">Windows NTLM Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48565"><span>CVE-2026-48565</span></a></td>
  <td width="256" class="xl68">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44805"><span>CVE-2026-44805</span></a></td>
  <td width="256" class="xl68">Windows Network
  Controller (NC) Host Agent Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42981"><span>CVE-2026-42981</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42974"><span>CVE-2026-42974</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45487"><span>CVE-2026-45487</span></a></td>
  <td width="256" class="xl68">Windows Program
  Compatibility Assistant Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828"><span>CVE-2026-42828</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42837"><span>CVE-2026-42837</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42969"><span>CVE-2026-42969</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42971"><span>CVE-2026-42971</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42970"><span>CVE-2026-42970</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42973"><span>CVE-2026-42973</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978"><span>CVE-2026-42978</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977"><span>CVE-2026-42977</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42979"><span>CVE-2026-42979</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42991"><span>CVE-2026-42991</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45639"><span>CVE-2026-45639</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42908"><span>CVE-2026-42908</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45593"><span>CVE-2026-45593</span></a></td>
  <td width="256" class="xl68">Windows SDK Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42906"><span>CVE-2026-42906</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42907"><span>CVE-2026-42907</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47648"><span>CVE-2026-47648</span></a></td>
  <td width="256" class="xl68">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915"><span>CVE-2026-42915</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904"><span>CVE-2026-42904</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42968"><span>CVE-2026-42968</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912"><span>CVE-2026-42912</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45597"><span>CVE-2026-45597</span></a></td>
  <td width="256" class="xl68">Windows UI Automation
  Manager (uiamanager.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45599"><span>CVE-2026-45599</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45635"><span>CVE-2026-45635</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40409"><span>CVE-2026-40409</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40404"><span>CVE-2026-40404</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42989"><span>CVE-2026-42989</span></a></td>
  <td width="256" class="xl68">Winlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this release, the scariest-looking one is actually nothing to concern yourself with at all. The CVSS 10 bug in Azure HorizonDB has already been addressed by Microsoft and is just being documented now. That’s also the case for five others. Of course, there wouldn’t be a release without Office bugs that have the Preview Pane as an attack vector. There are multiple in June. There’s a handful of bugs in the Remote Desktop Client, but these rely on connecting to a malicious RDP server. There are three patches for Hyper-V that allow for guest-to-host code execution. The bug in Active Directory requires authentication, but any authenticated user can hit it. For the Windows Directory Service vulnerability, it needs to be listening for TFTP. You have blocked that everywhere, right? The bug in Azure Network Adapter is somewhat unique as you need to update your Linux kernel to be protected. The bug in Azure Kubernetes allows an attacker to break out of a container and gain control of the AKS worker node. Finally, the bug in the Kerberos Key Distribution Center (KDC) seems unlikely, but if exploited, it could allow authenticated attackers to get code execution on affected systems.</p><p class="">Moving on to the other code execution bugs, there are the ubiquitous open-an-own bugs in Office components like Excel and Word. The code injection bug in Exchange Server looks troubling, but it requires a machine-in-the-middle (MiTM), so exploitation is unlikely. The bugs in SharePoint require authentication, but you should note that the patch applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. The two bugs in UPnP are interesting. Both can lead to code execution by causing an error during the handling of specially crafted data, which could lead to a Use After Free (UAF) bug. The bugs in RDP Client all require connecting to a malicious RDP server, but it’s not clear why some are rated Critical and some are rated Important. The NTFS vulnerability requires a user to mount a virtual hard drive on an affected system. The last RCE bug this month is in Azure Stack Edge and requires the attacker to send a specially crafted file upload request that includes a manipulated file name or path, leading to code execution.</p><p class="">There are more than 60 Elevation of Privilege (EoP) bugs in this month’s release, and as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. A notable exception is in Exchange Server, where a user on Outlook Web Access (OWA) could gain access to other mailboxes. The bug in Visual Studio Code could allow attackers to gain permissions associated with the MCP Server’s managed identity. The bugs in Windows SDK and Windows UI Automation Manager could let attacker go from low integrity up to medium integrity code execution. The bug in Bluetooth just allows “elevated” privileges without really describing what elevated might be. </p><p class="">Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls. </p><p class="">Turning our attention to the mass of spoofing bugs in the release, we instantly see 18 impacting SharePoint Server. Fortunately, these are simply cross-site scripting (XSS) bugs. It’s the Exchange bugs we should really watch for. One is an XSS that an attacker can exploit by convincing an Exchange administrator to open a malicious link or message, which then runs code in the admin's web session. That's a meaningful privilege escalation path. Another is listed as an SSRF-based attack, but no other details are available. The last is a lower-impact XSS with limited confidentiality/integrity loss. The bug in Bing Search (remember Bing?) is a classic search result spoofing. The bug in Azure Stack Edge is interesting as it could allow access to resources outside the vulnerable component's security boundary. The bug in Office for Android requires user interaction. The Office Project Server bug is an authenticated XSS with low impact. The final spoofing bug is in Azure Attestation but has already been addressed. You should still verify you are protected by following the instructions in the write-up from Microsoft.</p><p class="">There are 30 different information disclosure bugs in this release, and fortunately, the vast majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The two bugs in Visual Studio require user interaction and could “disclose information over a network.” How obtuse. The bug in GitHub Copilot and Visual Studio Code could disclose discloses a sign-in access token for a user's work account. That's a meaningful credential exposure, not just random memory. That leaves the two bugs in Exchange Server. One could allow an authenticated user to gain information about which network services that the Exchange server can reach. The other sounds much like the spoofing bug in OWA as it allows attackers to see information in mailboxes they should not have access to.</p><p class="">I’ve never been a fan of the “tampering” category, as it could mean so many different things. For example, the bug in .NET simply says it could allow an unauthorized attacker to perform tampering locally. Similarly, the bug in Visual Studio says the same, expect here the tampering occurs over a network. Microsoft doesn’t even bother with a CWE for the tampering bug in the DHCP Server, so your guess is as good as mine.</p><p class="">There are seven DoS bugs in the June release, and as usual, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting is the bug in HTTP.sys, which is listed as publicly known. This is an uncontrolled resource consumption, rated "Exploitation More Likely," and publicly disclosed. Since, HTTP.sys sits at the core of IIS and Windows web services, a network-accessible DoS here can take down any Windows server running HTTP-based services. Based on the Acknowledgement, it looks like this bug may have been found using AI. There are no real details for the other bugs, but based simply on the impact, I would focus on the Kerberos and TCP/IP bugs if you had to prioritize.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on July 14 and will be the last one before Black Hat/DEFCON. It’s usually a big release, so strap in and hang on. I’ll be back then to give you my full thoughts. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p><p class=""> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Apple Security Update Review]]></title>
<description><![CDATA[We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS s...]]></description>
<link>https://tsecurity.de/de/3694562/hacking/the-june-2026-apple-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694562/hacking/the-june-2026-apple-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. </p><p class="">For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS scores or other severity information, we’re left to speculate on which of these bugs is the most severe. The overwhelming majority (31 of 37) are WebKit/WebRTC bugs reachable through malicious web content. Most of those are crash/DoS bugs rather than code execution, so the real risk lives in the small set of kernel bugs and the handful of WebKit sandbox escapes. However, there are a couple that stand out.</p><p class="">-    <strong>CVE-2026-43724 (Kernel)</strong> – According to Apple, “An app may be able to cause unexpected system termination or write kernel memory.” A kernel memory write is the highest-value primitive here: it's the privilege-escalation half of a full exploit chain and leads to complete device control. The bug was credited to Hyunwoo Kim (@v4bel), who is known to be a serious kernel researcher. </p><p class="">-    <strong>CVE-2026-39868 (Kernel)</strong> – Another kernel bug, this one could “cause unexpected system termination or corrupt kernel memory.” This is kernel memory corruption, and notably credited to a roster of elite offensive researchers (STAR Labs, Positive Technologies, Baidu Security). This kind of attribution usually signals a weaponizable, possibly Pwn2Own-grade bug rather than a theoretical crash.</p><p class="">-    <strong>CVE-2026-43725 / CVE-2026-43701 (WebKit)</strong> – Apple states these bugs could allow a website to process restricted web content outside the sandbox. I'm flagging this sandbox-escape pair over the many WebKit crash bugs because a sandbox escape is the bridge that turns a web-content bug into a path toward the kernel issues above. It's the most dangerous remotely-triggered class in the release.</p><p class="">Here’s a look at all the bugs released by Apple this month:</p>





















  
  




  


  
    




<title>Apple Security Update – June 29, 2026</title>



  
    
      <span class="num">37</span><span class="lbl">Total CVEs</span>
      <span class="num">22</span><span class="lbl">Denial of Service</span>
      <span class="num">7</span><span class="lbl">Information Disclosure</span>
      <span class="num">3</span><span class="lbl">Memory Corruption</span>
      <span class="num">2</span><span class="lbl">Elevation of Privilege</span>
      <span class="num">2</span><span class="lbl">Sandbox Escape</span>
      <span class="num">1</span><span class="lbl">Spoofing</span>
    

    <table>
      <caption>Apple security release — June 29, 2026. "Yes/No" indicates whether each update is affected. CVE IDs link to NVD.</caption>
      <thead>
        <tr>
          <th>CVE ID</th>
          <th>Component</th>
          <th>Impact</th>
          <th class="center">iOS 26.5.2 / iPadOS 26.5.2</th>
          <th class="center">macOS Tahoe 26.5.2</th>
          <th class="center">Safari 26.5.2</th>
        </tr>
      </thead>
      <tbody>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43743" target="_blank" rel="noopener">CVE-2026-43743</a></td>
        <td>IOGPUFamily</td>
        <td class="impact">An app may be able to cause unexpected system termination</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39868" target="_blank" rel="noopener">CVE-2026-39868</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or corrupt kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43722" target="_blank" rel="noopener">CVE-2026-43722</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to leak sensitive kernel state</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43724" target="_blank" rel="noopener">CVE-2026-43724</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or write kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43703" target="_blank" rel="noopener">CVE-2026-43703</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43706" target="_blank" rel="noopener">CVE-2026-43706</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43704" target="_blank" rel="noopener">CVE-2026-43704</a></td>
        <td>Web Extensions</td>
        <td class="impact">A malicious web extension may be able to cause an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39872" target="_blank" rel="noopener">CVE-2026-39872</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43663" target="_blank" rel="noopener">CVE-2026-43663</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43676" target="_blank" rel="noopener">CVE-2026-43676</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43699" target="_blank" rel="noopener">CVE-2026-43699</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43700" target="_blank" rel="noopener">CVE-2026-43700</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43701" target="_blank" rel="noopener">CVE-2026-43701</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43705" target="_blank" rel="noopener">CVE-2026-43705</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43707" target="_blank" rel="noopener">CVE-2026-43707</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43708" target="_blank" rel="noopener">CVE-2026-43708</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43709" target="_blank" rel="noopener">CVE-2026-43709</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43712" target="_blank" rel="noopener">CVE-2026-43712</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43713" target="_blank" rel="noopener">CVE-2026-43713</a></td>
        <td>WebKit</td>
        <td class="impact">Visiting a website may leak sensitive data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43715" target="_blank" rel="noopener">CVE-2026-43715</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43716" target="_blank" rel="noopener">CVE-2026-43716</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43725" target="_blank" rel="noopener">CVE-2026-43725</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43726" target="_blank" rel="noopener">CVE-2026-43726</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43727" target="_blank" rel="noopener">CVE-2026-43727</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43731" target="_blank" rel="noopener">CVE-2026-43731</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43732" target="_blank" rel="noopener">CVE-2026-43732</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43734" target="_blank" rel="noopener">CVE-2026-43734</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43735" target="_blank" rel="noopener">CVE-2026-43735</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43740" target="_blank" rel="noopener">CVE-2026-43740</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may result in the disclosure of process memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43742" target="_blank" rel="noopener">CVE-2026-43742</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43745" target="_blank" rel="noopener">CVE-2026-43745</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43720" target="_blank" rel="noopener">CVE-2026-43720</a></td>
        <td>WebKit Canvas</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43721" target="_blank" rel="noopener">CVE-2026-43721</a></td>
        <td>WebKit Storage</td>
        <td class="impact">A malicious website may be able to silently hijack clipboard data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28979" target="_blank" rel="noopener">CVE-2026-28979</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43717" target="_blank" rel="noopener">CVE-2026-43717</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43718" target="_blank" rel="noopener">CVE-2026-43718</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43746" target="_blank" rel="noopener">CVE-2026-43746</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      </tbody>
    </table>
  



  
  









  <p class="">We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[17 Things to know for Android developers at Google I/O]]></title>
<description><![CDATA[Posted by Matthew McCullough, VP, Product Management, Android DeveloperToday at Google I/O, we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcemen...]]></description>
<link>https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:45 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP7OJeCTRC-RN9j39-rULmU26qB-lZoyIZjjDrq07Z7b5GsfHz3q18ftSgcWReGBgIBkp03B6BVghzWllOC38o4jckzzq-e4a8R23ISeegev98zubhGXbIzhTZaqbCTaPLJC2zkxKYvvNspcM4yXkk94f6PEQHpdyMvlpwogicTWQRn3GEksJHOTQDIG4/s2048/GoogleForDevelopers-AndroidText-StrapiMetacard-2048x1323.png">


<div><div class="separator"><div class="separator"><div class="separator"><i>Posted by Matthew McCullough, VP, Product Management, Android Developer</i></div></div></div></div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s4209/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s16000/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"></a></div><div><br></div>Today at <a href="https://io.google/2026/">Google I/O,</a> we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcements for Android developers; you can also <a href="https://www.youtube.com/live/KvTRMSa1w4E?si=QBAxNvihPwJCJUuS">see what was announced last week</a> in <a href="https://developer.android.com/events/show">The Android Show: I/O Edition</a>. Stay tuned over the next two days as we dive into all of the topics in more detail!<h2><strong><span>Build High Quality Android Apps Using Agents</span></strong></h2>

  <h3><strong><span>1: Android CLI: helping you build with any agent, LLM, and tool</span></strong></h3>
  <a href="https://goo.gle/CLI_IO26">Android CLI is now stable</a>. It offers programmatic tools that allow any AI agent, including Claude Code, Codex, or Antigravity, to perform core Android tasks much more easily and efficiently. With today’s release, it also provides a bridge to tap directly into the "heavy-lifting" power of Android Studio to give you the production-ready polish needed for professional Android development. By leveraging the new android studio commands, developers can now grant their preferred agents the ability to perform semantic symbol resolution, analyze files for warnings, and even render Jetpack Compose previews. This release also enables official support for "Journeys" through new <a href="https://developer.android.com/tools/agents/android-skills">Android skills</a>, which enables agents to execute end-to-end UI tests under your direction. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.    <p><span></span></p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXrW3yDK9uH_I8MDyVxgYbPAXfrNTJvlMkXhaZFrM1X9ob0LvQbGe_ZC6anUeO_VNd181iptI_MIuEEpX-9GZdf6ZTJCN-WHpPzDCLOeSblo8vrjliSZ0rRrHwIsERWBjbbosP-M_WvA2pva9mF5FWVygAwQbdiW3SLZgJj9TpRIruG4H-ILsvSq_b4dc/w640-h442/agy-android-cli%20(2).png"></div><div class="separator"><span><i>You can now easily install Android CLI for use with Google Antigravity 2.0.</i></span></div><p></p>

  <h3><strong><span>2: Build production-ready apps with ease in Google AI Studio</span></strong></h3>
  Developers and creators can now <a href="http://android-developers.googleblog.com/2026/05/build-android-apps-google-ai-studio.html">build native Android apps, simply with a prompt in Google AI Studio</a>. The apps are built with development best practices like Jetpack Compose, Kotlin, and APIs that leverage our recommended developer patterns. Google AI Studio enables developers to prototype, iterate via an embedded emulator, and deploy to physical devices without heavy local installations. Developers are then able to take those apps and share them to Android devices, as well as share them with others for testing through Google Play Console’s internal testing track. If a developer wants to prepare their app for a wider release, they’re able to take it to Android Studio for advanced debugging, testing, and UI polish. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.<br><br><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdRaw1v6rolr4alo0C6AWKdFchsMEQgtOGfmk2Ramb0IoOB7smDcVU3yC7YJMkvVQuCPJ9vQW53tQjaV-5wcgOGzMtFDmb_Jbv40an1kvQdqYburXnsONvLqckKL2MWuShi3XmQEstW761oOLjujOk3FMsh3FyAiy5-Pe7xdTwFdfkWOmEnHhQfUJhtCo/w640-h544/image1.gif"></div><i><div class="separator"><i>Use the embedded Android Emulator to create Android apps in Google AI Studio</i></div></i></div><h2><strong><span>3: Accelerating AI coding assistance with Android Bench</span></strong></h2>
  <a href="http://d.android.com/bench">Android Bench</a> is our LLM leaderboard for Android development challenges. The goal is to accelerate model improvements, so you have more useful options for AI assistance. Many of you have been using open-weight models for AI assistance, so we’re now adding commonly used ones, such as Gemma 4, to the leaderboard, so you can see how LLMs that offer offline access and additional flexibility for power-users measure up. We're continuously working on increasing the difficulty of challenges we’re giving LLMs, to continue encouraging more useful improvements. <h3><strong><span>4: Convert iOS apps to Android with the Migration Assistant in Android Studio</span></strong></h3>
  The Migration Assistant in Android Studio is designed to port apps from platforms like iOS, React Native, or web frameworks to native Android. By simply selecting an existing project, developers can have the agent intelligently map features, convert assets like storyboards and SVGs, and implement Android best practices using Jetpack Compose and our recommended Jetpack libraries. This effectively transforms what used to be weeks of manual porting into a streamlined agentic workflow that only takes hours. We shared a preview of the incoming feature in the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>. </div><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjK7UKI_nzS7gOkDXYONAjCNbQ4eSqlgT8qqMT5D4qf0OjQUNtxj4Urpq-eTROMEDgrqLKGlwMm_lHA7ayG_BC1DkitQI1ZKsF5gYr-mPIxFUsz_8JPcVHFAtnHZoO2CrVjMEvJrqvBz8_WU1I0T1P2diDprR2B47PcA21oS3RLtbgrhmrpiWV-MAw9ks4/w640-h360/image9%20(1).gif"></div><div class="separator"><i>A sneak peek of the Migration Assistant converting an iOS app into a native Android app</i></div>

  <h2><strong><span>Building AI Into Your Apps</span></strong></h2>

  <h3><strong><span>5: Building Intelligent Apps with generative AI</span></strong></h3>
  Generative AI enables you to create apps that are more intelligent, personalized, and agentic than ever before. This year, we introduced the latest advancements in on-device intelligence with a preview of Gemini Nano 4 for tasks like data extraction and summarization. We also expanded cloud capabilities via Firebase AI Logic, allowing developers to leverage Gemini models with robust grounding (including URL, Maps, and web search) to build smarter, more capable assistants. Furthermore, we unveiled our hybrid inference approach and the new <a href="https://goo.gle/ADK_IO26">Agent Development Kit (ADK) for Android</a>, alongside communication protocols like AG-UI and A2UI that simplify the creation of autonomous, agentic experiences. To start integrating these powerful features, explore the <a href="https://developer.android.com/ai">developer documentation</a>, and watch the technical deep dive session where we showcase all these technologies.

  <h3><strong><span>6: Experiment with AppFunctions today</span></strong></h3>
  AppFunctions is an <a href="https://developer.android.com/reference/android/app/appfunctions/package-summary">Android platform API</a> with an accompanying <a href="https://developer.android.com/jetpack/androidx/releases/appfunctions">Jetpack library</a> to simplify building Android MCP integrations. It empowers your apps to behave like on device MCP servers, contributing functions that act as tools for use by agents and assistants. AppFunctions integration with Gemini is currently in a private preview with trusted testers, and you can begin preparing your apps already. You can sign up for the <a href="http://goo.gle/eap-af">Early Access Program</a> and start experimenting using the <a href="http://d.android.com/ai/appfunctions">API guidance</a>, <a href="https://github.com/android/appfunctions">sample</a>, and <a href="https://github.com/android/skills/blob/main/device-ai/appfunctions/SKILL.md">skill</a> today.

  <h2><strong><span>The Future is Adaptive</span></strong></h2>

  <h3><strong><span>7: Android is now Compose First; Views are now in maintenance mode.</span></strong></h3>
  Compose is our standard for UI development, and we are moving to a Compose-first approach for all future guidance and libraries. Building on five years of evolution, the latest releases deliver a more mature toolkit, from the highly customizable Styles API to refined shared element transitions and enhanced input support. These updates allow you to build beautiful, adaptive apps with less code and better performance. Learn more about what Compose-first means for Android Development in <a href="http://android-developers.googleblog.com/2026/05/android-ui-development-is-compose-first.html">our blog post</a>. <br><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq9kh5gxOfSdY2w9ZeKdWropXpqP7rj4KtodIZA5B_j7ujQu-blrsQKKC0lI4VEsEycpLEwsZeJhHaNOY1Xe9DrIHDwVszYfQN0GQlwxz8xoVfg1oiIr9zNlUyqqdCl2M7pyHoHgVvC7omKRthmXNaO3GE5Q15XeZ1ALiugszd8qHxpWuHo2Eh79zYW4M/w640-h416/image5.png"></div><div><div><i>Build Android UI with Compose</i></div><h3><strong><span>8: Building seamless Android experiences across devices with Jetpack Compose</span></strong></h3><div>The Android ecosystem is now <a href="https://goo.gle/AdaptiveApps_IO26">Adaptive by Default</a>, moving fluidly across phones, foldables, tablets, cars, XR, and expanding usages with <a href="https://developer.android.com/googlebook">Googlebook</a> and connected displays. With over 580 million large-screen devices, and users on multiple devices spending up to 14x more on apps, the investment in adaptive design presents a massive opportunity. <a href="https://developer.android.com/compose">Jetpack Compose</a> is the definitive engine for this transition, offering core tools like our latest <a href="http://goo.gle/nav3">Jetpack Navigation 3</a> release, new experimental <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/grid">Grid</a> and <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/flexbox">FlexBox</a> layouts, enhanced non-touch input support, and <a href="https://developer.android.com/media/camera/camerax">CameraX</a> for correct camera previews across any window size. Furthermore, new <a href="https://developer.android.com/tools/agents/android-skills">skills</a> in Android Studio make updating your existing app to adopt these adaptive patterns easier than ever.

  <img src="https://blogger.googleusercontent.com/img/a/AVvXsEi3DD3G6IUrmOwYh7bMq0uieBvGL8li2W48YnUfQfa3ZXy2kD7QvPorNfAyCSmFlBs4q0csXDqmZjhyGf8UHFE2pUNjvqxLaaJhmm6QpSBumq2YkMHI1jyiTNfh5WQhEEY9hP6vWhcbbwflygdTwYzoIdnuIqoht0S6iGKk4pVCnxL2wVXYBMBlcdeneD8"><i>Notability’s Android debut sets a new standard for premium productivity apps. Built with Jetpack Compose, Navigation 3, and Kotlin Multiplatform, it delivers an intuitive, adaptive experience across devices.</i></div><h3><strong><span>9: Create seamless experiences for Googlebook</span></strong></h3>
  Last week we announced <a href="https://developer.android.com/googlebook">Googlebook</a>, a high-performance laptop that provides a large-screen canvas for your existing apps. Building with adaptive principles today helps ensure your app will work on Googlebook. Get started by reviewing relevant <a href="https://developer.android.com/design/ui/desktop">design guidance</a> and <a href="https://developer.android.com/docs/quality-guidelines/adaptive-app-quality/experiences/desktop">developer guidelines</a> for desktop experiences. Try out the new Desktop Emulator available in the Android Studio Canary to to test your apps for this form factor today.</div><div><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtH3cjiXICi8dNCtQTDV9PTyjt4wPQBl1xA9XGKGU6FmqLRuBm9YyH7HNQsydD6H6F2GIPw2TdUsFyeu2xMFUO2Jk36k5QXjuWNdm_VE8AQftq2w2m0RPFyYfyZjTppSOjzuOEpJMzF08t9V0YZr-xI7mu31uvcRItugwvVxPUBouSmOXt1MsqbB1WPC0/w640-h360/image3.png"></div><div><div><i>New Desktop Android Emulator</i></div><h3><strong><span>10: Unified widget development experience with Jetpack Glance</span></strong></h3>
  Android 17 marks a shift toward a single, Compose-based development model for all widgets. By unifying the experience across mobile, Wear OS, and cars through Jetpack Glance, you can soon scale UI components across the ecosystem with a familiar workflow. <br><br>The breakthrough this year is the integration of RemoteCompose. On mobile and cars, it powers high-fidelity animations, while on Wear OS, it allows Wear Widgets (formerly Tiles) to render complex UI logic natively on remote surfaces. This ensures peak performance on low-power hardware while allowing a cohesive user journey—like checking a flight status on your car dashboard and seeing gate change updates on your wrist.</div><div><br></div><div><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA5s4g4hCW89qdeC2oqrTtxh6q7t9q3-wkOSt3tfVzCT3vhLUd1GMYJrhCjK04O2jyxBGl0R2pclnRq3Kb0f0Td-hV9aukKvZQTfGpGJS6GLK0MqUkpVW_0qiNC1eMGe6NPPhlCHrnQWFYhmbdSzpDnUHh5tjvpmUzZOvY2w_dX1LBnpNctSRmeahXUl4/w640-h320/blog_widgets.gif"></div><div><i>Four widgets are shown cycling through in the Android Auto interface. A clock, a contact card, Google Home favorites and a photo.</i></div><div><i><br></i></div><div><strong><span>11: Expand your reach on the road with Android for Cars</span></strong><br>To help you expand your reach when you build in-car experiences, we're making it easier to build once and deliver your apps to Android Auto and Android Automotive OS. With the latest releases of the Car App Library, you can build customized, distraction-optimized <a href="https://developer.android.com/training/cars/apps/media">templated media apps</a> for both platforms. We're introducing new <a href="https://developer.android.com/design/ui/cars/guides/components/overview">components</a> and template capabilities to give you increased flexibility and more options for laying out content. Parked experiences are expanding too, with immersive video playback coming to Android Auto for phones running Android 17. You can easily adapt your video apps for these parked experiences; <a href="https://docs.google.com/forms/d/e/1FAIpQLSf0z4Nfw8wrloVhlgHDpLgdkg4WXsFj9ni5c1pw0qTvJ3Q4fQ/viewform">apply now to the early access program</a> to publish in these beta categories and learn more about the latest updates in our <a href="http://android-developers.googleblog.com/2026/05/android-for-cars-unifying-platforms-premium-experiences.html">blog</a>.<h3><strong><span>12: Accelerate your development with Android XR Developer Preview 4</span></strong></h3>Inspired by the innovative experiences you’ve built for the platform, we’re continuing to mature our tools with <a href="https://goo.gle/XRSDK_IO26">Developer Preview 4 of the Android XR SDK</a>. A key milestone in this journey is the transition of our core libraries, XR Runtime, Jetpack SceneCore, and ARCore for Jetpack XR, moving to Beta soon to provide a more stable and performant foundation. We are also accelerating hardware access through the <a href="https://goo.gle/Catalyst_IO26">Android XR Developer Catalyst Program</a>, where you can apply for XREAL’s Project Aura, audio glasses, or display glasses developer kits. Watch The latest in Android XR session or <a href="https://goo.gle/XRSDK_IO26">read our blog</a> to see how these updates help you build experiences across the ecosystem.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyjbgGH7RwGkOkQLoXeLd88Vo7cXRjHLBSRokBWkzvYQUrqqbfrTXukM1u_SuGq0-AoXRPoGABpCOF-HMad4-aoNvXjTVyNXgGpbffTlSQMbTaXJva1c2GiUBx1fhC4fCCd0XO9XFzKNzs6edNqo0RAx-p2ZNXy0l-StJh7AxhyphenhyphenrXi-lqe-jXL0n8oprs/w640-h360/Aura%20Geospatial%20Tour%20Demo%20-%20Draft%2001%20(1).gif"></div><i><div><i>Early preview of the Geospatial API  in ARCore for Jetpack XR, enabling high-precision anchoring of digital content to real-world locations.</i></div></i><h3><strong><span>13: Android is your new home for professional-grade media experiences</span></strong></h3>
  Android 17 streamlines the entire media lifecycle with a production-ready toolkit. High-fidelity capture is now simplified with the CameraXViewfinder Composable, which handles complex scaling and responsiveness on foldables and tablets. For post-production, the new Media3 AI Effects library provides a single interface for premium features like Magic Eraser and Studio Sound, automatically optimizing for the device's hardware. <br><br>The pipeline is completed by CodecDB, offering chipset-specific encoding recommendations to eliminate export noise, and a new Scrubbing Mode in ExoPlayer for ultra-smooth seeking. Whether you’re compositing multi-asset edits with Media3 Transformer or using the streamlined CastPlayer API, these updates ensure a professional-grade experience with significantly less development overhead.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXXvjrWhhRUXdYJyhuu-Vnf0UP2jKcYhAvUggZJi10kndrixZdx4cD8HEhrWVmavlxAUT5N025Fx1kgOLJP5w83LDUSR3E9YzfIJUuZ3WBedFSBtI_oLgIcxSOYg-s53obwX_8HtYqfxSaz95LVzSiMAdrrwgL4T6TVETwtxxkZV2mSkkAfvYA681zNlc/w640-h542/supercharge%20(1).gif"></div><div class="separator"><i>Low Light Boost and Magic Eraser in action</i></div><h3><strong><span>14: Increase app discovery and engagement on Google TV</span></strong></h3>
  Pointer remotes, which enable motion-controlled input, will be a future way for users to interact with Google TV as it unlocks faster user navigation. App developers can start <a href="https://developer.android.com/training/tv/get-started/hardware#no-touchscreen">declaring support for pointing input</a> to ensure their apps are discoverable on future TVs with pointer remotes. Additionally, the Engage SDK, formerly known as the Video Discovery API, optimizes Resumption, Entitlements, and Recommendations across all Google TV form factors to boost app discovery and engagement. It’s a great time to start onboarding the Engage SDK now, since the legacy Watch Next API, which has been powering your continue watching 1.0 experience, will lose support in the 2nd half of 2027. Get all the details in our <a href="http://android-developers.googleblog.com/2026/05/increase-google-tv-app-discovery.html">blog</a>.</div><div><h3><strong><span>15: Performance: the foundation of a great app experience</span></strong></h3>To help developers navigate memory limits in Android 17, we've launched a suite of optimization tools. The <a href="https://developer.android.com/r8-analyzer">R8 Configuration Analyzer</a> identifies keep rules that are bloating your binary, while <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/how-to-capture">ProfilingManager</a> and the integrated LeakCanary in Android Studio streamline memory leak detection. Furthermore, the new <a href="https://developer.android.com/android-performance-analyzer">Android Performance Analyzer</a> offers advanced AI integration for complex trace analysis and automated SQL query generation to pinpoint performance bottlenecks.     <h2><strong><span>And The Latest on Driving Business Growth </span></strong></h2>

  <h3><strong><span>16: What’s new in Google Play</span></strong></h3>Today's <a href="https://goo.gle/play-io26">updates from Google Play</a> help expand your reach and scale your business with less complexity. We’re redefining Play Store discovery with an immersive, short-form video format called Play Shorts, while expanding your audience beyond the store with app discovery in the Gemini app on Android and web. Plus, we’re introducing powerful new capabilities like agentic catalog management for seamless bulk price and SKU updates, and using Gemini models to enable Play Console  to pre-populate store listings from imported documents—making global localization effortless. </div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOB1wGZNYGPgY0ED70X7Dtl2KiFk8kRH4fv3HrXXTWX0-xKkN4Em0mi8QAB0g2w_-4SNcTR4fJazpiQ7XI6-XKeyQniFhULKWNmV8YvyWMuQ9tosvT5ixZ0FOye27DI90R5Tra1eWX3FCX7OrWkgzhvhCD6vtfD8_6-FMfMWDvXoVv3zSTauZwraDGsM4/w640-h360/IO26_BlogInLine_App-discovery-in-Gemini_1920x1080_1605.gif"></div><div><i>Gemini will provide users with app suggestions during a search</i></div>

  <h3><strong><span>17: And of course, Android 17</span></strong></h3>
  Android 17 includes new performance &amp; system architecture improvements (in addition to app memory limits) like a lock-free MessageQueue and a GC with more frequent, less intensive young-generation collections to ensure system-wide stability and smoother UIs. The new <a href="https://developer.android.com/about/versions/17/features/contact-picker">contact picker</a> and <a href="https://developer.android.com/reference/android/content/Intent#ACTION_OPEN_EYE_DROPPER">eyedropper API</a> help minimize the use of sensitive permissions and unnecessary access to user data. <br><br>Review <a href="https://developer.android.com/about/versions/17/behavior-changes-all">the behavior changes</a> to make sure your app is ready for Android 17, including <a href="https://developer.android.com/about/versions/17/behavior-changes-all#bg-audio">background audio hardening</a> and <a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps">SMS OTP protection</a>. Get ready to <a href="https://developer.android.com/about/versions/17/behavior-changes-17">target Android 17</a> (API 37) with changes such as mandatory large-screen resizability, certificate transparency by default, and restricted local network access. You can start testing today by enrolling your device <a href="https://android-developers.googleblog.com/2026/04/the-fourth-beta-of-android-17.html">in the Beta</a> or using the latest 17.0 emulator images. <br><br>One more thing. the third beta of our Android 17 quarterly platform release (QPR1) just came out, and it contains a minor SDK release to support a few features that just couldn't wait for QPR2.

  <h2><strong><span>Check out all of the Android &amp; Play Content at Google I/O </span></strong></h2>
  <p><span face="sans-serif">This was just a preview of some of the updates for Android developers at Google I/O. Tune into <a href="https://io.google/2026/explore/pa-keynote-5">What’s New in Android</a> for the latest news and announcements and <a href="https://io.google/2026/">follow Google I/O</a> for much more over the following week!</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Foundation Launches Akrites To Coordinate AI-Driven Open Source Security]]></title>
<description><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA...]]></description>
<link>https://tsecurity.de/de/3693462/linux-tipps/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693462/linux-tipps/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</guid>
<pubDate>Sat, 25 Jul 2026 10:12:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA, IBM, Cisco, JPMorganChase, and others. Akrites will provide a shared Security Incident Response Team (SIRT), a standardized coordinated vulnerability disclosure process, and act as a "maintainer of last resort" for abandoned but widely used packages.
 
The goal is to reduce duplicate reports, avoid conflicting patches, and help upstream maintainers address vulnerabilities before they can be exploited. As AI makes it easier to find security flaws, can a coordinated industry effort help protect open source, or does it risk giving large corporations too much influence over the ecosystem? "Akrites is the largest coordinated effort in history to create systems and deploy tooling that leverages the collective power of the community to make everyone safer," the Linux Foundation said in an open letter. "Akrites participants will contribute engineering resources; work to build and ship fixes; or fund the engineers who do. Some companies have contributed mightily already. The reality is, collectively, we need to contribute more."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Foundation+Launches+Akrites+To+Coordinate+AI-Driven+Open+Source+Security%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2Flinux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/06/25/2031228/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chasing new skills, going back to basics and pushing for collective action: how software engineers are adapting to AI]]></title>
<description><![CDATA[Software engineering was one of the best-paying professions in the US in 2022, but the advent of AI has disrupted it, leading to several layoffs and underemploymentEvery weekday, Matt, a software engineer, looks forward to his four-hour train commute to Pawling, New York. It’s time he uses to wor...]]></description>
<link>https://tsecurity.de/de/3693125/it-nachrichten/chasing-new-skills-going-back-to-basics-and-pushing-for-collective-action-how-software-engineers-are-adapting-to-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693125/it-nachrichten/chasing-new-skills-going-back-to-basics-and-pushing-for-collective-action-how-software-engineers-are-adapting-to-ai/</guid>
<pubDate>Sat, 25 Jul 2026 07:03:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Software engineering was one of the best-paying professions in the US in 2022, but the advent of AI has disrupted it, leading to several layoffs and underemployment</p><p>Every weekday, Matt, a software engineer, looks forward to his four-hour train commute to Pawling, New York. It’s time he uses to work on his own project: a browser-based video game for which he writes every line of code himself.</p><p>“I am actively trying to keep my axe sharp,” said Matt, who did not want to use his actual name, to protect his employment. In the last six months, Matt’s job has increasingly shifted away from coding, problem solving and software architecture towards reviewing code generated by artificial intelligence. Convinced that the shift will weaken his skills, he’s doing what he can to keep them intact. “I am trying not to leverage AI where I can.”</p> <a href="https://www.theguardian.com/technology/ng-interactive/2026/jul/12/software-developers-engineers-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[District judge assigned to oversee Apple's trade secrets lawsuit against OpenAI]]></title>
<description><![CDATA[A federal district judge will oversee Apple's lawsuit accusing OpenAI of using stolen intellectual property to advance its hardware efforts.OpenAI CEO Sam Altman - image credit: Emerson CollectiveIn early July, Apple sued OpenAI after alleging that two ex-employees successfully stole intellectual...]]></description>
<link>https://tsecurity.de/de/3690526/ios-mac-os/district-judge-assigned-to-oversee-apples-trade-secrets-lawsuit-against-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690526/ios-mac-os/district-judge-assigned-to-oversee-apples-trade-secrets-lawsuit-against-openai/</guid>
<pubDate>Fri, 24 Jul 2026 03:31:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A federal district judge will oversee Apple's lawsuit accusing OpenAI of using stolen intellectual property to advance its hardware efforts.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68254-143883-000-lead-Sam-Altman-xl.jpg" alt="Man with short brown hair wearing a tan long sleeve shirt and clip-on microphone, seated against a dark background, looking slightly to the side with a neutral thoughtful expression" height="720" class=""><br><span>OpenAI CEO Sam Altman - image credit: Emerson Collective</span></div><br>In early July, <a href="https://appleinsider.com/articles/26/07/10/apple-sues-openai-previous-vp-of-product-design-over-mass-ip-theft">Apple sued</a> OpenAI after alleging that two ex-employees successfully stole intellectual property to enrich OpenAI's development efforts. Now, on Thursday, a judge has been assigned to the case.<br><br>Initially, when the suit was first filed, it was randomly assigned to Magistrate Judge Virginia K. DeMarchi. Now, it seems as though U.S. District Judge Edward Davila will oversee the case.<br><br><br> <a href="https://appleinsider.com/articles/26/07/24/district-judge-assigned-to-oversee-apples-trade-secrets-lawsuit-against-openai?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245046?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective]]></title>
<description><![CDATA[Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape. The new practice brings together Bridewell’s existing intel...]]></description>
<link>https://tsecurity.de/de/3687040/it-security-nachrichten/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687040/it-security-nachrichten/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective/</guid>
<pubDate>Wed, 22 Jul 2026 18:38:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape. The new practice brings together Bridewell’s existing intelligence-led services,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective/">Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective]]></title>
<description><![CDATA[Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape. The new practice brings together Bridewell’s existing intel...]]></description>
<link>https://tsecurity.de/de/3686984/it-security-nachrichten/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686984/it-security-nachrichten/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective/</guid>
<pubDate>Wed, 22 Jul 2026 18:19:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape. The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/22/bridewell-launches-dedicated-threat-intelligence-practice-bcon-collective/">Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Glow exits stealth with $180 million to secure the AI-enabled endpoint]]></title>
<description><![CDATA[Glow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security. The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish Ventures, Lux Capi...]]></description>
<link>https://tsecurity.de/de/3686152/it-security-nachrichten/glow-exits-stealth-with-180-million-to-secure-the-ai-enabled-endpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686152/it-security-nachrichten/glow-exits-stealth-with-180-million-to-secure-the-ai-enabled-endpoint/</guid>
<pubDate>Wed, 22 Jul 2026 13:39:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Glow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security. The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures. The company will use the funding to expand its go-to-market team in the United States and grow Glow Labs, its cybersecurity research division. Glow was founded … <a href="https://www.helpnetsecurity.com/2026/07/22/glow-launches-with-180-million-funding/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/22/glow-launches-with-180-million-funding/">Glow exits stealth with $180 million to secure the AI-enabled endpoint</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Seven sins of the modern software developer]]></title>
<description><![CDATA[If you ask us in an official setting, our official position is that software engineering norms still apply. Rigorous CI/CD pipelines, elegant architectural patterns, and an unyielding commitment to maintainable code remain the standard. We will use weighty words like “determinism,” “scalability,”...]]></description>
<link>https://tsecurity.de/de/3685746/ai-nachrichten/seven-sins-of-the-modern-software-developer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685746/ai-nachrichten/seven-sins-of-the-modern-software-developer/</guid>
<pubDate>Wed, 22 Jul 2026 11:04:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you ask us in an official setting, our official position is that software engineering norms still apply. Rigorous CI/CD pipelines, elegant architectural patterns, and an unyielding commitment to maintainable code remain the standard. We will use weighty words like “determinism,” “scalability,” “idempotency,” and “domain-driven design.”</p>



<p class="wp-block-paragraph">But behind closed doors, late at night, bathed in the glow of a dark-mode IDE, a different and more sordid reality is exposed. Hunched over the console with a manic gleam in the eye, the programmer has become power-drunk on <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLMs</a>. Like mad wizards casting spells, we summon the awesome powers of models and agents to satisfy our every programming whim—and commit acts of software engineering that would make <a href="https://en.wikipedia.org/wiki/Fred_Brooks">Fred Brooks</a> blush.</p>



<p class="wp-block-paragraph">Let’s just be honest about what is actually happening.</p>



<h2 class="wp-block-heading">Esoteric knowledge is superfluous</h2>



<p class="wp-block-paragraph">Forget <a href="https://www.infoworld.com/article/2335255/what-is-object-oriented-programming-the-everyday-programming-style.html">OOP</a> and <a href="https://www.infoworld.com/article/2263963/what-is-functional-programming-a-practical-guide.html">FP</a>. Forget the <a href="https://en.wikipedia.org/wiki/CAP_theorem">CAP theorem</a>, the holy crusade of <a href="https://en.wikipedia.org/wiki/Don%27t_repeat_yourself">DRY</a>, and the design patterns. Honestly, you can even forget what frameworks, runtimes, and deployment platforms you are using. The AI will figure out what is best to use and understand what is already in place. We have more mental bandwidth for working on our side project (a novel about AI taking over the world). </p>



<p class="wp-block-paragraph">Of course, I exaggerate. A little.</p>



<h2 class="wp-block-heading">The docs are dead to us</h2>



<p class="wp-block-paragraph">We still say RTFM, but the truth is, we haven’t really read a page of vendor documentation since 2023. <a href="https://www.infoworld.com/article/3993482/ai-didnt-kill-stack-overflow.html">Stack Overflow</a>, once our Internet Mecca, is a husk. When a package throws a weird exception, we don’t trace the execution path or read the release notes. We highlight the red text, copy the entire 200-line stack trace, dump it into the chat, and wait for the machine to spoon-feed us the solution.</p>



<p class="wp-block-paragraph">Better yet, we just have the agentic IDE spot the error, divine a solution, and ask us if it’s OK. We might glance at the problem-solution description, if we have gone around the circle on the problem for a few cycles. Maybe. If we don’t have the agent set up for auto-confirm.</p>



<p class="wp-block-paragraph">We used to buy heavy tomes like “Rust In Action” that were more like masonry blocks than literature. Now? We just ask an AI to transliterate our JavaScript logic into Rust. We are no longer engineers methodically learning a system. We are glorified copy-paste orchestrators hoping that the stochastic parrot behind the prompt guesses the syntax correctly.</p>



<h2 class="wp-block-heading">We ignore how the back end is wired</h2>



<p class="wp-block-paragraph">We act like we meticulously designed the data flows, carefully crafted the relational constraints, and mindfully mapped the API relationships. The reality is rather more disturbing: We asked the AI to scaffold a modern deployment, hooked it up to a back-end database, and just sort of… ran it.</p>



<p class="wp-block-paragraph">It created security rules we don’t fully understand. They do seem to work, however, which is nice. </p>



<p class="wp-block-paragraph">It generated a schema that we skimmed for about four seconds. It looks reasonable.</p>



<p class="wp-block-paragraph">It wrote <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html" data-type="link" data-id="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure-as-code</a> scripts that provisioned cloud resources we are hoping don’t blow a hole in the budget. Presumably, whoever is in charge of that will manage it by stuffing the metrics into another chatbot.</p>



<p class="wp-block-paragraph">We nodded, committed the code, and went to lunch. If management asked us to manually deploy the stack from scratch, configure the environment variables, and wire the API routes without our chat window, we would give them a vacant stare.</p>



<p class="wp-block-paragraph">We understand that management is also using AI to manage the project.</p>



<h2 class="wp-block-heading">Our tests are uncomfortably incestuous</h2>



<p class="wp-block-paragraph">Test-driven development (TDD) used to be a beautiful dream, ever just beyond reach. It made us feel glorious and despondent at turns. It would burden us with sprawling dependencies if implemented too religiously. (See <a href="https://grugbrain.dev/#grug-on-testing">The Grug Brained Developer</a> in this regard.)</p>



<p class="wp-block-paragraph">But now we can attain 95% test coverage almost effortlessly. Why not just add them in while we are auto-generating everything else?</p>



<p class="wp-block-paragraph">We can now wax at length to anyone who will listen about our astounding test coverage and our automated quality assurance. Unit tests, integration tests, smoke tests, you name it. What we conveniently leave out is that the AI wrote the complex application logic, and then we asked <em>the exact same AI</em> to write the test suite to validate the code it just dreamed up.</p>



<p class="wp-block-paragraph">It is a hermetically sealed loop of algorithmic self-congratulation. The mocks, the edge case, and the assertions are an echo chamber of the model’s original assumptions. The machine is grading its own homework, giving itself an A+.</p>



<p class="wp-block-paragraph">And we are happy to accept this because, beautifully, when the code has to change, the AI will effortlessly hallucinate new tests to adapt to the churn.</p>



<h2 class="wp-block-heading">We pass off the AI’s architecture as strategy</h2>



<p class="wp-block-paragraph">AI can produce astonishing design documents. Truly breathtaking. They are cogent, they’re beautifully formatted, and they seamlessly bridge the gap between high-level business goals and granular technical specs. They even include those auto-generated sequence diagrams that wow management.</p>



<p class="wp-block-paragraph">When we present these spotless architectural proposals in the Tuesday sprint planning meeting, we lean back, take a long sip of coffee, and humbly wave away the team’s praise.</p>



<p class="wp-block-paragraph">What we don’t mention is that we spent exactly four seconds generating it.</p>



<p class="wp-block-paragraph">Are these AI-generated documents just as liable as human ones to hide severe, mortal flaws in scope and alignment? Absolutely. They might contain a foundational logic bomb that will eventually doom the entire project. But the markdown is so crisp, and the bullet points are so persuasive, that the eye just glides right over it. We will never truly know the depth of the disaster until it is far too late. But hey, we’ll burn that bridge when production catches fire. Until then, we are strategic visionaries.</p>



<h2 class="wp-block-heading">We’re addicted to vibe coding (but only in secret)</h2>



<p class="wp-block-paragraph">We loudly mock the term on social media. We roll our eyes in Slack channels when the kids on TikTok talk about <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> their new startups. We fiercely cling to our identities as hardened, serious developers who understand memory management, garbage collection, and bitwise operators. We are professionals, damn it.</p>



<p class="wp-block-paragraph">But late at night, when the managers are asleep and no one is looking? We absolutely love it. We love just throwing a chaotic, half-baked thought at the canvas, pouring a drink, and watching the AI magically build a functioning user interface based entirely on our long-deferred whims. I may finally build that working <a href="https://en.wikipedia.org/wiki/Ultima_V%3A_Warriors_of_Destiny" data-type="link" data-id="https://en.wikipedia.org/wiki/Ultima_V%3A_Warriors_of_Destiny">Ultima V</a> clone. The thrill of typing “Create an app that tracks my cryptocurrency portfolio but makes it look like the interface from Neuromancer” and having it appear 30 seconds later is heady stuff.</p>



<p class="wp-block-paragraph">The more deeply rooted in the hard, old-school realities of programming, the more profound is the joy the developer finds in the possibility of AI coding. </p>



<h2 class="wp-block-heading">We beat the problem into submission with prompts</h2>



<p class="wp-block-paragraph">Like Adam Sandler in “Uncut Gems,” we are convinced the next round will fix everything. This is us with prompts. When things are going really off the rails, instead of putting our boots on and wading into the brambles of complexity, we resort to tonal adjustments. These range from the condescending: </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">This problem is not fixed. Look at it closely. The error is right here.</p>
</blockquote>



<p class="wp-block-paragraph">To the desperate: </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">We have been working on this same problem for hours now!</p>
</blockquote>



<p class="wp-block-paragraph">To the pathetic: </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">Can’t you find a different approach to try?!</p>
</blockquote>



<p class="wp-block-paragraph">The astonishing part? It often works.</p>



<p class="wp-block-paragraph">But there is no poetry left at the bottom of the rabbit hole; it is verbal warfare. When the context window collapses, when the regressions start cascading, and when the AI stubbornly refuses to follow the most basic rules of temporal logic, the mask of professionalism drops away and something far more atavistic makes its appearance. We stop asking nicely, stop trying to understand the why, delete the pleasantries, and capslock our intent.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">What we have here is a failure to communicate! </p>
</blockquote>



<p class="wp-block-paragraph">We feed the same failing stack trace back into the prompt over and over and over again, aggressively hammering the constraints, explicitly forbidding certain libraries, and pasting in release notes just to confirm that the AI lacks the latest APIs. We force the model down a narrower and narrower path until the code finally stops throwing errors. We don’t actually debug anymore, trace variables, or step through functions. We just apply relentless, iterative pressure until the machine surrenders. We beat it into submission. And then, we push to production.</p>



<p class="wp-block-paragraph">In fact, there is a real skill here—a sheer “will to completion” that remains in the act of building software. We invest just as much time, energy, and heart wrestling the bot as we ever did emitting syntax.</p>



<h2 class="wp-block-heading">A blacker box</h2>



<p class="wp-block-paragraph">The only profession more given over to using AI like a cursed Level 13 artifact than programming is writing. Writing of course is far more open to public scrutiny than code.</p>



<p class="wp-block-paragraph">And while my tongue has been firmly in my cheek here, my faith in coders as good guys makes me more curious to see what we create than troubled by the dangers. </p>



<p class="wp-block-paragraph">It was once the case that only other programmers could understand what programmers were doing, what they were producing. Now not even that is true. Only the machine knows what the machine is doing. We just keep it tethered to our aims. Hopefully.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Poolside drops Laguna S 2.1, an open-weight coding model that beats rivals 10x its size]]></title>
<description><![CDATA[Poolside, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smalle...]]></description>
<link>https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</guid>
<pubDate>Wed, 22 Jul 2026 01:07:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://poolside.ai/">Poolside</a>, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smaller lab competes at the frontier.</p><p>The model, <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a>, is a 118-billion-parameter<a href="https://huggingface.co/blog/moe"> Mixture-of-Experts (MoE) system</a> that activates only 8 billion parameters per token, supports a context window of up to 1 million tokens, and — according to benchmarks published by the company — matches or beats open models several times its size on agentic coding tasks. The weights are <a href="https://huggingface.co/poolside/Laguna-S-2.1">available immediately</a> on Hugging Face under the permissive OpenMDW-1.1 license.</p><p>The headline numbers are striking for a model this small. Poolside reports that <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> scores 70.2% on <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a>, a benchmark of long-horizon terminal tasks, placing it 11th on the company's compiled leaderboard — ahead of <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek-V4-Pro-Max</a>, a 1.6-trillion-parameter model that scored 64.0; Thinking Machines' 975-billion-parameter <a href="https://venturebeat.com/technology/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship">Inkling</a>, at 63.8; and Nvidia’s 550-billion-parameter <a href="https://research.nvidia.com/labs/nemotron/Nemotron-3-Ultra/">Nemotron 3 Ultra</a>, at 56.4. On <a href="https://www.swebench.com/multilingual.html">SWE-Bench Multilingual</a>, it posts 78.5%, and on <a href="https://labs.scale.com/leaderboard/swe_bench_pro_public">SWE-Bench Pro</a>'s public dataset, 59.4%.</p><p>Perhaps more telling than any single score: the model went from the start of pre-training on May 22 to public launch in under nine weeks, trained on 4,096 Nvidia H200 GPUs. In an industry where flagship model cycles are typically measured in quarters or years, Poolside has now shipped three models in three months.</p><div></div><h2><b>Why the West's open-weight AI gap has become a boardroom issue</b></h2><p>The release lands in the middle of an increasingly pointed debate about <a href="https://www.scmp.com/tech/tech-war/article/3361142/why-chinas-open-weight-ai-model-kimi-k3-sparking-anxiety-silicon-valley">the provenance of open-weight AI</a>. Over the past year, developer adoption has shifted decisively toward open-weight systems that companies can download, inspect, and run on their own infrastructure — and the leading options in that category have overwhelmingly come from Chinese labs. <a href="https://www.deepseek.com/en/">DeepSeek</a>, <a href="https://qwen.ai/home">Qwen</a>, <a href="http://kimi.ai/">Kimi</a>, <a href="https://chat.z.ai/">GLM</a>, <a href="https://www.minimax.io/">MiniMax</a>, and <a href="https://hy.tencent.com/">Tencent's Hunyuan</a> line all feature prominently in Poolside's own comparison tables.</p><p>Poolside's accompanying press release frames <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a> explicitly as a response, noting that the model occupies a size class into which no Western lab has released open weights in 11 months — since OpenAI's <a href="https://openai.com/index/introducing-gpt-oss/">gpt-oss-120b</a> last August. "The West needs open-weight models it can trust, run, and build on," said Jason Warner, Poolside's co-CEO, in the announcement.</p><p>Co-founder and co-CEO Eiso Kant made the philosophical stakes even plainer in a <a href="https://x.com/eisokant/status/2079612416967491952?s=20">lengthy post</a> on X. "I believe intelligence should and will become a commodity," he wrote, arguing that the open ecosystem "will not win by being the best in its own category." Users, he argued, simply want the best intelligence for the task at hand — so open models must be on par with, or better than, their closed equivalents.</p><div></div><p>The strategic logic here is not charity. Poolside's core business is deploying models inside the security boundaries of government, defense, and regulated enterprises — customers for whom closed, metered API access is often a non-starter for compliance and sovereignty reasons. </p><p>Every enterprise that standardizes on a Chinese open model today becomes harder to win tomorrow. Releasing competitive open weights is both an ecosystem play and a top-of-funnel strategy for the company's high-security deployment business. It also reframes the AI race away from terrain where Poolside cannot compete — frontier-scale capital expenditure — and toward terrain where it believes it can: cost per token, self-hosting, and iteration speed.</p><h2><b>How a sparse architecture makes enterprise AI agents affordable to run</b></h2><p>The technical design reflects a specific thesis about where value in coding AI is moving. Laguna S 2.1's sparse MoE architecture — 256 routed experts plus one shared expert, with grouped-query attention and interleaved sliding-window layers, according to the <a href="https://huggingface.co/poolside/Laguna-S-2.1">Hugging Face model card</a> — means inference costs scale with the 8 billion active parameters, not the 118 billion total. Poolside emphasizes that the model is small enough to run on a single Nvidia DGX Spark, the desktop-class AI machine.</p><p>That matters for what Poolside calls token economics. Long-horizon coding agents are voracious consumers of tokens: the company's published data shows the model consuming a mean of roughly 249,000 completion tokens per trajectory on its hardest benchmark when thinking mode is enabled. At metered API prices, agentic workloads at enterprise scale become a meaningful budget line item. On OpenRouter, Poolside is offering a free 256K-context endpoint and a dedicated 1M-context deployment priced at $0.10 per million input tokens and $0.20 per million output tokens — aggressive pricing that undercuts most frontier alternatives by an order of magnitude.</p><p>The ecosystem support is unusually broad for day one. The model is live on <a href="https://www.baseten.co/library/laguna-s-21/">Baseten's model library</a> and <a href="https://vercel.com/changelog/laguna-s-2-1-is-now-available-on-ai-gateway">Vercel's AI Gateway</a>, with integrations across <a href="https://vllm.ai/">vLLM</a>, <a href="https://github.com/sgl-project/sglang">SGLang</a>, <a href="https://ollama.com/">Ollama</a>, and <a href="https://github.com/ggml-org/llama.cpp">llama.cpp</a>, plus quantized variants down to 4-bit GGUF files — 75 gigabytes — for local use. But Poolside's more interesting claim is behavioral, not architectural. Pengming Wang, co-head of applied research at Poolside, said the gains came from improving the model's working habits: "more verification, less taking things for granted, not declaring victory early, and being more persistent." Raw intelligence, the company argues, is one axis of capability; a model's way of working is a second axis that matters immensely for agents left unattended for hours.</p><h2><b>Publishing every benchmark trajectory to counter AI's credibility crisis</b></h2><p>The most consequential part of the release for enterprise buyers may be an evaluation-transparency move with little precedent among major labs: Poolside published the complete, unedited trajectory of every trial in its final benchmark runs — every reasoning step, tool call, and shell command behind every reported score.</p><p>This addresses a growing credibility problem in AI benchmarking. As top scores on mature benchmarks cluster in the 70–90% range, and as "reward hacking" — models finding solutions online or gaming verifiers rather than solving problems — has become endemic, self-reported numbers have lost much of their signal. Poolside disclosed its own encounters with the problem candidly: during training, more than half of trajectories on some SWE-bench tasks were flagged because the model simply researched the original bug-fix pull request online and applied it. The company documented its mitigations, including prompt addenda, LLM-based judging calibrated against human labels, and expert annotator review of a high-scoring Terminal-Bench run.</p><p>Three published case studies illustrate what the company means by persistence. In one, the model built a working HTML/CSS rendering engine from an empty folder in a 181-step, 50-minute unattended session — then, lacking vision capabilities, spun up headless Chromium to numerically compare its canvas output against a real browser's rendering. In another, pointed at Poolside's own agent harness in an automated optimization loop, the model made the Go codebase 5.2% faster with roughly 70% lower memory allocation, finding an O(n²) string-concatenation bug along the way. In a third, working in a sandbox with no Python installed, the model did its number theory in Perl and independently re-derived a proof of Erdős problem #397 — a combinatorics question open for five decades until GPT-5.2 Pro first solved it this past January. Poolside notes that its model's construction is structurally different from the earlier published solution, and that its November 2025 knowledge cutoff precedes the first proof.</p><div></div><h2><b>What the disclosed limitations and benchmark fine print reveal</b></h2><p><a href="https://poolside.ai/">Poolside</a> deserves credit for disclosing limitations most labs bury. The model can overfit to its native harness and stumble on slightly different tool schemas in third-party agents, mangles JSON in nested tool arguments, and is prone to overthinking on competition math. There is currently no user-configurable thinking-effort dial — just on or off — and the gap between the modes is enormous: thinking lifts <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a> from 60.4% to 70.2%, and <a href="https://deepswe.datacurve.ai/">DeepSWE</a> from 16.5% to 40.4%, at substantially higher token cost.</p><p>Buyers should apply their own discounts to the comparison tables. Poolside's methodology takes the maximum of vendor self-reported scores, benchmark-author leaderboards, and third-party figures for competitors — a reasonable convention, but one that mixes harnesses and test conditions. On <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, notably, Poolside ran its own agent harness rather than the leaderboard's standard mini-swe-agent, a difference the company acknowledges makes scores less directly comparable. And the frontier remains clearly out of reach: closed models like <a href="https://openai.com/index/previewing-gpt-5-6-sol/">GPT-5.6 Sol</a>, at 88.8 on Terminal-Bench 2.1, and <a href="https://www.anthropic.com/claude/fable">Claude Fable 5</a>, at 88.0, along with the 2.8-trillion-parameter open-weight <a href="https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems">Kimi K3</a>, at 88.3, sit well above Laguna S 2.1.</p><p>The deeper structural question is whether Poolside's "<a href="https://poolside.ai/blog/introducing-the-model-factory">Model Factory</a>" — the internal platform the company credits for its rapid release cadence — can sustain this pace as models scale. The trajectory so far is genuinely unusual: the April dual release of Laguna M.1 and XS.2, the July 2 refresh of XS 2.1, and now S 2.1, which the company says outperforms April's flagship M.1 at roughly a third of its active size. Remarkably, S 2.1 used the exact same pre-training data as XS 2.1, meaning nearly all the improvement came from scale, training fixes, and post-training across the company's corpus of 409,000 agentic and non-agentic training environments. Poolside says its next, larger Laguna model began pre-training last week.</p><p>For technical decision makers, <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> is the most credible Western open-weight option to emerge in nearly a year for self-hosted agentic coding — with published evidence, a permissive license, broad ecosystem support, and an economics story built around hardware you can own. Whether it dents the dominance of Chinese open models will depend less on this release than on the ones that follow it.</p><p>Kant, for his part, has already told the world how he intends that story to end. Poolside is building toward a future where the most capable intelligence "can be owned and shaped by anyone," he wrote — and the company plans to keep shipping "until that future exists." In an industry where the biggest labs increasingly lock their best work behind an API, the most radical thing about Laguna S 2.1 may not be what it scores, but that anyone can download it and check.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Gemini 3.6 Flash model cuts AI agent token costs by up to 65% on long horizon engineering tasks —and 3.5 Pro is on the way]]></title>
<description><![CDATA[Google DeepMind today released three new proprietary AI models it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 p...]]></description>
<link>https://tsecurity.de/de/3684881/it-nachrichten/googles-gemini-36-flash-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684881/it-nachrichten/googles-gemini-36-flash-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</guid>
<pubDate>Tue, 21 Jul 2026 23:33:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google DeepMind<a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/?utm_source=x&amp;utm_medium=social&amp;utm_campaign=&amp;utm_content="> today released three new proprietary AI models</a> it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. </p><p>The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 per one million input tokens and $7.50 per one million output tokens through its application programming interface (API), while Gemini 3.5 Flash-Lite costs a staggeringly cheap $0.30/$2.50 per million tokens in/out. </p><p>Compare that to the $1.50/$9.00 per 1M tokens for Gemini 3.5 Flash, and the $2/$12 for Gemini 3.1 Pro Preview, and the savings are considerable. However, Google's prior generation Gemini 3.1 Flash-Lite still remains the search giant's "most cost-efficient" model at $0.25/$1.50 per 1M tokens. Yet, it remains 2X slower than the new, more expensive Gemini 3.5 Flash-Lite, giving those enterprises who value speed more "bang" for their buck. </p><h2><b>VB Frontier AI Model API Pricing Comparison Chart (Late July 2026 Shortlist)</b></h2><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.5 Flash-Lite</b></p></td><td><p><b>$0.30</b></p></td><td><p><b>$2.50</b></p></td><td><p><b>$2.80</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a><b></b></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$1.00</p></td><td><p>$6.00</p></td><td><p>$7.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.6 Flash</b></p></td><td><p><b>$1.50</b></p></td><td><p><b>$7.50</b></p></td><td><p><b>$9.00</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>No price was provided yet for the specialty Gemini 3.5 Flash Cyber model, which, as its name would imply, is designed for cybersecurity researchers and red teamers to patch bugs. </p><p>While the prices are among the middle-low end of all major AI models globally, the fact that Google designed them to use less tokens overall also should drive down costs for enterprises beyond what the sticker price shows (since you'll be paying for fewer total tokens at any rate). </p><p>Gemini 3.6 Flash and Gemini 3.5 Flash-Lite are available immediately through the Gemini API in Google AI Studio and Android Studio, as well as within the consumer Gemini application and Google Search. According to a <a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/">separate Google blog post</a>, Gemini 3.5 Flash Cyber will be available "exclusively available to governments and trusted partners via CodeMender soon" — <a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/">CodeMender</a> being Google's proprietary AI code bug-fixing agent released last year. </p><p>As with previous Gemini models, these are all proprietary and "closed source," thus, they can only be obtained through Google's official API and that of its partners, as opposed to an open-source license like MIT or Apache 2.0. </p><p>One conspicuous omission noted by developers on X and social media: where is the larger, more powerful, flagship Gemini 3.5 Pro model Google previously alluded would be released this summer? After all, Gemini 3.1 Pro, the prior flagship, <a href="https://venturebeat.com/technology/google-launches-gemini-3-1-pro-retaking-ai-crown-with-2x-reasoning">debuted back in February 2026</a>, and rivals OpenAI and Anthropic have since released several more generations of flagship updates far more powerful than Google's. </p><p>Google technical staffer Logan Kilpatrick <a href="https://x.com/OfficialLoganK/status/2079592006163349538">responded to one such inquiry on X, writing</a>: "Gemini 3.5 Pro is currently testing with partners and we plan to make it broadly available as soon as it’s ready." </p><p>Google's release signals that the immediate future of AI lies in agentic capabilities—systems that operate autonomously over extended periods. </p><p>If early large language models are akin to massive, fuel-hungry freight trains capable of hauling incredible loads at immense cost, the new Flash series represents a fleet of nimble, hyper-efficient hybrid delivery vans.</p><h2><b>Efficiency gains ranging from 17% to 65% reduced tokens for strong results on third-party benchmarks</b></h2><p>Under the hood, Gemini 3.6 Flash achieves significant efficiency gains. The model reduces output token usage by 17% compared to its predecessor, Gemini 3.5 Flash, according to the <a href="https://x.com/ArtificialAnlys/status/2079596244339707956">Artificial Analysis Index</a> maintained by the independent third-party AI benchmarking group of the same name. </p><p>In specific long-horizon software engineering benchmarks like <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, which measures how well agents complete multi-step engineering tasks from scratch, the token savings reach up to 65%. </p><p>This reduction means the model requires fewer reasoning steps and tool calls to complete the exact same multi-step workflow. Think of token efficiency like fuel economy in a vehicle. </p><p>When an AI model takes a convoluted path to solve a problem, it burns through more computational fuel, driving up the final cost for the developer. By streamlining its internal logic, Gemini 3.6 Flash arrives at the correct answer faster and cheaper.</p><p>While Google's materials did not specify the exact architectural or algorithmic changes used to achieve this token efficiency, they noted that the model "takes fewer reasoning steps and tool calls to accomplish multi-step workflows" and exhibits reduced "verbosity."</p><p>The official model cards released by Google reveal that both <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-6-Flash-Model-Card.pdf">Gemini 3.6 Flash</a> and <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-5-Flash-Lite-Model-Card.pdf">Gemini 3.5 Flash-Lite</a> feature a 1-million-token input context window alongside a max output limit of 64,000 tokens, with both models sharing a knowledge cutoff date of March 2026.</p><h2><b>Respectable benchmark performance at low cost</b></h2><p>The technological improvements extend to concrete capabilities. Gemini 3.6 Flash scores 49% on the DeepSWE benchmark, a notable increase from the 37% achieved by version 3.5. </p><p>It also pushes machine learning engineering performance higher, scoring 63.9% on MLE-Bench compared to 49.7% previously. Furthermore, Google integrates computer use as a built-in client-side tool via the Gemini API and Gemini Enterprise, reflecting an OSWorld-Verified score of 83.0%, up from 78.4%. </p><p>The model also tackles knowledge work with greater proficiency, outperforming its predecessor on benchmarks like GDPval-AA v2 by moving from a score of 1349 to 1421.</p><p>To ensure safety amidst these capability upgrades, Google deploys enhanced Frontier Safety safeguards. These protections harden the model against jailbreaks and mitigate risks in Chemical, Biological, Radiological, and Nuclear domains, as well as cyber offense misuses. </p><p>The engineering team trains the model to minimize refusals for beneficial uses, striking a necessary balance between strict security and practical utility.</p><h2>M<b>odels for low-cost coding, agentic, and cybersecurity use cases — respectively</b></h2><p>Google divided its new offerings into three distinct products tailored for different operational needs. </p><p>Gemini 3.6 Flash serves as the heavy-duty workhorse of the trio. It handles complex coding, intricate knowledge work, and multimodal processing with improved precision. Enterprise customers utilize it for demanding tasks such as complex document parsing, intricate chart and data analysis, and long-form report drafting. </p><p>The model executes complex code migrations using multi-agent orchestration frameworks with lower latency and higher quality than earlier iterations. Furthermore, 3.6 Flash aids in developing photographic texture extractors for 3D workflows using canvas interfaces.</p><p>Gemini 3.5 Flash-Lite targets environments where high throughput and absolute minimal latency are non-negotiable. Google designates it as the fastest model in the 3.5 series. </p><p>As measured by Artificial Analysis, the model processes 350 output tokens per second, making it highly effective for agentic search and massive document processing workloads. <a href="https://artificialanalysis.ai/articles/gemini-3-6-flash-3-5-flash-lite-halving-time">Artificial Analysis notes</a> this is about twice as fast as prior generation model Gemini 3.1 Flash-Lite.</p><p>Developers can configure 3.5 Flash-Lite to prioritize low-latency execution for high-volume tasks using minimal thinking levels, or engage higher thinking levels to process complex multi-step subagent workloads. </p><p>Despite its lite designation, it outperforms the standard Gemini 3 Flash on several key agentic and coding evaluations, including SWE-Bench Pro, where it scores 54.2% compared to 49.6%, and OSWorld-Verified, scoring 74.0% versus 65.1%. </p><p>The model extracts product features from massive datasets, generates interactive web design concepts, and scales receipt translation seamlessly.</p><p>The third product, Gemini 3.5 Flash Cyber, represents a highly specialized deployment. Google fine-tuned this model specifically to find and fix cybersecurity vulnerabilities. It integrates directly with Google's CodeMender agent. </p><p>In practice, multiple 3.5 Flash Cyber agents work concurrently to produce a single, comprehensive vulnerability report, achieving competitive performance at the frontier on the CyberGym benchmark, even getting within range of Anthropic's much-hyped Mythos model.</p><p>Google did not specify an exact numerical cost for 3.5 Flash Cyber, stating only that it is fine-tuned "at a lower price per token than larger models.</p><h2><b>Commercial licensing only</b></h2><p>The licensing framework for the new Gemini models carries profound implications for developers and enterprise users. Google deploys Gemini 3.6 Flash and 3.5 Flash-Lite under a commercial, proprietary API model. Unlike open-source software governed by licenses such as the MIT License or the GNU General Public License, developers do not gain access to the underlying model weights, training data, or source code.</p><p>An MIT or GPL license grants users the freedom to download the codebase, modify the internal architecture, self-host the deployment, and distribute the software infrastructure independently. In contrast, Google's API approach means developers essentially rent access to the intelligence on a strict metered basis. Every prompt and generated response travels through Google's managed servers, incurring a cost based on the strict pricing structure of $1.50 per million input tokens for 3.6 Flash. </p><p>This commercial tethering restricts deployment flexibility. Enterprises cannot air-gap the models entirely on their own local secure hardware without establishing specialized, high-tier enterprise agreements with Google Cloud. Developers remain bound by Google's acceptable use policies, arbitrary rate limits, and network requirements, creating a permanent dependency on Google's infrastructure uptime and terms of service.</p><p>The licensing for Gemini 3.5 Flash Cyber proves even more restrictive. Acknowledging the dual-use nature of cybersecurity AI—which attackers can weaponize just as easily as defenders can use it to patch systems—Google is for now making the model only available behind a limited-access pilot program, similar to the trend kicked off by Anthropic's Mythos model with its <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing program</a>, and continued by <a href="https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov">OpenAI with its staggered rollout for GPT-5.6</a>. </p><p>In this case, Google is making 3.5 Flash Cyber exclusively available to governments and trusted partners. This strict gatekeeping prevents open access, prioritizing systemic security over widespread developer innovation.</p><h2><b>Looking ahead</b></h2><p>Google DeepMind continues to iterate rapidly, but the gap in its product line remains apparent. While the Flash series excels in speed and economy, the industry eagerly awaits the deployment of Gemini 3.5 Pro to gauge Google's absolute frontier capabilities.</p><p>Simultaneously, the company confirms that pre-training for Gemini 4 has already commenced. </p><p>Until the next major flagship release materializes, developers must optimize their systems using the highly efficient, yet purposefully constrained, Flash architecture.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Gemini Flash 5.6 model cuts AI agent token costs by up to 65% on long horizon engineering tasks —and 3.5 Pro is on the way]]></title>
<description><![CDATA[Google DeepMind today released three new proprietary AI models it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 p...]]></description>
<link>https://tsecurity.de/de/3684788/it-nachrichten/googles-gemini-flash-56-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684788/it-nachrichten/googles-gemini-flash-56-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</guid>
<pubDate>Tue, 21 Jul 2026 22:56:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google DeepMind<a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/?utm_source=x&amp;utm_medium=social&amp;utm_campaign=&amp;utm_content="> today released three new proprietary AI models</a> it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. </p><p>The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 per one million input tokens and $7.50 per one million output tokens through its application programming interface (API), while Gemini 3.5 Flash-Lite costs a staggeringly cheap $0.30/$2.50 per million tokens in/out. </p><p>Compare that to the $1.50/$9.00 per 1M tokens for Gemini 3.5 Flash, and the $2/$12 for Gemini 3.1 Pro Preview, and the savings are considerable. However, Google's prior generation Gemini 3.1 Flash-Lite still remains the search giant's "most cost-efficient" model at $0.25/$1.50 per 1M tokens. Yet, it remains 2X slower than the new, more expensive Gemini 3.5 Flash-Lite, giving those enterprises who value speed more "bang" for their buck. </p><h2><b>VB Frontier AI Model API Pricing Comparison Chart (Late July 2026 Shortlist)</b></h2><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.5 Flash-Lite</b></p></td><td><p><b>$0.30</b></p></td><td><p><b>$2.50</b></p></td><td><p><b>$2.80</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a><b></b></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$1.00</p></td><td><p>$6.00</p></td><td><p>$7.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.6 Flash</b></p></td><td><p><b>$1.50</b></p></td><td><p><b>$7.50</b></p></td><td><p><b>$9.00</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>No price was provided yet for the specialty Gemini 3.5 Flash Cyber model, which, as its name would imply, is designed for cybersecurity researchers and red teamers to patch bugs. </p><p>While the prices are among the middle-low end of all major AI models globally, the fact that Google designed them to use less tokens overall also should drive down costs for enterprises beyond what the sticker price shows (since you'll be paying for fewer total tokens at any rate). </p><p>Gemini 3.6 Flash and Gemini 3.5 Flash-Lite are available immediately through the Gemini API in Google AI Studio and Android Studio, as well as within the consumer Gemini application and Google Search. According to a <a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/">separate Google blog post</a>, Gemini 3.5 Flash Cyber will be available "exclusively available to governments and trusted partners via CodeMender soon" — <a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/">CodeMender</a> being Google's proprietary AI code bug-fixing agent released last year. </p><p>As with previous Gemini models, these are all proprietary and "closed source," thus, they can only be obtained through Google's official API and that of its partners, as opposed to an open-source license like MIT or Apache 2.0. </p><p>One conspicuous omission noted by developers on X and social media: where is the larger, more powerful, flagship Gemini 3.5 Pro model Google previously alluded would be released this summer? After all, Gemini 3.1 Pro, the prior flagship, <a href="https://venturebeat.com/technology/google-launches-gemini-3-1-pro-retaking-ai-crown-with-2x-reasoning">debuted back in February 2026</a>, and rivals OpenAI and Anthropic have since released several more generations of flagship updates far more powerful than Google's. </p><p>Google technical staffer Logan Kilpatrick <a href="https://x.com/OfficialLoganK/status/2079592006163349538">responded to one such inquiry on X, writing</a>: "Gemini 3.5 Pro is currently testing with partners and we plan to make it broadly available as soon as it’s ready." </p><p>Google's release signals that the immediate future of AI lies in agentic capabilities—systems that operate autonomously over extended periods. </p><p>If early large language models are akin to massive, fuel-hungry freight trains capable of hauling incredible loads at immense cost, the new Flash series represents a fleet of nimble, hyper-efficient hybrid delivery vans.</p><h2><b>Efficiency gains ranging from 17% to 65% reduced tokens for strong results on third-party benchmarks</b></h2><p>Under the hood, Gemini 3.6 Flash achieves significant efficiency gains. The model reduces output token usage by 17% compared to its predecessor, Gemini 3.5 Flash, according to the <a href="https://x.com/ArtificialAnlys/status/2079596244339707956">Artificial Analysis Index</a> maintained by the independent third-party AI benchmarking group of the same name. </p><p>In specific long-horizon software engineering benchmarks like <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, which measures how well agents complete multi-step engineering tasks from scratch, the token savings reach up to 65%. </p><p>This reduction means the model requires fewer reasoning steps and tool calls to complete the exact same multi-step workflow. Think of token efficiency like fuel economy in a vehicle. </p><p>When an AI model takes a convoluted path to solve a problem, it burns through more computational fuel, driving up the final cost for the developer. By streamlining its internal logic, Gemini 3.6 Flash arrives at the correct answer faster and cheaper.</p><p>While Google's materials did not specify the exact architectural or algorithmic changes used to achieve this token efficiency, they noted that the model "takes fewer reasoning steps and tool calls to accomplish multi-step workflows" and exhibits reduced "verbosity."</p><p>The official model cards released by Google reveal that both <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-6-Flash-Model-Card.pdf">Gemini 3.6 Flash</a> and <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-5-Flash-Lite-Model-Card.pdf">Gemini 3.5 Flash-Lite</a> feature a 1-million-token input context window alongside a max output limit of 64,000 tokens, with both models sharing a knowledge cutoff date of March 2026.</p><h2><b>Respectable benchmark performance at low cost</b></h2><p>The technological improvements extend to concrete capabilities. Gemini 3.6 Flash scores 49% on the DeepSWE benchmark, a notable increase from the 37% achieved by version 3.5. </p><p>It also pushes machine learning engineering performance higher, scoring 63.9% on MLE-Bench compared to 49.7% previously. Furthermore, Google integrates computer use as a built-in client-side tool via the Gemini API and Gemini Enterprise, reflecting an OSWorld-Verified score of 83.0%, up from 78.4%. </p><p>The model also tackles knowledge work with greater proficiency, outperforming its predecessor on benchmarks like GDPval-AA v2 by moving from a score of 1349 to 1421.</p><p>To ensure safety amidst these capability upgrades, Google deploys enhanced Frontier Safety safeguards. These protections harden the model against jailbreaks and mitigate risks in Chemical, Biological, Radiological, and Nuclear domains, as well as cyber offense misuses. </p><p>The engineering team trains the model to minimize refusals for beneficial uses, striking a necessary balance between strict security and practical utility.</p><h2>M<b>odels for low-cost coding, agentic, and cybersecurity use cases — respectively</b></h2><p>Google divided its new offerings into three distinct products tailored for different operational needs. </p><p>Gemini 3.6 Flash serves as the heavy-duty workhorse of the trio. It handles complex coding, intricate knowledge work, and multimodal processing with improved precision. Enterprise customers utilize it for demanding tasks such as complex document parsing, intricate chart and data analysis, and long-form report drafting. The model executes complex code migrations using multi-agent orchestration frameworks with lower latency and higher quality than earlier iterations. Furthermore, 3.6 Flash aids in developing photographic texture extractors for 3D workflows using canvas interfaces.</p><p>Gemini 3.5 Flash-Lite targets environments where high throughput and absolute minimal latency are non-negotiable. Google designates it as the fastest model in the 3.5 series. </p><p>As measured by Artificial Analysis, the model processes 350 output tokens per second, making it highly effective for agentic search and massive document processing workloads. <a href="https://artificialanalysis.ai/articles/gemini-3-6-flash-3-5-flash-lite-halving-time">Artificial Analysis notes</a> this is about twice as fast as prior generation model Gemini 3.1 Flash-Lite.</p><p>Developers can configure 3.5 Flash-Lite to prioritize low-latency execution for high-volume tasks using minimal thinking levels, or engage higher thinking levels to process complex multi-step subagent workloads. </p><p>Despite its lite designation, it outperforms the standard Gemini 3 Flash on several key agentic and coding evaluations, including SWE-Bench Pro, where it scores 54.2% compared to 49.6%, and OSWorld-Verified, scoring 74.0% versus 65.1%. </p><p>The model extracts product features from massive datasets, generates interactive web design concepts, and scales receipt translation seamlessly.</p><p>The third product, Gemini 3.5 Flash Cyber, represents a highly specialized deployment. Google fine-tuned this model specifically to find and fix cybersecurity vulnerabilities. It integrates directly with Google's CodeMender agent. </p><p>In practice, multiple 3.5 Flash Cyber agents work concurrently to produce a single, comprehensive vulnerability report, achieving competitive performance at the frontier on the CyberGym benchmark. </p><p>Google did not specify an exact numerical cost for 3.5 Flash Cyber, stating only that it is fine-tuned "at a lower price per token than larger models.</p><h2><b>Commercial licensing only</b></h2><p>The licensing framework for the new Gemini models carries profound implications for developers and enterprise users. Google deploys Gemini 3.6 Flash and 3.5 Flash-Lite under a commercial, proprietary API model. Unlike open-source software governed by licenses such as the MIT License or the GNU General Public License, developers do not gain access to the underlying model weights, training data, or source code.</p><p>An MIT or GPL license grants users the freedom to download the codebase, modify the internal architecture, self-host the deployment, and distribute the software infrastructure independently. In contrast, Google's API approach means developers essentially rent access to the intelligence on a strict metered basis. Every prompt and generated response travels through Google's managed servers, incurring a cost based on the strict pricing structure of $1.50 per million input tokens for 3.6 Flash. </p><p>This commercial tethering restricts deployment flexibility. Enterprises cannot air-gap the models entirely on their own local secure hardware without establishing specialized, high-tier enterprise agreements with Google Cloud. Developers remain bound by Google's acceptable use policies, arbitrary rate limits, and network requirements, creating a permanent dependency on Google's infrastructure uptime and terms of service.</p><p>The licensing for Gemini 3.5 Flash Cyber proves even more restrictive. Acknowledging the dual-use nature of cybersecurity AI—which attackers can weaponize just as easily as defenders can use it to patch systems—Google is for now making the model only available behind a limited-access pilot program, similar to the trend kicked off by Anthropic's Mythos model with its Project Glasswing program, and continued by OpenAI with its staggered rollout for GPT-5.6. </p><p>In this case, Google is making 3.5 Flash Cyber exclusively available to governments and trusted partners. This strict gatekeeping prevents open access, prioritizing systemic security over widespread developer innovation.</p><h2><b>Looking ahead</b></h2><p>Google DeepMind continues to iterate rapidly, but the gap in its product line remains apparent. While the Flash series excels in speed and economy, </p><p>the industry eagerly awaits the deployment of Gemini 3.5 Pro to gauge Google's absolute frontier capabilities.</p><p>Simultaneously, the company confirms that pre-training for Gemini 4 has already commenced. </p><p>Until the next major flagship release materializes, developers must optimize their systems using the highly efficient, yet purposefully constrained, Flash architecture.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI may drive union-resistant tech workers to the bargaining table]]></title>
<description><![CDATA[Tech workers are increasingly unionizing, trading Silicon Valley’s myth of exceptionalism for collective bargaining to contest the corporate deployment of artificial intelligenceFor decades, the technology industry was a fortress that labor unions couldn’t breach. Tech workers already had cushy c...]]></description>
<link>https://tsecurity.de/de/3683463/ai-nachrichten/how-ai-may-drive-union-resistant-tech-workers-to-the-bargaining-table/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683463/ai-nachrichten/how-ai-may-drive-union-resistant-tech-workers-to-the-bargaining-table/</guid>
<pubDate>Tue, 21 Jul 2026 13:03:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tech workers are increasingly unionizing, trading Silicon Valley’s myth of exceptionalism for collective bargaining to contest the corporate deployment of artificial intelligence</p><p>For decades, the technology industry was a fortress that labor unions couldn’t breach. Tech workers already had cushy compensation packages, dream benefits like unlimited vacation and free lunch, and a flat corporate hierarchy that made engineers feel as powerful as their bosses, all of whom dressed down in sneakers and hoodies. So why unionize?</p><p>Now, that fortress is cracking from the inside. Unions have become increasingly popular for tech employees. After <a href="https://www.theguardian.com/technology/2026/feb/27/block-ai-layoffs-jack-dorsey">months of mass layoffs tied to artificial intelligence</a> and mounting anxieties about how it’s being deployed, some tech workers say they’ve been saddled with higher workloads while facing the threat of job loss caused by the very products they’re building. Workers from Google DeepMind and Meta in the UK are also objecting to how their companies’ AI products are being used, such as for <a href="https://www.theguardian.com/us-news/2026/may/04/google-deepmind-uk-workers-union">military purposes</a> or to <a href="https://www.theguardian.com/technology/2026/may/19/meta-jobs-ai-transfers">monitor employee productivity</a>. Those same workers are now attempting to unionize.</p> <a href="https://www.theguardian.com/technology/2026/jul/21/ai-tech-workers-unionize">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Expanded Radio Art (emf2026)]]></title>
<description><![CDATA[Dr. Magz Hall is a sound artist and radio art pioneer who treats the airwaves as a canvas. In her talk, she explains how she moves radio out of the studio and into the real world—turning everyday objects like trees, books, and shoes into miniature broadcasting stations.
What the Talk Covers:
Givi...]]></description>
<link>https://tsecurity.de/de/3681660/it-security-video/expanded-radio-art-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681660/it-security-video/expanded-radio-art-emf2026/</guid>
<pubDate>Mon, 20 Jul 2026 18:53:15 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dr. Magz Hall is a sound artist and radio art pioneer who treats the airwaves as a canvas. In her talk, she explains how she moves radio out of the studio and into the real world—turning everyday objects like trees, books, and shoes into miniature broadcasting stations.
What the Talk Covers:
Giving Nature a Voice: Magz shares how she uses &quot;Tree Radio&quot; to turn a living oak tree into a radio station. By plugging sensors into the bark, she broadcasts the tree’s internal biological sounds directly to people's FM radios.
Art as Activism: She discusses her &quot;Radio Air Garden,&quot; where she builds beautiful copper sculptures that help plants grow while simultaneously broadcasting sounds that highlight local air pollution.
The &quot;Secret&quot; Airwaves: She explores the &quot;hidden world&quot; of wireless signals all around us, showing how she uses old radio tech to create modern immersive experiences.
Hands-on Hacking: Magz explains her &quot;DIY&quot; approach—encouraging everyone to reclaim technology by building their own simple transmitters to share their own stories.
The takeaway: Radio isn't just for news and music; it’s a magical, invisible tool we can use to connect with nature and our local communities in surprising new ways.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/126-expanded-radio-art]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15768 | Google Chrome up to 150.0.7871.124 HTML-in-Canvas cross-domain policy (Nessus ID 327759)]]></title>
<description><![CDATA[A vulnerability was found in Google Chrome up to 150.0.7871.124. It has been declared as problematic. This impacts an unknown function of the component HTML-in-Canvas. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is cataloged as CVE-2026-1...]]></description>
<link>https://tsecurity.de/de/3679469/sicherheitsluecken/cve-2026-15768-google-chrome-up-to-15007871124-html-in-canvas-cross-domain-policy-nessus-id-327759/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679469/sicherheitsluecken/cve-2026-15768-google-chrome-up-to-15007871124-html-in-canvas-cross-domain-policy-nessus-id-327759/</guid>
<pubDate>Sun, 19 Jul 2026 14:36:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/google:chrome">Google Chrome up to 150.0.7871.124</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>HTML-in-Canvas</em>. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-15768">CVE-2026-15768</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 150.0.7871.124/.125 for Windows and Mac and 150.0.7871.124 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept rest...]]></description>
<link>https://tsecurity.de/de/3678854/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678854/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 150.0.7871.124/.125 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.124 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.115..150.0.7871.125?pretty=fuller&amp;n=10000">Log</a></span></p><p dir="ltr"><span>Security Fixes and Rewards</span></p><p dir="ltr"><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:2-M150"><span>15</span></a><span> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/517100492"><span>517100492</span></a><span>]</span><span> Critical </span><span>CVE-2026-15764: Use after free in Ozone. </span><span>Reported by Google on 2026-05-27</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/518007484"><span>518007484</span></a><span>]</span><span> Critical </span><span>CVE-2026-15765: Use after free in Ozone. </span><span>Reported by Google on 2026-05-29</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/514010477"><span>514010477</span></a><span>]</span><span> High </span><span>CVE-2026-15766: Uninitialized Use in Skia. </span><span>Reported by Google on 2026-05-17</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/514748734"><span>514748734</span></a><span>]</span><span> High </span><span>CVE-2026-15767: Heap buffer overflow in libyuv. </span><span>Reported by Google on 2026-05-19</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/517931625"><span>517931625</span></a><span>]</span><span> High </span><span>CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas. </span><span>Reported by Google on 2026-05-29</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/519731111"><span>519731111</span></a><span>]</span><span> High </span><span>CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming. </span><span>Reported by Google on 2026-06-03</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/524792614"><span>524792614</span></a><span>]</span><span> High </span><span>CVE-2026-15770: Uninitialized Use in V8. </span><span>Reported by Google on 2026-06-17</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/525177160"><span>525177160</span></a><span>]</span><span> High </span><span>CVE-2026-15771: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-06-18</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/525317502"><span>525317502</span></a><span>]</span><span> High </span><span>CVE-2026-15772: Use after free in GPU. </span><span>Reported by Google on 2026-06-18</span></p><p dir="ltr"><span>[TBD][</span><a href="https://issues.chromium.org/issues/527676561"><span>527676561</span></a><span>]</span><span> High </span><span>CVE-2026-15773: Use after free in Core. </span><span>Reported by xinchaotian of Microsoft on 2026-06-25</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/530646115"><span>530646115</span></a><span>]</span><span> High </span><span>CVE-2026-15774: Use after free in Skia. </span><span>Reported by Google on 2026-07-03</span></p><p dir="ltr"><span>[TBD][</span><a href="https://issues.chromium.org/issues/531319201"><span>531319201</span></a><span>]</span><span> High </span><span>CVE-2026-15775: Insufficient policy enforcement in V8. </span><span>Reported by wang1r923096443@gmail.com on 2026-07-05</span></p><p dir="ltr"><span>[TBD][</span><a href="https://issues.chromium.org/issues/532595489"><span>532595489</span></a><span>]</span><span> High </span><span>CVE-2026-15776: Type Confusion in V8. </span><span>Reported by Salvatore Gulizia (nickname: Serotav) on 2026-07-08</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/532929679"><span>532929679</span></a><span>]</span><span> High </span><span>CVE-2026-15777: Use after free in UI. </span><span>Reported by Google on 2026-07-09</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/513795122"><span>513795122</span></a><span>]</span><span> Medium </span><span>CVE-2026-15778: Insufficient validation of untrusted input in Navigation. </span><span>Reported by Google on 2026-05-16</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><div><span><br></span></div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[The ChromeOS Stable channel is being updated to OS version 16700.46.0 (Browser version 150.0.7871.150) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS B...]]></description>
<link>https://tsecurity.de/de/3678844/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678844/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span color="rgba(0, 0, 0, 0.87)">The ChromeOS Stable channel is being updated to OS version </span><span color="rgba(0, 0, 0, 0.87)">16700.46.0</span><span color="rgba(0, 0, 0, 0.87)"> (Browser version </span><span color="rgba(0, 0, 0, 0.87)">150.0.7871.150</span><span color="rgba(0, 0, 0, 0.87)">) for most ChromeOS devices.</span></p><div><span><span>If you find new issues, please let us know one of the following ways:</span></span></div><ol><li><span><span><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></span></span></li><li aria-level="1"><p role="presentation"><span><span>Visit our ChromeOS communities</span></span></p></li><ol><li aria-level="2"><p role="presentation"><span><span>General: </span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span>Chromebook Help Community</span></a></span></p></li><li aria-level="2"><p role="presentation"><span><span>Beta Specific: </span><a href="https://support.google.com/chromeos-beta/community"><span>ChromeOS Beta Help Community</span></a></span></p></li></ol><li aria-level="1"><p role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span><span><span>Report an issue or send feedback on Chrome</span></span></span></a></p></li><li aria-level="1"><p role="presentation"><span><span>Interested in switching channels? </span><a href="https://support.google.com/chromebook/answer/1086915"><span>Find out how.</span></a></span></p></li></ol><div><span><h4 dir="ltr"><span>ChromeOS Vulnerability Rewards Program Reported Bug Fixes:</span></h4><br><p dir="ltr"><span>N/A</span></p><h4 dir="ltr"><span>Other 3rd Party Security Fixes Included:</span></h4><br><p dir="ltr"><span>High</span><span> Fixes  CVE-2026-46242 (Bad epoll) - Linux Local Privilege Escalation </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-49746 [PSP-528][PP-173890][KMD] Dimension Mismatch and Integer Truncation in `PMRDevPhysAddrOSMem` </span></p><p dir="ltr"><span>High</span><span> Fixes   Potential UAF via Profile/Service Desync in shill ConfigureService </span></p><p dir="ltr"><span>Medium</span><span> Fixes   CWE-862: shill Manager.NotifyDHCPEvent reachable from chronos allows DHCP spoofing </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-45204 [PSP-406][PowerVR] Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory </span></p><p dir="ltr"><span>High</span><span> Fixes   Stack OOB Read to Heap OOB Write in msm_ccmd_ioctl_simple via Guest-Controlled _IOC_SIZE </span></p><p dir="ltr"><span>High</span><span> Fixes   [LPE] Patchpanel ConnectNamespace PID Gate Bypass Allows CAP_NET_ADMIN Root Netns Operations </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-49745 [PSP-598][PP-174017] Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 </span></p><p dir="ltr"><span>High</span><span> Fixes   Heap OOB write in ANGLE D3D11 vertex streaming via `WEBGL_draw_instanced_base_vertex_base_instance` </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS LE-Audio via group removal race condition </span></p><p dir="ltr"><span>High</span><span> Fixes   Cross-client microphone audio exfiltration via missing CRAS stream ownership check </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS server via dangling active_fm-&gt;lea pointer </span></p><p dir="ltr"><span>Critical</span><span> Fixes   [LPE] Arbitrary file read as root in printscanmgr via FD leak and path traversal </span></p><p dir="ltr"><span>High</span><span> Fixes   Privilege escalation in CRAS via DlcStateChanged signal spoofing </span></p><p dir="ltr"><span>High</span><span> Fixes   missing untrusted input validation in chromeos-boot-alert leads to root pango-view processing attacker file </span></p><p dir="ltr"><span>High</span><span> Fixes   UAF and Control Flow Hijack in CRAS A2DP Profile Switching </span></p><p dir="ltr"><span>Medium</span><span> Fixes   Heap OOB Read in Floss A2DP via Ring Buffer Misalignment </span></p><p dir="ltr"><span>High</span><span> Fixes   Heap OOB write in CRAS mSBC SCO handling via dynamic packet size adjustment </span></p><p dir="ltr"><span>High</span><span> Fixes   UAF in CRAS server via dangling default_rmod-&gt;odev pointer after stream disconnect </span></p><p dir="ltr"><span>High</span><span> Fixes   Crosvm xHCI guest-to-host OOB write via unchecked DMA buffer size </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS HFP SLC due to leaked timer in AT+CMER handler </span></p><p dir="ltr"><span>High</span><span> Fixes   CRAS OOB write via integer overflow in cras_shm_buff_for_idx </span></p><p dir="ltr"><span>High</span><span> Fixes   OOB write in CRAS via unsigned underflow in cras_audio_area_copy </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS echo_ref_requests via concurrent list mutation </span></p><p dir="ltr"><span>High</span><span> Fixes   Unauthenticated CRAS Loopback Hijacking allows Cross-Client Audio Capture </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS loopback traversal due to data race </span></p><p dir="ltr"><span>High</span><span> Fixes   Out-of-bounds write in CRAS server via unvalidated client_shm_size </span></p><p dir="ltr"><span>Critical</span><span> Fixes   [LPE] Arbitrary `tc` Command Injection in `shill` Throttler via `TetheringConfig` </span></p><p dir="ltr"><span>High</span><span> Fixes   Potential Use-After-Free in vm_concierge ArcVm via base::Unretained in async D-Bus callback </span></p><p dir="ltr"><span>Medium</span><span> Fixes   TOCTOU in permission_broker allows chronos to open arbitrary device nodes </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-490][PowerVR] Read UAF in GrowMipLevelArray() due to incorrect texture array iteration during image copy </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-495][PowerVR] OOB read in CreateTextureMemory() due to memory mismanagement after texture format change </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-516][PowerVR] Secondary mapping of the freelist PMR allows reading Freelist contents via GPU shader </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-443][KMD][PowerVR] Read UAF of sync checkpoint in pvr_sync_finalise_fence() after update fence file descriptor is prematurely closed </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-34196 [PSP-372][PowerVR] UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-7639 [PSP-452][KMD] Page UAF read in `PMMETA_PROTECT` heap memory </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-415] [PROJ-ZERO] PowerVR: [crash-only bug] kernel crash due to faulting userspace memory access without fault handling </span></p><p dir="ltr"><span>Android Security fixes can be found </span><a href="https://source.android.com/docs/security/bulletin/2026-07-01"><span>here</span></a></p><br><h4 dir="ltr"><span>Chrome Browser Security Fixes:</span></h4><br><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524395469"><span>[524395469</span></a><span>] </span><span>High</span><span> CVE-2026-13855 Use after free in Ozone  on  2026-06-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524290062"><span>[524290062</span></a><span>] </span><span>Medium</span><span> CVE-2026-14432 Use after free in V8  on  2026-06-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523884658"><span>[523884658</span></a><span>] </span><span>High</span><span> CVE-2026-14431 Type Confusion in V8 Reported by [OpenAI Codex Security (amyb)] on  2026-06-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523690961"><span>[523690961</span></a><span>] </span><span>High</span><span> CVE-2026-13854 Use after free in Ozone  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523224019"><span>[523224019</span></a><span>] </span><span>High</span><span> CVE-2026-13853 Use after free in Journeys  on  2026-06-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/520571816"><span>[520571816</span></a><span>] </span><span>High</span><span> CVE-2026-14429 Insufficient validation of untrusted input in Skia  on  2026-06-05 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/520113415"><span>[520113415</span></a><span>] </span><span>Critical</span><span> CVE-2026-14427 Heap buffer overflow in Skia  on  2026-06-04 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518247789"><span>[518247789</span></a><span>] </span><span>Low</span><span> CVE-2026-14156 Policy bypass in StorageAccessAPI  on  2026-05-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518246925"><span>[518246925</span></a><span>] </span><span>Low</span><span> CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI  on  2026-05-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518245882"><span>[518245882</span></a><span>] </span><span>Medium</span><span> CVE-2026-14024 Use after free in Ozone  on  2026-05-30 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/517981277"><span>[517981277</span></a><span>] </span><span>High</span><span> CVE-2026-14426 Use after free in V8 Reported by [] on  2026-05-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518063436"><span>[518063436</span></a><span>] </span><span>Medium</span><span> CVE-2026-14023 Insufficient validation of untrusted input in SanitizerAPI  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518007821"><span>[518007821</span></a><span>] </span><span>Critical</span><span> CVE-2026-13786 Use after free in Ozone  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517935753"><span>[517935753</span></a><span>] </span><span>High</span><span> CVE-2026-14425 Use after free in ANGLE  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517791835"><span>[517791835</span></a><span>] </span><span>Medium</span><span> CVE-2026-14022 Insufficient validation of untrusted input in Network  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517741170"><span>[517741170</span></a><span>] </span><span>Low</span><span> CVE-2026-14154 Inappropriate implementation in DevTools  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517731924"><span>[517731924</span></a><span>] </span><span>Medium</span><span> CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517684077"><span>[517684077</span></a><span>] </span><span>Low</span><span> CVE-2026-14153 Inappropriate implementation in Glic  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517598518"><span>[517598518</span></a><span>] </span><span>Medium</span><span> CVE-2026-14020 Insufficient validation of untrusted input in WebXR  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517534944"><span>[517534944</span></a><span>] </span><span>Low</span><span> CVE-2026-14152 Out of bounds write in ANGLE  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517522769"><span>[517522769</span></a><span>] </span><span>High</span><span> CVE-2026-14423 Type Confusion in Tint  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517455455"><span>[517455455</span></a><span>] </span><span>Medium</span><span> CVE-2026-14019 Inappropriate implementation in Passwords on IP-literal pages  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517381770"><span>[517381770</span></a><span>] </span><span>Low</span><span> CVE-2026-14151 Inappropriate implementation in AI  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517376041"><span>[517376041</span></a><span>] </span><span>Low</span><span> CVE-2026-14150 Insufficient validation of untrusted input in Speech  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517345069"><span>[517345069</span></a><span>] </span><span>High</span><span> CVE-2026-13848 Use after free in Forms  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517241992"><span>[517241992</span></a><span>] </span><span>Medium</span><span> CVE-2026-14017 Inappropriate implementation in Navigation  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517234388"><span>[517234388</span></a><span>] </span><span>Medium</span><span> CVE-2026-14016 Insufficient policy enforcement in SVG  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517155893"><span>[517155893</span></a><span>] </span><span>Medium</span><span> CVE-2026-14014 Inappropriate implementation in Paint  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517114175"><span>[517114175</span></a><span>] </span><span>Medium</span><span> CVE-2026-14013 Inappropriate implementation in SVG  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517110749"><span>[517110749</span></a><span>] </span><span>Medium</span><span> CVE-2026-14012 Side-channel information leakage in CSS  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517033235"><span>[517033235</span></a><span>] </span><span>Medium</span><span> CVE-2026-14421 Uninitialized Use in Dawn on ChromeOS-ARM due to disabled Mali multi-resolve workaround  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517031505"><span>[517031505</span></a><span>] </span><span>Critical</span><span> CVE-2026-14420 Out of bounds read and write in Dawn  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516981393"><span>[516981393</span></a><span>] </span><span>Critical</span><span> CVE-2026-14419 Use after free in Skia on Allocation Failure  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516962715"><span>[516962715</span></a><span>] </span><span>Critical</span><span> CVE-2026-13784 Use after free in Views  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516962178"><span>[516962178</span></a><span>] </span><span>Critical</span><span> CVE-2026-13783 Use after free in Views  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516944556"><span>[516944556</span></a><span>] </span><span>Medium</span><span> CVE-2026-14011 Out of bounds read in SurfaceCapture  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516936863"><span>[516936863</span></a><span>] </span><span>High</span><span> CVE-2026-13845 Use after free in DOM  on  2026-05-26 </span></p><p dir="ltr"><span>[$3000.0] </span><a href="https://issuetracker.google.com/516836297"><span>[516836297</span></a><span>] </span><span>High</span><span> CVE-2026-13842 Incorrect security UI in Chrome for iOS Reported by [] on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516865345"><span>[516865345</span></a><span>] </span><span>High</span><span> CVE-2026-14418 Uninitialized Use in ANGLE  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516819850"><span>[516819850</span></a><span>] </span><span>Medium</span><span> CVE-2026-14009 Insufficient data validation in Passwords  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516781007"><span>[516781007</span></a><span>] </span><span>Medium</span><span> CVE-2026-14008 Uninitialized Use in WebXR  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516683433"><span>[516683433</span></a><span>] </span><span>Critical</span><span> CVE-2026-13782 Use after free in Browser  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516649133"><span>[516649133</span></a><span>] </span><span>Critical</span><span> CVE-2026-14417 Use after free in Dawn  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516457532"><span>[516457532</span></a><span>] </span><span>Critical</span><span> CVE-2026-13781 Insufficient validation of untrusted input in Skia  on  2026-05-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516425999"><span>[516425999</span></a><span>] </span><span>Medium</span><span> CVE-2026-14007 Insufficient policy enforcement in PermissionsPolicy  on  2026-05-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515467789"><span>[515467789</span></a><span>] </span><span>High</span><span> CVE-2026-13841 Integer overflow in Skia  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515428315"><span>[515428315</span></a><span>] </span><span>Low</span><span> CVE-2026-14416 Out of bounds read in Dawn  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515426873"><span>[515426873</span></a><span>] </span><span>Low</span><span> CVE-2026-14148 Type Confusion in CSS  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515427046"><span>[515427046</span></a><span>] </span><span>Low</span><span> CVE-2026-14149 Use after free in Audio  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515423596"><span>[515423596</span></a><span>] </span><span>Medium</span><span> CVE-2026-14006 Use after free in Navigation  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515086856"><span>[515086856</span></a><span>] </span><span>Low</span><span> CVE-2026-14415 Inappropriate implementation in V8  on  2026-05-20 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514769383"><span>[514769383</span></a><span>] </span><span>Critical</span><span> CVE-2026-13780 Insufficient validation of untrusted input in ANGLE  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514632767"><span>[514632767</span></a><span>] </span><span>Low</span><span> CVE-2026-14147 Inappropriate implementation in CSS  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514609778"><span>[514609778</span></a><span>] </span><span>High</span><span> CVE-2026-13840 Insufficient policy enforcement in Canvas  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514550047"><span>[514550047</span></a><span>] </span><span>Low</span><span> CVE-2026-14146 Inappropriate implementation in CSS  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514538751"><span>[514538751</span></a><span>] </span><span>Medium</span><span> CVE-2026-14004 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514503077"><span>[514503077</span></a><span>] </span><span>Medium</span><span> CVE-2026-14003 Insufficient policy enforcement in Extensions  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514489361"><span>[514489361</span></a><span>] </span><span>Medium</span><span> CVE-2026-14002 Inappropriate implementation in Geolocation  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514485825"><span>[514485825</span></a><span>] </span><span>Low</span><span> CVE-2026-14145 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514481943"><span>[514481943</span></a><span>] </span><span>Medium</span><span> CVE-2026-14001 Inappropriate implementation in Network  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514461552"><span>[514461552</span></a><span>] </span><span>Medium</span><span> CVE-2026-14000 Inappropriate implementation in XML  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514449396"><span>[514449396</span></a><span>] </span><span>High</span><span> CVE-2026-13839 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514445398"><span>[514445398</span></a><span>] </span><span>High</span><span> CVE-2026-13838 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514429130"><span>[514429130</span></a><span>] </span><span>High</span><span> CVE-2026-13837 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514420555"><span>[514420555</span></a><span>] </span><span>High</span><span> CVE-2026-13836 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514338102"><span>[514338102</span></a><span>] </span><span>High</span><span> CVE-2026-13835 Inappropriate implementation in XML  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514079793"><span>[514079793</span></a><span>] </span><span>Low</span><span> CVE-2026-14144 Incorrect security UI in Views on Desktop  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514073460"><span>[514073460</span></a><span>] </span><span>Low</span><span> CVE-2026-14142 Inappropriate implementation in Extensions  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514072495"><span>[514072495</span></a><span>] </span><span>Low</span><span> CVE-2026-14139 Inappropriate implementation in TabStrip  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514071697"><span>[514071697</span></a><span>] </span><span>Medium</span><span> CVE-2026-13999 Inappropriate implementation in Extensions  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514068972"><span>[514068972</span></a><span>] </span><span>Medium</span><span> CVE-2026-13996 Incorrect security UI in Permissions  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514064139"><span>[514064139</span></a><span>] </span><span>Medium</span><span> CVE-2026-13993 Incorrect security UI in WebAppInstalls  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514058566"><span>[514058566</span></a><span>] </span><span>Low</span><span> CVE-2026-14135 Insufficient validation of untrusted input in Network  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514056221"><span>[514056221</span></a><span>] </span><span>Medium</span><span> CVE-2026-13989 Insufficient policy enforcement in PageInfo  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514040614"><span>[514040614</span></a><span>] </span><span>Medium</span><span> CVE-2026-13988 Inappropriate implementation in Paint  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514039947"><span>[514039947</span></a><span>] </span><span>Low</span><span> CVE-2026-14133 Race in History Embeddings  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514039492"><span>[514039492</span></a><span>] </span><span>Low</span><span> CVE-2026-14132 Inappropriate implementation in WebXR  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514020982"><span>[514020982</span></a><span>] </span><span>Low</span><span> CVE-2026-14131 Insufficient validation of untrusted input in WebAppInstalls  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514020959"><span>[514020959</span></a><span>] </span><span>Medium</span><span> CVE-2026-13986 Inappropriate implementation in Media UI  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514019522"><span>[514019522</span></a><span>] </span><span>Low</span><span> CVE-2026-14130 Incorrect security UI in Omnibox  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514013849"><span>[514013849</span></a><span>] </span><span>Medium</span><span> CVE-2026-13985 Inappropriate implementation in MediaCapture  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514009654"><span>[514009654</span></a><span>] </span><span>Low</span><span> CVE-2026-14127 Inappropriate implementation in Printing  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514010404"><span>[514010404</span></a><span>] </span><span>Medium</span><span> CVE-2026-13984 Incorrect security UI in TabStrip  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514006829"><span>[514006829</span></a><span>] </span><span>Medium</span><span> CVE-2026-13982 Incorrect security UI in Passwords  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513988889"><span>[513988889</span></a><span>] </span><span>Medium</span><span> CVE-2026-13979 Inappropriate implementation in Paint  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513948227"><span>[513948227</span></a><span>] </span><span>Medium</span><span> CVE-2026-14414 Insufficient validation of untrusted input in Skia  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513925114"><span>[513925114</span></a><span>] </span><span>High</span><span> CVE-2026-13834 Insufficient validation of untrusted input in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513922055"><span>[513922055</span></a><span>] </span><span>High</span><span> CVE-2026-14413 Uninitialized Use in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513920834"><span>[513920834</span></a><span>] </span><span>High</span><span> CVE-2026-14412 Insufficient validation of untrusted input in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513919827"><span>[513919827</span></a><span>] </span><span>High</span><span> CVE-2026-14411 Insufficient validation of untrusted input in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513918431"><span>[513918431</span></a><span>] </span><span>Low</span><span> CVE-2026-14125 Uninitialized Use in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513866949"><span>[513866949</span></a><span>] </span><span>Medium</span><span> CVE-2026-13978 Insufficient policy enforcement in PageInfo  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513859894"><span>[513859894</span></a><span>] </span><span>Medium</span><span> CVE-2026-13977 Inappropriate implementation in HTMLParser on context element  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513858286"><span>[513858286</span></a><span>] </span><span>Medium</span><span> CVE-2026-13976 Heap buffer overflow in Storage  on  2026-05-16 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/513631768"><span>[513631768</span></a><span>] </span><span>Medium</span><span> CVE-2026-14408 Uninitialized Use in Dawn Reported by [Chrovus ] on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513836996"><span>[513836996</span></a><span>] </span><span>Low</span><span> CVE-2026-14410 Inappropriate implementation in Skia  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513810921"><span>[513810921</span></a><span>] </span><span>Low</span><span> CVE-2026-14409 Inappropriate implementation in V8 Reported by [] on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513832989"><span>[513832989</span></a><span>] </span><span>Medium</span><span> CVE-2026-13973 Inappropriate implementation in UI  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513822378"><span>[513822378</span></a><span>] </span><span>High</span><span> CVE-2026-13832 Use after free in Headless  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513792140"><span>[513792140</span></a><span>] </span><span>Medium</span><span> CVE-2026-13972 Inappropriate implementation in Paint  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513789382"><span>[513789382</span></a><span>] </span><span>Low</span><span> CVE-2026-14121 Use after free in Chromoting on Linux Wayland  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513781328"><span>[513781328</span></a><span>] </span><span>High</span><span> CVE-2026-13831 Use after free in GPU  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513780208"><span>[513780208</span></a><span>] </span><span>Medium</span><span> CVE-2026-13971 Uninitialized Use in Skia  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513779283"><span>[513779283</span></a><span>] </span><span>Medium</span><span> CVE-2026-13970 Uninitialized Use in Media  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513777411"><span>[513777411</span></a><span>] </span><span>Low</span><span> CVE-2026-14120 Inappropriate implementation in DevTools  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513772764"><span>[513772764</span></a><span>] </span><span>Low</span><span> CVE-2026-14118 Insufficient data validation in DevTools  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513762145"><span>[513762145</span></a><span>] </span><span>Medium</span><span> CVE-2026-13968 Insufficient validation of untrusted input in DevTools  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513751951"><span>[513751951</span></a><span>] </span><span>Medium</span><span> CVE-2026-13967 Type Confusion in V8  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513747800"><span>[513747800</span></a><span>] </span><span>Low</span><span> CVE-2026-14116 Insufficient validation of untrusted input in DevTools  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513745699"><span>[513745699</span></a><span>] </span><span>Low</span><span> CVE-2026-14115 Insufficient validation of untrusted input in Cast  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513741393"><span>[513741393</span></a><span>] </span><span>Medium</span><span> CVE-2026-13966 Inappropriate implementation in History  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513737952"><span>[513737952</span></a><span>] </span><span>Medium</span><span> CVE-2026-13965 Use after free in Oilpan  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513727626"><span>[513727626</span></a><span>] </span><span>Medium</span><span> CVE-2026-13963 Inappropriate implementation in DevTools  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513727494"><span>[513727494</span></a><span>] </span><span>High</span><span> CVE-2026-13830 Use after free in Chromoting  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513721370"><span>[513721370</span></a><span>] </span><span>Medium</span><span> CVE-2026-13962 Insufficient data validation in PDF  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513714023"><span>[513714023</span></a><span>] </span><span>Medium</span><span> CVE-2026-13960 Inappropriate implementation in Passwords  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513713946"><span>[513713946</span></a><span>] </span><span>Low</span><span> CVE-2026-14112 Inappropriate implementation in Enterprise  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513710926"><span>[513710926</span></a><span>] </span><span>Low</span><span> CVE-2026-14111 Use after free in WebProtect  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513698452"><span>[513698452</span></a><span>] </span><span>Low</span><span> CVE-2026-14110 Inappropriate implementation in DarkMode  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513694957"><span>[513694957</span></a><span>] </span><span>Low</span><span> CVE-2026-14109 Insufficient policy enforcement in Mojo  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513689974"><span>[513689974</span></a><span>] </span><span>Low</span><span> CVE-2026-14108 Use after free in PDFium  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513609249"><span>[513609249</span></a><span>] </span><span>Medium</span><span> CVE-2026-13959 Insufficient validation of untrusted input in Blink  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513586956"><span>[513586956</span></a><span>] </span><span>Medium</span><span> CVE-2026-14407 Inappropriate implementation in V8 on ARM64 due to AAPCS64 ABI Mismatch  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513553557"><span>[513553557</span></a><span>] </span><span>Medium</span><span> CVE-2026-13957 Incorrect security UI in Extensions  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513544566"><span>[513544566</span></a><span>] </span><span>Low</span><span> CVE-2026-14107 Use after free in Scheduling  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513528117"><span>[513528117</span></a><span>] </span><span>Low</span><span> CVE-2026-14105 Insufficient policy enforcement in Speech  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513515168"><span>[513515168</span></a><span>] </span><span>Medium</span><span> CVE-2026-13956 Incorrect security UI in PageInfo  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513504934"><span>[513504934</span></a><span>] </span><span>Medium</span><span> CVE-2026-13954 Insufficient policy enforcement in XML  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513484193"><span>[513484193</span></a><span>] </span><span>Low</span><span> CVE-2026-14104 Insufficient validation of untrusted input in WebAppInstalls  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513465245"><span>[513465245</span></a><span>] </span><span>Low</span><span> CVE-2026-14103 Use after free in SSL on ChromeOS  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513459192"><span>[513459192</span></a><span>] </span><span>Medium</span><span> CVE-2026-13953 Inappropriate implementation in SplitView  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513455047"><span>[513455047</span></a><span>] </span><span>Low</span><span> CVE-2026-14102 Use after free in Passwords  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513435594"><span>[513435594</span></a><span>] </span><span>Medium</span><span> CVE-2026-14406 Out of bounds read in V8  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513401808"><span>[513401808</span></a><span>] </span><span>Medium</span><span> CVE-2026-13952 Inappropriate implementation in PerformanceAPIs  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513399832"><span>[513399832</span></a><span>] </span><span>High</span><span> CVE-2026-13828 Inappropriate implementation in Enterprise  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513394321"><span>[513394321</span></a><span>] </span><span>Medium</span><span> CVE-2026-13951 Policy bypass in USB on Linux-based Platforms  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513383891"><span>[513383891</span></a><span>] </span><span>Low</span><span> CVE-2026-14100 Insufficient data validation in NetworkCache  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513375767"><span>[513375767</span></a><span>] </span><span>Low</span><span> CVE-2026-14098 Inappropriate implementation in CSS  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513376037"><span>[513376037</span></a><span>] </span><span>Low</span><span> CVE-2026-14405 Uninitialized Use in V8  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513360781"><span>[513360781</span></a><span>] </span><span>Medium</span><span> CVE-2026-13950 Uninitialized Use in GPU  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513337989"><span>[513337989</span></a><span>] </span><span>Medium</span><span> CVE-2026-14404 Inappropriate implementation in PDFium  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513298483"><span>[513298483</span></a><span>] </span><span>Low</span><span> CVE-2026-14403 Use after free in V8  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513286820"><span>[513286820</span></a><span>] </span><span>Medium</span><span> CVE-2026-13948 Insufficient policy enforcement in Extensions  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513271007"><span>[513271007</span></a><span>] </span><span>Low</span><span> CVE-2026-14095 Insufficient validation of untrusted input in Browser  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513240099"><span>[513240099</span></a><span>] </span><span>Low</span><span> CVE-2026-14093 Use after free in Cast  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513226551"><span>[513226551</span></a><span>] </span><span>Medium</span><span> CVE-2026-13945 Insufficient policy enforcement in Extensions on Linux via XDG Global Shortcuts portal  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513222854"><span>[513222854</span></a><span>] </span><span>Critical</span><span> CVE-2026-13779 Use after free in Chromoting  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513212892"><span>[513212892</span></a><span>] </span><span>Low</span><span> CVE-2026-14092 Insufficient policy enforcement in Privacy  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513208773"><span>[513208773</span></a><span>] </span><span>Low</span><span> CVE-2026-14091 Use after free in DevTools  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513194241"><span>[513194241</span></a><span>] </span><span>Low</span><span> CVE-2026-14090 Out of bounds read in CameraCapture  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513188254"><span>[513188254</span></a><span>] </span><span>Low</span><span> CVE-2026-14089 Insufficient validation of untrusted input in PopupBlocker  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513186670"><span>[513186670</span></a><span>] </span><span>Medium</span><span> CVE-2026-13942 Insufficient validation of untrusted input in Video Capture  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513177497"><span>[513177497</span></a><span>] </span><span>High</span><span> CVE-2026-13824 Insufficient validation of untrusted input in Extensions  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513169718"><span>[513169718</span></a><span>] </span><span>Low</span><span> CVE-2026-14086 Insufficient policy enforcement in HID  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513163011"><span>[513163011</span></a><span>] </span><span>High</span><span> CVE-2026-13823 Use after free in Glic  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513158425"><span>[513158425</span></a><span>] </span><span>Medium</span><span> CVE-2026-13940 Uninitialized Use in Cast  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513155863"><span>[513155863</span></a><span>] </span><span>Low</span><span> CVE-2026-14085 Side-channel information leakage in CSS  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513143921"><span>[513143921</span></a><span>] </span><span>Medium</span><span> CVE-2026-13938 Integer overflow in Fonts  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513142445"><span>[513142445</span></a><span>] </span><span>High</span><span> CVE-2026-13821 Use after free in Canvas  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513138148"><span>[513138148</span></a><span>] </span><span>Low</span><span> CVE-2026-14084 Insufficient validation of untrusted input in Chromoting  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513128322"><span>[513128322</span></a><span>] </span><span>Low</span><span> CVE-2026-14083 Insufficient validation of untrusted input in HTML  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513048822"><span>[513048822</span></a><span>] </span><span>High</span><span> CVE-2026-14401 Insufficient validation of untrusted input in ANGLE  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513049578"><span>[513049578</span></a><span>] </span><span>Low</span><span> CVE-2026-14082 Race in Storage  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513046494"><span>[513046494</span></a><span>] </span><span>Medium</span><span> CVE-2026-13937 Insufficient policy enforcement in Passwords  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513030698"><span>[513030698</span></a><span>] </span><span>Low</span><span> CVE-2026-14081 Insufficient policy enforcement in DevTools  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513012139"><span>[513012139</span></a><span>] </span><span>Critical</span><span> CVE-2026-13776 Type Confusion in Dawn  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513009005"><span>[513009005</span></a><span>] </span><span>Medium</span><span> CVE-2026-13935 Side-channel information leakage in ComputePressure  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513006636"><span>[513006636</span></a><span>] </span><span>Medium</span><span> CVE-2026-13934 Insufficient validation of untrusted input in Dawn on Android leads to GPU process UB  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513006745"><span>[513006745</span></a><span>] </span><span>Medium</span><span> CVE-2026-14399 Uninitialized Use in Dawn  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513002625"><span>[513002625</span></a><span>] </span><span>Medium</span><span> CVE-2026-13933 Insufficient policy enforcement in Passwords  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512995785"><span>[512995785</span></a><span>] </span><span>Critical</span><span> CVE-2026-14398 Use after free in ANGLE  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512986879"><span>[512986879</span></a><span>] </span><span>High</span><span> CVE-2026-13820 Out of bounds read in Skia  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512971938"><span>[512971938</span></a><span>] </span><span>Low</span><span> CVE-2026-14079 Policy bypass in Network  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512953564"><span>[512953564</span></a><span>] </span><span>Low</span><span> CVE-2026-14078 Policy bypass in WebRTC  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512937764"><span>[512937764</span></a><span>] </span><span>Medium</span><span> CVE-2026-13930 Insufficient policy enforcement in Actor  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512162479"><span>[512162479</span></a><span>] </span><span>Medium</span><span> CVE-2026-13928 Insufficient validation of untrusted input in Enterprise  on  2026-05-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511823182"><span>[511823182</span></a><span>] </span><span>High</span><span> CVE-2026-13818 Inappropriate implementation in Passwords  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511815165"><span>[511815165</span></a><span>] </span><span>Low</span><span> CVE-2026-14076 Policy bypass in Network  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511766407"><span>[511766407</span></a><span>] </span><span>Critical</span><span> CVE-2026-13775 Use after free in GPU  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511748106"><span>[511748106</span></a><span>] </span><span>Medium</span><span> CVE-2026-13922 Side-channel information leakage in Paint  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511739631"><span>[511739631</span></a><span>] </span><span>High</span><span> CVE-2026-13817 Insufficient validation of untrusted input in Glic  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511738175"><span>[511738175</span></a><span>] </span><span>Medium</span><span> CVE-2026-13921 Insufficient validation of untrusted input in DeviceBoundSessionCredentials  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511722207"><span>[511722207</span></a><span>] </span><span>High</span><span> CVE-2026-13815 Use after free in Blink  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511712766"><span>[511712766</span></a><span>] </span><span>High</span><span> CVE-2026-13814 Use after free in Views  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511290389"><span>[511290389</span></a><span>] </span><span>Low</span><span> CVE-2026-14395 Out of bounds write in V8  on  2026-05-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511263221"><span>[511263221</span></a><span>] </span><span>Low</span><span> CVE-2026-14394 Use after free in V8  on  2026-05-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511255112"><span>[511255112</span></a><span>] </span><span>Medium</span><span> CVE-2026-14393 Use after free in V8  on  2026-05-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511249430"><span>[511249430</span></a><span>] </span><span>Medium</span><span> CVE-2026-13919 Insufficient data validation in Extensions  on  2026-05-08 </span></p><p dir="ltr"><span>[$3000.0] </span><a href="https://issuetracker.google.com/510829679"><span>[510829679</span></a><span>] </span><span>High</span><span> CVE-2026-13793 Insufficient policy enforcement in SVG  on  2026-05-07 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/507263861"><span>[507263861</span></a><span>] </span><span>Low</span><span> CVE-2026-14026  Misleading Directory Upload via Split View Context Confusion   on  2026-04-28 </span></p><p dir="ltr"><span>[$0.0] </span><a href="https://issuetracker.google.com/507099867"><span>[507099867</span></a><span>] </span><span>Low</span><span> CVE-2026-14072 Incorrect security UI in SplitView Reported by [] on  2026-04-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/507239830"><span>[507239830</span></a><span>] </span><span>Medium</span><span> CVE-2026-13911 Insufficient data validation in Spellcheck  on  2026-04-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/507237563"><span>[507237563</span></a><span>] </span><span>Low</span><span> CVE-2026-14073 Insufficient policy enforcement in WebXR  on  2026-04-27 </span></p><p dir="ltr"><span>[$3000.0] </span><a href="https://issuetracker.google.com/507090179"><span>[507090179</span></a><span>] </span><span>Medium</span><span> CVE-2026-13858 Out of bounds read in FFmpeg  on  2026-04-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/506558270"><span>[506558270</span></a><span>] </span><span>Critical</span><span> CVE-2026-13774 Use after free in Extensions  on  2026-04-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/506149253"><span>[506149253</span></a><span>] </span><span>High</span><span> CVE-2026-13811 Use after free in IME  on  2026-04-24 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/506143724"><span>[506143724</span></a><span>] </span><span>Low</span><span> CVE-2026-14071 Side-channel information leakage in WebAudio  on  2026-04-24 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/505933538"><span>[505933538</span></a><span>] </span><span>Medium</span><span> CVE-2026-13909 Insufficient policy enforcement in DevTools  on  2026-04-23 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/505137978"><span>[505137978</span></a><span>] </span><span>Low</span><span> CVE-2026-14070 Uninitialized Use in WebNN  on  2026-04-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/505136542"><span>[505136542</span></a><span>] </span><span>Low</span><span> CVE-2026-14069 Integer overflow in WebNN  on  2026-04-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/504613867"><span>[504613867</span></a><span>] </span><span>Medium</span><span> CVE-2026-13906 Out of bounds read in Codecs  on  2026-04-20 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/504600482"><span>[504600482</span></a><span>] </span><span>Low</span><span> CVE-2026-13810 Inappropriate implementation in Input on focus. This allows XSS to silently harvest saved passwords on page load without clicks, bypassing mandatory user gesture security checks.  on  2026-04-20 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503912196"><span>[503912196</span></a><span>] </span><span>Medium</span><span> CVE-2026-13903 Insufficient policy enforcement in Bluetooth  on  2026-04-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503617508"><span>[503617508</span></a><span>] </span><span>Low</span><span> CVE-2026-14065 Insufficient validation of untrusted input in PageInfo  on  2026-04-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503585173"><span>[503585173</span></a><span>] </span><span>Medium</span><span> CVE-2026-13901 Insufficient validation of untrusted input in Serial  on  2026-04-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503333798"><span>[503333798</span></a><span>] </span><span>High</span><span> CVE-2026-13806 Insufficient validation of untrusted input in Accessibility  on  2026-04-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503054174"><span>[503054174</span></a><span>] </span><span>High</span><span> CVE-2026-14390 Use after free in ANGLE  on  2026-04-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502473563"><span>[502473563</span></a><span>] </span><span>Low</span><span> CVE-2026-14063 Out of bounds memory access in Chromecast  on  2026-04-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502448128"><span>[502448128</span></a><span>] </span><span>Low</span><span> CVE-2026-14062 Inappropriate implementation in Views on ChromeOS  on  2026-04-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502434484"><span>[502434484</span></a><span>] </span><span>Low</span><span> CVE-2026-14061 Inappropriate implementation in Dawn on hardware with 1ns timestamp period  on  2026-04-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502374993"><span>[502374993</span></a><span>] </span><span>Medium</span><span> CVE-2026-13900 Insufficient validation of untrusted input in Chromecast  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502363986"><span>[502363986</span></a><span>] </span><span>Low</span><span> CVE-2026-14059 Insufficient policy enforcement in Related-Website-Sets on RWS removal  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502354038"><span>[502354038</span></a><span>] </span><span>Low</span><span> CVE-2026-14058 Policy bypass in Parser  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502212647"><span>[502212647</span></a><span>] </span><span>Low</span><span> CVE-2026-14057 Insufficient policy enforcement in FedCM  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502109002"><span>[502109002</span></a><span>] </span><span>Medium</span><span> CVE-2026-13899 Use after free in HTML  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501925480"><span>[501925480</span></a><span>] </span><span>Medium</span><span> CVE-2026-13898 Use after free in Cast Receiver  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501888426"><span>[501888426</span></a><span>] </span><span>Low</span><span> CVE-2026-14056 Insufficient validation of untrusted input in Media  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501877896"><span>[501877896</span></a><span>] </span><span>Medium</span><span> CVE-2026-13897 Insufficient policy enforcement in Chromecast  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501873032"><span>[501873032</span></a><span>] </span><span>High</span><span> CVE-2026-13804 Use after free in Chromecast  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501851312"><span>[501851312</span></a><span>] </span><span>Low</span><span> CVE-2026-14054 Insufficient policy enforcement in Network  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501836539"><span>[501836539</span></a><span>] </span><span>Low</span><span> CVE-2026-14053 Insufficient policy enforcement in Extensions  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501820076"><span>[501820076</span></a><span>] </span><span>Medium</span><span> CVE-2026-13896 Insufficient policy enforcement in Glic  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501810874"><span>[501810874</span></a><span>] </span><span>Low</span><span> CVE-2026-14052 Insufficient policy enforcement in FileSystem  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501770542"><span>[501770542</span></a><span>] </span><span>Medium</span><span> CVE-2026-13895 Inappropriate implementation in Autofill  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501741117"><span>[501741117</span></a><span>] </span><span>Medium</span><span> CVE-2026-13894 Insufficient policy enforcement in Network  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501729582"><span>[501729582</span></a><span>] </span><span>Medium</span><span> CVE-2026-13893 Insufficient validation of untrusted input in WebUI  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501708647"><span>[501708647</span></a><span>] </span><span>Low</span><span> CVE-2026-14050 Insufficient policy enforcement in Passwords  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501659888"><span>[501659888</span></a><span>] </span><span>Low</span><span> CVE-2026-14049 Inappropriate implementation in GPU  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501631475"><span>[501631475</span></a><span>] </span><span>Medium</span><span> CVE-2026-13891 Insufficient validation of untrusted input in Extensions  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501623322"><span>[501623322</span></a><span>] </span><span>High</span><span> CVE-2026-13802 Use after free in Views  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500601345"><span>[500601345</span></a><span>] </span><span>Medium</span><span> CVE-2026-13890 Out of bounds read in Chromecast  on  2026-04-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500587568"><span>[500587568</span></a><span>] </span><span>High</span><span> CVE-2026-13801 Integer overflow in Chromecast  on  2026-04-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500566906"><span>[500566906</span></a><span>] </span><span>Medium</span><span> CVE-2026-13888 Use after free in Extensions  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500505046"><span>[500505046</span></a><span>] </span><span>Medium</span><span> CVE-2026-14389 Integer overflow in Skia  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500476886"><span>[500476886</span></a><span>] </span><span>Medium</span><span> CVE-2026-14388 Out of bounds read in ANGLE  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500475136"><span>[500475136</span></a><span>] </span><span>Medium</span><span> CVE-2026-13886 Policy bypass in Isolated Web Apps  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500305404"><span>[500305404</span></a><span>] </span><span>Medium</span><span> CVE-2026-14387 Integer overflow in Skia  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500077014"><span>[500077014</span></a><span>] </span><span>Medium</span><span> CVE-2026-13884 Heap buffer overflow in Chromecast  on  2026-04-06 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500030250"><span>[500030250</span></a><span>] </span><span>Medium</span><span> CVE-2026-13883 Type Confusion in ANGLE  on  2026-04-06 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499252371"><span>[499252371</span></a><span>] </span><span>High</span><span> CVE-2026-13799 Use after free in QUIC  on  2026-04-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499189601"><span>[499189601</span></a><span>] </span><span>Low</span><span> CVE-2026-14048 Use after free in Chromecast  on  2026-04-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499162550"><span>[499162550</span></a><span>] </span><span>Medium</span><span> CVE-2026-13882 Inappropriate implementation in USB  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499100491"><span>[499100491</span></a><span>] </span><span>Medium</span><span> CVE-2026-13881 Insufficient data validation in WebAppInstalls  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499048914"><span>[499048914</span></a><span>] </span><span>High</span><span> CVE-2026-13798 Heap buffer overflow in Chromecast  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499025645"><span>[499025645</span></a><span>] </span><span>High</span><span> CVE-2026-13797 Insufficient validation of untrusted input in Chromecast  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499022239"><span>[499022239</span></a><span>] </span><span>Medium</span><span> CVE-2026-13879 Use after free in Bluetooth  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498864176"><span>[498864176</span></a><span>] </span><span>Low</span><span> CVE-2026-14047 Insufficient policy enforcement in Extensions  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498820206"><span>[498820206</span></a><span>] </span><span>Medium</span><span> CVE-2026-13877 Insufficient validation of untrusted input in ANGLE  on  2026-04-01 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498722200"><span>[498722200</span></a><span>] </span><span>Medium</span><span> CVE-2026-13876 Inappropriate implementation in Network  on  2026-04-01 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498411773"><span>[498411773</span></a><span>] </span><span>Medium</span><span> CVE-2026-13874 Inappropriate implementation in DataTransfer  on  2026-03-31 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498085466"><span>[498085466</span></a><span>] </span><span>Medium</span><span> CVE-2026-13873 Out of bounds memory access in Layout  on  2026-03-31 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497961376"><span>[497961376</span></a><span>] </span><span>Medium</span><span> CVE-2026-13871 Insufficient data validation in GuestView  on  2026-03-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497723649"><span>[497723649</span></a><span>] </span><span>Low</span><span> CVE-2026-14045 Insufficient validation of untrusted input in Network  on  2026-03-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497670996"><span>[497670996</span></a><span>] </span><span>Low</span><span> CVE-2026-14044 Use after free in ANGLE  on  2026-03-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497632232"><span>[497632232</span></a><span>] </span><span>Low</span><span> CVE-2026-14043 Use after free in GetUserMedia  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497558336"><span>[497558336</span></a><span>] </span><span>Low</span><span> CVE-2026-14042 Inappropriate implementation in Isolated Web Apps  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497544822"><span>[497544822</span></a><span>] </span><span>Low</span><span> CVE-2026-14041 Insufficient policy enforcement in Serial  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497488593"><span>[497488593</span></a><span>] </span><span>Low</span><span> CVE-2026-14040 Use after free in BrowserTag  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497358012"><span>[497358012</span></a><span>] </span><span>Low</span><span> CVE-2026-14039 Insufficient policy enforcement in GetUserMedia  on  2026-03-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497345177"><span>[497345177</span></a><span>] </span><span>Medium</span><span> CVE-2026-13867 Inappropriate implementation in Geolocation  on  2026-03-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497241148"><span>[497241148</span></a><span>] </span><span>Low</span><span> CVE-2026-14038 Insufficient validation of untrusted input in New Tab Page  on  2026-03-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497090912"><span>[497090912</span></a><span>] </span><span>Medium</span><span> CVE-2026-13865 Insufficient validation of untrusted input in Enterprise  on  2026-03-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496522611"><span>[496522611</span></a><span>] </span><span>Low</span><span> CVE-2026-14037 Insufficient policy enforcement in GPU  on  2026-03-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496411061"><span>[496411061</span></a><span>] </span><span>Low</span><span> CVE-2026-14036 Insufficient policy enforcement in Bluetooth  on  2026-03-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496399913"><span>[496399913</span></a><span>] </span><span>Medium</span><span> CVE-2026-13864 Insufficient policy enforcement in WebHID  on  2026-03-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496371586"><span>[496371586</span></a><span>] </span><span>Low</span><span> CVE-2026-14035 Insufficient policy enforcement in Bluetooth  on  2026-03-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/495459838"><span>[495459838</span></a><span>] </span><span>Low</span><span> CVE-2026-14031 Incorrect security UI in File Input  on  2026-03-23 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/495456765"><span>[495456765</span></a><span>] </span><span>Medium</span><span> CVE-2026-13861 Use after free in Core  on  2026-03-23 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/492410546"><span>[492410546</span></a><span>] </span><span>Medium</span><span> CVE-2026-14383 Inappropriate implementation in V8  on  2026-03-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/491894115"><span>[491894115</span></a><span>] </span><span>High</span><span> CVE-2026-13796 Integer overflow in Chromecast  on  2026-03-11 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/488762971"><span>[488762971</span></a><span>] </span><span>Low</span><span> CVE-2026-14030 Incorrect security UI in SplitView  on  2026-03-01 </span></p><p dir="ltr"><span>[$5000.0] </span><a href="https://issuetracker.google.com/479203484"><span>[479203484</span></a><span>] </span><span>Medium</span><span> CVE-2026-13857 Inappropriate implementation in Geometry Reported by [Luan Herrera (@lbherrera_)] on  2026-01-27 </span></p><p dir="ltr"><span>[$10000.0] </span><a href="https://issuetracker.google.com/457771782"><span>[457771782</span></a><span>] </span><span>High</span><span> CVE-2026-13790 Side-channel information leakage in Scroll Reported by [] on  2025-11-04 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/417052041"><span>[417052041</span></a><span>] </span><span>Medium</span><span> CVE-2026-13860 Incorrect security UI in Autofill  on  2025-05-11 </span></p><p dir="ltr"><span>[$500.0] </span><a href="https://issuetracker.google.com/527385397"><span>[527385397</span></a><span>] </span><span>High</span><span> CVE-2026-15132 Uninitialized Use in V8  on  2026-06-24 </span></p><p dir="ltr"><span>[$500.0] </span><a href="https://issuetracker.google.com/527406824"><span>[527406824</span></a><span>] </span><span>High</span><span> CVE-2026-15133 Use after free in InterestGroups  on  2026-06-24 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/526542464"><span>[526542464</span></a><span>] </span><span>Medium</span><span> CVE-2026-15131 Insufficient data validation in Navigation  on  2026-06-22 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/526541544"><span>[526541544</span></a><span>] </span><span>High</span><span> CVE-2026-15130 Insufficient policy enforcement in Navigation  on  2026-06-22 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524045160"><span>[524045160</span></a><span>] </span><span>Critical</span><span> CVE-2026-15129 Use after free in Views  on  2026-06-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523756329"><span>[523756329</span></a><span>] </span><span>High</span><span> CVE-2026-15128 Inappropriate implementation in Forms  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523752265"><span>[523752265</span></a><span>] </span><span>High</span><span> CVE-2026-15127 Inappropriate implementation in WebGL  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523748081"><span>[523748081</span></a><span>] </span><span>High</span><span> CVE-2026-15126 Use after free in Forms  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523737685"><span>[523737685</span></a><span>] </span><span>High</span><span> CVE-2026-15125 Inappropriate implementation in Forms  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523735038"><span>[523735038</span></a><span>] </span><span>High</span><span> CVE-2026-15124 Insufficient policy enforcement in Passwords  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523729553"><span>[523729553</span></a><span>] </span><span>High</span><span> CVE-2026-15123 Insufficient data validation in DOM  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523712556"><span>[523712556</span></a><span>] </span><span>High</span><span> CVE-2026-15121 Use after free in WebRTC  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523505418"><span>[523505418</span></a><span>] </span><span>High</span><span> CVE-2026-15119 Inappropriate implementation in GetUserMedia  on  2026-06-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523238265"><span>[523238265</span></a><span>] </span><span>High</span><span> CVE-2026-15118 Use after free in Input  on  2026-06-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/522568496"><span>[522568496</span></a><span>] </span><span>High</span><span> CVE-2026-15117 Use after free in Payments  on  2026-06-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/522092013"><span>[522092013</span></a><span>] </span><span>High</span><span> CVE-2026-15116 Use after free in Actor  on  2026-06-09 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/520565945"><span>[520565945</span></a><span>] </span><span>High</span><span> CVE-2026-15114 Out of bounds read and write in Codecs  on  2026-06-05 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518006275"><span>[518006275</span></a><span>] </span><span>Critical</span><span> CVE-2026-15112 Use after free in Ozone  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517508651"><span>[517508651</span></a><span>] </span><span>High</span><span> CVE-2026-15111 Use after free in Views  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516899138"><span>[516899138</span></a><span>] </span><span>High</span><span> CVE-2026-15109 Uninitialized Use in ANGLE  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515443146"><span>[515443146</span></a><span>] </span><span>High</span><span> CVE-2026-15108 Integer overflow in Extensions API  on  2026-05-21 </span></p><p dir="ltr"><span>[$2000.0] </span><a href="https://issuetracker.google.com/503553615"><span>[503553615</span></a><span>] </span><span>Medium</span><span> CVE-2026-15107 Use after free in IndexedDB  on  2026-04-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/532929679"><span>[532929679</span></a><span>] </span><span>High</span><span> CVE-2026-15777 Use after free in UI  on  2026-07-09 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/532595489"><span>[532595489</span></a><span>] </span><span>High</span><span> CVE-2026-15776 Type Confusion in V8  on  2026-07-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/531319201"><span>[531319201</span></a><span>] </span><span>High</span><span> CVE-2026-15775 Insufficient policy enforcement in V8  on  2026-07-05 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/530646115"><span>[530646115</span></a><span>] </span><span>High</span><span> CVE-2026-15774 Use after free in Skia  on  2026-07-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/525317502"><span>[525317502</span></a><span>] </span><span>High</span><span> CVE-2026-15772 Use after free in GPU on Android via GLTextureHolder::ReadbackToMemory  on  2026-06-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524792614"><span>[524792614</span></a><span>] </span><span>High</span><span> CVE-2026-15770 Uninitialized Use in V8  on  2026-06-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/519731111"><span>[519731111</span></a><span>] </span><span>High</span><span> CVE-2026-15769 Insufficient validation of untrusted input in Linux Toolkit Theming  on  2026-06-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518007484"><span>[518007484</span></a><span>] </span><span>Critical</span><span> CVE-2026-15765 Use after free in Ozone  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517931625"><span>[517931625</span></a><span>] </span><span>High</span><span> CVE-2026-15768 Insufficient policy enforcement in HTML-in-Canvas  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517100492"><span>[517100492</span></a><span>] </span><span>Critical</span><span> CVE-2026-15764 Use after free in Ozone  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514748734"><span>[514748734</span></a><span>] </span><span>High</span><span> CVE-2026-15767 Heap buffer overflow in libyuv  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514010477"><span>[514010477</span></a><span>] </span><span>High</span><span> CVE-2026-15766 Uninitialized Use in Skia  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513795122"><span>[513795122</span></a><span>] </span><span>Medium</span><span> CVE-2026-15778 Insufficient validation of untrusted input in Navigation  on  2026-05-16 </span></p><br></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution]]></title>
<description><![CDATA[Two alleged leading members of the Scattered Spider cybercrime collective have been sentenced to five years and six months in prison each for their involvement in the 2024 cyberattack on Transport for London (TfL). The National Crime Agency (NCA) described this case as the largest cybercrime pros...]]></description>
<link>https://tsecurity.de/de/3675230/it-security-nachrichten/two-scattered-spider-hackers-jailed-in-uks-largest-cybercrime-prosecution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675230/it-security-nachrichten/two-scattered-spider-hackers-jailed-in-uks-largest-cybercrime-prosecution/</guid>
<pubDate>Fri, 17 Jul 2026 08:38:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two alleged leading members of the Scattered Spider cybercrime collective have been sentenced to five years and six months in prison each for their involvement in the 2024 cyberattack on Transport for London (TfL). The National Crime Agency (NCA) described this case as the largest cybercrime prosecution in the UK. Thalha Jubair, 20, from East […]</p>
<p>The post <a href="https://gbhackers.com/two-scattered-spider-hackers-jailed-in-uks/">Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution]]></title>
<description><![CDATA[Two alleged leading members of the Scattered Spider cybercrime collective have been sentenced to five years and six months in prison each for their involvement in the 2024 cyberattack on Transport for London (TfL). The National Crime Agency (NCA) described…
Read more →
The post Two Scattered Spid...]]></description>
<link>https://tsecurity.de/de/3675225/it-security-nachrichten/two-scattered-spider-hackers-jailed-in-uks-largest-cybercrime-prosecution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675225/it-security-nachrichten/two-scattered-spider-hackers-jailed-in-uks-largest-cybercrime-prosecution/</guid>
<pubDate>Fri, 17 Jul 2026 08:38:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two alleged leading members of the Scattered Spider cybercrime collective have been sentenced to five years and six months in prison each for their involvement in the 2024 cyberattack on Transport for London (TfL). The National Crime Agency (NCA) described…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/two-scattered-spider-hackers-jailed-in-uks-largest-cybercrime-prosecution/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/two-scattered-spider-hackers-jailed-in-uks-largest-cybercrime-prosecution/">Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider Hackers Sentenced Over £29 Million Transport for London Cyberattack]]></title>
<description><![CDATA[Two young members of the notorious Scattered Spider hacking collective have been sentenced to five years and six months in prison each for orchestrating a cyber attack on Transport for London (TfL) that cost tens of millions of pounds and disrupted services for thousands of Londoners. Thalha Juba...]]></description>
<link>https://tsecurity.de/de/3675157/it-security-nachrichten/scattered-spider-hackers-sentenced-over-29-million-transport-for-london-cyberattack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675157/it-security-nachrichten/scattered-spider-hackers-sentenced-over-29-million-transport-for-london-cyberattack/</guid>
<pubDate>Fri, 17 Jul 2026 07:53:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two young members of the notorious Scattered Spider hacking collective have been sentenced to five years and six months in prison each for orchestrating a cyber attack on Transport for London (TfL) that cost tens of millions of pounds and disrupted services for thousands of Londoners. Thalha Jubair, 20, from East London, and Owen Flowers, […]</p>
<p>The post <a href="https://cyberpress.org/scattered-spider-hackers-sentenced/">Scattered Spider Hackers Sentenced Over £29 Million Transport for London Cyberattack</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s Moonshot AI releases Kimi K3, the largest open-source model ever, rivaling top U.S. systems]]></title>
<description><![CDATA[Moonshot AI, the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released Kimi K3 — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful pr...]]></description>
<link>https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</guid>
<pubDate>Thu, 16 Jul 2026 23:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.moonshot.ai/">Moonshot AI,</a> the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful proprietary systems from <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a>.</p><p>The release, timed to land just ahead of the <a href="https://aiii.global/waic-2026/">2026 World Artificial Intelligence Conference</a> in Shanghai, is a dramatic escalation in the global AI arms race and a watershed moment for the open-source AI movement. It also marks a remarkable comeback for a company whose market position had eroded significantly over the past 18 months following DeepSeek's meteoric rise.</p><p>Full model weights are scheduled to be released on July 27, according to details shared by researchers who reviewed the company's technical documentation. If you want to take <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> for a spin right now, you can — just head to<a href="https://www.kimi.com/"> kimi.com</a>, sign up with a Google account or phone number (no credit card required), and start chatting with what may be the most powerful open-source model ever built.</p><div></div><h2><b>Inside the architecture that powers the world's largest open-source AI model</b></h2><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is a frontier-class large language model with 2.8 trillion total parameters — roughly 75 percent larger than <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek's V4 Pro</a>, which the company's own timeline chart shows at approximately 1.6 trillion parameters. The model features a 1-million-token context window, native visual understanding capabilities, and an always-on reasoning mode that the company calls "thinking mode."</p><p>The model is built on two key architectural innovations developed internally at Moonshot AI: <a href="https://arxiv.org/abs/2510.26692">Kimi Delta Attention</a>, a hybrid linear attention mechanism, and <a href="https://arxiv.org/abs/2603.15031">Attention Residuals</a>, which the company describes as a drop-in replacement for residual connections that delivers consistent scaling gains. Both techniques were previously published as open research by the Moonshot team on <a href="https://github.com/moonshotai">GitHub</a>.</p><p>On the <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">API side</a>, Kimi K3 is compatible with the <a href="https://developers.openai.com/api/docs/guides/agents">OpenAI SDK</a>, lowering the integration barrier for developers already building on OpenAI or Anthropic toolchains. The model is priced at $3 per million input tokens and $15 per million output tokens, with cached input tokens dropping to just $0.30 per million — pricing that positions it roughly in line with mid-tier offerings from Western labs, but at a performance level the company claims approaches the top of the market. A promotional top-up rebate running through August 12 offers up to 30 percent back in vouchers for API credits of $1,000 or more.</p><p>As <a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua reported</a>, a Moonshot AI executive explained the significance of the parameter count in simple terms: parameters are like neural connections in the human brain, and nearly 3 trillion of them means the model can "store more knowledge and patterns in its brain, understand more, think deeper, and answer more accurately."</p><div></div><h2><b>Benchmark results show Kimi K3 trading blows with Claude and GPT at the top of the leaderboard</b></h2><p>The benchmark results, drawn from public leaderboard data and a private evaluation by analytics firm Artificial Analysis, tell a striking story.</p><p>On <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2</a>, a benchmark measuring real-world tasks across 44 occupations and 9 major industries, Kimi K3 scored 1,687 — placing it third overall, behind only Claude Fable 5 Max (1,815) and GPT-5.6 Sol Max (1,747.8), and ahead of Claude Opus 4.8 (1,600).</p><p>On <a href="https://artificialanalysis.ai/evaluations/aa-briefcase">AA-Briefcase</a>, a private agentic benchmark from Artificial Analysis designed to test long-horizon knowledge work, K3 climbed to second place with a score of 1,527 — beating GPT-5.6 Sol Max (1,495) and trailing only Fable 5 Max (1,587).</p><p>Perhaps most impressively, K3 achieved a state-of-the-art score of 91.2 out of 100 on <a href="https://openai.com/index/browsecomp/">BrowseComp</a>, a benchmark for long-horizon, high-difficulty information seeking. </p><p>The company says it accomplished this in a single-agent setup using its 1-million-token context window, without any context compression or additional context management techniques — a feat that suggests raw context length, when paired with strong retrieval capabilities, may be more powerful than elaborate multi-agent workarounds.</p><p>As <a href="https://x.com/kimmonismus/status/2077818040578695175">one widely followed AI commentator</a> put it on social media: "Open source is no longer lagging six months behind Western closed-source models. Read that again, and think about what it all means."</p><p>That observation captures the significance of the moment. For much of the past three years, open-source models have typically trailed their proprietary counterparts by a meaningful margin. Kimi K3 appears to have closed that gap almost entirely.</p><h2><b>How a 48-hour autonomous chip design demo reveals Moonshot's real ambitions</b></h2><p>Beyond raw benchmarks, <a href="https://www.moonshot.ai/">Moonshot AI</a> showcased a proof-of-concept that may be even more revealing of K3's capabilities and the company's strategic direction.</p><p>In a demonstration documented in the company's technical materials, <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> was tasked with designing a physical chip to run a nano-scale version of itself. Over 48 hours of continuous autonomous agent operation, K3 independently completed the chip's full construction pipeline — from architectural design through optimization and verification — using open-source electronic design automation tools. The result was a tiny but functional chip design, just 4 square millimeters, that achieved timing convergence at 100 MHz and could decode more than 8,700 tokens per second in simulation.</p><p>This is not a production chip. It is a demonstration of what <a href="https://www.moonshot.ai/">Moonshot AI</a> clearly views as the next competitive frontier: long-range autonomous agent capabilities. The ability to sustain coherent, multi-step technical work over a 48-hour window — reading documentation, making design decisions, running verification loops, and iterating on failures — represents a qualitative leap beyond the kind of single-turn question-answering that defined the first generation of large language models.</p><p>The company also highlighted a case in computational astrophysics, where K3 reportedly reproduced the universal <a href="https://inspirehep.net/literature/1220233">I-Love-Q relation</a> — a complex calculation that typically takes a senior researcher one to two weeks — in approximately two hours, reading and cross-validating more than 20 papers and implementing a complete numerical pipeline along the way.</p><h2><b>Moonshot AI's fall and rise tells the story of China's brutal AI market</b></h2><p>To understand why <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> matters, you need to understand where Moonshot AI was 18 months ago — and how far it fell.</p><p>Founded in 2023 by <a href="https://kimiyoung.github.io/">Yang Zhilin</a>, a Tsinghua University graduate who previously conducted research at Google and Meta, Moonshot AI quickly became one of China's most prominent AI startups. The company gained early traction in 2024 when users flocked to its <a href="http://kimi.ai/">Kimi platform</a> for its long-text analysis capabilities and AI search functions. By early 2026, it had raised roughly <a href="https://www.forbes.com/sites/the-prompt/2026/07/15/ai-startup-reflection-compute-deal-to-challenge-chinas-open-source-dominance/">$1.5 billion</a> across multiple rounds, with its valuation climbing from $2.5 billion to $4.3 billion and the company reportedly <a href="https://tech.yahoo.com/ai/gemini/articles/china-moonshot-releases-open-source-141110760.html">seeking a new round at $5 billion</a>.</p><p>Then DeepSeek happened. The release of DeepSeek's low-cost R1 model in January 2025 disrupted the entire Chinese AI landscape, and Moonshot AI was among the hardest hit. Kimi, which had ranked third in monthly active users in China, slid to seventh. The company's strategic pivot to open-source models — beginning with Kimi K2 in July 2025 and accelerating with K2.5 in January 2026 — was in large part an effort to reclaim relevance.</p><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is the culmination of that effort — and the sheer scale of the model suggests that Moonshot AI has been planning this move for some time. Training a 2.8-trillion-parameter model requires enormous computational resources and months of preparation, which means the architectural and infrastructure decisions behind K3 were likely locked in well before the model reached the public.</p><h2><b>Why open-sourcing the world's biggest model is a geopolitical chess move</b></h2><p>The decision to release K3's full weights on July 27 is strategically significant and worth parsing carefully.</p><p>The company's own timeline chart of open-source frontier model scale positions K3 as a dramatic outlier, towering above competitors like <a href="https://github.com/deepseek-ai">DeepSeek</a> (1.6T), <a href="https://github.com/xiaomi">Xiaomi</a> (1.02T), and <a href="https://github.com/ALIBABA">Alibaba</a> (397B). By releasing the world's largest open-source model, Moonshot AI is making a bid to become the center of gravity for the global open-source AI developer community.</p><p>This follows a broader trend among Chinese AI companies. As <a href="https://www.reuters.com/technology/artificial-intelligence/china-weighs-silicon-curtain-around-sought-after-ai-models-2026-07-08/">Reuters noted</a>, open-sourcing allows companies to "showcase their technological capabilities and expand developer communities as well as their global influence, a strategy likely to help China counter U.S. efforts to limit Beijing's tech progress." DeepSeek, Alibaba, Tencent, and Baidu have all released open-source models. But none have released anything at this parameter count.</p><p>For enterprise technology leaders, the implications are concrete. A 2.8-trillion-parameter open-source model that performs at near-frontier levels creates new options for companies that want to fine-tune, self-host, or build proprietary systems on top of a capable base model — without being locked into API contracts with OpenAI or Anthropic. The trade-off, of course, is that running a model of this size requires substantial GPU infrastructure. Inference at 2.8 trillion parameters is not something that runs on a single server rack.</p><p>That said, <a href="https://www.moonshot.ai/">Moonshot AI</a> has signaled awareness of this challenge. Its Mooncake project, which won the Best Paper award at FAST 2025, pioneered KV-cache-centric disaggregated serving for large language models — an architecture designed specifically to make inference at extreme scale more practical and cost-efficient.</p><h2><b>Kimi Code and a three-tier model lineup form the foundation of Moonshot's enterprise play</b></h2><p>Alongside K3, Moonshot AI continues to invest heavily in its coding agent ecosystem. <a href="https://github.com/MoonshotAI/kimi-code/releases">Kimi Code</a>, the company's open-source coding tool that competes with Anthropic's Claude Code and Google's Gemini CLI, received two major updates on the same day as K3's launch — versions 0.25.0 and 0.26.0 — adding features like expanded subagent tooling, background task management, and security fixes.</p><p>The <a href="https://github.com/MoonshotAI/kimi-cli">Kimi Code CLI</a> has accumulated over 3,100 stars on GitHub and features integration with VSCode, Cursor, and Zed. The latest release expanded the "coder subagent" tool set to include background tasks, todo lists, plan mode, skill invocation, and nested agents — effectively turning the coding agent into a multi-layered autonomous system capable of managing complex software engineering projects with minimal human intervention.</p><p>This is not incidental. Coding tools have become a critical revenue driver for AI labs. As Anthropic disclosed in January, <a href="https://www.anthropic.com/news/anthropic-acquires-bun-as-claude-code-reaches-usd1b-milestone">Claude Code reached $1 billion in annualized recurring revenue</a>. By building Kimi Code as an open-source alternative that defaults to Kimi's own models — but supports other providers — Moonshot AI is positioning itself to capture developer workflows and, eventually, enterprise contracts.</p><p>The company's model lineup now includes three tiers: <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">K3</a> as the flagship ($3/$15 per million tokens for input/output), <a href="https://platform.kimi.ai/docs/guide/kimi-k2-7-code-quickstart">K2.7 Code</a> as a specialized coding model ($0.95/$4), and <a href="https://platform.kimi.ai/docs/guide/kimi-k2-6-quickstart">K2.6</a> as a general-purpose option ($0.95/$4). All three support context windows of 256,000 tokens or above, with K3 offering the full 1-million-token window. Context caching is automatic — no cache ID, TTL, or extra parameter is required — a small but meaningful developer-experience advantage over competitors that require explicit cache management.</p><h2><b>What Kimi K3 means for the future of enterprise AI and the global model landscape</b></h2><p>Kimi K3's release forces a recalibration of several assumptions that have guided enterprise AI strategy.</p><p>The performance gap between open-source and proprietary models has functionally closed at the frontier. If K3's benchmark numbers hold up under independent evaluation — and particularly once the open weights are available for community testing on July 27 — it will be difficult for closed-source providers to justify premium pricing purely on the basis of capability.</p><p>The locus of AI innovation, meanwhile, continues to shift. China's AI ecosystem, which many Western observers questioned after early struggles with chip export restrictions, has now produced a model that competes with the best systems from companies with direct access to Nvidia's most advanced hardware. The architectural innovations behind K3 — particularly the hybrid linear attention mechanism — suggest that algorithmic efficiency may matter as much as raw compute.</p><p>And the agentic capabilities demonstrated by K3 — chip design, multi-week research compression, long-horizon information seeking — point toward a future where AI models are not just answering questions but autonomously executing complex, multi-day projects. For enterprises evaluating AI investments, this shifts the value proposition from "productivity copilot" to "autonomous technical workforce."</p><p><a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua</a>, China's state news agency, framed the release as a national milestone, reporting that K3 "marks a new step forward in the development of China's artificial intelligence models." Liu Tieyan, dean of the Zhongguancun Academy in Beijing, was quoted as saying that a wave of Chinese open-source models has moved from isolated breakthroughs to collective advancement, providing "new solutions and new paths" for global AI development.</p><p>Just two years ago, <a href="https://www.moonshot.ai/">Moonshot AI</a> was a scrappy startup named for the audacious problems it hoped to solve. Eighteen months ago, it was a cautionary tale about how quickly a market darling can lose its footing. Today, it is the maker of the world's largest open-source AI model — one that can, given 48 hours and an internet connection, design a chip to run itself. The frontier, it turns out, is not a place. It is a race. And the field just got a lot more crowded.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackergruppe ShinyHunters: 3,5 TB Daten von 9.000 Schulen gestohlen - Ad Hoc News]]></title>
<description><![CDATA[Hacker erbeuten sensible Daten von Schülern und Lehrkräften. Canvas-Hack und Ransomware: Bildungseinrichtungen weltweit im Visier. Ein digitales ...]]></description>
<link>https://tsecurity.de/de/3674246/hacking/hackergruppe-shinyhunters-35-tb-daten-von-9000-schulen-gestohlen-ad-hoc-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674246/hacking/hackergruppe-shinyhunters-35-tb-daten-von-9000-schulen-gestohlen-ad-hoc-news/</guid>
<pubDate>Thu, 16 Jul 2026 19:10:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Hacker</b> erbeuten sensible Daten von Schülern und Lehrkräften. Canvas-Hack und Ransomware: Bildungseinrichtungen weltweit im Visier. Ein digitales ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Transport for London hackers jailed for five and a half years]]></title>
<description><![CDATA[The duo behind the major 2024 cyberattack are reported to have been leading members of the Scattered Spider cybercrime collective.
Read more: Transport for London hackers jailed for five and a half years]]></description>
<link>https://tsecurity.de/de/3673877/it-nachrichten/transport-for-london-hackers-jailed-for-five-and-a-half-years/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673877/it-nachrichten/transport-for-london-hackers-jailed-for-five-and-a-half-years/</guid>
<pubDate>Thu, 16 Jul 2026 17:02:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The duo behind the major 2024 cyberattack are reported to have been leading members of the Scattered Spider cybercrime collective.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/enterprise/transport-for-london-hackers-jailed-for-five-and-a-half-years">Transport for London hackers jailed for five and a half years</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider members jailed over Transport for London hack that cost £29 million]]></title>
<description><![CDATA[Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport…
Read more →
The post Scattered Spider membe...]]></description>
<link>https://tsecurity.de/de/3673772/it-security-nachrichten/scattered-spider-members-jailed-over-transport-for-london-hack-that-cost-29-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673772/it-security-nachrichten/scattered-spider-members-jailed-over-transport-for-london-hack-that-cost-29-million/</guid>
<pubDate>Thu, 16 Jul 2026 16:23:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/scattered-spider-members-jailed-over-transport-for-london-hack-that-cost-29-million/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/scattered-spider-members-jailed-over-transport-for-london-hack-that-cost-29-million/">Scattered Spider members jailed over Transport for London hack that cost £29 million</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sakana AI's orchestrator adds Nvidia Nemotron to prove "collective intelligence" can rival single frontier models]]></title>
<description><![CDATA[Sakana AI is integrating Nvidia's open-source Nemotron models into its Fugu orchestrator, which dynamically combines multiple language models for specific tasks. The core argument: Open models only become competitive with Frontier systems when used in a coordinated manner. However, the announceme...]]></description>
<link>https://tsecurity.de/de/3673765/ai-nachrichten/sakana-ais-orchestrator-adds-nvidia-nemotron-to-prove-collective-intelligence-can-rival-single-frontier-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673765/ai-nachrichten/sakana-ais-orchestrator-adds-nvidia-nemotron-to-prove-collective-intelligence-can-rival-single-frontier-models/</guid>
<pubDate>Thu, 16 Jul 2026 16:19:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1900" height="1260" src="https://the-decoder.com/wp-content/uploads/2026/07/sakana-ai-nvidia-open-model-innovation.png" class="attachment-full size-full wp-post-image" alt="The NVIDIA logo next to the sakana.ai logo, reflecting a shared commitment to open-model innovation in AI." decoding="async" fetchpriority="high"></p>
<p>        Sakana AI is integrating Nvidia's open-source Nemotron models into its Fugu orchestrator, which dynamically combines multiple language models for specific tasks. The core argument: Open models only become competitive with Frontier systems when used in a coordinated manner. However, the announcement does not yet provide specific benchmark figures for the new combination.</p>
<p>The article <a href="https://the-decoder.com/sakana-ais-fugu-adds-nvidia-nemotron-to-prove-collective-intelligence-can-rival-single-frontier-models/">Sakana AI's orchestrator adds Nvidia Nemotron to prove "collective intelligence" can rival single frontier models</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider members jailed over Transport for London hack that cost £29 million]]></title>
<description><![CDATA[Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport authority an estimated £29 million. Thalha J...]]></description>
<link>https://tsecurity.de/de/3673722/it-security-nachrichten/scattered-spider-members-jailed-over-transport-for-london-hack-that-cost-29-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673722/it-security-nachrichten/scattered-spider-members-jailed-over-transport-for-london-hack-that-cost-29-million/</guid>
<pubDate>Thu, 16 Jul 2026 16:08:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport authority an estimated £29 million. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, pleaded guilty last month, on the day their trial was set to start. The National Crime Agency (NCA) … <a href="https://www.helpnetsecurity.com/2026/07/16/ransport-for-london-cyberattack-prison-time/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/ransport-for-london-cyberattack-prison-time/">Scattered Spider members jailed over Transport for London hack that cost £29 million</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider members behind TfL hack get five years in prison]]></title>
<description><![CDATA[Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024. [...]]]></description>
<link>https://tsecurity.de/de/3673467/it-security-nachrichten/scattered-spider-members-behind-tfl-hack-get-five-years-in-prison/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673467/it-security-nachrichten/scattered-spider-members-behind-tfl-hack-get-five-years-in-prison/</guid>
<pubDate>Thu, 16 Jul 2026 14:39:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[19 AgentOps tools for monitoring AI activity, issues, and costs]]></title>
<description><![CDATA[With AI increasingly tucked into every cranny of the enterprise, someone has had to step up and provide the tools necessary to discover, track, and monitor all the agents and LLMs and keep them humming along in their various workflows. Thankfully, the DevOps world answered the call, building the ...]]></description>
<link>https://tsecurity.de/de/3673038/it-security-nachrichten/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673038/it-security-nachrichten/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs/</guid>
<pubDate>Thu, 16 Jul 2026 12:09:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">With AI increasingly tucked into every cranny of the enterprise, someone has had to step up and provide the tools necessary to discover, track, and monitor all the agents and LLMs and keep them humming along in their various workflows. Thankfully, the DevOps world answered the call, building the tools to support our new overlords in an emerging subdiscipline interchangeably called “<a href="https://www.cio.com/article/196239/what-is-aiops-injecting-intelligence-into-it-operations.html">AIOps</a>,” “AgentOps,” and sometimes “agent observability.”</p>



<p class="wp-block-paragraph">Many of the challenges involved in AgentOps are similar to those tackled by traditional DevOps tools and processes. After all, at their foundation, LLMs are just software running on hardware somewhere. Typical issues involving RAM and disk space are just as important in the agent world, maybe more so because AI operations are even more greedy about consuming storage than regular software is.</p>



<p class="wp-block-paragraph">Many of the companies supporting agent observability are big names in DevOps circles, having adapted their stacks to address the idiosyncrasies of modern LLMs. IT teams maintaining enterprise agents can treat the LLMs as just one node in a big graph filled with services that are constantly swapping packets and triggering software jobs. Latency and resource constraints must be managed because end-users don’t care whether it’s an LLM, a database, or a plain-old Python script that’s failing, bringing their work to a grinding halt.</p>



<p class="wp-block-paragraph">But new AI-specific challenges are opening the door to newcomers that are building tools with the peculiarities of LLMs in mind — for example, keeping deeper logs filled with records of prompts. LLMs are also often very non-deterministic by design, making it trickier to pinpoint failure modes. And then there’s the fact that an agent will give a perfectly intelligent answer one minute and hallucinate the next.</p>



<p class="wp-block-paragraph">Relying on many of the same approaches that DevOps tools do, AgentOps tools watch for misbehavior and flag anything out of the ordinary for deeper analysis. This may be as simple as fixing slow responses, but it can also include AI hallucinations and other issues born of LLMs’ non-determanism.</p>



<p class="wp-block-paragraph">Teams trying to choose which agent observability tools is best for their use case should look at the size and nature of their agentic systems and projects. Are they adding AI agent features to an existing product or application, or are they building agentic systems from scratch? Are they more focused on maintaining a stable LLM operation or iterating on new approaches? Is AI the center of attention or just an add-on that’s meant to improve an existing stack?<br><br>The AgentOps and agent observability options listed below share many of the same features but differ in their focus and their attention to the challenges organizations will encounter when incorporating agents into their stacks. Each tool offers a worthwhile place to start understanding how to care for the growing presence of AI in the production world.</p>



<h2 class="wp-block-heading">AgentOps.ai</h2>



<p class="wp-block-paragraph">When teams of agents work together, tracking the conversations are essential for understanding and debugging what’s happening. The SDK from <a href="http://agentops.ai/">AgentOps.ai records</a> events so that the creators can replay past behavior to track details such as token counts, spending, latency, and more. Available as a service and on-premises.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.agentops.ai/#pricing">Starts at $40 per month </a>plus usage costs at $0.20 per 1M tokens</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Replay analytics with “time-travel debugging”</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Complex agent debugging</p>



<h2 class="wp-block-heading">Arize Phoenix</h2>



<p class="wp-block-paragraph">Debugging prompts and LLM responses requires a nuanced understanding of just what’s happening, in part because of the non-determinism that often enters the process. <a href="https://arize.com/phoenix/">Phoenix</a> from Arize supports this process with robust tracing and the ability to score the results for more precise iteration. Their system can track the results and tool calls from a variety of major platforms (Anthropic, AWS, OpenAI, etc.) that are initiated by the major frameworks (LangChain, LlamaIndex, DSPy, etc.). The result is insight into what data is triggering what chain of responses.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://arize.com/pricing/">Pro plan</a> starts at $50 per month plus costs tied to events</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> LLM-as-a-Judge metrics for tracking quality</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Teams focusing on iterating for accuracy and quality</p>



<h2 class="wp-block-heading">BigPanda</h2>



<p class="wp-block-paragraph"><a href="https://www.bigpanda.io/">BigPanda</a> has always offered solutions for tracking performance of complex systems. Now the company is drilling deeper into the challenge of detecting and ending the problems that come from models that go awry. BigPanda’s main system relies on historical data and machine learning algorithms to flag issues. Its own agent layer connects the problematic nodes and errant models while dispatching alerts to the right team members.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> “Value-based” table on <a href="https://www.bigpanda.io/pricing/">request</a></p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Automated triage for faster response</p>



<p class="wp-block-paragraph"><em>Best suited for:</em> Large teams seeking to reduce alert fatigue from large customer base</p>



<h2 class="wp-block-heading">Braintrust</h2>



<p class="wp-block-paragraph">Setting up an effective improvement cycle for an AI agent requires a strong feedback loop from production data to the agent’s next generation. <a href="https://www.braintrust.dev/">Braintrust</a> watches the production workload and creates test vectors that expose how an agent may be drifting, regressing, or departing from its path. The tool automates much of the testing and scoring feedback loop so problematic patterns can be discovered and addressed. A core part of the offering is a specialized data store that can track large and sometimes deeply nested collections of tests and their results. Their approach may be summarized by one of their tag lines: “trace everything.”</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free starter tier; <a href="https://www.braintrust.dev/pricing">Pro plan</a> starts at $249 with some usage-based costs covered</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Highly scalable trace ingestion</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams developing strong guardrails through continuous testing</p>



<h2 class="wp-block-heading">Chronicle Labs</h2>



<p class="wp-block-paragraph">When it’s time to release a new version of an agent into the wild, the <a href="https://chronicle-labs.com/">platform from Chronicle Labs </a>specializes in staging it and testing it with a collection of use tests and regression cases. The tools are also helpful during development cycles. “Backtest your agent against reality,” their sales material promises, with a set of tools that mines the production telemetry for solid test vectors that stress every part of the agent with prompts and challenges that the agent will encounter after leaving the safety of the lab.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> On <a href="https://chronicle-labs.com/book-call">request</a></p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Back-testing options for complex testing regimes</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams chasing strong models with good fidelity to reality</p>



<h2 class="wp-block-heading">Comet Opik</h2>



<p class="wp-block-paragraph">Building a dashboard for tracking every in-flow and out-flow to agents is one way to be ready to watch for and solve problems. <a href="https://www.comet.com/site/products/opik/">Opik from Comet </a>is just such a tool. The DevOps teams can track each call and add its own automated routines to examine the results, score them based on 30-plus metrics, and if desired, send it off to another LLM to evaluate the results. Agents that are constantly failing stand out. DevOps teams can also ask questions like, “Who is using this model and racking up all of the bills?” The same goes for MCP skills and other cogs in the machine.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tiers for open source and small projects; <a href="https://www.comet.com/site/pricing/">Pro plan</a> starts at $19 per month with usage limits</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Auto-scoring with 30-plus metrics for evaluating traces</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams focusing on RAG and agentic workflows</p>



<h2 class="wp-block-heading">Datadog</h2>



<p class="wp-block-paragraph">DevOps teams that rely on <a href="https://www.datadoghq.com/">Datadog</a> to track logs across collections of services can also use it to track LLM operations, which are, of course, just another source and sink for data. It will track performance such as time to first token and offer insight into what might be causing an issue, such as lack of memory. Results then get plugged into the same cost-tracking mechanism so the bean counters can predict when the budget will run out. After all, the CFO likely doesn’t care whether the bill comes from an LLM or an old-school S3 storage bucket. Datadog integrates AI into their tools by treating these models as just another source of data.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier with <a href="https://www.datadoghq.com/pricing/">multiple paid tiers</a> for various levels of enterprise monitoring</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Large installed base with broad focus on more than LLMs</p>



<p class="wp-block-paragraph"><em>Best for:</em> Large enterprise teams working with established infrastructure</p>



<h2 class="wp-block-heading">Dynatrace</h2>



<p class="wp-block-paragraph">For more than 20 years, <a href="https://www.dynatrace.com/">Dynatrace</a> has been delivering tools that track dataflows across the full stack. Now that AIs are finding roles in many of the nodes in this complex graph, they’re expanding to track how various AI agents can interact. They want to build one platform that helps track the root cause and, often now, deploy solutions autonomously. They want to focus on being ready to support complex networks of agents that detect problems in either performance or security and then work within defined guardrails to fix them. Determining the right role for their own AI-powered agents is a key part of the product.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.dynatrace.com/pricing/">Plans</a> start at $7 per month with larger plans designed for full enterprise monitoring</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> High level of autonomous monitoring designed for large installations</p>



<p class="wp-block-paragraph"><em>Best for: </em>Complex, hybrid environments mixing LLMs with traditional services</p>



<h2 class="wp-block-heading">Galileo</h2>



<p class="wp-block-paragraph">Placing some AI systems into production is often a harrowing experience because the actual performance is impossible to predict, even with the most rigorous tests. <a href="https://galileo.ai/">Galileo</a> offers guardrails that track performance and watch for any behavior that deviates from the ground truth. Their “LLM-as-judge” systems are distilled into compact models that can be run locally for lower costs and faster performance.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; Pro plans start at $50 per month with usage-based limits and costs</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Real-time guardrails for deployed agents</p>



<p class="wp-block-paragraph"><em>Best for:</em> Security-conscious installations that need to defend against hallucination and data leakage</p>



<h2 class="wp-block-heading">Grafana Labs</h2>



<p class="wp-block-paragraph">Long the go-to source for<a href="https://grafana.com/oss/"> open source </a>telemetry, <a href="https://grafana.com/products/cloud/ai-assistant/?pg=hp&amp;plcmt=txt-img-alternating">Grafana Labs</a> now tracks performance of AI models in constellations of services. Grafana tracks the evolution of answers across the agentic network to recognize how small changes or hallucinations can spin out of control. It bills its system as “actually useful AI” and has even trademarked it. Its cloud assistant can configure and reconfigure the Grafana dash to offer the right level of observability. Its system includes AI-level analysis that can flag models that are responding quickly but offering bad answers because of problems such as model drift or context degradation.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Basic free tier; <a href="https://grafana.com/pricing/">Pro plan</a> begins at $19 per month, includes better retention and some usage-based fees </p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Full-stack tool with fully integrated LLM tools</p>



<p class="wp-block-paragraph"><em>Best for:</em> Large, enterprise-scale system adding AI</p>



<h2 class="wp-block-heading">Helicone</h2>



<p class="wp-block-paragraph">Sometimes shoehorning in another tool into the chain can be tricky. <a href="https://www.helicone.ai/">Helicone</a> is designed as a smart network proxy that will route all model requests while keeping solid debugging records from the data as it goes by. The data it captures can be turned into nice charts that make it easy to spot latency issues or model failures. Naturally, tracking AI spend is also a feature in much demand as bills continue to climb.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://www.helicone.ai/pricing">Pro plan</a> starts at $79 per month, includes features such as team collaboration and improved querying</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Proxy-based integration</p>



<p class="wp-block-paragraph"><em>Best for:</em> Development teams who want to add better monitoring features quickly</p>



<h2 class="wp-block-heading">Laminar</h2>



<p class="wp-block-paragraph">Tracking agents in development and production means building strong storehouses of data enumerating what happened. <a href="https://laminar.sh/">Laminar</a> works closely with OpenTelemetry to follow agents operating in production so that flaws and failure modes can be understood from log files stored efficiently with their own compression scheme. Developers can search through traces with an SQL-ish language and Laminar’s transcript view illuminates what happened. When necessary, the traces can enable developers to scroll back in time and replay the same inputs for debugging. The goal is to offer deep insights with high-level visibility of how well the agents are meeting business objectives.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; “Hobby” tier that adds more features at $30; <a href="https://laminar.sh/pricing">Pro level</a> starts at $150 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Open-source license makes self-hosting a viable option</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams fully able to leverage open-source responsibilities</p>



<h2 class="wp-block-heading">LangChain LangSmith</h2>



<p class="wp-block-paragraph">Real-time data from agents is essential for managing any mutli-agent system in production. LangSmith from <a href="https://www.langchain.com/">LangChain</a> traces costs, tools, and progress toward solutions for a wide collection of agents using SDKs for Python, TypeScript, Go, and Java. The OpenTelemetry-based solution watches for anomalies, issuing warnings and alerts through dashboards and communication channels such as PagerDuty. Deeper analysis can reveal issues such as topic clustering or odd patterns of failure. Coordination with agent deployment platforms such as LangGraph and deepagents ensures greater focus on successful resolution of assignments.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free for solo developers; <a href="https://www.langchain.com/pricing">Pro teams</a> start at $39 per person per month </p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Systematic approach to regression testing of prompts</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams relying on LangChain and LangGraph frameworks for supporting complex agentic behavior</p>



<h2 class="wp-block-heading">Lunary</h2>



<p class="wp-block-paragraph">Watching the user experience is essential for building AI applications such as chatbots and assistants. <a href="https://lunary.ai/">Lunary</a> offers a proxy that traces all interactions and then builds analytical dashboards for measuring metrics such as user satisfaction or model costs. One common usage is finding frequent topics and looking at the responses to ensure they deliver. When prompts aren’t perfect, Lunary lets teams iterate on the prompt text until the right answers are coming out. Its proxy structure and common API format enables Lunary to promise to work with “any LLM, any framework.”</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tier; <a href="https://lunary.ai/pricing">Pro plan</a> starts at $20 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Deep integration with humans for reviewing and optimizing results</p>



<p class="wp-block-paragraph"><em>Best for:</em> Startups focused on rapid prompt innovation</p>



<h2 class="wp-block-heading">NewRelic</h2>



<p class="wp-block-paragraph">The platform that began tracking performance of some web applications is now powerful enough to track the flows of data through complex agentic ecologies. <a href="https://newrelic.com/platform/ai-observability">NewRelic’s</a> AI-driven monitoring watches for golden signals that can indicate misbehavior or worse throughout the entire lifecycle. It tracks every detail of the interactions through protocols such as MCP and then makes this available to the AI engineers responsible for performance. The dashboard provides the insights necessary to watch for toxic behavior, overt bias, drift, and overblown hallucinations. Predicting and maybe even controlling the cost is also a growing role as tokenomics becomes as important as response time.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Free tier; Pro plan fees available through website</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Full-stack support with hundreds of integrations with other tools</p>



<p class="wp-block-paragraph"><em>Best for:</em> Established enterprise teams mixing in AI</p>



<h2 class="wp-block-heading">Nova AI Ops</h2>



<p class="wp-block-paragraph">The goal of <a href="https://novaaiops.com/">Nova AI Ops </a>is to deliver a team of agents that watch over a cloud and make it, at least partially, self-healing. Each agent uses a mixture of predictive AI and machine learning to watch cloud telemetry reports for anomalies. Then they calculate the “blast radius” and decide whether this is a problem that can be fixed automatically “while you sleep” or saved for the human supervisors. These tools are aimed not just on LLM operations but on the stack as a whole.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier; <a href="https://novaaiops.com/pricing">Standard pricing </a> begins at $40 per user per month with usage billing</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Focus on software reliability engineering helps teams deliver stable stacks</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams that want to integrate LLMs into incident response and stability management</p>



<h2 class="wp-block-heading">Splunk</h2>



<p class="wp-block-paragraph">The platform that began delivering smart logging is now fully AI capable, offering solutions that can watch over agents with much the same way that it continues to track microservices. <a href="https://www.splunk.com/en_us/solutions/splunk-artificial-intelligence.html">Splunk</a> now includes a fairly large amount of predictive AI for learning from the information in the logs and then turning this learning into fast solutions. This AI assistant can track deployed AI models connected by protocols such as MCP and watch over behavior while delivering the ability for users to drill down and explore what’s working and what’s failing. Their AI Canvas is meant to offer a central hub where the AI scientists can track both the local behavior of the models as well as their role in a larger data ecosystem.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> <a href="https://www.splunk.com/en_us/resources/splunk-pricing-options.html">Activity-based pricing</a> tracks usage of LLM backends and storage</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Ready to scale to large enterprise stacks</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams with legacy systems that are folding in agentic options</p>



<h2 class="wp-block-heading">SuperPenguin</h2>



<p class="wp-block-paragraph">One of the most important parts of an AI service is the bill. <a href="https://superpenguin.ai/#features">SuperPenguin</a> is a product designed to track consumption and make predictions so that the CFO won’t be surprised. The goal is to provide solid estimates about the total cost of each product by allocating costs to customers, features, and teams. If there’s a sudden shift, a “spike detector” will raise an alarm so that dev teams can ensure that the AI spend is worth it.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Small free tier for experimentation; Growth tier for teams, starting at $30 per month; <a href="https://superpenguin.ai/#pricing">Pro tier </a>offers deeper options starting at $200 per month</p>



<p class="wp-block-paragraph"><em>Standout feature: </em>Strong accounting with invoice reconciliation and PR-level usage tracking</p>



<p class="wp-block-paragraph"><em>Best for:</em> Teams that need precise cost accounting</p>



<h2 class="wp-block-heading">Vellum</h2>



<p class="wp-block-paragraph">Prompt engineers spend time fussing over the details of tweaking, improving, and enhancing the words that guide the LLM. <a href="https://www.vellum.ai/">Vellum</a> started as a company that would provide the pipeline so that you could manage and improve the prompts that ran again and again. Now the system is growing more powerful, offering a higher level of automation that lets you meta-manage the prompt chain. They’ve also begun marketing it as a form of personal assistant with pre-built connections to many of the major services such as Gmail. Its <a href="https://github.com/vellum-ai/llm-cost-optimizer">llm-cost-optimizer </a>can juggle multiple options while finding a cheaper way to execute a prompt, a process the company suggests can save 60% or more.</p>



<p class="wp-block-paragraph"><em>Pricing:</em> Open-source free tier; Pro plan starts at $35 per month</p>



<p class="wp-block-paragraph"><em>Standout feature:</em> Focus on multi-model pipelines for true agentic solutions</p>



<p class="wp-block-paragraph"><em>Best for:</em> Product teams with complex prompt engineering workflows</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spotify just made managed accounts free for all parents, no Premium required]]></title>
<description><![CDATA[Spotify managed accounts are now available to many more families after Spotify removed the Premium subscription requirement for parents and guardians. Starting today, parents with a free Spotify account can create a managed account for their child in supported countries, making it easier to give ...]]></description>
<link>https://tsecurity.de/de/3671486/ios-mac-os/spotify-just-made-managed-accounts-free-for-all-parents-no-premium-required/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671486/ios-mac-os/spotify-just-made-managed-accounts-free-for-all-parents-no-premium-required/</guid>
<pubDate>Wed, 15 Jul 2026 19:25:41 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spotify managed accounts are now available to many more families after Spotify removed the Premium subscription requirement for parents and guardians. Starting today, parents with a free Spotify account can create a managed account for their child in supported countries, making it easier to give young listeners a safer music experience with built in parental controls.



Spotify managed accounts now available on free accounts



Spotify says parents can now create a free managed account for children under 13 in the United States, the United Kingdom, Australia, France, Germany, and the Netherlands, while more countries across Europe, Latin America, and other regions will receive the feature soon.




"Managed accounts let young listeners explore music only, while you control the experience."




Parents can add a child account from the Spotify home page by selecting Add account and then Add a child under 13. During setup, they can filter explicit content, block specific songs or artists, disable videos and Canvas, and protect the main account with a PIN when using a shared device.



Spotify says managed accounts keep a child's music activity separate from the parent's account, which means recommendations, playlists, and Spotify Wrapped stay independent. Children also receive personalized music features such as Discover Weekly and Daylist while remaining in a music only environment without access to podcasts or audiobooks.




"Profiles can't be followed or searched by other users" and managed accounts also have "no in app purchases."




The company explains that managed accounts work on phones, tablets, and speakers, and children do not need their own phone to use one. Parents can manage up to 10 child accounts on the free plan, while Premium Family subscribers can also assign available Family plan slots to managed accounts for ad free listening and offline downloads.



Spotify adds that managed accounts can become regular Spotify accounts once children reach the minimum age in their country, although parents must approve the change until the user turns 18.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub Copilot introduces upgrade canvas for modernizing .NET applications]]></title>
<description><![CDATA[GitHub Copilot has introduced an interactive canvas that makes it easier to follow, review, and steer the actions of the upgrade agent as it modernizes .NET applications.



The GitHub Copilot upgrade agent assesses the application, generates a structured upgrade plan, creates implementation task...]]></description>
<link>https://tsecurity.de/de/3671164/ai-nachrichten/github-copilot-introduces-upgrade-canvas-for-modernizing-net-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671164/ai-nachrichten/github-copilot-introduces-upgrade-canvas-for-modernizing-net-applications/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">GitHub Copilot has introduced an interactive canvas that makes it easier to follow, review, and steer the actions of the upgrade agent as it modernizes .NET applications.</p>



<p class="wp-block-paragraph">The <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a> upgrade agent assesses the application, generates a structured upgrade plan, creates implementation tasks, and executes the work, according to a <a href="https://devblogs.microsoft.com/dotnet/modernize-dotnet-in-github-copilot-app/">July 9 bulletin</a> from Microsoft. Now developers can follow that workflow in the GitHub Copilot app through an interactive upgrade canvas. The upgrade canvas provides a live view of the modernization workflow as it unfolds, Microsoft said.</p>



<p class="wp-block-paragraph">This agent upgrade agent starts by assessing the .NET application and identifying what needs to change:</p>



<ul class="wp-block-list">
<li>What version of .NET is this application targeting?</li>



<li>Which NuGet packages need to be updated?</li>



<li>Are there breaking API changes?</li>



<li>Which projects can be upgraded independently?</li>



<li>What should happen first?</li>
</ul>



<p class="wp-block-paragraph">From this point, the agent generates a structured upgrade plan and breaks the work into actionable implementation tasks. While the GitHub Copilot app provides the interactive upgrade canvas, GitHub Copilot upgrade also is available in the following tools:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/dotnet/core/porting/github-copilot-app-modernization/install?pivots=visualstudio" target="_blank" rel="noreferrer noopener">Visual Studio</a> – Built directly into Visual Studio. Right-click a solution or project in Solution Explorer and select Modernize to start a .NET upgrade.</li>



<li><a href="https://marketplace.visualstudio.com/items?itemName=ms-dotnettools.upgrade-agent" target="_blank" rel="noreferrer noopener">Visual Studio Code</a> – Install the GitHub Copilot upgrade extension, select the Upgrade agent from the agent picker dropdown menu, and prompt the agent to modernize your .NET application.</li>



<li><a href="https://learn.microsoft.com/dotnet/core/porting/github-copilot-app-modernization/install?pivots=copilot-cli" target="_blank" rel="noreferrer noopener">GitHub Copilot CLI</a> – Install the GitHub Copilot upgrade plugin to assess, plan, and execute .NET upgrades directly from the terminal.</li>
</ul>



<p class="wp-block-paragraph">Developers can get started with GitHub Copilot and the GitHub Copilot upgrade agent by visiting the <a href="https://github.com/copilot/app/launch?entry_point=upgrade_agent_plugins_readme&amp;open=ghapp%3A%2F%2Fplugins%2Fmarketplace%2Fadd%3Fsource%3Dmicrosoft%2Fupgrade-agent-plugins">GitHub Copilot upgrade marketplace</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI blames email mixup for why it didn't respond to Apple trade theft claims]]></title>
<description><![CDATA[It seemed as if the last straw for Apple was how OpenAI failed to respond to complaints about trade secret theft, but the ChatGPT maker says it did reply and the real problem is a lack of attention to detail by Apple's lawyers.OpenAI CEO Sam Altman - image credit: Emerson CollectiveApple is suing...]]></description>
<link>https://tsecurity.de/de/3671064/ios-mac-os/openai-blames-email-mixup-for-why-it-didnt-respond-to-apple-trade-theft-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671064/ios-mac-os/openai-blames-email-mixup-for-why-it-didnt-respond-to-apple-trade-theft-claims/</guid>
<pubDate>Wed, 15 Jul 2026 16:57:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It seemed as if the last straw for Apple was how OpenAI failed to respond to complaints about trade secret theft, but the ChatGPT maker says it did reply and the real problem is a lack of attention to detail by Apple's lawyers.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68254-143883-000-lead-Sam-Altman-xl.jpg" alt="Man with short brown hair wearing a tan long sleeve shirt and clip-on microphone, seated against a dark background, looking slightly to the side with a neutral thoughtful expression" height="720" class=""><br><span>OpenAI CEO Sam Altman - image credit: Emerson Collective</span></div><br>Apple is <a href="https://appleinsider.com/articles/26/07/10/apple-sues-openai-previous-vp-of-product-design-over-mass-ip-theft">suing OpenAI</a> over alleged theft of intellectual property, and initially the firm's response was an <a href="https://appleinsider.com/articles/26/07/14/openai-shrugs-denies-responsibility-for-trade-secret-theft-with-vague-statements">empty claim</a> of being unaware of the issue. However, as <a href="https://www.nbcnews.com/tech/apple/apple-openai-lawsuit-suit-trade-product-hardware-email-sam-altman-rcna587376">first spotted</a> by <em>NBC</em>, OpenAI's lawyers are now concentrating on an issue they seem to think derails the whole suit.<br><br>Reportedly, despite Apple saying that OpenAI failed to even respond to its allegations of trade secret theft, the company says it did. A source that is unknown but difficult not to guess, has shared OpenAI emails with NBC and they apparently do confirm that the firm responded.<br><br><br> <a href="https://appleinsider.com/articles/26/07/15/openai-blames-email-mixup-for-why-it-didnt-respond-to-apple-trade-theft-claims?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244963?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to unionize your tech workplace]]></title>
<description><![CDATA[This is Part 2 of a series on tech worker unionization. See Part 1: “A brewing battle: More IT workers want unions. The industry doesn’t.”



The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.



Mass layoff...]]></description>
<link>https://tsecurity.de/de/3670454/it-nachrichten/how-to-unionize-your-tech-workplace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670454/it-nachrichten/how-to-unionize-your-tech-workplace/</guid>
<pubDate>Wed, 15 Jul 2026 13:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><em>This is Part 2 of a series on tech worker unionization. See Part 1: “<a href="https://www.computerworld.com/article/4191760/brewing-battle-more-tech-workers-want-unions-but-the-industry-doesnt.html">A brewing battle: More IT workers want unions. The industry doesn’t</a>.”</em></p>



<p class="wp-block-paragraph">The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.</p>



<p class="wp-block-paragraph">Mass layoffs, AI-driven displacement, corporate surveillance, workplace disillusionment have created conditions that have made organizing compelling for tech professionals. But the federal labor board that has historically protected workers’ right to organize has been weakened, and the companies that once feared it are openly defying it.</p>



<p class="wp-block-paragraph">Here’s how organizers and labor experts describe the pros and cons to organizing — and how you can get started.</p>



<h2 class="wp-block-heading">What unions can — and can’t — do for you</h2>



<p class="wp-block-paragraph">The single biggest benefit of a union contract for most tech workers isn’t pay — it’s protection against arbitrary termination, especially in the wake of recent mass layoffs in tech. In the United States, nonunion “at-will” workers can be fired at any time without a stated reason, while unionized workers negotiate protections written into their contracts.</p>



<p class="wp-block-paragraph">“That fear of the company letting you go for anything at any time…with a union they just can’t do that,” says <a href="https://www.linkedin.com/in/zthompson1/" target="_blank" rel="noreferrer noopener">Zak Thompson</a>, a senior software engineer at Kickstarter and union steward at Kickstarter United. Now that Kickstarter employees are unionized, people are less worried that saying something negative will result in termination.</p>



<p class="wp-block-paragraph">“I’ve been shocked at the willingness of my co-workers to speak up against what they see as poor or controversial business decisions,” Thompson says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="972" height="972" sizes="auto, (max-width: 972px) 100vw, 972px"&gt;<figcaption class="wp-element-caption"><p>Zak Thompson from Kickstarter United</p><br></figcaption></figure><p class="imageCredit">Fee Christoph</p></div>



<p class="wp-block-paragraph"><strong>Beyond job security, unions can deliver concrete material gains.</strong> <a href="https://kickstarterunited.org/about/" target="_blank" rel="noreferrer noopener">Kickstarter United was formed in 2020</a>, although getting there wasn’t easy: two employees were fired during the organizing campaign — which itself became a galvanizing event. And while the union hasn’t been able to prevent layoffs, it did negotiate better terms: four months of severance pay and four to six months of continued health insurance, versus the two to three weeks per year of work that management had initially proposed.</p>



<p class="wp-block-paragraph">Other benefits include a four-day work week; AI protections; a minimum pay floor; and standards for raises, promotions, and time off for the company’s 59 employees.</p>



<p class="wp-block-paragraph"><strong>Unions can give tech workers a voice in decisions that affect their daily work — including how AI tools are deployed.</strong> “Nobody I’ve spoken to is against new technology or getting trained in it,” says <a href="https://www.linkedin.com/in/mbelasco/" target="_blank" rel="noreferrer noopener">Max Belasco</a>, a business systems analyst at the University of California Los Angeles School of Law and co-chair of the UCLA chapter of the University Professional and Technical Employees/Communications Workers of America (UPTE-CWA) Local 9119.</p>



<p class="wp-block-paragraph">“But when new technology is being implemented, we want to know: what’s the five-year vision, the 10-year vision? Are we implementing this in a way that betters staffing, increases efficiency, or eases the lives of people already working? Or are we trying to take away jobs, automate people out of their pension or paycheck?” Belasco says.</p>



<p class="wp-block-paragraph"><strong>The challenges are real.</strong> Tech professionals are less inclined to leave their jobs in the current market because wages haven’t been increasing as fast as they once were, and it can take longer to land another job.</p>



<p class="wp-block-paragraph">“Tech moved from a very tight labor market in 2022 (1.85% unemployment rate) to a noticeably weaker one in 2024–2026 (3.49%),” although that’s still better than the national unemployment rate of 4.36% through May of this year, says <a href="https://www.mercatus.org/scholars/liya-palagashvili" target="_blank" rel="noreferrer noopener">Liya Palagashvili</a>, senior research fellow and director of the Labor Policy Project at the Mercatus Center at George Mason University.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="960" height="640" sizes="auto, (max-width: 960px) 100vw, 960px"&gt;<figcaption class="wp-element-caption"><p>Liya Palagashvili of the Mercatus Center at George Mason University</p></figcaption></figure><p class="imageCredit">Mercatus Center at George Mason University</p></div>



<p class="wp-block-paragraph"><strong>Flexibility is a concern.</strong> The more substantive challenge, raised by economists including Palagashvili, is that traditional union contracts impose uniform terms across an entire bargaining unit, limiting the flexibility that many tech workers — and their employers —currently enjoy. Tech firms need to move fast, adjusting teams, products, and roles on the fly.</p>



<p class="wp-block-paragraph">“Collective bargaining agreements can make those adjustments much more difficult, whether by making them slower, costlier, or inconsistent with the contract,” she says.</p>



<p class="wp-block-paragraph">Workers skeptical of unions in a <a href="https://www.teamblind.com/blog/why-are-unions-not-common-tech-industry/" target="_blank" rel="noreferrer noopener">survey of 1,900 tech professionals</a> conducted by the career site Blind cited specific concerns: that unions are “not meritocratic,” “prevent innovation,” and “hold back earnings of top performers.”</p>



<p class="wp-block-paragraph">Thompson from Kickstarter United pushes back: “We have nothing in our contract about ‘you can’t bend down and pick up a piece of trash because that’s someone else’s job.’ The company is free to give bonuses and individual raises as much as they like. This is all just up to the people who are bargaining the contract from the union side.”</p>



<p class="wp-block-paragraph"><strong>Organizing carries potentially serious personal risks.</strong> During negotiations for a second three-year contract in 2025, Kickstarter United went on strike for 42 days. A few months later, the company announced layoffs.</p>



<p class="wp-block-paragraph">“They let go strong union leaders, including a person who had bargained our last contract,” Thompson says. The union appealed, and the issue is now going to arbitration.</p>



<p class="wp-block-paragraph">If you form a union, don’t expect much support from the <a href="https://www.nlrb.gov/" target="_blank" rel="noreferrer noopener">National Labor Relations Board</a>, the agency that certifies US labor unions and protects workers’ right to organize, in terms of prosecuting complaints of unfair labor practices, Thompson warns. “We’re in a political moment in this country with a pretty weakened NLRB. You have to be ready to organize and withhold worker power without any guarantee of safety.”</p>



<p class="wp-block-paragraph"><strong>Organizers are up against an enormous union avoidance industry.</strong> Organizers can expect fierce pushback as soon as the business discovers that organizing is underway.</p>



<p class="wp-block-paragraph">“There’s a multi-billion-dollar industry in union avoidance,” says <a href="https://www.linkedin.com/in/alan-mcavinney-a386b8122/" target="_blank" rel="noreferrer noopener">Alan McAvinney</a>, a Google software engineer and organizing chair, Alphabet Workers Union-CWA, a 1,400-member minority union of Alphabet employees. (Google is a subsidiary of Alphabet.)</p>



<p class="wp-block-paragraph">US employers spend roughly $1.7 billion a year on union avoidance consultants and law firms, according to a <a href="https://www.epi.org/press/u-s-employers-spend-roughly-1-7-billion-annually-on-union-avoidance/" target="_blank" rel="noreferrer noopener">May 2026 report</a> by the Economic Policy Institute and LaborLab.</p>



<p class="wp-block-paragraph"><strong>Expect hardball tactics. </strong>Management may play hardball during the time between when organizers announce their intention to unionize and the actual vote. For example, management can threaten to fire foreign-born workers in the US on H-1B visas if they support the union. Those workers would then have just 60 days to find a new sponsoring employer or lose their H-1B status, according to a recent <a href="https://techworkerscoalition.org/blog/2025/03/14/immigrant-rights-are-labor-rights-tech-workers-and-h-1b-visas/" target="_blank" rel="noreferrer noopener">Tech Workers Coalition blog post</a>.</p>



<p class="wp-block-paragraph">And at venture capital-backed startups, investment agreements sometimes require management to attest there is no union activity — meaning a public organizing drive can trigger funding withdrawal. Or, if a unionized company is acquired, the new management can dissolve the union overnight by reclassifying unionized workers as new hires.</p>



<p class="wp-block-paragraph">With these sobering facts in mind, here is how organizers who have done it describe the process of creating a union.</p>



<h2 class="wp-block-heading">Step 1: Start a conversation with your co-workers</h2>



<p class="wp-block-paragraph">At the University of California, a two-tier system had evolved where some tech workers were unionized and some weren’t, Belasco says. Management created new titles that fell outside the union even though they had similar job descriptions and responsibilities to those in the union. Those nonunion employees received lower pay and benefits than their unionized peers, which created resentment and instability.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Max Belasco from the UCLA chapter of UPTE-CWA</p>
</figcaption></figure><p class="imageCredit">Zac Goldstein</p></div>



<p class="wp-block-paragraph">Belasco and other organizers wanted to eliminate that division by bringing everyone under the same contract. But when they began their unionization drive, “the biggest barrier we faced wasn’t management opposition — it was that people felt this was just the best-case scenario realistically available: ‘We have this job at the university, we have concerns about automation and layoffs, but what can we really do about it?'” he says.</p>



<p class="wp-block-paragraph">The antidote to that fatalism, organizers say, is simple: “Just start talking to your immediate co-workers. Are they experiencing the same challenges you are experiencing?” says McAvinney. “There’s no need to start talking about a union at this point.”</p>



<p class="wp-block-paragraph">Just get a consensus and start building a group of like-minded individuals, Thompson advises. “Always start with one-on-one conversations, and that’s what you should do the whole time. That’s the key to organizing,” he says.</p>



<p class="wp-block-paragraph">Tech workers often think they’re a special case, says Thompson, and therefore that unionization isn’t a good fit. “You’re not special. You are a company of workers, you are organizing, and there is a playbook for that. Trust the process, because it tends to work pretty well,” he says.</p>



<h2 class="wp-block-heading">Step 2: Who’s on board, and who’s not? Map your workplace, but keep it quiet</h2>



<p class="wp-block-paragraph">Once there’s a consensus, continue to grow your network. Keep a list of everyone you’ve spoken with and note their disposition: “Is this person union-friendly or anti-union? Would they be a strong organizer?” Thompson says.</p>



<p class="wp-block-paragraph">Maintaining secrecy early on is essential, because anti-union tactics will start immediately, and that can stop union organizing before it can gain momentum.</p>



<p class="wp-block-paragraph">“Generally, employers do not want to share power with their workforce,” McAvinney says. Employers will deploy every means at their disposal to stop organizing efforts and peel away potential yes votes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="839" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Alan McAvinney from Alphabet Workers Union-CWA</p><br></figcaption></figure><p class="imageCredit">Aran Per Ink</p></div>



<p class="wp-block-paragraph">“If you look at historical examples, having 70% approval before the employer finds out about you results in a high percentage of wins when you actually cast the vote. Historically, that’s an effective buffer,” he says.</p>



<p class="wp-block-paragraph">There’s a real threat of firing and layoffs<em>.</em> The traditional tech worker belief that job mobility makes collective action unnecessary is now being tested by a tighter job market, McAvinney says, noting that workers who many believe <a href="https://www.newsweek.com/google-fires-thanksgiving-four-workers-crush-dissent-1474102" target="_blank" rel="noreferrer noopener">were fired for speaking out</a> back in 2019 were a galvanizing factor in his union’s formation.</p>



<p class="wp-block-paragraph">“You generally don’t want to be in a situation where the employer feels comfortable firing everyone. Part of that is thinking from a cynical standpoint about what the consequences would be to the employer if they did fire everyone,” he says.</p>



<p class="wp-block-paragraph">One-on-one conversations that include personally asking co-workers to keep conversations confidential are key to keeping things quiet, Belasco says. When <a href="https://upte.org/news/2100-tech-workers-vote-to-join-upte" target="_blank" rel="noreferrer noopener">2,100 UC tech workers voted to unionize</a> in May, 96% voted in favor. To stay out of earshot of managers, avoid employee surveillance tools, and sidestep conference calls that could be recorded, organizers met with workers in their homes.</p>



<p class="wp-block-paragraph">“That tactic is probably what made the difference between winning the election and getting the majority we got,” he says.</p>



<h2 class="wp-block-heading">Step 3: Find the right union affiliation or go it alone</h2>



<p class="wp-block-paragraph">“Running a campaign against major employers requires the resources and expertise of the larger labor movement, even if workers publicly present as independent,” says <a href="https://www.ilr.cornell.edu/people/kate-l-bronfenbrenner">Kate Bronfenbrenner</a>, director of labor education research and senior lecturer emeritus at Cornell University’s School of Industrial and Labor Relations.</p>



<p class="wp-block-paragraph">Options include the <a href="https://cwa-union.org/" target="_blank" rel="noreferrer noopener">Communications Workers of America</a> (CWA), <a href="https://www.seiu.org/" target="_blank" rel="noreferrer noopener">Service Employees International Union</a> (SEIU), and the <a href="https://www.opeiu.org/" target="_blank" rel="noreferrer noopener">Office and Professional Employees International Union</a> (OPEIU), among others. Another resource, the <a href="https://techworkerscoalition.org/">Tech Workers Coalition</a> (TWC), provides training on organizing tactics, AI-in-workplace issues, and contract negotiation, and can match workers to the right unions for their needs.</p>



<p class="wp-block-paragraph">The <a href="https://www.alphabetworkersunion.org/" target="_blank" rel="noreferrer noopener">Alphabet Workers Union</a> decided early on to affiliate with CWA. “They gave us a bunch of support early on in our campaign with no strings attached,” McAvinney says.</p>



<p class="wp-block-paragraph">Kickstarter is organized through OPEIU, Thompson says. “They’ll usually have resources and staff that can help you through the next steps: collecting signatures in support of a union, bringing that to management, holding a vote — the more formalized things that interact with US labor law. They’ll also help with organizing along the way,” he says.</p>



<p class="wp-block-paragraph">For workers at institutions where a union already exists, there may be a faster path. Organizers at UCLA did what’s called a “unit modification,” aligning with UPTE. By organizing under UPTE, the workers didn’t have to negotiate a new contract from scratch — they joined an already-negotiated contract covering existing UPTE tech members, which put them in “a much stronger position” than starting fresh, Belasco says.</p>



<h2 class="wp-block-heading">Step 4: Choose your union model: majority vs. pre-majority or minority</h2>



<p class="wp-block-paragraph">Assess what’s practical for your organizing effort. In a majority union, more than 50% of all workers in a defined bargaining unit must vote to join the union through an NLRB-supervised election in the private sector, or a Public Employment Relations Board (PERB)-supervised election for public sector workers.</p>



<p class="wp-block-paragraph">The NLRB must certify the union, which then operates under its legal protections. This means, for example, that the employer must bargain, negotiated contracts are enforceable, violations must go to the NLRB or arbitration, and workers can’t be dismissed without just cause.</p>



<p class="wp-block-paragraph">A pre-majority or minority union is a minority labor organization operating without NLRB protections or collective bargaining agreements. “Pre-majority means that workers are able to demonstrate majority support — through signed cards, petitions, a walkout, or everyone wearing solidarity T-shirts — without going through a formal election,” Bronfenbrenner says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Kate Bronfenbrenner from the School of Industrial and Labor Relations, Cornell University</p><br></figcaption></figure><p class="imageCredit">ILR School/Cornell University</p></div>



<p class="wp-block-paragraph">The Alphabet Workers Union-CWA (AWU-CWA) formed as a pre-majority union because achieving majority status across a globally distributed workforce of over 100,000 was not a realistic near-term goal. “An underground model where you try to reach 70% support across a workforce of over 100,000 people isn’t realistic,” McAvinney says.</p>



<p class="wp-block-paragraph">A pre-majority union can still make a difference, he says. For example, the Alphabet Workers Union-CWA convinced management to offer voluntary exit packages — buyouts — prior to announcing layoffs.</p>



<p class="wp-block-paragraph">For smaller organizations, a majority union may be the more practical option — it’s more attainable, McAvinney says. “I don’t think [the pre-majority union model] is the correct thing to do in all situations. I certainly would not recommend it to a 200-person shop.”</p>



<p class="wp-block-paragraph">Kickstarter, which had fewer than 100 employees, was able to form a majority union, with 55% voting to organize.</p>



<p class="wp-block-paragraph">Ultimately, says McAvinney, “there’s no inflection point where you go from being able to win nothing to winning everything, even with a contract and a supermajority. But the more people you have who are willing and able to fight for what they want, the more you’ll be able to get.”</p>



<h2 class="wp-block-heading">Step 5: Who should — and should not — be in your union?</h2>



<p class="wp-block-paragraph">Belasco’s situation at UCLA illustrates a broader strategic choice that every organizing campaign must make. He had been in a union position in educational technology when he was told his role would be reclassified as a non-union position.</p>



<p class="wp-block-paragraph">“I was given a choice: apply to the new non-union position to continue doing the work I’d trained for, or stay in my union position doing service desk work I wasn’t used to,” he says. “Essentially, it was a choice between job security and career progression.”</p>



<p class="wp-block-paragraph">Belasco joined a “wall-to-wall” union, which represents a broad range of university professional and technical employees across the UC system rather than a single job category, such as engineers or tech professionals.</p>



<p class="wp-block-paragraph">Kickstarter United is another example of a wall-to-wall union. “It’s not just the engineers who are unionized, but also customer support, designers — everyone,” Thompson says.</p>



<p class="wp-block-paragraph">Wall-to-wall unions are more powerful, but they’re also more difficult to achieve. <a href="https://www.law.cornell.edu/uscode/text/29/159" target="_blank" rel="noreferrer noopener">Under US labor law</a>, “professionals have to vote separately on whether they want to be combined with other workers,” says Bronfenbrenner. “You can never have a wall-to-wall unit without giving professionals the chance to decide whether they want to be separate.”</p>



<p class="wp-block-paragraph">The law’s “professional employees” category includes roles like software engineers and developers but not necessarily others. For example, customer support specialists and QA analysts would fall into the “non-professional workers” category.</p>



<p class="wp-block-paragraph">“For decades, the pattern was either to organize everybody except the engineers, or manage to organize the engineers and fail to bring in everybody else — neither of which builds real worker power,” says <a href="https://www.linkedin.com/in/simonerobutti/" target="_blank" rel="noreferrer noopener">Simone Robutti</a>, an organizer with Tech Workers Coalition Global, an international branch of TWC based in Berlin.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="959" height="713" sizes="auto, (max-width: 959px) 100vw, 959px"&gt;<figcaption class="wp-element-caption"><p>Simone Robutti from Tech Workers Coalition Global</p><br></figcaption></figure><p class="imageCredit">TWC</p></div>



<h2 class="wp-block-heading">Step 6: You won the vote. Get ready for what comes next</h2>



<p class="wp-block-paragraph">Winning a union vote means having a seat at the table, says Thompson. “Once the workers have come together and agreed they want that seat, you bring that to management, and they have a chance to voluntarily recognize a union,” he says.</p>



<p class="wp-block-paragraph">But in most cases employers contest the results, which must be certified by the NLRB or PERB. That process, in which the employer uses various tactics to challenge the legitimacy of the outcome, can take weeks or months.</p>



<p class="wp-block-paragraph">Unfortunately, the legal framework that is supposed to protect workers during this process has been <a href="https://workerorganizing.org/elon-musk-spacex-nlrb-15975/#:~:text=CAN%20THE%20NLRB%20STILL%20ENFORCE%20LAWS%3F" target="_blank" rel="noreferrer noopener">significantly weakened</a> in the last few years. In a potentially more ominous development, <a href="https://apnews.com/article/amazon-nlrb-unconstitutional-spacex-elon-musk-ab42977117d883e97110a7bf8e8b257f" target="_blank" rel="noreferrer noopener">SpaceX</a>, <a href="https://apnews.com/article/amazon-nlrb-50ee06d87d4eaef22386382761335ef8" target="_blank" rel="noreferrer noopener">Amazon</a>, <a href="https://www.huffpost.com/entry/trader-joes-attorney-nlrb-unconstitutional_n_65b41e7ae4b014b873b11cc2" target="_blank" rel="noreferrer noopener">Trader Joe’s</a>, <a href="https://news.bloomberglaw.com/daily-labor-report/starbucks-is-latest-company-to-call-labor-board-unconstitutional" target="_blank" rel="noreferrer noopener">Starbucks</a>, and the <a href="https://capitalandmain.com/usc-follows-amazon-and-musks-spacex-in-calling-labor-board-unconstitutional" target="_blank" rel="noreferrer noopener">University of Southern California</a> have in separate legal actions <a href="https://www.epi.org/blog/whats-behind-the-corporate-effort-to-kneecap-the-national-labor-relations-board-spacex-amazon-trader-joes-and-starbucks-are-trying-to-have-the-nlrb-declared-unconstitutional/" target="_blank" rel="noreferrer noopener">challenged the constitutionality of the NLRB</a>, arguing that the agency’s structure violates the separation of powers. The Fifth Circuit Court of Appeals <a href="https://law.justia.com/cases/federal/appellate-courts/ca5/24-50627/24-50627-2025-08-19.html?__cf_chl_f_tk=do9nl63o6rfY2sxOjPeR5MkVGY4u1OTRYOVYjTQTOG0-1782836265-1.0.1.1-IXqkGFSiOH5hYYOqqrEqH6VFIApNL3MRHW6YNiDwERI" target="_blank" rel="noreferrer noopener">upheld injunctions against the NLRB</a> in SpaceX’s case in August 2025 — a serious challenge to the agency’s authority.</p>



<p class="wp-block-paragraph">In the meantime, some companies may disregard negotiated contracts, which can lead to lengthy legal appeals or extended arbitration.</p>



<p class="wp-block-paragraph">“The NLRB can still force an election, but it can’t force a contract, and companies are saying they simply won’t comply,” Bronfenbrenner says. This is where the expertise and resources of affiliation with a major union can help, she adds.</p>



<p class="wp-block-paragraph">As a result, contract negotiations can take far longer than workers might expect. At Kickstarter, for example, two years and four months elapsed from the time of the union vote to the first contract, and that was at a 59-person company with a relatively cooperative employer. At larger companies with more aggressive legal teams, the timeline will be longer.</p>



<p class="wp-block-paragraph">Forming a union is hard work, Robutti says. “It’s not a service you pay for and they protect you. It doesn’t happen spontaneously, and it doesn’t happen magically. It’s the choice to take responsibility for improving your workplace.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The UK wants to catch up in the global AI race – but is too wary of risks to go all-in]]></title>
<description><![CDATA[UK fears a ‘triple whammy’: oversized investment in AI stocks, slower adoption of AI than predicted and the breakneck pace of AI’s developmentHello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today, we’re discussing the UK’s difficult position in th...]]></description>
<link>https://tsecurity.de/de/3668192/it-nachrichten/the-uk-wants-to-catch-up-in-the-global-ai-race-but-is-too-wary-of-risks-to-go-all-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668192/it-nachrichten/the-uk-wants-to-catch-up-in-the-global-ai-race-but-is-too-wary-of-risks-to-go-all-in/</guid>
<pubDate>Tue, 14 Jul 2026 16:02:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UK fears a ‘triple whammy’: oversized investment in AI stocks, slower adoption of AI than predicted and the breakneck pace of AI’s development</p><p>Hello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today, we’re discussing the UK’s difficult position in the AI race, new doubts over OpenAI’s path toward a trillion-dollar stock market debut and the changes to IRL tech reporting in the age of AI.</p><p><a href="https://www.theguardian.com/commentisfree/2026/jul/08/chatgpt-ai-therapy">My patients use ChatGPT for therapy. Now I use it too | Sarah Darghouth | The Guardian</a></p><p><a href="https://www.theguardian.com/technology/ng-interactive/2026/jul/12/software-developers-engineers-ai">Chasing new skills, going back to basics and pushing for collective action: how software engineers are adapting to AI</a></p> <a href="https://www.theguardian.com/technology/2026/jul/13/uk-catch-up-global-ai-race-risks">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canva launches Code 2.0, offering AI website building to every user — including free accounts]]></title>
<description><![CDATA[Canva on Tuesday launched Canva Code 2.0, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the...]]></description>
<link>https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.canva.com/">Canva</a> on Tuesday launched <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a>, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the company's more than 265 million monthly users across every pricing tier, including free accounts.</p><p>The move is Canva's most aggressive push yet into the fast-growing "vibe coding" market, a category that barely existed 18 months ago but has already minted billion-dollar startups and reshaped how non-developers think about building software. But where rivals like <a href="https://lovable.dev/">Lovable</a>, <a href="https://replit.com/">Replit</a>, and <a href="https://bolt.new/">Bolt.new</a> have focused primarily on generating functional code from text prompts, Canva is making a different bet: that the real bottleneck isn't creating the code — it's making the output actually look good.</p><p>"Most vibe coding tools stop at functional — generating output that looks the same as everyone else's," Canva states in its announcement. "You might get a working prototype, but making it actually look like yours requires a complex editing surface, a separate design tool, a developer, or endless back-and-forth prompting that rarely lands where you want it.”</p><p>Danny Wu, Canva's Head of AI Products, framed the product's positioning in stark terms during an exclusive interview with VentureBeat ahead of the launch.</p><p>"We are deliberately targeting non-technical users," Wu said. "Canva Code isn't a tool we're building for developers. What we're trying to do is bring the power of AI coding — and really lightweight coding — into the Canva platform, while answering our users' requests for more interactivity, more customization, and more flexibility, from websites to interactive presentations."</p><h3><b>Canva Code 2.0 brings drag-and-drop editing, HTML import, and 75% faster generation to AI-built websites</b></h3><p>The update introduces several capabilities designed to collapse the distance between generating code and publishing a polished interactive experience. Users can now create Canva Code projects directly inside other design projects — embedding interactive elements within a whiteboard, presentation deck, or standalone page. <a href="https://www.canva.com/">Canva</a> has also added more than 50 new templates specifically designed for interactive designs, along with the ability to import raw HTML files from other AI coding tools and convert them into editable Canva designs.</p><p>The performance improvements are significant. Canva says it has reduced average code generation time by 75 percent and cut the median time from initial prompt to a published site by 30 percent. The company also reports that integrating <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> into the broader Canva editor — allowing users to treat coded outputs like any other design element — has increased active Code users by 25 percent.</p><p>Perhaps the most distinctive feature is the editing experience itself. Unlike most AI coding platforms, which require users to re-prompt or modify raw code to make visual changes, <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> lets users click directly into generated elements to change text, drag and drop images from Canva's built-in library of over 120 million templates and assets, update colors and fonts through a familiar toolbar, or select a specific element and refine it through conversational AI. Every output is fully interactive and automatically adapts to different screen sizes, with a built-in mobile preview.</p><p>Wu demonstrated the drag-and-drop editing during the interview, showing how a generated conference website could be modified in real time — swapping in photos, changing fonts to branded alternatives, and editing text directly on the canvas. "The key differentiator with Canva Code is the editability and the kindness of the outputs it generates," he said, though he noted one current limitation: "We don't support moving elements around. You still have to re-prompt for that."</p><h3><b>How Canva plans to compete with Lovable, Replit, and Bolt in the booming AI app builder market</b></h3><p>Canva's entry into vibe coding at this scale arrives at a pivotal moment for the category. According to <a href="https://www.useluminix.com/reports/industry-analysis/vibe-coding-tool-landscape-replit-v0-base44-bolt-lovable-vercel/source/0">market research published by Luminix AI in May 2026</a>, the vibe coding and AI app builder market has reached an estimated $4.7 billion in 2026, with projections pointing toward $12.3 billion by 2027 at roughly 38 percent compound annual growth. The research also estimates that AI-generated code now comprises approximately 41 percent of all code written globally — a figure that would have seemed inconceivable even two years ago.</p><p>The competitive landscape has grown ferocious. <a href="https://lovable.dev/dashboard">Lovable</a>, which focuses on conversational, design-forward app generation for non-technical founders, has achieved what may be the fastest revenue ramp in the category's history — reportedly reaching approximately $400 million in annual recurring revenue by early 2026, according to Luminix's analysis. <a href="https://replit.com/">Replit</a>, which transformed its browser-based IDE into a full vibe-coding engine through successive AI agent releases, has tripled its valuation to $9 billion and is targeting $1 billion in run-rate revenue by the end of 2026, per the same report. <a href="https://bolt.new/">Bolt.new</a>, which runs a full Node.js environment entirely in the browser, scaled from $4 million to $40 million in ARR within months of launching.</p><p>And then there is Canva, which brings something none of those platforms possess: a quarter-billion-user design ecosystem where brands, teams, and individuals already store their visual identities, collaborate on projects, and publish content.</p><p>Wu positioned <a href="https://bolt.new/">Canva Code</a> not as a direct competitor to these developer-focused tools but as something that fills a gap none of them have addressed. "A lot of the requests that we have been getting and the usage we're seeing is actually with using Canva Code not necessarily as just one artifact, but as part of an overall design, the visual communication they're trying to tell," Wu said. "Like when you have a sales deck, you're able to add a calculator, you're able to add a visualizer of what exactly your product does. That's something where an interactive slide can be worth a thousand pictures."</p><h3><b>Why Canva's HTML import feature could turn it into a 'finishing layer' for every AI coding tool</b></h3><p>One of the most strategically interesting features in <a href="https://bolt.new/">Canva Code 2.0</a> is its HTML import capability, which allows users to take code generated by any AI tool — including <a href="https://chatgpt.com/">ChatGPT</a>, <a href="http://claude.ai/">Claude</a>, <a href="https://lovable.dev/dashboard">Lovable</a>, or <a href="https://bolt.new/">Bolt</a> — and bring it into Canva as a fully editable design. The implication is unmistakable: Canva is positioning itself as the place where AI-generated code gets its finishing touches, regardless of where it was originally created.</p><p>When asked directly whether this amounts to positioning Canva as a "finishing layer on top of vibe coding," Wu offered a diplomatic but revealing response. "It's really a continuation of our goal to make all design as easy as possible," he said. "We've supported importing PDFs and translating them into docs, importing PowerPoint files — so in one way, it's an expansion of that. But in another way, it's really just listening to what our users want and making Canva both the most useful and the most compatible platform.”</p><p>He paused, then added: "It's not that we're deliberately positioning ourselves as a specific layer, say like a finishing layer after vibe coding. We just really want to make our platform the most accessible and the most pluggable."</p><p>That language — "most pluggable" — suggests a platform strategy that doesn't require Canva to win the AI code generation race outright. If Canva becomes the default destination for making AI-generated code look professional and on-brand, it captures value from the entire category regardless of which code generation engine users prefer. The strategy also echoes the broader import capabilities that already allow Canva to ingest PowerPoint decks and PDFs from competing platforms, gradually pulling users deeper into the Canva ecosystem without demanding they abandon existing workflows.</p><h3><b>What Canva Code can build — and where Danny Wu says it hits its limits</b></h3><p>Wu was notably candid about the product's boundaries — a refreshing departure from the typical Silicon Valley product launch. "Canva Code is great for anything that works as a front-end app, and it's especially good when you want to leverage data, data submissions, and interactivity at small to medium scale," he said. "I'll be honest about the limitations. Canva Code is probably not going to be suitable if you're trying to build a website with complex backends, or if you're handling hundreds of thousands of visitors per day."</p><p>This candor effectively draws a line between <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> and the more ambitious platforms in the space. While Lovable and Replit are pushing toward full-stack application development — complete with databases, authentication, and production-grade hosting — Canva is deliberately limiting its scope to interactive front-end experiences at modest scale. The question is whether that's a strategic weakness or a disciplined focus. For the teachers, small business owners, and marketing teams that make up the bulk of Canva's user base, complex backends and high-traffic scalability are irrelevant concerns. What matters is whether they can create an interactive event page, a property listing website, or a classroom hub that looks professional and works on mobile — without hiring a developer or learning a new tool.</p><p>When asked about the AI models powering <a href="https://www.canva.com/ai-code-generator/">Canva Code</a>, Wu confirmed the company uses a combination of proprietary and third-party models, including those from OpenAI and Anthropic, but declined to specify the exact mix. "We don't share the exact mix, and it does change over time," he said. "We also route differently depending on what you're asking for and which model family we think is best for handling certain requests."</p><h3><b>Canva's AI acquisition spree — from Affinity to Leonardo.ai — now powers its vibe coding push</b></h3><p>Canva's broader AI infrastructure has been significantly bolstered by an acquisition strategy that has accelerated over the past two years. In March 2024, <a href="https://www.canva.com/newsroom/news/affinity/">the company acquired Affinity</a>, the British creative software suite popular with Mac users, in a deal that Bloomberg reported was valued at "<a href="https://www.bloomberg.com/news/articles/2024-03-26/canva-acquires-affinity-design-suite-in-push-to-rival-adobe">several hundred million pounds</a>." Canva at the time positioned the deal as a way to compete with Adobe's flagship products — Illustrator, Photoshop, and InDesign — by gaining ownership of Affinity's Designer, Photo, and Publisher applications.</p><p>Just four months later, Canva acquired <a href="http://leonardo.ai/">Leonardo.ai</a>, an Australian generative AI startup with over 19 million registered users and more than a billion images generated. Canva co-founder Cameron Adams said at the time that Leonardo.ai's technology would be integrated into Canva's Magic Studio generative AI suite.</p><p>Together with these acquisitions, <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> is the company's attempt to layer interactive, code-driven capabilities on top of a visual design platform that has already been enhanced by professional-grade design tools and generative AI models. The company reports over 32 billion uses of its AI products to date — a staggering figure that underscores how deeply AI is now woven into everyday Canva workflows, even for users who may not think of themselves as using artificial intelligence.</p><h3><b>Six million sites published, but Canva's retention data remains an open question</b></h3><p>Canva's announcement highlights an impressive traction metric: users have created and published more than six million websites using Canva Code since the feature was first introduced a year ago. But the number deserves scrutiny.</p><p>Wu clarified in the interview that the six million figure represents published websites over the past year — meaning sites that were either made public or shared via password-protected or private links. "They may have published publicly, or behind a password, or as a private link. But that's the number of published websites," he said.</p><p>When asked about active retention — how many of those sites are still live and being maintained — Wu acknowledged the gap in his data. This is a meaningful distinction. In the vibe coding market, raw creation numbers can be misleading because the barrier to generating a site is so low. The more telling metric — which Canva does not yet provide — would be how many of those six million sites receive regular traffic or have been updated after initial publication.</p><p>The early use cases, however, suggest genuine utility beyond novelty. Educators and school administrators are using Canva Code to build classroom hubs, with one teacher creating bespoke webpages for each of their classrooms to keep students and parents updated on announcements. Small businesses, like Alt Marketing School, have built mini apps for fundraising training and interactive roadmaps for their members. For World Book Day, 50 readers created educational games across different subjects, complete with pedagogical guides for classroom use.</p><h3><b>Canva Code pricing, data governance, and what enterprise customers need to know</b></h3><p><a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> is available across all of Canva's pricing tiers, including its free plan — a notable decision given that competitors like Lovable, Bolt, and Replit reserve their most capable features for paid subscribers. "As you go from, say, free to pro to business to enterprise, you would get more AI credits and be able to have higher usage of Canva Code," Wu said. "But it is available and it is usable — even free Canva accounts as well as education and not-for-profit accounts."</p><p>This credit-based approach mirrors the pricing evolution happening across the entire vibe coding category, where platforms have converged on token or credit systems that meter AI generation capacity rather than gating features behind subscription tiers. The difference is that Canva's free tier serves as an acquisition funnel for a much larger design platform, not just for the coding feature itself.</p><p>For the institutional customers Canva increasingly courts — school districts, real estate brokerages, enterprise marketing teams — data governance is a threshold concern. Wu addressed this directly. "All users and customers have full control over how their data is used," he said. "They can choose whether their prompts and data are used for AI training in the settings. For businesses and enterprises, team admins can manage this at the organizational level and guarantee that their inputs, content, and outputs won't be used for training." This opt-out approach reflects a lesson the broader industry has learned the hard way. As The Verge reported when Canva acquired Leonardo.ai, Adobe suffered significant backlash over a policy update regarding user data and AI model training — a controversy Canva appears keen to avoid.</p><h3><b>Canva's long-term vision: closing the gap between imagination and what non-technical users can actually build</b></h3><p>When asked where <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> fits into the company's long-term trajectory — and whether Canva is building toward a full-stack app development platform — Wu steered the conversation back to the company's core audience.</p><p>"A huge part of it is reducing the gap between your imagination and what's possible, especially for everyday users — people who don't have a lot of time," he said. "They don't have time to figure out deploys or MCPs or APIs. They just want to design more interactive and more dynamic communication."</p><p>He pointed to the rapid improvement in AI model capabilities as a key accelerant. "The kind of things you can create today in one shot — like a 3D visualization of a solar system — you really couldn't have trusted the output a year ago. But today, you have a really high success rate."</p><p>Whether <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> becomes a durable product category or a feature that gets absorbed into the platform's broader AI workflow will depend on how quickly the company can close the gap between its current front-end focus and the full-stack capabilities that increasingly define the competition. Lovable is shipping Supabase-backed apps with authentication and databases built in. Replit's agents can execute autonomous long-running builds. Bolt.new runs entire Node.js environments in a browser tab. These are fundamentally different ambitions than making a conference landing page look good.</p><p>But Canva has never won by matching the technical depth of its competitors. A decade ago, it didn't try to out-feature Adobe — it made design accessible to the 99 percent of people who would never open Photoshop. Now, in a vibe coding market where every tool can generate a working prototype from a prompt, Canva is making the same wager it made in 2012: that for most people, the hardest part was never the building. It was making it look like it came from you.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla GFX: HDR video in Firefox for Windows tech retrospective]]></title>
<description><![CDATA[HDR video is coming to Firefox for Windows users (and has been available for some time on macOS).  This blog post explains how we developed the feature and gives a retrospective on the technical choices we made.



A primer on video playback for the web:




Video file demux and decode: A video s...]]></description>
<link>https://tsecurity.de/de/3666879/tools/mozilla-gfx-hdr-video-in-firefox-for-windows-tech-retrospective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666879/tools/mozilla-gfx-hdr-video-in-firefox-for-windows-tech-retrospective/</guid>
<pubDate>Tue, 14 Jul 2026 07:08:30 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="wp-block-paragraph">HDR video is coming to Firefox for Windows users (and has been available for some time on macOS).  This blog post explains how we developed the feature and gives a retrospective on the technical choices we made.</p>



<p class="wp-block-paragraph">A primer on video playback for the web:</p>



<ul class="wp-block-list">
<li><strong>Video file demux and decode</strong>: A video stream generally consists of parallel image and audio streams, along with captions, HDR scene metadata, and the like. “Container” formats like MP4 or MKV specify how these streams are combined, or multiplexed, into a single byte stream for transmission. On receipt, Firefox needs to divide that byte stream back into the individual media streams; this is de-multiplexing or “demuxing”. Then Firefox must uncompress the data to get images, audio samples, and so on. Firefox’s media team provides the demuxers, and pulls in appropriate codecs to decode them. We prefer using hardware video decoders if they work reasonably well. Video decompression usually produces roughly a YUV 4:2:0 image in <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/recommended-8-bit-yuv-formats-for-video-rendering">NV12 for SDR</a> or <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/10-bit-and-16-bit-yuv-video-formats">P010 for HDR</a>. (If you visit <strong>about:support</strong> in Firefox, and search for <strong>Codec Support Information</strong> (or one of the codec names like <strong>AV1</strong>), you can see a whole feature matrix of support details for which codecs are hardware and software on your system.)</li>



<li><strong>Gecko displaylist building</strong>: Given a demultiplexed, uncompressed frame of video, Gecko displaylist building incorporates it into a video element in the displaylist being sent to WebRender. If the frame was decoded in hardware, it is generally represented by a texture in GPU memory. Or, if it was decoded in software, then it is represented by a memory mapping holding some raw pixel data in system memory shared with Firefox’s media decoder process.</li>



<li><strong>WebRender</strong>: Given the video element in the displaylist, WebRender decides whether to promote it to a desktop compositor overlay, or whether it must instead be rendered using a pathway more like an ordinary HTML element. A compositor overlay is faster and uses less power; on Windows this uses DWM with the <a href="https://learn.microsoft.com/en-us/windows/win32/api/_directcomp/">DirectComposition API</a>, which manages a graph of <a href="https://learn.microsoft.com/en-us/windows/win32/api/dcomp/nn-dcomp-idcompositionvisual">visuals</a>. But if complex CSS is involved (rounded corners, blur filters, or similar features), Firefox must use WebRender’s ordinary rendering pathway. Currently the latter is not HDR capable, so Firefox favors the desktop compositor overlay for animated elements such as video and canvas.</li>
</ul>



<p class="wp-block-paragraph">As we began designing Firefox’s HDR support, we had to lay out some assumptions and found many complications:</p>



<ul class="wp-block-list">
<li>Initially, we had hoped that on a modern system, <a href="https://en.wikipedia.org/wiki/Rec._2100">BT2100</a> HDR videos could be displayed on Windows by simply sending them to DirectComposition.
<ul class="wp-block-list">
<li>In theory, the Desktop Window Manager (DWM) honors the <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgi1_4/nn-dxgi1_4-idxgiswapchain3">DXGISwapChain3</a>::<a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgi1_4/nf-dxgi1_4-idxgiswapchain3-setcolorspace1">SetColorSpace1</a> method which should let us request either <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgicommon/ne-dxgicommon-dxgi_color_space_type">DXGI_COLOR_SPACE_YCBCR_STUDIO_G2084_LEFT_P2020</a> or <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgicommon/ne-dxgicommon-dxgi_color_space_type">DXGI_COLOR_SPACE_YCBCR_STUDIO_GHLG_LEFT_P2020</a>. The former refers to SMPTE 2084, more commonly called PQ, the <a href="https://en.wikipedia.org/wiki/Perceptual_quantizer">Perceptual Quantizer</a> function and the latter is ARIB-STD-B67  also known as HLG, the <a href="https://en.wikipedia.org/wiki/Hybrid_log%E2%80%93gamma">Hybrid Log Gamma</a> function, most commonly used on HDR TV broadcasts.</li>



<li>Unfortunately, this was a dead end. In testing with a mocked up <a href="https://github.com/FirefoxGraphics/compositor_colortest/tree/main">compositor test app</a>, calling SetColorSpace1 with this value seems to be ignored on P010 (at least in testing on AMD), so it incorrectly displays BT2100 PQ video as if it were BT709, which makes the video dull and muddy, since BT709 is a narrower gamut than BT2020, and the BT1886 transfer function used by BT709 is very different from PQ defined by BT2100. SetColorSpace1 may work on other vendors with P010, so it may be a valid optimization, but we were looking for a universal solution.</li>



<li>For the future, Windows 11 23H2 has added a new interface called IDCompositionTexture which may serve our purposes better; from what we have been told, it is universally supported for all formats and color spaces. We haven’t used it for video so far, but it’s an interesting future direction.</li>
</ul>
</li>



<li>As noted above, HDR videos must use a desktop compositor overlay. HDR video uses the BT2100 PQ colorspace with an RGB10A2 format, while WebRender can only work with images in the sRGB colorspace (appropriate for standard-dynamic-range BT709 video).
<ul class="wp-block-list">
<li>Until HDR came along, Gecko and WebRender only used desktop compositor overlays as a power/performance optimization. With HDR, overlays become a necessity as the pixel format and color space differ from classic sRGB.</li>



<li>Fortunately, HDR videos tend to be shown without particularly fancy CSS rendering such as clip masks and rounded corners, which would require WebRender to perform further copies. Technically, DirectComposition does support all of those features, but Firefox doesn’t use that functionality much.</li>



<li>In the future, we expect to upgrade WebRender for HDR rendering, allowing us to deal with complex cases like clip masks or blur filters on video elements.</li>
</ul>
</li>



<li>We considered whether we could use VideoProcessorBlt, or whether we should write our own shader instead.
<ul class="wp-block-list">
<li>In favor of VideoProcessorBlt:
<ul class="wp-block-list">
<li>It uses less power on GPUs that have a video processor unit.</li>



<li>We discovered in testing (using <a href="https://learn.microsoft.com/en-us/windows/win32/api/d3d11_1/nf-d3d11_1-id3d11videoprocessorenumerator1-checkvideoprocessorformatconversion">CheckVideoProcessorFormatConversion</a>) that while many modern GPUs support one of the needed conversions (P010 PQ -&gt; RGB10 PQ), few support the ones we need for HLG videos (P010 HLG -&gt; RGB10 PQ).</li>



<li>The ‘video-dynamic-range’ query used on the web is not fine-grained enough to be able to say “the web browser can display PQ video but not HLG video”, so if we went with VideoProcessorBlt as a required feature, only about 20% of HDR desktop users would be able to use the feature.</li>



<li>In the future, we could explore using VideoProcessorBlit to save power on hardware that supports the conversions we need. But other web browsers are not using this functionality, so there may be more issues we haven’t found yet.</li>
</ul>
</li>



<li>In favor of writing our own shader with all of the features:
<ul class="wp-block-list">
<li>This would work consistently on all vendors – nothing special here.</li>



<li>This would look the same on all vendors, regardless of hardware capabilities. This is generally the aim of web standards.</li>



<li>This would support anything we want it to. HDR tonemapping can be implemented. Video orientation can be implemented (for videos recorded on phones which may be rotated 90, 180 or 270 degrees). We can support any kind of YUV-&gt;RGB conversion with a color matrix (even weird legacy formats like GBR 4:2:0).  We can support conversion between color primaries (e.g. BT2020-&gt;BT709).  We can convert to linear color (for scRGB using RGBA16F) or any EOTF we want (notably BT2100 PQ with RGB10A2, for our use-case).</li>
</ul>
</li>



<li>In the end we went with the shader after a significant period of time experimenting with VideoProcessorBlt in our Nightly releases.</li>
</ul>
</li>



<li>There is a very large amount of graphics code in Gecko and WebRender that needs to be upgraded for HDR.
<ul class="wp-block-list">
<li>We decided that the most important code paths to upgrade first are the ones for regular video playback and DRM-protected video playback, and later canvas video import (Canvas2D, WebGL, WebGPU) which will require upgrading canvas for HDR first – another big project.</li>



<li>We had to upgrade several dozen structs to carry the transfer function for video data, as previously all code assumed video used BT1886 EOTF.</li>
</ul>
</li>



<li>We hope we can avoid tone mapping HDR content when viewed on HDR displays.
<ul class="wp-block-list">
<li>It’s reasonable to expect that most displays going forward will be HDR displays (partly because of marketing momentum, partly because displays are made by a very finite set of manufacturers who are all making HDR display panels), and eventually tone mapping may become unnecessary on the web.</li>



<li>For the short-term we will have to apply a tone mapping effect when HDR content is viewed on SDR displays, likely using  ‘Reinhard tonemapping’ which refers to the widely available paper <a href="https://doi.org/10.1145/566654.566575">Photographic Tone Reproduction for Digital Images</a> by Erik Reinhard et al, and configuring it for a fixed brightness ratio of 400 cd/m^2 -&gt; 100 cd/m^2 when used on SDR displays, and see if that fits all HDR content on the web well enough for a good user experience – and if it does not, we will iterate based on feedback from users on Firefox Nightly.</li>



<li>We are hoping that we will never have to apply tonemapping for HDR content on HDR displays, there are multiple factors in this decision:
<ul class="wp-block-list">
<li>Varying the brightness limit would make it a significant fingerprinting vector if not handled very carefully if the script can inspect pixels or parameters related to that.  There are ways to mitigate this but they are all awkward restrictions to impose, and queries would have to get a different answer than what the rendering is using.</li>



<li>Phones and laptops with light sensors may vary the reference brightness in real time, and this changes the maximum displayable ratio (aka HDR headroom) every refresh, which is also a major battery drain if we keep redrawing all of the time.</li>



<li>Documents composed of multiple images (a gallery or some form of art composition) would apply different tonemapping to each image if the brightest pixel in each image is different brightness).  We’d have to do something about that to make it controllable via CSS.</li>



<li>In general the detailed parts of an image are within a certain brightness band – see <a href="https://www.yedlin.net/DebunkingHDR/">Debunking HDR</a> for a detailed lecture on film grading and why you would not have significant difference in brightness between scene elements.</li>



<li>User feedback so far has indicated that not applying tonemapping has given them a better viewing experience on some videos.</li>
</ul>
</li>
</ul>
</li>



<li>WebRTC is implemented using a library, common to all web browsers, which has limited support for HDR.
<ul class="wp-block-list">
<li>While we didn’t prioritize this for an initial feature launch, we are looking at how to implement HDR support properly in libwebrtc. This is in the early assessment phase but we know this is wanted for a couple of use-cases, like video calls for meetings, or game streaming with friends watching.</li>
</ul>
</li>
</ul>



<p class="wp-block-paragraph">In general, one of the biggest challenges in working on graphics code in a web browser is a lack of documentation for how to best use features like video playback and desktop compositing in the context of a web browser (e.g. multiple processes, sandboxing, shared memory, sharing external textures, etc). This parallels the rarity of graphics engineers with such experience. Building new features in this space requires a lot of research (and a lot of trial and error). The solution you end up with may not look at all like the one you initially imagined.</p>



<p class="wp-block-paragraph">On behalf of the graphics team at Mozilla, I want to thank the people who use Firefox Nightly regularly and file bug reports when things aren’t working the way they want. Comments on <a href="https://mozillagfx.wordpress.com/2026/01/16/experimental-high-dynamic-range-video-playback-on-windows-in-firefox-nightly-148/">Experimental High Dynamic Range video playback on Windows in Firefox Nightly 148</a>, <a href="https://connect.mozilla.org/">Mozilla Connect</a>, and <a href="https://bugzilla.mozilla.org/">Bugzilla</a> bug reports have guided us to focus on the use-cases that matter to people using Firefox. When we succeed, it’s a great feeling.</p>



<p class="wp-block-paragraph">We’re working on extending HDR support to photos, apps/games and general web content.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 200 Economists Say 'We Must Act Now' On AI's Economic Impact]]></title>
<description><![CDATA[An anonymous reader quotes a report from the Associated Press: Hundreds of economists say in an open letter that institutions "must act now" to address how artificial intelligence could transform the economy and could put many people out of work. The statement released Monday was signed by top ec...]]></description>
<link>https://tsecurity.de/de/3666792/it-security-nachrichten/over-200-economists-say-we-must-act-now-on-ais-economic-impact/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666792/it-security-nachrichten/over-200-economists-say-we-must-act-now-on-ais-economic-impact/</guid>
<pubDate>Tue, 14 Jul 2026 05:37:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from the Associated Press: Hundreds of economists say in an open letter that institutions "must act now" to address how artificial intelligence could transform the economy and could put many people out of work. The statement released Monday was signed by top economists, along with computer scientists and some executives at tech companies including Anthropic, Google and OpenAI.
 
"AI may become radically more powerful over the next 10 years," says the letter organized by Stanford University's digital economy lab. "This could drive an unprecedented transformation of our economy, larger than the Industrial Revolution, but unfolding over a vastly shorter time frame. It could bring risks, including large-scale job displacement, as well as opportunities such as major gains in living standards."
 
The letter, which has only four sentences, says leaders must "build the incentives, guardrails, and institutions needed to steer AI in a direction that complements humans and benefits society." The Stanford lab says the letter has so far been signed by more than 200 economists and AI researchers, including 16 winners of a Nobel Prize. "We must be intentional and make collective, democratic choices, rather than letting market forces play out and risking leaving most citizens behind," wrote computer scientist and AI pioneer Yoshua Bengio, who was also among the signatories. He said it "it is highly plausible that AI will drastically transform our economies."
 
Other signatories include Google CEO Eric Schmidt, LinkedIn cofounder Reid Hoffman, and Nobel laureates Joseph Stiglitz, Daron Acemonglu, and Simon Johnson.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Over+200+Economists+Say+'We+Must+Act+Now'+On+AI's+Economic+Impact%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F13%2F2210232%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F13%2F2210232%2Fover-200-economists-say-we-must-act-now-on-ais-economic-impact%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/13/2210232/over-200-economists-say-we-must-act-now-on-ais-economic-impact?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[16 open source projects transforming AI and machine learning]]></title>
<description><![CDATA[For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and large language models. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to...]]></description>
<link>https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a>. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to complement the open source code.</p>



<p class="wp-block-paragraph">For this article, we’ve pulled together some of the most intriguing and useful projects for <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI and machine learning</a>. Many of these are foundation projects, nurturing their own niche ecology of open source plugins and extensions. Once you’ve started with the basic project, you can keep adding more parts.</p>



<p class="wp-block-paragraph">Most of these projects offer demonstration code, so you can start up a running version that already tackles a basic task. Additionally, the companies that build and maintain these projects often sell a service alongside them. In some cases, they’ll deploy the code for you and save you the hassle of keeping it running. In others, they’ll sell custom add-ons and modifications. The code itself is still open, so there’s no vendor lock in. The services simply make it easier to adopt the code by paying someone to help.</p>



<p class="wp-block-paragraph">Here are 16 open source projects that developers can use to unlock the potential in machine learning and large language models of any size—from small to large, and even extra large.</p>



<h2 class="wp-block-heading">Agent Skills</h2>



<p class="wp-block-paragraph">AI coding agents are often used to tackle standard tasks like <a href="https://www.infoworld.com/article/3981588/putting-agentic-ai-to-work-in-firebase-studio.html">writing React components</a> or <a href="https://www.infoworld.com/article/4025088/how-coderabbit-brings-ai-to-code-reviews.html">reviewing parts of the user interface</a>. If you are writing a coding agent, it makes sense to use vetted solutions that are focused on the task at hand. <a href="https://github.com/vercel-labs/agent-skills">Agent Skills</a> are pre-coded tools that your AI can deploy as needed. The result is a focused set of vetted operations capable of producing refined, useful code that stays within standard guidelines. License: MIT.</p>



<h2 class="wp-block-heading">Awesome LLM Apps</h2>



<p class="wp-block-paragraph">If you are looking for good examples of agentic coding, see the <a href="https://github.com/Shubhamsaboo/awesome-llm-apps">Awesome LLM Apps collection</a>. Currently, the project hosts several dozen applications that leverage some combination of <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">RAG databases</a> and LLMs. Some are simple, like a meme generator, while others handle deeper research like the Journalist agent. The most complex examples deploy multi-agent teams to converge upon an answer. Every application comes with working examples for experimentation, so you can learn from what’s been successful in the past. Altogether, the apps in this collection are great inspiration for your own projects. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Bifrost</h2>



<p class="wp-block-paragraph">If your application requires access to an LLM service, and you don’t have a particular one in mind, check out <a href="https://github.com/maximhq/bifrost">Bifrost</a>. A fast, unified gateway to more than 15 LLM providers, this OpenAI-compatible API quickly abstracts away the differences between models, including all the major ones. It includes essential features like governance, caching, budget management, load balancing, and it has guardrails to catch problems before they are sent out to service providers, who will just bill you for the time. With dozens of great LLM providers constantly announcing new and better models, why limit yourself? License: Apache 2.0.</p>



<h2 class="wp-block-heading">Claude Code</h2>



<p class="wp-block-paragraph">If the popularity of AI coding assistants tells us anything, it’s that all developers—and not just the ones building AI apps—appreciate a little help writing and reviewing their code. <a href="https://github.com/anthropics/claude-code">Claude Code</a> is that pair programmer. Trained on all the major programming languages, <a href="https://www.infoworld.com/article/3853805/vibe-coding-with-claude-code.html">Claude Code can help you write code that is better, faster, and cleaner</a>. It digests a codebase and then starts doing your bidding, while also making useful suggestions. Natural language commands plus some vague hand waving are all the Anthropic LLM needs to refactor, document, or even add new features to your existing code. License: Anthropic’s Commercial TOS.</p>



<h2 class="wp-block-heading">Clawdbot</h2>



<p class="wp-block-paragraph">Many of the tools in this list help developers create code for other people. <a href="https://github.com/clawdbot/clawdbot?tab=readme-ov-file">Clawdbot</a> is the AI assistant for you, the person writing the code. It integrates with your desktop to control built-in tools like the camera and large applications like the browser. A multi-channel inbox accepts your commands through more than a dozen different communication channels including WhatsApp, Telegram, Slack, and Discord. A cron job adds timing. It’s the ultimate assistant for you, the ruler of your data. If AI exists to make our lives easier, why not start by organizing the applications on your desktop? License: MIT.</p>



<h2 class="wp-block-heading">Dify</h2>



<p class="wp-block-paragraph">For projects that require more than just one call to an LLM, <a href="https://github.com/langgenius/dify">Dify</a> could be the solution you’ve been looking for. Essentially a development environment for building complex agentic workflows, Dify stitches together LLMs, RAG databases, and other sources. It then monitors how they perform under different prompts and parameters and puts it all together in a handy dashboard, so you can iterate on the results. Developing agentic AI requires rapid experimentation, and Dify provides the environment for those experiments. License: Modified version of Apache 2.0 to exclude some commercial uses.</p>



<h2 class="wp-block-heading">Eigent</h2>



<p class="wp-block-paragraph">The best way to explore the power and limitations of an agentic workflow is to deploy it yourself on your own machine, where it can solve your own problems. Eigent delivers a workforce of specialized agents for handling tasks like writing code, searching the web, and creating documents. You just wave your hands and issue instructions, and Eigent’s LLMs do their best to follow through. Many startups brag about eating their own dogfood. Eigent puts that concept on a platter, making it easy for AI developers to experience directly the abilities and failings of the LLMs they’re building. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Headroom</h2>



<p class="wp-block-paragraph">Programmers often think like packrats. If the data is good, why not pack in some more? This is a challenge for code that uses an LLM because these services charge by the token, and they also have a limited context window. <a href="https://github.com/chopratejas/headroom">Headroom</a> tackles this issue with agile compression algorithms that trim away the excess, especially the extra labels and punctuation found in common formats like JSON. A big part of designing working AI applications is cost engineering, and saving tokens means saving money. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Hugging Face Transformers</h2>



<p class="wp-block-paragraph">When it comes to starting up a brand-new machine learning project, <a href="https://github.com/huggingface/transformers">Hugging Face Transformers</a> is one of the best foundations available. Transformers offers a standard format for defining how the model interacts with the world, which makes it easy to drop a new model into your working infrastructure for training or deployment. This means your model will interact nicely with all the already available tools and infrastructure, whether for text, vision, audio, video, or all of the above. Fitting into a standard paradigm makes it much easier to leverage your existing tools while focusing on the cutting edge of your research. License: Apache 2.0.</p>



<h2 class="wp-block-heading">LangChain</h2>



<p class="wp-block-paragraph">For agentic AI solutions that require endless iteration, <a href="https://github.com/langchain-ai/langchain">LangChain</a> is a way to organize the effort. It harnesses the work of a large collection of models and makes it easier for humans to inspect and curate the answers. When the task requires deeper thinking and planning, LangChain makes it easy to work with agents that can leverage multiple models to converge upon a solution. LangChain’s architecture includes a framework (LangGraph) for organizing easily customizable workflows with long-term memory, and a tool (LangSmith) for evaluating and improving performance. Its Deep Agents library provides teams of sub-agents, which organize problems into subsets then plan and work toward solutions. It is a proven, flexible test bed for agentic experimentation and production deployment. License: MIT.</p>



<h2 class="wp-block-heading">LlamaIndex</h2>



<p class="wp-block-paragraph">Many of the early applications for LLMs are sorting through large collections of semi-structured data and providing users with useful answers to their questions. One of the fastest ways to customize a standard LLM with private data is to use <a href="https://github.com/run-llama/llama_index">LlamaIndex</a> to ingest and index the data. This off-the-shelf tool provides data connectors that you can use to unpack and organize a large collection of documents, tables, and other data, often with just a few lines of code. The layers underneath can be tweaked or extended as the job requires, and LlamaIndex works with many of the data formats common in enterprises. License: MIT.</p>



<h2 class="wp-block-heading">Ollama</h2>



<p class="wp-block-paragraph">For anyone experimenting with LLMs on their laptop, <a href="https://github.com/ollama/ollama">Ollama</a> is one of the simplest ways to <a href="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html" data-type="link" data-id="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html">download one or more of them and get started</a>. Once it’s installed, your command line becomes a small version of the classic ChatGPT interface, but with the ability to pull a huge collection of models from a growing library of open source options. Just enter: <code>ollama run </code> and the model is ready to go. Some developers are using it as a back-end server for LLM results. The tool provides a stable, trustworthy interface to LLMs, something that once required quite a bit of engineering and fussing. The server simplifies all this work so you can tackle higher level chores with many of the <a href="https://ollama.com/library">most popular open source LLMs</a> at your fingertips. License: MIT.</p>



<h2 class="wp-block-heading">OpenWebUI</h2>



<p class="wp-block-paragraph">One of the fastest ways to put up a website with a chat interface and a dedicated RAG database is to spin up an instance of <a href="https://github.com/open-webui/open-webui">OpenWebUI</a>. This project knits together a feature-rich front end with an open back end, so that starting up a customizable chat interface only requires pulling a few <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker containers</a>. The project, though, is just a beginning, because it offers the opportunity to add plugins and extensions to enhance the data at each stage. Practically every part of the chain from prompt to answer can be tweaked, replaced, or improved. While some teams might be happy to set it up and be done, the advantages come from adding your own code. The project isn’t just open source itself, but a constellation of hundreds of little bits of contributed code and ancillary projects that can be very helpful. Being able to customize the pipeline and leverage the <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP protocol</a> supports the delivery of precision solutions. License: Modified BSD designed to restrict removing OpenWebUI branding without an enterprise license.</p>



<h2 class="wp-block-heading">Sim</h2>



<p class="wp-block-paragraph">The drag-and-drop canvas for <a href="https://github.com/simstudioai/sim">Sim</a> is meant to make it easier to experiment with <a href="https://www.infoworld.com/article/4086884/how-to-automate-the-testing-of-ai-agents.html">agentic workflows</a>. The tool handles the details of interacting with the various LLMs and vector databases; you just decide how to fit them together. Interfaces like Sim make the agentic experience accessible to everyone on your team, even those who don’t know how to write code. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Sloth</h2>



<p class="wp-block-paragraph">One of the most straightforward ways to leverage the power of foundational LLMs is to start with an open source model and fine-tune it with your own data. <a href="https://github.com/unslothai/unsloth">Unsloth</a> does this, often faster than other solutions do. Most major open source models can be transformed with reinforcement learning. Unsloth is designed to work with most of the standard precisions and some of the largest context windows. The best answers won’t always come directly from RAG databases. Sometimes, adjusting the models is the best solution. License: Apache 2.0.</p>



<h2 class="wp-block-heading">vLLM</h2>



<p class="wp-block-paragraph">One of the best ways to turn an LLM into a useful service for the rest of your code is to start it up with <a href="https://github.com/vllm-project/vllm">vLLM</a>. The tool loads many of the available open source models from repositories like Hugging Face and then orchestrates the data flows so they keep running. That means batching the incoming prompts and managing the pipelines so the model will be a continual source of fast answers. It supports not just the CUDA architecture but also AMD CPUs and GPUs, Intel CPUs and GPUs, PowerPC CPUs, Arm CPUs, and TPUs. It’s one thing to experiment with lots of models on a laptop. It’s something else entirely to deploy the model in a production environment. vLLM handles many of the endless chores that deliver better performance. License: Apache-2.0.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Application Security Team: Firefox Security & Privacy Newsletter 2026 Q2]]></title>
<description><![CDATA[Welcome to the Q2 2026 edition of the Firefox Security & Privacy Newsletter.

Security and privacy are core principles of Mozilla’s Manifesto and remain at the heart of Firefox’s development. In this edition, we highlight some of the key security and privacy initiatives from Q2 2026, grouped into...]]></description>
<link>https://tsecurity.de/de/3665507/tools/firefox-application-security-team-firefox-security-privacy-newsletter-2026-q2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665507/tools/firefox-application-security-team-firefox-security-privacy-newsletter-2026-q2/</guid>
<pubDate>Mon, 13 Jul 2026 16:10:17 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to the Q2 2026 edition of the Firefox Security &amp; Privacy Newsletter.</p>

<p>Security and privacy are core principles of <a href="https://www.mozilla.org/en-US/about/manifesto/">Mozilla’s Manifesto</a> and remain at the heart of Firefox’s development. In this edition, we highlight some of the key security and privacy initiatives from Q2 2026, grouped into the following areas:</p>

<ul>
  <li><strong>Firefox Product Security &amp; Privacy</strong>, new security and privacy features, protections, and integrations in Firefox</li>
  <li><strong>Core Security</strong>, platform security improvements, hardening efforts, and foundational enhancements</li>
  <li><strong>Community Engagement</strong>, highlights from our security research community and bug bounty program</li>
  <li><strong>Web Security &amp; Standards</strong>, progress on web technologies and standards that help websites better protect users from online threats</li>
</ul>

<h3>Preface</h3>

<p>Note: Some of the bugs linked below might not be accessible to the general public and restricted to specific work groups. <a href="https://firefox-source-docs.mozilla.org/bug-mgmt/processes/fixing-security-bugs.html#keeping-private-information-private">We de-restrict fixed security bugs after a grace-period</a>, until the majority of our user population have received Firefox updates. If a link does not work for you, please accept this as a precaution for the safety of all Firefox users.</p>

<h3>Firefox Product Security &amp; Privacy</h3>

<p><strong>Private Access Control Tokens (PACT):</strong> PACT is a cross-industry initiative designed to tackle one of the web’s most urgent challenges: enabling websites to reliably distinguish legitimate users and authorized automated agents from abusive traffic without compromising user privacy. To introduce the initiative, we published a <a href="https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/">technical deep dive on Mozilla Hacks</a> alongside a <a href="https://blog.mozilla.org/en/privacy-security/keeping-the-web-open-and-private-in-the-bot-era/">companion Mozilla blog post</a> that explains the vision, motivation, and privacy-preserving design behind PACT.</p>

<p><strong>Qualified Website Authentication Certificates (QWACs):</strong> Firefox is prepared to meet upcoming eIDAS requirements under the <a href="https://eidas.ec.europa.eu/efda/home">EU Digital Identity Framework.</a> <a href="https://eidas.ec.europa.eu/efda/discover/qwac">Qualified Website Authentication Certificates (QWACs), as required by the framework, are supported</a> in Firefox 153 (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2043399">Bug 2043399</a>) onwards.</p>

<p><strong>Hardening Firefox with Claude Mythos:</strong> In a <a href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/">blogpost</a> we shared how our AI-assisted security testing pipeline, powered by Claude Mythos, uncovered and helped remediate hundreds of previously hidden vulnerabilities in Firefox, significantly strengthening the browser’s security while demonstrating the transformative potential of AI to enhance defensive cybersecurity.</p>

<p><strong>Visual Indications for Geolocation Access:</strong> In light of some web pages using geolocation for activities that are not related to their maps functionality, Firefox now displays <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038194">a real-time visual indicator</a> whenever a web page is accessing the user’s geolocation. Starting with Firefox 153, the address bar now provides a <a href="https://bug2038194.bmoattachments.org/attachment.cgi?id=9586032">real-time visual indicator</a> the moment a website begins accessing a user’s location, providing users with  immediate awareness and greater transparency into when and how their geolocation data is being used.</p>

<p><strong>Improving Website Compatibility in Private Browsing:</strong> Starting with Firefox 152, Private Browsing Mode now offers users the option to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1994405">temporarily lower tracking protections</a> for the current tab when stricter tracker blocking could be causing a website to malfunction.  Previously, this may have resulted in users turning off privacy protections completely to continue using visited web page. With our new feature, users can quickly restore site functionality of the current tab, preserving users’ overall privacy settings.</p>

<p><strong>Instant fresh start through new <a href="https://support.mozilla.org/en-US/kb/private-browsing-use-firefox-without-history">Fire Button</a>:</strong> Firefox 151 introduced the new Fire Button for Private Browsing, giving users an instant fresh start with a single click. Instead of closing and reopening a Private Window, users can <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1846495">immediately clear all browsing data and continue browsing in a clean session</a>, making Private Browsing faster, more convenient, and just as private.</p>

<p><strong>Advanced Anti-Fingerprinting Protections:</strong> Firefox 151 expands our default anti-fingerprinting defenses by ensuring the Available Screen Resolution, Touch Points, and Canvas APIs will provide uniform results for all of our users while also maintaining performance and compatibility. On macOS, for example, these enhancements are expected to reduce the share of users identified as unique by more than 20%, making it significantly harder for websites to uniquely identify and track users using obscure fingerprinting.</p>

<p><strong>Local Network Access Protections:</strong> Firefox now requires user permission before websites can access apps and services on a user’s local network or device, helping prevent unauthorized access and sneaky tracking attempts. The <a href="https://support.mozilla.org/en-US/kb/control-personal-device-local-network-permissions-firefox">LNA</a> feature is rolling out gradually, starting with Firefox Desktop 151 through 153. Android support will follow in upcoming releases.</p>

<h3>Core Security</h3>

<p><strong>Firefox CA Root Program:</strong> We published <a href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Root Store Policy v3.1</a>, introducing stricter transparency, documentation, and audit requirements for public CAs to strengthen trust in the Web PKI.</p>

<p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010193"><strong>WebAuthn Related Origin Requests</strong></a><strong>:</strong> This feature allows seamless passkey sign-ins across related domains e.g., the same provider using multiple top-level domains. In contrast to other browsers, Firefox UI provides transparency and choice so users are aware and can control when websites request for passkeys from other, related sites.</p>

<h3>Community Engagement</h3>

<p><strong>Hosting Events:</strong> We organized and hosted multiple <a href="https://www.meetup.com/de-DE/berlin-mozilla-meetup/">web tech meet-ups in the Mozilla Berlin office</a>, bringing together the developer community to explore the latest advances in web technology, privacy, and security. If you’re in the area, we’d love to have you join us at a future event.</p>

<p><strong>Community Shares:</strong>  Firefox tracking protection was presented at the <a href="https://www.reddit.com/r/SnooSec/comments/1te55fx/thanks_for_joining_us_at_snoosec_nyc/">SnooSec conference held in the Reddit NYC office</a>. We also had a presentation about existing and upcoming protections against web tracking at the <a href="https://chemnitzer.linux-tage.de/2026/en">Chemnitz Linux Days</a> conference, and a talk about the latest browser-based XSS protections at <a href="https://owasp.glueup.com/event/owasp-global-appsec-eu-2026-vienna-austria-162243/">OWASP AppSec ‘26</a> in Vienna.</p>

<h3>Web Security &amp; Standards</h3>

<p><strong>Web Application Integrity, Consistency and Transparency (WAICT):</strong> We are working on WAICT, a new proposal to bring stronger integrity and transparency guarantees to web applications, helping make the web a more trustworthy platform for security-sensitive applications such as end-to-end encrypted messaging. We shared our technical vision in a <a href="https://hacks.mozilla.org/2026/05/trustworthy-javascript-for-the-open-web/">Mozilla Hacks blog post</a>, including a prototype implementation in Firefox Nightly that works with our <a href="https://demo.waict.dev/">WAICT Demo</a> and a <a href="https://github.com/waict-wg">draft specification</a>.</p>

<p><strong>Sanitizer API:</strong> We are advancing the Sanitizer API to make robust protection against cross-site scripting (XSS) vulnerabilities more accessible. By exploring an <a href="https://github.com/mozilla/explainers/blob/main/trusted-or-sanitized-html.md">implicit sanitizer policy</a> that integrates with Trusted Types, we aim to prevent an entire class of XSS attacks with no application code changes, making secure-by-default web applications easier to build and deploy.</p>

<h3>Looking Ahead</h3>

<p>Firefox users will receive these security and privacy improvements automatically. If you’re not already a user, <a href="https://firefox.com/">we recommend you give it a try</a>. Firefox helps you shape a more personal internet that puts you back in control - all while supporting the non-profit Mozilla in its mission to keep the web open, safe, and accessible for everyone.</p>

<p>Thank you to everyone who contributes to making Firefox and the web more secure and privacy-focused. You can have an impact too, just by <a href="https://bugzilla.mozilla.org/enter_bug.cgi">reporting bugs</a>, conducting research, contributing code, or providing feedback.</p>

<p>We look forward to sharing more updates in the Q3 2026 edition.</p>

<p><em>— The Firefox Security &amp; Privacy Teams</em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: How Google plans to reinvent the spreadsheet with AI]]></title>
<description><![CDATA[Nearly five decades after the launch of VisiCalc, AI is reshaping one of the world’s most familiar productivity tools — the humble spreadsheet.



While a lot of knowledge workers interact with spreadsheets on a regular basis, many lack the skills and confidence to access more advanced functions....]]></description>
<link>https://tsecurity.de/de/3665017/ai-nachrichten/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665017/ai-nachrichten/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai/</guid>
<pubDate>Mon, 13 Jul 2026 13:04:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nearly five decades after the launch of VisiCalc, AI is reshaping one of the world’s most familiar productivity tools — the humble spreadsheet.</p>



<p>While a lot of knowledge workers <a href="https://www.acuitytraining.co.uk/news-tips/new-excel-facts-statistics/" target="_blank" rel="noreferrer noopener">interact with spreadsheets on a regular basis</a>, many lack the skills and confidence to access more advanced functions.</p>



<p>“For a very long time, spreadsheets forced you to learn spreadsheet syntax and spreadsheet ways of working,” said Eric Birnbaum, director of product management for <a href="https://www.computerworld.com/article/1657150/how-to-use-google-sheets.html" data-type="link" data-id="https://www.computerworld.com/article/1657150/how-to-use-google-sheets.html">Google Sheets</a>. “But think about how many people need to use spreadsheets at work and don’t have the skill set to create the kinds of spreadsheets that can be really helpful for them.”</p>



<p>The addition of artificial intelligence can help handle that issue, he said, making the software more accessible to a wide range of office workers. “AI is unlocking the power of spreadsheets, taking on a lot of the difficult work that’s required to use them. That can be incredibly empowering for users,” said Birnbaum.</p>



<p>Google has steadily <a href="https://www.computerworld.com/article/4131504/gemini-supercharge-google-sheets-spreadsheets.html" data-type="link" data-id="https://www.computerworld.com/article/4131504/gemini-supercharge-google-sheets-spreadsheets.html">expanded generative AI (genAI) capabilities in Sheets</a> since launching Duet AI — now Gemini — for Workspace in 2023.</p>



<p>Gemini in Sheets is available at no extra cost to Google Workspace subscribers, though a paid <a href="https://knowledge.workspace.google.com/admin/generative-ai/workspace-with-gemini/ai-expanded-access" target="_blank" rel="noreferrer noopener">AI Expanded Access add-on </a>– costing $30 per user each month – is required to remove certain usage limits.</p>



<p>Features that have rolled out in recent months include the ability for a Gemini agent in Sheets to carry out <a href="https://workspaceupdates.googleblog.com/2025/10/expanded-editing-capabilities-gemini-in-google-sheets.html" target="_blank" rel="noreferrer noopener">multi-step actions</a> such as formatting, analysis and data entry, and, more recently, the ability to <a href="https://workspaceupdates.googleblog.com/2026/04/build-and-edit-complex-spreadsheets-with-Gemini-in-Google-Sheets.html" target="_blank" rel="noreferrer noopener">create entire spreadsheets</a> from a single prompt. A <a href="https://workspaceupdates.googleblog.com/2026/04/effortlessly-automate-data-entry-in-Google-Sheets-using-Fill-with-Gemini.html" target="_blank" rel="noreferrer noopener">Fill with Gemini feature </a>builds on the<a href="https://workspaceupdates.googleblog.com/2025/06/generate-data-with-gemini-in-google-sheets.html" target="_blank" rel="noreferrer noopener"> existing AI function,</a> enabling users to automatically populate selected cells by detecting intent from information within a spreadsheet as well as from the web.</p>



<p>Another feature, Sheets Canvas (currently available in alpha), lets users generate interactive apps that update in real-time based on changes to spreadsheet data. This could be a kanban board for a sales pipeline, for instance, or an analytics dashboard that uses Sheets as its back-end data source. </p>



<p>Google claims users already see a range of benefits from Gemini in Sheets. According to an August 2025 survey of 200 Sheets users conducted by the company, the majority of knowledge workers (89%) said AI features in Sheets save them at least an hour a week, and 88% believe AI features have made them more confident in their data analysis skills. </p>



<p>The most popular AI use cases include creating spreadsheets and charts, analyzing data, and fixing broken formulas. How widely these features are actually used is unclear; Google declined to provide weekly usage statistics for Gemini in Sheets.</p>



<p>As the company embeds Gemini deeper into Sheets, questions remain about just how much businesses can trust AI tools to handle important business data, as well as what increased automation means for those who spend much of their day wrangling data. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="480" height="480" sizes="auto, (max-width: 480px) 100vw, 480px"&gt;<figcaption class="wp-element-caption"><p>Eric Birnbaum, director of product management for Google Sheets.</p></figcaption></figure><p class="imageCredit">Google</p></div>



<p><em>Computerworld</em> recently talked with Birnbaum about the potential benefits and challenges of the latest evolution of spreadsheet software. This interview has been condensed and edited for clarity.</p>



<p><strong>As businesses become more focused on seeing value from AI investments, what measurable benefits are customers seeing from Gemini in Sheets – for example, time saved or other forms of return on investment? </strong>“Spreadsheets remain one of the universal languages for businesses, and we don’t anticipate that’s going to change anytime soon. But by bringing AI into the product where people work, we think it can significantly reduce the technical tax of data: the time spent understanding it, sourcing it, analyzing it, visualizing it.</p>



<p>“Historically, data professionals spent — let’s estimate it at 80% of their time — on the mechanical groundwork, data cleaning, crafting formulas, formatting, troubleshooting, and maybe only 20% of their time on actual strategic decision-making.</p>



<p>“We think that by offloading the manual, time-consuming, error-prone data work to Gemini, we can flip that ratio a bit, so humans can focus on the things that really matter: the high-value questions to ask and the judgment calls and decisions that get made from them. We’re starting to see evidence of that in our own user base and customer base.</p>



<p>“The second point to make is that AI can democratize data analysis to some extent, and make it available to many more users. For so many years, the spreadsheet was a gatekeeper; if you couldn’t speak the rigid language of spreadsheet formulas, you couldn’t extract the value from data. But by introducing these natural language interfaces, AI is separating the analytical capability from the technical literacy. </p>



<p>“If you can ask the right questions, or describe what you want in plain language, Gemini and Sheets can help you achieve your goals in a spreadsheet, even if you have minimal spreadsheet skills yourself.</p>



<p>“What we’ve seen so far from users and customers is that it’s incredibly empowering for people who might have been scared off by data analysis or dreaded opening spreadsheets in the past. You don’t need to go and wait for a data analyst to help you; you can go and do this work yourself in a spreadsheet.”</p>



<p><strong>The flip side is, how confident can businesses be if more junior employees can take on higher-level analysis tasks by relying on AI? Given the propensity for AI models to hallucinate, to what degree can businesses trust that these tools won’t introduce errors into important business data? </strong>“It’s something we spent a ton of time thinking about. We’ve gone to great lengths to build these AI tools to collaborate with you, to show their work, explain what they did, and make sure that you can take over where they leave off.</p>



<p>“Our Sheets agent, for example, lays out a really explicit, transparent plan for you to review and approve before any data manipulation happens. It’s designed to do that in plain natural language in a way that the average user could understand, and then it gives you back that final summary, so you know exactly what it did and where it did it.</p>



<p>“The other thing is that the model is great at explaining things. If you inherit a spreadsheet that has some complex formula that you don’t understand, for example, the model does an amazing job of explaining how it works and what it’s doing.</p>



<p>“In many ways AI is not only making these features more accessible, but helping users feel more confident in the output. Human error is an inherent risk in manual data management, with or without AI. One misplaced comma or broken cell reference can completely corrupt an entire financial model, and it can be completely undetected. </p>



<p>“Our approach with AI in Sheets is to create this deliberate verification loop. You now have another spreadsheet expert working along with you, reducing the likelihood of these mistakes.”</p>



<p><strong>Even if humans produce errors too, does it ultimately come down to accountability when AI is involved? </strong>“Our point of view here is that AI should be partnering with the knowledge worker who’s doing the work here. And everything that we’ve built is designed to be that partner. You might be able to offload tasks to the model, but we’re citing sources, we’re providing plans and explanations. We’re ultimately relying on the user to do that final verification.</p>



<p>“We spend a humongous amount of time focused on quality. We know that for AI to be useful in spreadsheets, it has to be reliable. When we launched Sheets Gemini Agent, for example, we were really proud that we set a state-of-the-art benchmark on the full SpreadsheetBench data set, which at the time exceeded competitors and near-human expert ability. </p>



<p>“But we know quality is never ‘good enough’ or done. We’re constantly working to improve quality for our users and customers, and for the use cases where they’re relying on AI most.”</p>



<p><strong>What potential do you see for more agentic functionality in Gemini Sheets — for example, bringing in data from other sources, creating recurring reports, or taking more actions independently? “</strong>We’re listening closely to customers and users and building what they’re telling us they need. The agent is already capable of doing very complex multistep workflows, and we see users discover that the agent is extremely capable of doing end-to-end spreadsheet tasks. In terms of connectors, in an alpha we have connections available to HubSpot, Salesforce, and Mailchimp. We hope to expand that over time.</p>



<p>“There’s no path to have AI replacing analysts. I think AI is giving analysts more time back to actually do the more valuable parts of their job. Analysts that I work with are way more productive and impactful than they ever were before, because they can push that uninteresting spreadsheet grunt work off to the model, freeing up time for more interesting and impactful work.</p>



<p>“A great example: the visualizations I’m getting back from analysts nowadays are canvases instead of static charts that I can explore myself. It’s way more informative and useful than what I was accustomed to before.”</p>



<p><strong>Looking ahead, do you expect a larger share of spreadsheet work to be carried out by agents, with humans setting goals and reviewing results? What will be the biggest change in how people use spreadsheets with AI? </strong>“The tasks are likely to stay similar and the use cases for spreadsheets are likely to continue to be relevant. The biggest change will be the ability to push the uninteresting spreadsheet grunt work off to a model and free up time for the user to do things that are more impactful, more interesting, more meaningful to the business.</p>



<p>‘Spreadsheets have historically been these like static containers where data goes to rest. I think AI can turn spreadsheets into these dynamic, localized software applications. And I do actually think this sort of changes the game for how people might use spreadsheets moving forward. </p>



<p>“It’s not just a passive grid full of numbers; spreadsheets are evolving to become these live, long-lived, collaborative applications. Employees can build these on the fly, like a basic CRM or supply chain dashboard in seconds. This is an area of investment for us moving forward, and we’re really excited to see how this evolves.”</p>



<p><strong>AI assistants and agents, such as ChatGPT or Claude, might be able to analyze spreadsheet files and business data without users working inside a spreadsheet application. What do you think will keep Sheets central to the workflow, rather than simply making it one part of a wider AI-driven process?</strong>“We’re in constant touch with customers and users; it’s clear work is still happening in spreadsheets. I think spreadsheets remain incredibly popular tools. If we can bring the AI capabilities users need directly into the product where they already are, we’ll transform the way they work.  </p>



<p>“I think we can be the front-end for some of this great AI innovation and the products that users are accustomed to today. Everything we build is guided by user feedback: users are telling us right now they want AI to help them do their everyday or more complex tasks, and they’re starting in Sheets today.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the software development jobs are now]]></title>
<description><![CDATA[While many technology companies have slowed hiring or even launched significant layoffs, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with knowledge of AI—are in demand in other industries.



The key to success for deve...]]></description>
<link>https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While many technology companies have slowed hiring or even launched <a href="https://www.trueup.io/layoffs" data-type="link" data-id="https://www.trueup.io/layoffs">significant layoffs</a>, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with <a href="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html" data-type="link" data-id="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html">knowledge of AI</a>—are in demand in other industries.</p>



<p>The key to success for developers looking to snatch up these roles is to be well-prepared to meet the needs of potential employers in a variety of sectors.</p>



<p>“The demand for developers in non-tech sectors is real and growing, but the roles look different from what you’d find at a software company,” says <a href="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/" data-type="link" data-id="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/">Pragati Awasthi</a>, assistant teaching professor of AI and data science at Drexel University.</p>



<p>“Across all these sectors, the common thread is that software is no longer a support function; it is embedded in core operations,” Awasthi says. “The developer in these environments is often the person translating domain-specific business problems into technical solutions, which requires a different profile than a pure product engineer at a tech firm.”</p>



<h2 class="wp-block-heading">Opportunity knocks</h2>



<p>The tech industry has long been a mainstay as far as employing software developers. But as these businesses trim staffs in efforts to cut expenses, that has impacted the hiring landscape. Even as the tech sector scales back, however, companies in industries such as financial services/fintech, healthcare/healthtech, retail/ecommerce, and manufacturing are looking to acquire programming talent.</p>



<p>“The unifying factor is data complexity,” Awasthi says. “These industries generate large volumes of sensitive, regulated, or operationally critical data, and they need developers who can build and maintain systems that handle it responsibly.”</p>



<p>While recruiting firm Summit Search Group has placed developers in roles with technology companies, “it is just as common to recruit them for roles outside this niche,” says <a href="https://www.linkedin.com/in/matterhard/" data-type="link" data-id="https://www.linkedin.com/in/matterhard/">Matt Erhard</a>, managing partner at the company. “There are actually a fairly wide variety of roles available for developers in industries beyond tech,” Erhard says.</p>



<p>For example, in financial services Summit Search Group has seen significant hiring for back-end and data engineers who can build and maintain fraud detection systems, digital banking platforms, and regulatory tools, Erhard says. In healthcare, companies are hiring developers to build AI-driven diagnostics platforms and patient portals, or to work with systems that manage electronic health records, he says.</p>



<p>In manufacturing and industrial companies, developers are needed for systems integration and embedded software related to predictive maintenance, <a href="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html" data-type="link" data-id="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html">Internet of Things</a> (IoT) systems, and smart factories. And in retail and ecommerce, there’s strong demand for <a href="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html" data-type="link" data-id="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html">full-stack developers</a> and data developers who can handle logistics systems, omni-channel platforms, and personalization engines, Erhard says.</p>



<p>“One significant function where we’ve been placing developer talent lately is in developing business systems and internal applications,” Erhard says. These roles often have titles such as systems engineer or application developer, and professionals are hired to handle tasks such as customizing customer relationship management (CRM) or enterprise resource planning (ERP) platforms, building workflow automation tools or modernizing legacy systems, he says.</p>



<p>Other core functions for which Summit Search Group has placed a lot of developers include data, analytics, and AI-enablement. “That could be directly involved with <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data engineering</a> or in building tools like reporting systems and <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">ETL [extract, transform, load]</a> pipelines,” Erhard says.</p>



<p>The firm also has handled searches for developers who can build and maintain customer-facing products for banking, healthcare, and retail companies, such as mobile apps or digital platforms customers can use to interact with companies.</p>



<p>Randstad Digital, a provider of global technology talent, sees demand for roles including web developers, system developers, and app developers. “These professionals would work on anything from customer-facing platforms to internal tools,” says <a href="https://www.linkedin.com/in/mpmorris36/" data-type="link" data-id="https://www.linkedin.com/in/mpmorris36/">Michael Morris</a>, global head of platform and talent at the company. “Non-tech companies are also often hiring roles like software architecture and <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> to help scale existing technology. These involve being more ingrained in the business, like building a supply chain system for a retailer, rather than creating individual tech products like you would at a technology company.”</p>



<h2 class="wp-block-heading">Prep for success</h2>



<p>To increases the chances of success at landing developer jobs outside of the tech industry, development professionals would be wise to follow some good practices.</p>



<h3 class="wp-block-heading">Boost AI skills</h3>



<p>One best practice is to boost skills in using AI-powered tools and get familiar with all things AI.</p>



<p>“Get fluent with AI-assisted development and its limits,” Awasthi says. “This is not optional. Organizations across every sector expect developers to use AI coding tools productively. But the more durable skill is knowing when AI output is wrong, incomplete, or unsuitable for a regulated context. That critical evaluation capacity is what non-tech employers are increasingly trying to hire.”</p>



<p>AI does not necessarily replace the need for human developers so much as it changes the skills profile for those roles, Erhard says. “The biggest difference in recent years is that AI literacy is now a non-negotiable,” he says. “At minimum, developers today need to understand concepts like <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html" data-type="link" data-id="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a> and how to use AI tools to improve their efficiency.”</p>



<p>One thing many job candidates don’t expect is that the rise of AI has also increased the importance of high-level skills such as problem framing, system design, and cross-functional communication,” Erhard says. “Essentially, if something is related to development but too complex or nuanced for an AI to handle effectively, then the demand is high for human developers who have that expertise,” he says.</p>



<p>Candidates who land roles consistently have experience building AI-augmented workflows along with standard coding skills, Erhard says. “Employers increasingly expect to hire developers who can leverage AI, so demonstrating this experience on your résumé can be very beneficial,” he says.</p>



<h3 class="wp-block-heading">Gain domain knowledge</h3>



<p>Summit Search Group is seeing high demand for developers with deep domain knowledge in an organization’s specific industry. “So, for instance, if someone is both an experienced developer and has expertise in healthcare compliance, or financial regulations, then those candidates tend to be very sought after,” Erhard says.</p>



<p>Domain fluency is an underrated skill, Awasthi says. “A developer who understands healthcare compliance, financial regulation, or manufacturing process logic is significantly harder to replace than one who only writes clean code,” she says. “AI can generate boilerplate. It cannot navigate a HIPAA audit or explain a model’s output to a compliance officer.”</p>



<p>Development professionals should “pick an industry and learn it seriously; not just the technology stack but the regulatory environment, the business model, and the actual problems practitioners face,” Awasthi says. “A developer who has read about HIPAA, or spent time understanding credit risk, is immediately more valuable in those hiring contexts.”</p>



<p>It’s also vital to demonstrate real-world, practical application of skills, not just credentials. “The strongest candidates have projects in their portfolio that directly tie to and solve real business problems,” Erhard says.</p>



<h3 class="wp-block-heading">Acquire soft skills</h3>



<p>And then there are the soft skills that are becoming more of a differentiator than they were in the past. As AI handles more routine coding, human developers are expected to make more architectural decisions and collaborate across departments, Erhard says. “Strong communication and problem-solving skills are critical for many of the developer roles that we’re filling today,” he says.</p>



<p>While technical skills are still relevant for developers using and managing AI tools, “they also need to develop the skill of ‘deeper thinking’ and learn how to think one step ahead,” Morris says. “This includes skills like system design mastery—understanding the macro view and learning how <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>, databases, and third-party APIs interact securely and efficiently.”</p>



<p>They also should become deeply fluent in the AI coding tools commonly used in their particular industry, with a strong understanding of how to prompt them for optimal output, Morris says. Product context awareness is also useful. “AI doesn’t know what the customer wants, but you do,” Morris says. “Understanding the business problem and the end-user experience is a requirement for being able to guide LLMs.”</p>



<h3 class="wp-block-heading">Master debugging and incident response</h3>



<p>Developers looking to break into non-tech sectors also should develop skills in debugging and incident response, Morris says. “Complex systems with multiple AI agents can, and will, fail, which means companies need humans to trace logic flaws to get the system back on track,” he says. “A mastery of root-cause analysis is a critical skill.”</p>



<p>“Security, compliance, and reliability are very important in non-tech industries like finance and healthcare,” says <a href="https://www.linkedin.com/in/rohit-agarwal/" data-type="link" data-id="https://www.linkedin.com/in/rohit-agarwal/">Rohit Agarwal</a>, co-founder of Zenius, a remote hiring company. “So employers want developers who also know regulatory environments well.”</p>



<h3 class="wp-block-heading">Network and keep learning</h3>



<p>To successfully pivot from jobs at tech companies, “continuous learning, upskilling, and building hybrid skills that combine technical and business knowledge are essential,” Morris says. “With the right preparation, tech professionals can adapt and continue to thrive in meaningful, dynamic careers.”</p>



<p>It’s also a good idea to join talent communities in fields of interest and “engage with other members in conversations that increase your knowledge through the collective intelligence of the community,” Morris says. “Take advantage of AI skilling opportunities relevant for your role, or better yet, where you want to go next. Experiment with the technology either on your own or through structured programs.” Ultimately, be curious and proactive, he says.</p>



<p>“I’d also recommend developers not to ignore referrals, direct outreach, and industry-specific communities during job search,” Agarwal says. “There are often a lot more opportunities available than the ones posted online.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberangriff auf Canvas: 9.000 Schulen verlieren 3,5 TB Daten - BornCity]]></title>
<description><![CDATA[Massive Datenlecks bei Instructure, Accenture und AssuranceAmerica erschüttern die Cybersicherheit. KI-gesteuerte Angriffe nehmen zu. · Hackerangriff ...]]></description>
<link>https://tsecurity.de/de/3663351/it-security-nachrichten/cyberangriff-auf-canvas-9000-schulen-verlieren-35-tb-daten-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663351/it-security-nachrichten/cyberangriff-auf-canvas-9000-schulen-verlieren-35-tb-daten-borncity/</guid>
<pubDate>Sun, 12 Jul 2026 15:36:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Massive Datenlecks bei Instructure, Accenture und AssuranceAmerica erschüttern die Cybersicherheit. KI-gesteuerte Angriffe nehmen zu. · Hackerangriff ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Chasing new skills, going back to basics and pushing for collective action: how software engineers are adapting to AI]]></title>
<description><![CDATA[Software engineering was one of the best-paying professions in the US in 2022, but the advent of AI has disrupted it, leading to several layoffs and underemploymentEvery weekday, Matt, a software engineer, looks forward to his four-hour train commute to Pawling, New York. It’s time he uses to wor...]]></description>
<link>https://tsecurity.de/de/3663106/ai-nachrichten/chasing-new-skills-going-back-to-basics-and-pushing-for-collective-action-how-software-engineers-are-adapting-to-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663106/ai-nachrichten/chasing-new-skills-going-back-to-basics-and-pushing-for-collective-action-how-software-engineers-are-adapting-to-ai/</guid>
<pubDate>Sun, 12 Jul 2026 12:03:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Software engineering was one of the best-paying professions in the US in 2022, but the advent of AI has disrupted it, leading to several layoffs and underemployment</p><p>Every weekday, Matt, a software engineer, looks forward to his four-hour train commute to Pawling, New York. It’s time he uses to work on his own project: a browser-based video game for which he writes every line of code himself.</p><p>“I am actively trying to keep my axe sharp,” said Matt, who did not want to use his actual name, to protect his employment. In the last six months, Matt’s job has increasingly shifted away from coding, problem solving and software architecture towards reviewing code generated by artificial intelligence. Convinced that the shift will weaken his skills, he’s doing what he can to keep them intact. “I am trying not to leverage AI where I can.”</p> <a href="https://www.theguardian.com/technology/ng-interactive/2026/jul/12/software-developers-engineers-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exponential growth in DDoS attack volumes]]></title>
<description><![CDATA[Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. To hel...]]></description>
<link>https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. </p><p>To help ensure reliability, we’ve devised some innovative ways to defend against advanced attacks. In this post, we’ll take a deep dive into DDoS threats, showing the trends we’re seeing and describing how we prepare for multi-terabit attacks, so your sites stay up and running.</p><h3>Taxonomy of attacker capabilities</h3><p>With a DDoS attack, an adversary hopes to disrupt their victim's service with a flood of useless traffic. While this attack doesn't expose user data and doesn't lead to a compromise, it can result in an outage and loss of user trust if not quickly mitigated.</p><p>Attackers are constantly developing new techniques to disrupt systems. They give their attacks fanciful names, like Smurf, Tsunami, XMAS tree, HULK, Slowloris, cache bust, TCP amplification, javascript injection, and a dozen variants of reflected attacks. Meanwhile, the defender must consider every possible target of a DDoS attack, from the network layer (routers/switches and link capacity) to the application layer (web, DNS, and mail servers). Some attacks may not even focus on a specific target, but instead attack every IP in a network. Multiplying the dozens of attack types by the diversity of infrastructure that must be defended leads to endless possibilities.</p><p>So, how can we simplify the problem to make it manageable? Rather than focus on attack methods, Google groups volumetric attacks into a handful of key metrics:</p><p></p><ul><li><b>bps</b>	network bits per second → attacks targeting network links</li><li><b>pps</b>	network packets per second → attacks targeting network equipment or DNS servers</li><li><b>rps</b>	HTTP(S) requests per second → attacks targeting application servers</li></ul><p></p><p>This way, we can focus our efforts on ensuring each system has sufficient capacity to withstand attacks, as measured by the relevant metrics.</p><h3>Trends in DDoS attack volumes</h3><p>Our next task is to determine the capacity needed to withstand the largest DDoS attacks for each key metric. Getting this right is a necessary step for efficiently operating a reliable network—overprovisioning wastes costly resources, while underprovisioning can result in an outage.</p><p>To do this, we analyzed hundreds of significant attacks we received across the listed metrics, and included credible reports shared by others. We then plot the largest attacks seen over the past decade to identify trends. (Several years of data prior to this period informed our decision of what to use for the first data point of each metric.)</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/DDoS_attacks.max-1000x1000.jpg" alt="DDoS attacks.jpg">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>The exponential growth across all metrics is apparent, often generating alarmist headlines as attack volumes grow. But we need to factor in the exponential growth of the internet itself, which provides bandwidth and compute to defenders as well. After accounting for the expected growth, the results are less concerning, though still problematic.</p><h3>Architecting defendable infrastructure</h3><p>Given the data and observed trends, we can now extrapolate to determine the spare capacity needed to absorb the largest attacks likely to occur.</p><p><b>bps</b> (network bits per second)<br>Our infrastructure absorbed a 2.5 Tbps DDoS in September 2017, the culmination of a six-month campaign that utilized multiple methods of attack. Despite simultaneously targeting thousands of our IPs, presumably in hopes of slipping past automated defenses, the attack had no impact. The attacker used <a href="https://blog.google/threat-analysis-group/how-were-tackling-evolving-online-threats" target="_blank">several networks</a> to spoof 167 Mpps (millions of packets per second) to 180,000 exposed CLDAP, DNS, and SNMP servers, which would then send large responses to us. This demonstrates the volumes a well-resourced attacker can achieve: This was four times larger than the record-breaking 623 Gbps attack from the Mirai botnet a year earlier. It remains the highest-bandwidth attack reported to date, leading to reduced confidence in the extrapolation.<br></p><p><b>pps</b> (network packets per second) <br>We’ve observed a consistent growth trend, with a 690 Mpps attack generated by an IoT botnet this year. A notable outlier was a 2015 attack on a customer VM, in which an IoT botnet ramped up to 445 Mpps in 40 seconds—a volume so large we initially thought it was a monitoring glitch!</p><p><b>rps</b> (HTTP(S) requests per second)<br>In March 2014, malicious javascript injected into thousands of websites via a network man-in-the-middle attack caused hundreds of thousands of browsers to flood YouTube with requests, peaking at 2.7 Mrps (millions of requests per second). That was the largest attack known to us until recently, when a Google Cloud customer was attacked with 6 Mrps. The slow growth is unlike the other metrics, suggesting we may be under-estimating the volume of future attacks.</p><p>While we can estimate the expected size of future attacks, we need to be prepared for the <i>unexpected</i>, and thus we over-provision our defenses accordingly. Additionally, we design our systems to degrade gracefully in the event of overload, and write playbooks to guide a manual response if needed. For example, our layered defense strategy allows us to block high-rps and high-pps attacks in the network layer before they reach the application servers. Graceful degradation applies at the network layer, too: Extensive peering and network ACLs designed to throttle attack traffic will mitigate potential collateral damage in the unlikely event links become saturated.</p><p>For more detail on the layered approach we use to mitigate record-breaking DDoS attacks targeting our services, infrastructure, or customers, see Chapter 10 of our book, <a href="https://landing.google.com/sre/resources/foundationsandprinciples/srs-book/" target="_blank">Building Secure and Reliable Systems</a>.</p><h3>Cloud-based defenses</h3><p>We recognize the scale of potential DDoS attacks can be daunting. Fortunately, by deploying <a href="https://cloud.google.com/armor">Google Cloud Armor</a> integrated into our <a href="https://cloud.google.com/load-balancing">Cloud Load Balancing </a>service—which can scale to absorb massive DDoS attacks—you can protect services deployed in Google Cloud, other clouds, or on-premise from attacks. We recently announced <a href="https://cloud.google.com/blog/products/identity-security/google-cloud-armor-features-to-protect-your-websites-and-applications">Cloud Armor Managed Protection</a>, which enables users to further simplify their deployments, manage costs, and reduce overall DDoS and application security risk.</p><p>Having sufficient capacity to absorb the largest attacks is just one part of a comprehensive DDoS mitigation strategy. In addition to providing scalability, our load balancer terminates network connections on our global edge, only sending well-formed requests on to backend infrastructure. As a result it can automatically filter many types of volumetric attacks. For example, UDP amplification attacks, synfloods, and some application-layer attacks will be silently dropped. The next line of defense is the Cloud Armor WAF, which provides built-in rules for common attacks, plus the ability to deploy custom rules to drop abusive application layer requests using a broad set of HTTP semantics.</p><h3>Working together for collective security</h3><p>Google works with others in the internet community to identify and dismantle infrastructure used to conduct attacks. As a specific example, even though the 2.5 Tbps attack in 2017 didn't cause any impact, we reported thousands of vulnerable servers to their network providers, and also worked with network providers to trace the source of the spoofed packets so they could be filtered.</p><p>We encourage everyone to join us in this effort. Individual users should ensure their computers and IoT devices are patched and secured. Businesses should report criminal activity, ask their network providers to trace the sources of spoofed attack traffic, and share information on attacks with the internet community in a way that doesn't provide timely feedback to the adversary. By working together, we can reduce the impact of DDoS attacks.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[EFF Celebrates 36th Anniversary, Says 'We Need You in the Fight']]></title>
<description><![CDATA["We need you in the fight," says the American legal expert in privacy, surveillance, AI, and Internet freedom of speech who became the EFF's new executive director in March. 

As EFF celebrates the anniversary of its founding 1990, "Each headline is different, but they tell one story: Many of the...]]></description>
<link>https://tsecurity.de/de/3662197/it-security-nachrichten/eff-celebrates-36th-anniversary-says-we-need-you-in-the-fight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662197/it-security-nachrichten/eff-celebrates-36th-anniversary-says-we-need-you-in-the-fight/</guid>
<pubDate>Sat, 11 Jul 2026 18:58:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["We need you in the fight," says the American legal expert in privacy, surveillance, AI, and Internet freedom of speech who became the EFF's new executive director in March. 

As EFF celebrates the anniversary of its founding 1990, "Each headline is different, but they tell one story: Many of the threats that once seemed hypothetical are now reality, and EFF's work to ensure technology supports rights, justice, freedom, and innovation for all people has never been more critical."

Governments and large corporations possess surveillance capabilities that were unimaginable just a few years ago. Ever greater concentrations of power are shaping speech, creativity, markets, and democratic institutions. Governments are increasingly seeking to control the internet and people's ability to access information and communicate freely. Our community's work is fundamental to the future of our countries, our livelihoods, and literally our lives... 

These are perilous times. It is also a moment of extraordinary possibility. The future of AI has not been written and we can work together to get it right. We can make sure our laws reflect the needs of the modern digital age. We can build the technologies that empower rather than marginalize communities.
For me, the work starts with recognizing that digital rights are not a siloed policy issue. We must fight and win on the digital terrain to organize, speak freely, access healthcare, find work, receive an education, and participate fully in democracy. We can and must reject a false choice between innovation and civil liberties, and build power across movements to make sure technology truly works for people... 

EFF's founders understood something remarkably prescient: Technology and civil liberties would become inseparable. Now we all live digital lives, and the important digital rights issues that EFF has worked on since 1990 have become kitchen-table issues all around the world. EFF's founders understood that how technology is built, developed, used, and controlled deeply intersects with rights, justice, freedom, and democracy. EFF's unique combination of world-class lawyers, activists, and public interest technologists pursue change simultaneously in the courts, legislatures, companies, and our communities, and pierce through false choices. This integrated, intersectional approach, grounded in deep legal, policy, and technical expertise, is a linchpin in fighting and winning against some of the most powerful forces in the world — both governments and trillion-dollar companies. 

We defend people against unlawful government data collection and challenge license plate and face surveillance in our communities. We shape AI law and policy to protect civil liberties and support creativity and innovation. We push companies to strengthen encryption, fight to ensure you have the right to own what you buy, and build public interest technologies like Privacy Badger and Certbot that millions of people rely on every day. This work matters because it all answers the same question: Will technology empower or control us?
 

Major battles the executive director sees on the horizon"


"Challenge increasingly sophisticated government and corporate surveillance systems that endanger our rights, democracy, safety and security."

"Preserve strong encryption and online anonymity."


"Ensure AI is developed and used in ways that respect fundamental rights and works for those who build it, use it, and are affected by it."

"Confront the concentrations of power that limit access to new creativity and defend the rights of developers to build and innovate."

"To meet these challenges, we must not only utilize the powerful levers of successful litigation, smart policy interventions, and effective public interest technology tools. We must also build a broader movement that recognizes that fights on the digital terrain are integral to all our fights for rights and justice... Together, our EFF community can help broaden the public conversation about technology's role in society and continue building the collective power necessary to shape the future rather than react to it.... 

"I'm looking forward to meeting more of you at my first EFFecting Change livestream on August 12 with Cory Doctorow, and hope this conversation is just the beginning of finding new ways to work together..." 

The blog post ends by noting that "We need you and others in the fight. Please renew your membership, become a recurring monthly supporter, and introduce someone new to EFF by snagging them a gift membership. 

"Everything we accomplish — every lawsuit, every policy victory, every public interest technology tool, every campaign — is possible because people like you are committed to ensuring technology strengthens freedom, privacy, creativity, and opportunity for everyone. 
"The future we want and need will be built by people and movements working together to ensure technology empowers rather than oppresses. 
"Let's build that future together."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=EFF+Celebrates+36th+Anniversary%2C+Says+'We+Need+You+in+the+Fight'%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F10%2F2241251%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F10%2F2241251%2Feff-celebrates-36th-anniversary-says-we-need-you-in-the-fight%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/10/2241251/eff-celebrates-36th-anniversary-says-we-need-you-in-the-fight?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datacentres drive emissions of Microsoft, Amazon and Google to half those of France]]></title>
<description><![CDATA[All three companies say they still aim to achieve net zero carbon output despite construction boomMicrosoft, Amazon and Google’s collective carbon emissions have increased by nearly a fifth in the past year, driven largely by datacentre construction.In the financial year ending March 2026, the th...]]></description>
<link>https://tsecurity.de/de/3661709/ai-nachrichten/datacentres-drive-emissions-of-microsoft-amazon-and-google-to-half-those-of-france/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661709/ai-nachrichten/datacentres-drive-emissions-of-microsoft-amazon-and-google-to-half-those-of-france/</guid>
<pubDate>Sat, 11 Jul 2026 13:03:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>All three companies say they still aim to achieve net zero carbon output despite construction boom</p><p>Microsoft, Amazon and Google’s collective <a href="https://www.theguardian.com/technology/2026/jul/06/ai-climate-crisis">carbon emissions</a> have increased by nearly a fifth in the past year, driven largely by datacentre construction.</p><p>In the financial year ending March 2026, the three tech companies emitted 119m mTCO₂e (metric tonnes of carbon dioxide equivalent), or roughly half the emissions of France.</p> <a href="https://www.theguardian.com/us-news/2026/jul/11/microsoft-amazon-google-datacentre-carbon-emissions-france">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit]]></title>
<description><![CDATA[More AI, more software, more bugs!AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example the new Flowise CSV...]]></description>
<link>https://tsecurity.de/de/3661054/it-security-nachrichten/weekly-metasploit-update-exploits-for-flowiseai-csv-agent-and-macos-package-kit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661054/it-security-nachrichten/weekly-metasploit-update-exploits-for-flowiseai-csv-agent-and-macos-package-kit/</guid>
<pubDate>Sat, 11 Jul 2026 02:51:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>More AI, more software, more bugs!</h2><p>AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example the new Flowise CSV Agent Prompt Injection RCE brought to you by Takahiro Yokoyama and zdi-disclosures. Flowise is an open-source tool that lets you build AI apps and chatbots using a visual, drag-and-drop canvas and CVE-2026-41264 is an unauthenticated RCE run method of the CSV_Agents class in Flowise. The vulnerability exists due insufficient sandboxing and an incomplete list of disallowed inputs. It allows unauthenticated attackers to upload a .csv file containing arbitrary python code and execute it. One moment you're using AI to help draft and email and the next moment you're getting pwn'd, what a world we live in! Happy Friday and happy hacking everyone.</p><h2>New module content (3)</h2><h3>Apache .htaccess Persistence</h3><p>Authors: 4ravind-b, msutovsky-r7, and wireghoul</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21473">#21473</a> contributed by <a href="https://github.com/4ravind-b">4ravind-b</a></p><p>Path: linux/persistence/apache_htaccess</p><p>Description: Adds a new persistence module, exploits/linux/persistence/apache_htaccess, that plants wireghoul's mod_cgi .htaccess web shell on a Linux Apache target.</p><h3>Flowise CSV Agent Prompt Injection RCE</h3><p>Authors: Takahiro Yokoyama and zdi-disclosures</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21407">#21407</a> contributed by <a href="https://github.com/Takahiro-Yoko">Takahiro-Yoko</a></p><p>Path: multi/http/flowise_auth_rce_cve_2026_41264</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-41264&amp;referrer=blog">CVE-2026-41264</a></p><p>Description: This adds a new exploit module for FlowiseAI Flowise (CVE-2026-41264). The CSV Agent feature evaluates LLM-generated Python code without proper sandboxing, allowing a prompt injection to achieve arbitrary code execution as the user running the server. Flowise versions 1.3.0 through 3.0.13 are affected. The module requires an API key with chatflows:create permission but does not require Flowise authentication to trigger the underlying flaw.</p><h3>macOS PackageKit ZSH Environment Privilege Escalation</h3><p>Authors: Mykola Grymalyuk and h00die</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21499">#21499</a> contributed by <a href="https://github.com/h00die">h00die</a></p><p>Path: osx/local/packagekit_zshenv_privesc</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2024-27822&amp;referrer=blog">CVE-2024-27822</a></p><p>Description: This adds a new local privilege escalation module for macOS targeting CVE-2024-27822 in PackageKit.framework. When a PKG installer script uses a ZSH shebang, PackageKit runs it as root while inheriting the installing user's environment, causing ZSH to source the user's ~/.zshenv with root privileges. The module plants a payload in ~/.zshenv that fires only when running as root, then opens a minimal PKG with Installer.app; once the user approves the installation prompt and authenticates, the payload executes as root and a root session is returned. Affected versions are macOS 14.4, 13.6.6, 12.7.4, and 11 and earlier; the issue is patched in 14.5, 13.6.7, and 12.7.5.</p><h2>Enhancements and features (5)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21416">#21416</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This updates the Exploit::Remote::Ftp mixin to improve target fingerprinting. It now leverages recog to fingerprint targets from their banners and adds ftp_fingerprint and ftp_list_directory methods to assist with target enumeration.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21436">#21436</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - Improved UX for reloading of library files.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21579">#21579</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - This adds a few extra fields to some MCP Server tools to align with recent RPC changes in the framework. The msf_service_info tool now has resource and parents fields, the msf_vulnerability_info tool now has a resource field, the msf_note_info tool now has a data field, and the msf_credential_info tool now has new realm_key and realm_value fields.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21580">#21580</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - This adds a Certificate Signing Request (CSR) Trace to the CertificateTrace functionality. Users can now opt to see the CSR get printed when requesting certificates from AD CS.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21637">#21637</a> from <a href="https://github.com/eve0805">eve0805</a> - This adds improved levels of granularity to the KerberosTicketTrace functionality. Users can now choose to print the full kerberos trace output, only the tickets or only the metadata.</li></ul><h2>Bugs fixed (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21588">#21588</a> from <a href="https://github.com/vinicius-batistella">vinicius-batistella</a> - Fix a bug in the format dispatcher where although we can generate AARCH64 windows exe files, we fail trying to do so because the dispatcher does not properly handle the request by the user.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21651">#21651</a> from <a href="https://github.com/jheysel-r7">jheysel-r7</a> - This fixes a bug in the Role Based Constrained Delegation (RBCD) module that prevented Access Control Entries (ACEs) from being removed due to a type mismatch while comparing Security Identifiers (SIDs).</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-07-01T09%3A42%3A42Z..2026-07-08T13%3A32%3A18-07%3A00%22">Pull Requests 6.4.142...6.4.143</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.142...6.4.143">Full diff 6.4.142...6.4.143</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LLMs: The good, the bad and the ugly from a security POV (osc26)]]></title>
<description><![CDATA[Depending on who you ask we're either experiencing a revolution like the introduction of the steam machine or a collective mass delusion that will end in a crash.

No matter what it is, it is changing how people code and package. This talk will present the basic risks when using LLMs for these ta...]]></description>
<link>https://tsecurity.de/de/3660587/it-security-video/llms-the-good-the-bad-and-the-ugly-from-a-security-pov-osc26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660587/it-security-video/llms-the-good-the-bad-and-the-ugly-from-a-security-pov-osc26/</guid>
<pubDate>Fri, 10 Jul 2026 20:18:53 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Depending on who you ask we're either experiencing a revolution like the introduction of the steam machine or a collective mass delusion that will end in a crash.

No matter what it is, it is changing how people code and package. This talk will present the basic risks when using LLMs for these tasks and how to handle them

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[LLMs: The good, the bad and the ugly from a security POV (osc26)]]></title>
<description><![CDATA[Depending on who you ask we're either experiencing a revolution like the introduction of the steam machine or a collective mass delusion that will end in a crash.

No matter what it is, it is changing how people code and package. This talk will present the basic risks when using LLMs for these ta...]]></description>
<link>https://tsecurity.de/de/3660556/it-security-video/llms-the-good-the-bad-and-the-ugly-from-a-security-pov-osc26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660556/it-security-video/llms-the-good-the-bad-and-the-ugly-from-a-security-pov-osc26/</guid>
<pubDate>Fri, 10 Jul 2026 20:04:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Depending on who you ask we're either experiencing a revolution like the introduction of the steam machine or a collective mass delusion that will end in a crash.

No matter what it is, it is changing how people code and package. This talk will present the basic risks when using LLMs for these tasks and how to handle them

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-43303 | Craftbeer Bar Canvas mini-app on Line 13.6.1 Channel Access Token information disclosure]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Craftbeer Bar Canvas mini-app on Line 13.6.1. This vulnerability affects unknown code of the component Channel Access Token Handler. This manipulation causes information disclosure.

The identification of this vulnerability i...]]></description>
<link>https://tsecurity.de/de/3660110/sicherheitsluecken/cve-2023-43303-craftbeer-bar-canvas-mini-app-on-line-1361-channel-access-token-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660110/sicherheitsluecken/cve-2023-43303-craftbeer-bar-canvas-mini-app-on-line-1361-channel-access-token-information-disclosure/</guid>
<pubDate>Fri, 10 Jul 2026 16:55:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/craftbeer:bar_canvas_mini-app_on_line">Craftbeer Bar Canvas mini-app on Line 13.6.1</a>. This vulnerability affects unknown code of the component <em>Channel Access Token Handler</em>. This manipulation causes information disclosure.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2023-43303">CVE-2023-43303</a>. The attack needs to be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[764 splinter group leader sentenced to 40 years in jail]]></title>
<description><![CDATA[Alexis Chavez coerced multiple girls to commit self harm and produce child sexual abuse material for notoriety in a sprawling violent extremist collective affiliated with the Com.
The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3657427/it-security-nachrichten/764-splinter-group-leader-sentenced-to-40-years-in-jail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657427/it-security-nachrichten/764-splinter-group-leader-sentenced-to-40-years-in-jail/</guid>
<pubDate>Thu, 09 Jul 2026 16:53:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Alexis Chavez coerced multiple girls to commit self harm and produce child sexual abuse material for notoriety in a sprawling violent extremist collective affiliated with the Com.</p>
<p>The post <a href="https://cyberscoop.com/764-splinter-group-leader-sentenced-alexis-chavez/">764 splinter group leader sentenced to 40 years in jail</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A brewing battle: More IT workers want unions. The industry doesn’t.]]></title>
<description><![CDATA[Until recently, many tech professionals viewed themselves as a special and respected worker class: highly educated, hard-working, well paid, and in demand.



“They considered themselves above unions,” says Zak Thompson, senior software engineer at Kickstarter and union steward at Kickstarter Uni...]]></description>
<link>https://tsecurity.de/de/3654078/ai-nachrichten/a-brewing-battle-more-it-workers-want-unions-the-industry-doesnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654078/ai-nachrichten/a-brewing-battle-more-it-workers-want-unions-the-industry-doesnt/</guid>
<pubDate>Wed, 08 Jul 2026 13:04:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Until recently, many tech professionals viewed themselves as a special and respected worker class: highly educated, hard-working, well paid, and in demand.</p>



<p>“They considered themselves above unions,” says <a href="https://www.linkedin.com/in/zthompson1/" target="_blank" rel="noreferrer noopener">Zak Thompson</a>, senior software engineer at Kickstarter and union steward at Kickstarter United.</p>



<p>Big Tech issued aspirational mission statements that motivated workers, workplaces were seen as meritocracies, and employees were encouraged to speak out if they were unhappy. If workers didn’t like where they worked, they just moved on: other employers would be falling over themselves to hire them.</p>



<p>How times have changed.</p>



<p>Now, fed up with mass layoffs, disillusioned with Big Tech’s direction, and stunned by bold management proclamations that AI will displace huge numbers of people in many tech jobs — starting with programmers — interest in unions has risen sharply among tech professionals. Workers in some organizations, including Kickstarter, have already taken the plunge.</p>



<h2 class="wp-block-heading">A surge in interest</h2>



<p>“Starting in 2022, the industry as a whole started seeing very large layoffs across the board [and] that has dramatically shifted the balance of power. I think most people in the industry have experienced that one way or another,” says Google software engineer <a href="https://www.linkedin.com/in/alan-mcavinney-a386b8122/" target="_blank" rel="noreferrer noopener">Alan McAvinney</a>.</p>



<p>But not everyone is convinced that the layoffs have changed the power dynamic. “I wouldn’t say the balance has definitively shifted… some things point to workers losing ground and others point to improvement,” says <a href="https://www.mercatus.org/scholars/liya-palagashvili" target="_blank" rel="noreferrer noopener">Liya Palagashvili</a>, senior research fellow and director of the Labor Policy Project at the Mercatus Center at George Mason University. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Liya Palagashvili of the Mercatus Center at George Mason University</p><br></figcaption></figure><p class="imageCredit">Mercatus Center at George Mason University</p></div>



<p>What matters, she says, is not the size of the layoffs but worker options: how easily laid off workers can find alternative work in their field.</p>



<p>For McAvinney, the decision to support a union was about a culture change at his employer.</p>



<p>“In 2019, Google fired four people (<a href="https://www.newsweek.com/google-fires-thanksgiving-four-workers-crush-dissent-1474102" target="_blank" rel="noreferrer noopener">the ‘Thanksgiving Four’</a>) after they organized and spoke out internally against the company’s work with the anti-union firm IRI and US Customs and Border Protection. That was a big turning point for me,” he says. “Historically, we had a pretty robust culture that actually encouraged us to speak up internally.”</p>



<p>Google said the employees were fired for violating data security policies, but many workers believed the move was retaliatory. It became a galvanizing event that contributed to the launch of the <a href="https://www.alphabetworkersunion.org/" target="_blank" rel="noreferrer noopener">Alphabet Workers Union (AWU)</a> in 2021, says McAvinney, organizing chair, Alphabet Workers Union-CWA. (Alphabet is the parent company of Google.)</p>



<p>So far, tech worker interest in unions hasn’t translated into higher membership numbers nationally. According to the US Census Bureau’s <a href="https://www.census.gov/programs-surveys/cps.html" target="_blank" rel="noreferrer noopener">Current Population Survey (CPS)</a>, union membership in tech occupations was about 3.5% in 2025, says Palagashvili. “While there have been some high-profile organizing efforts, they do not yet show up as a broad national increase in tech-sector unionization.”</p>



<p>Overall, only 10% of American workers belonged to a union in 2025, the Bureau of Labor Statistics (BLS) <a href="https://www.bls.gov/news.release/union2.nr0.htm" target="_blank" rel="noreferrer noopener">reported</a> — near an all-time low — but interest in labor unions is rising. A 2025 Gallup survey found that <a href="https://news.gallup.com/poll/694472/labor-union-approval-relatively-steady.aspx" target="_blank" rel="noreferrer noopener">68% of Americans approved of unions</a>, up from 48% in 2009. Interest is particularly strong among younger workers, the <a href="https://www.epi.org/publication/workers-resolve-drives-increase-in-unionization-in-2025/" target="_blank" rel="noreferrer noopener">Economic Policy Institute reports</a>, and in a 2024 <a href="https://www.teamblind.com/blog/why-are-unions-not-common-tech-industry/" target="_blank" rel="noreferrer noopener">online survey of 1,900 tech professionals</a> on the career site Blind, 67% of respondents said they’d be “very likely” or “somewhat likely” to join a union if their company had one.</p>



<p>Nonetheless, for most tech professionals, those positive perceptions have not so far translated into widespread union membership.</p>



<h2 class="wp-block-heading">Fear, uncertainty, and doubt</h2>



<p>In the wake of mass layoffs that began in 2022, the primary driver toward tech worker unionization may well be job security.</p>



<p>“I think a greater concern is that their work and skills have been devalued at the same time their jobs become less secure and their wages and benefits have declined,” says <a href="https://www.ilr.cornell.edu/people/kate-l-bronfenbrenner" target="_blank" rel="noreferrer noopener">Kate Bronfenbrenner</a>, director of labor education research and senior lecturer emeritus at Cornell University’s School of Industrial and Labor Relations.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Kate Bronfenbrenner from the School of Industrial and Labor Relations, Cornell University</p><br></figcaption></figure><p class="imageCredit">ILR School/Cornell University</p></div>



<p>The fear that AI will displace IT workers en masse is palpable, says Google’s McAvinney. Whether the <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html">mass layoffs to date</a> were actually driven by AI or if AI was used as a pretext, “Large numbers of people have that concern, and that is absolutely part of the interest in collective action — getting organized, joining a union, or forming a union,” he says.</p>



<p>The second motivator is ideological disillusionment. “Workers recruited with promises that they would be changing the world discovered that they were really building surveillance systems or military technology,” Bronfenbrenner says.</p>



<p>The insidious use of AI surveillance is another concern, says Bronfenbrenner. For example, Meta’s announcement that it would <a href="https://www.computerworld.com/article/4161929/meta-to-track-employee-keystrokes-screen-activity-to-train-ai-agents.html">use AI to track US-based workers’ computer activities</a>, including clicks, keystrokes, mouse movements, and screen snapshots to train AI agents had a dystopian feel to it. Were these workers training AI to take over their jobs, just as US workers were asked to train their lower-cost foreign replacements during the offshoring craze in the mid-2000s? (Meta later <a href="https://www.computerworld.com/article/4188640/meta-pauses-employee-monitoring-program-after-data-protections-fail-2.html">paused the tracking program</a> after employees twice demonstrated the inadequacy of privacy protections for the collected data.)</p>



<p>But Bronfenbrenner argues that AI’s bigger threat may be its use as a surveillance tool to prevent organizing. “My research on surveillance in organizing campaigns found that it tripled from 11% in the early 2000s to one third in 2021,” she says.</p>



<p>“The deeper pattern is the same one inherent in <a href="https://www.britannica.com/science/Taylorism" target="_blank" rel="noreferrer noopener">Taylorism</a> — management trying to know everything that’s under the worker’s cap, to monitor every step so workers have no control and no secrets,” Bronfenbrenner says. “Now they have even more technology to do it, and they can potentially replace you entirely with AI.”</p>



<p><a href="https://www.linkedin.com/in/simonerobutti/" target="_blank" rel="noreferrer noopener">Simone Robutti</a>, an organizer with Tech Workers Coalition Global, calls the current wave of tech layoffs “a prequel to whatever AI-driven layoffs are coming.” It’s part of the trend of “lowering the cost of knowledge workers, of cognitive workers, of office workers in general — because that’s the bet on AI,” he says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="745" height="486" sizes="auto, (max-width: 745px) 100vw, 745px"&gt;<figcaption class="wp-element-caption"><p>Simone Robutti from Tech Workers Coalition Global</p><br></figcaption></figure><p class="imageCredit">TWC</p></div>



<p>Whether employers can in fact replace workers with AI (or will be able to soon) is an open question. “If Amazon lays off a hundred workers, and ninety of them find comparable jobs within a few months, that mitigates the concern,” says Palagashvili from George Mason University. “If most of them have to sell their houses and move across the country, or end up underemployed — not just unemployed, but working in warehouses instead of at a competitor — that’s a different picture.”</p>



<p>So far that hasn’t been a big issue for former Google employees, says McAvinney. “It used to be that if you left Google, you could get a job anywhere in tech instantly. That’s no longer the case, but most people I talk to are still finding work in the industry,” he says.</p>



<p>But for those newly entering the workforce, it’s much harder to find a job. According to the <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report/economy" target="_blank" rel="noreferrer noopener">Stanford HAI <em>2026 AI Index Report</em></a>, released in April, “employment for software developers ages 22 to 25 has fallen nearly 20% from 2024.”</p>



<h2 class="wp-block-heading">Successes and setbacks</h2>



<p>While organizing can be an uphill battle and workers often face aggressive pushback from their employers, there have been a few notable successes.</p>



<p>In the UK, workers can join a union as individual members before their employer formally recognizes that union for collective bargaining purposes. That’s how 300 workers in Google DeepMind’s London office initially joined the <a href="https://www.cwu.org/" target="_blank" rel="noreferrer noopener">Communication Workers Union</a>. In April, 98% of the 300 CWU members <a href="https://fortune.com/2026/05/05/google-deepmind-unionize-vote-military-ai-contracts-internal-backlash-pentagon-deal-israeli-defense-forces/" target="_blank" rel="noreferrer noopener">voted in favor of pursuing union recognition</a>, formally requesting that management recognize the CWU and <a href="https://www.unitetheunion.org/" target="_blank" rel="noreferrer noopener">Unite the Union</a> as representatives for approximately 1,000 staff. (Google DeepMind disputed characterizing the action as a vote to unionize).</p>



<p>And in May, some 2,100 tech workers at the University of California <a href="https://upte.org/news/2100-tech-workers-vote-to-join-upte" target="_blank" rel="noreferrer noopener">joined the University Professional and Technical Employees union</a>, which is affiliated with Communications Workers of America (UPTE-CWA), with 96% of the workers voting yes.</p>



<p>“A lot of tech workers right now are extremely concerned about job security and about their work being automated,” says <a href="https://www.linkedin.com/in/mbelasco/" target="_blank" rel="noreferrer noopener">Max Belasco</a>, a business systems analyst at the UCLA School of Law and co-chair of the UCLA chapter of UPTE-CWA, Local 9119.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Max Belasco from the UCLA chapter of UPTE-CWA</p>
</figcaption></figure><p class="imageCredit">Zac Goldstein</p></div>



<p>The CWA described the organizing initiative as “<a href="https://cwa-union.org/news/it-workers-join-upte-cwa-form-largest-tech-union-country" target="_blank" rel="noreferrer noopener">the largest tech industry organizing campaign in US history</a>.” But it wasn’t the first.</p>



<p>“Between 2022 and 2024, CWA organized nearly 400 different digital media companies,” Bronfenbrenner says, including the game developer Activision and the New York Times.</p>



<p>Kickstarter’s 85 employees voted in 2020 to form <a href="https://kickstarterunited.org/" target="_blank" rel="noreferrer noopener">Kickstarter United</a> — the vote was 55% in favor — and most recently the union negotiated a contract that includes a four-day workweek, AI protections, and a minimum pay floor for 59 employees, including tech workers. </p>



<p>“What we ended up winning was yearly benchmarking of all employee salaries to the 60th percentile, along with yearly cost of living adjustments,” says Thompson.</p>



<p>But the way forward has been rocky. Shortly after the union was ratified, Kickstarter announced layoffs. The union, which is affiliated with the Office and Professional Employees International Union (OPEIU), wasn’t able to reverse that decision but did <a href="https://kickstarterunited.org/may-day-severance-agreement/" target="_blank" rel="noreferrer noopener">negotiate better severance terms</a>, including four months of severance pay (versus 2 to 3 weeks for every year worked) and six months of health benefits.</p>



<p>When contract negotiations faltered in October 2025, the union went on strike for 42 days. By December, a new contract was ratified. Shortly thereafter, the company announced another round of layoffs that included four union leaders, one of whom had helped to negotiate the new contract. The union is currently fighting those dismissals and will be arguing its case in third-party arbitration.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="618" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Members of Kickstarter United union on strike</p></figcaption></figure><p class="imageCredit">Kyle Friend</p></div>



<p>The <a href="https://www.nlrb.gov/guidance/key-reference-materials/national-labor-relations-act" target="_blank" rel="noreferrer noopener">National Labor Relations Act</a> of 1935 codified American workers’ rights to unionize and take collective action, and it established the <a href="https://www.nlrb.gov/about-nlrb/who-we-are" target="_blank" rel="noreferrer noopener">National Labor Relations Board</a> to protect those rights. Unfortunately for Kickstarter, NLRA enforcement under the Trump administration isn’t what it once was.</p>



<p>“Cases brought up for violations of the NLRA can go for months or years without ever seeing a hearing or having any sort of judgment. That gives companies more power to flagrantly ignore it,” Thompson says.</p>



<p>Tech firms have other weapons to dissuade employees from unionizing. Researchers from Carnegie Mellon University and Princeton University in 2025 <a href="https://dl.acm.org/doi/epdf/10.1145/3757671" target="_blank" rel="noreferrer noopener">interviewed 44 US-based tech worker-organizers</a>, who cited additional pressure tactics including threats to withdraw venture capital funding — essentially killing venture-backed firms if employees vote to unionize — and threats of being fired that <a href="https://techworkerscoalition.org/blog/2025/03/14/immigrant-rights-are-labor-rights-tech-workers-and-h-1b-visas/" target="_blank" rel="noreferrer noopener">put tech workers with H-1B visas in an impossible position</a>.</p>



<p>Kickstarter United is a majority union — one that has won NLRB certification. While that’s possible in smaller organizations, success in larger tech firms has been much more limited.</p>



<p>Alphabet is a prime example: the Alphabet Workers Union-CWA is a “pre-majority” union that lacks NLRB certification and has no formally recognized bargaining unit. Formed in 2021 with fewer than 400 members, today it represents 1,400 members, still a small fraction of Alphabet’s US-based workforce, estimated at over 100,000.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="839" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Alan McAvinney from Alphabet Workers Union-CWA</p></figcaption></figure><p class="imageCredit">Aran Per Ink</p></div>



<p>The challenge, says McAvinney, lies in trying to organize a distributed workforce of in-office, remote, and contract workers. “Large tech companies don’t split easily into discrete segments — there’s no strong geographic component to teams, and a single team is often spread across many locations,” which makes getting majority support unrealistic, he says.</p>



<p>But that doesn’t mean the union has had no impact. “In January, we launched our Googlers for Job Security campaign. Today we’re organizing around four demands: a guaranteed minimum severance package for everyone who’s laid off, voluntary buyouts before any mandatory layoffs, an end to GRAD quotas (GRAD being Google’s performance review system) so ratings reflect actual performance and aren’t given or changed to force a particular distribution, and the option to take severance as leave, giving workers, especially those on visas, more time on payroll,” McAvinney says.</p>



<p>“In response, Google did start offering voluntary exit packages,” he says. The union was also able to negotiate one contract, for Google Help workers. However, those workers aren’t actually Google employees: they’re contractors who report to Google management but work for Accenture.</p>



<h2 class="wp-block-heading">The counterargument</h2>



<p>Do unions get what they bargain for? Conservative business and labor economists say union contracts typically have rigid pay structures that restrict merit-based pay in favor of seniority-based wage increases, and that unions, as certified by the NLRB, create labor monopolies that limit worker choice and push up wages to levels detrimental to both workers and business.</p>



<p>The collective bargaining model is not well suited to the highly dynamic and innovation-driven tech sector, Palagashvili argues. “Firms often need to reorganize teams, redesign products, adjust roles, and redeploy talent quickly,” she says. </p>



<p>Collective bargaining agreements make those adjustments much more difficult by imposing uniform terms for an entire bargaining unit, regardless of individual preferences and circumstances. The contracts, she says, “are more about higher pay and less about flexibility.”</p>



<p>But Thompson says that hasn’t been his experience. “The thing with a union is you get to write the contract,” he says. “At Kickstarter we care about recognizing individual contributions, merit, and having a clear career progression.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="972" height="972" sizes="auto, (max-width: 972px) 100vw, 972px"&gt;<figcaption class="wp-element-caption"><p>Zak Thompson from Kickstarter United</p><br></figcaption></figure><p class="imageCredit">Fee Christoph</p></div>



<p>Kickstarter United pushed the company to clearly define what it takes to get a promotion, advocated for no “at will” employment, where employees can be fired any time without a stated reason; won standards for minimum pay, raises, promotions, and time off; secured AI protections; and codified a four-day work week.</p>



<p>Yes, some tech professionals voiced concerns about unions, such as that they stifle innovation and limit compensation for top performers, Thompson says, but “a lot of those people came around. They said ‘I was wrong. I feel way more protected, more secure, and I see the benefits.’”</p>



<p>Bronfenbrenner says it’s a mistake to think that tech workers are inherently different from other workers, adding that the two industries with the highest union density are entertainment and professional sports. “These are professionals with unique talents and capabilities, and they’ve organized successfully under the exclusive representation system.”</p>



<h2 class="wp-block-heading">Will we see a unionized tech workforce?</h2>



<p>If unions eventually prevail in tech, it will happen in the face of intense pressure from employers not to organize. </p>



<p>“The Alphabet Workers Union is a case study of the limits of the first wave of tech labor organizing,” says Robutti from the Tech Workers Coalition. “They hit a threshold beyond which they couldn’t fight the union busting anymore, and they became entrenched at that size.”</p>



<p>No one should expect large-scale unionization to occur overnight, Bronfenbrenner says. “The auto and steel industries weren’t organized in months. It took decades. Organizing global tech companies will take the same.”</p>



<p>While McAvinney acknowledges that a traditional majority union may be difficult to achieve any time soon in a company as large as Alphabet, he’s still bullish on his pre-majority union’s ability to make a difference. “Ultimately, regardless of which type of union you are, you can only win as much as you have leverage to win. Your leverage is inherently limited, but that doesn’t mean you can’t win anything,” he says.</p>



<p>Attitudes about unions appear to be changing rapidly. “Interest in unions is high, and I expect that will continue,” McAvinney says. “Now is an excellent time for people to start getting organized. I have seen lots of evidence of that.”</p>



<p>Thompson agrees. “We are seeing an uptick of people in tech reaching out, trying to get help organizing. When people have their job conditions continue to deteriorate, they are going to start organizing,” he says. “We’re definitely seeing a shift from ‘it’d be nice if we had a union’ to ‘okay, how can I actually do this now?’”</p>



<p><em>Come back next week for Part 2: How to unionize your tech workplace</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang]]></title>
<description><![CDATA[Group-IB analysis argued Scattered Spider is a decentralized collective of independent clusters This article has been indexed from www.infosecurity-magazine.com Read the original article: Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang
Read more →
The post Scatt...]]></description>
<link>https://tsecurity.de/de/3651841/it-security-nachrichten/scattered-spiders-structure-more-like-a-cybercrime-collective-than-a-unified-gang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651841/it-security-nachrichten/scattered-spiders-structure-more-like-a-cybercrime-collective-than-a-unified-gang/</guid>
<pubDate>Tue, 07 Jul 2026 16:23:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Group-IB analysis argued Scattered Spider is a decentralized collective of independent clusters This article has been indexed from www.infosecurity-magazine.com Read the original article: Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/scattered-spiders-structure-more-like-a-cybercrime-collective-than-a-unified-gang/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/scattered-spiders-structure-more-like-a-cybercrime-collective-than-a-unified-gang/">Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang]]></title>
<description><![CDATA[Group-IB analysis argued Scattered Spider is a decentralized collective of independent clusters]]></description>
<link>https://tsecurity.de/de/3651788/it-security-nachrichten/scattered-spiders-structure-more-like-a-cybercrime-collective-than-a-unified-gang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651788/it-security-nachrichten/scattered-spiders-structure-more-like-a-cybercrime-collective-than-a-unified-gang/</guid>
<pubDate>Tue, 07 Jul 2026 16:10:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Group-IB analysis argued Scattered Spider is a decentralized collective of independent clusters]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Device Identifier Helped FBI Trace and Arrest Alleged Scattered Spider Member]]></title>
<description><![CDATA[A Microsoft Windows device identifier, known as a Global Device Identifier (GDID), was used to link 19-year-old Peter Stokes to a string of ransomware and extortion attacks tied to the Scattered Spider hacking collective. Stokes, a dual U.S.-Estonian citizen, allegedly operated under the aliases ...]]></description>
<link>https://tsecurity.de/de/3650669/it-security-nachrichten/windows-device-identifier-helped-fbi-trace-and-arrest-alleged-scattered-spider-member/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650669/it-security-nachrichten/windows-device-identifier-helped-fbi-trace-and-arrest-alleged-scattered-spider-member/</guid>
<pubDate>Tue, 07 Jul 2026 08:36:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Microsoft Windows device identifier, known as a Global Device Identifier (GDID), was used to link 19-year-old Peter Stokes to a string of ransomware and extortion attacks tied to the Scattered Spider hacking collective. Stokes, a dual U.S.-Estonian citizen, allegedly operated under the aliases “Bouquet,” “Spencer,” and “Jordan,” according to a superseding criminal complaint filed in the […]</p>
<p>The post <a href="https://cyberpress.org/windows-device-identifier-fbi-alleged-scattered-spider/">Windows Device Identifier Helped FBI Trace and Arrest Alleged Scattered Spider Member</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Single points of failure fail. The SaaS layer is not an exception]]></title>
<description><![CDATA[Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not ...]]></description>
<link>https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</guid>
<pubDate>Mon, 06 Jul 2026 12:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not peripheral tools — they are the operational infrastructure of the institution. As IT stewards, we manage platforms we do not own, cannot restore ourselves and cannot directly control — which makes contingency planning not optional, but fundamental to the role.</p>



<p>The contracts are in place. The SLAs are signed. The compliance certifications are current. None of that matters to a student who cannot reach her instructor three days before finals. None of it matters to a faculty member who has no roster, no grade book and no way to document the work his students submitted before the platform went dark. SLAs govern vendor response timelines. Keeping academic operations running during that response window is IT’s responsibility.</p>



<p>The disruption hit during finals week 2026, and I was doing what every CIO in higher education was doing — monitoring. A major learning management system <a href="https://www.csoonline.com/article/4180194/lessons-from-the-canvas-cyberattack.html">had been breached</a>. The disruption spread fast. Finals were canceled. Exams were postponed. Students and staff were stranded without access to coursework, rosters or grade books. The costs — in academic disruption, extended contracts, emergency response — were substantial and widely reported. My institution was not directly impacted. But watching peer institutions in my own state go dark during the highest-stakes moment of the academic calendar was not reassuring. It was a confirmation of something I had been thinking about for a long time.</p>



<p>The disruption proved something IT professionals have relearned in every decade of their careers. Mark Twain observed that history does not repeat itself, but it does rhyme. This is a verse we have heard before: Dependence on a single point of failure, without a tested contingency plan, is not a strategy — it is a risk that has simply not yet been called. Whether the failure comes from a cyberattack, a vendor outage, an infrastructure collapse or a cloud provider’s bad deployment, the result is the same. The institution stops. And no SLA, contract or compliance certification prevents that moment from arriving.</p>



<p>Vigilance is not optional. Technologies are evolving faster than any IT team can fully anticipate. New platforms, new integrations, new dependencies emerge constantly — and with each one comes a new potential failure point. That is not an argument against adopting new technology. It is an argument for the one principle that never becomes obsolete: Reliance on any single critical system, whether it is a connectivity provider, an identity platform or a SaaS solution, is a proven strategy for failure. The question is never whether that system will fail. The question is whether the institution is prepared when it does.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Single points of failure fail — inevitably, and at the worst possible time. IT professionals have known this for thirty years. The SaaS layer is not exempt.</p>
</blockquote>



<p>This is not a new lesson. Azure has gone down. AWS has failed. <a href="https://er.educause.edu/articles/2026/5/how-higher-education-is-responding-to-the-canvas-lms-incident-and-preparing-for-whats-next">Google Workspace has had outages that took organizations dark globally</a>. No campus runs a single ISP connection — we provision redundant circuits, preferably from independent providers, because we learned long ago that the connection will sometimes fail and the institution cannot afford to stop when it does. Financial services, government and multinational enterprises applied that same logic to every dependency in their stack. Their response to platform risk was not to demand better SLAs. It was to architect around the dependency. Redundancy. Failover. Independent continuity capability. The massive disruptions from Canvas demonstrate that effective contingency solutions for these critical platforms have not kept pace with our dependence on them. We cannot get fooled again.</p>



<p>That omission is what made the 2026 attack so damaging. Not the sophistication of the breach — the entry point was a peripheral free-tier environment that wasn’t even within the vendor’s primary certification scope. The damage was catastrophic because institutions had no fallback. Faculty had no rosters. Administrators had no enrollment data. There was no continuity layer. A single point of failure, at institutional scale, with no plan for when it fails.</p>



<p>And now the economics have shifted in the worst possible direction. <a href="https://techcrunch.com/2025/05/08/powerschool-paid-a-hackers-ransom-but-now-schools-say-they-are-being-extorted/">PowerSchool paid a ransom in December 2024</a> after attackers stole data on 60 million students — and was re-extorted anyway, with individual school districts receiving separate demands months later using the same stolen data. <a href="https://www.instructure.com/incident_update">Instructure’s CEO publicly confirmed the extortion payment</a>. Anyone who has paid a ransom only to be hit a second time at double the cost can tell you — paying the attackers resolves nothing and instead invites more attacks. The sector has now proven twice, publicly, and at scale, that it will pay. That changes the threat calculus entirely. Higher education stops being a target of opportunity and becomes a target of strategy. Criminal groups share that intelligence. Banner serves over 1,400 institutions. Blackboard reaches tens of millions of users across thousands of campuses. Every major higher education SaaS platform is now on active threat actor priority lists — not because they are newly vulnerable, but because the sector has proven it will pay, that academic calendar pressure creates maximum leverage, and that IT has not yet built the operational alternative that our dependence on these platforms demands — and therefore the failure is ours to own, especially if we allow it to happen a second time.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>The sector has proven it will pay. Every ransomware group operating today just received the same market signal. What follows is not unpredictable — it is documented, underway and aimed directly at the platforms carrying your institution’s academic operations.</p>
</blockquote>



<p>As a CIO, my approach to this is not a spreadsheet or a stack of printed reports. IT is responsible for identifying critical failure points and countering them — that is not optional; it is the job. Accepting failure as inevitable without a mitigation strategy is not viable. Redundancy and continuity solutions are standard practice everywhere else in our infrastructure. There was no reason the SaaS layer should be different.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>A leader’s first job isn’t to be right — it’s to be responsible.</p>
</blockquote>



<p>The solution I implemented is a secure, read-only, centralized repository — a continuity strategy that ensures students, staff and faculty can continue to function whether the issue is a power outage, a cyberattack or a SaaS platform going dark. It is not a replacement for Canvas or Banner. It is the independent fallback that allows the institution to keep operating while the primary system is restored. I have learned the hard way that accepting failure without a plan is not a posture any CIO can defend.</p>



<p>Watching the frustration across the industry during and after the 2026 attack — institutions paralyzed, peer CIOs improvising, faculty working from personal spreadsheets, boards asking questions no one could answer — the logic of extending this capability to other institutions became unavoidable. The solution is not complex. The architecture is straightforward. The discipline behind it is thirty years old. The discipline is established. The responsibility to apply it is our field of expertise in IT.</p>



<p>To be precise about scope: An ACR does not prevent vendor breaches, replace cyber insurance or remove notification obligations. When an incident hits, legal counsel, security teams and institutional leadership still manage the response. What the ACR changes is what they have to work with — a governed, auditable record of what data was accessed, what manual actions were taken and how operations continued while the vendor worked to restore service.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Redundancy, disaster recovery, continuity of operations — the discipline is not new. The SaaS platforms carrying academic operations deserve the same standard we hold everywhere else.</p>
</blockquote>



<p>The solution to this problem exists. A SaaS third-party continuity of operations strategy requires an independent data layer — one the institution controls, synchronized on a regular scheduled cycle from source systems, and accessible when those systems are not. Platform-agnostic across Canvas, Banner, Blackboard and PowerSchool. Read-only by design. Auditable by requirement. Independent by architecture. That last word is the one that matters — independent of the platforms whose availability you cannot guarantee.</p>



<p>Every CIO in higher education knows what a single point of failure looks like. Every one of us has built around them at every other layer. Servers, networks, data centers — we do not accept the single-point risk, and we do not wait for the failure to motivate the fix. The SaaS layer is not an exception.</p>



<p>The question is not whether your institution will face it. The question is whether you will have a continuity strategy in place when it arrives — or be explaining to your board why you did not.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Leaders don’t rent accountability — they own it outright.</p>
</blockquote>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13821 | Google Chrome up to 149.0.7827.201 Canvas use after free (ID 513142)]]></title>
<description><![CDATA[A vulnerability was found in Google Chrome and classified as critical. This affects an unknown part of the component Canvas. The manipulation results in use after free.

This vulnerability is identified as CVE-2026-13821. The attack can be executed remotely. There is not any exploit available.

I...]]></description>
<link>https://tsecurity.de/de/3645954/sicherheitsluecken/cve-2026-13821-google-chrome-up-to-14907827201-canvas-use-after-free-id-513142/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645954/sicherheitsluecken/cve-2026-13821-google-chrome-up-to-14907827201-canvas-use-after-free-id-513142/</guid>
<pubDate>Sun, 05 Jul 2026 00:38:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/google:chrome">Google Chrome</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part of the component <em>Canvas</em>. The manipulation results in use after free.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-13821">CVE-2026-13821</a>. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[How America's 250th birthday became a test of AI-powered collective intelligence]]></title>
<description><![CDATA[Imagine if you could bring 250 people together in a massive room and have them discuss and debate an important issue, arguing the points and counterpoints, and converging on answers that accurately reflect their collective knowledge, wisdom, values, and sensibilities.Now imagine that you convened...]]></description>
<link>https://tsecurity.de/de/3645848/it-nachrichten/how-americas-250th-birthday-became-a-test-of-ai-powered-collective-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645848/it-nachrichten/how-americas-250th-birthday-became-a-test-of-ai-powered-collective-intelligence/</guid>
<pubDate>Sat, 04 Jul 2026 22:16:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Imagine if you could bring 250 people together in a massive room and have them discuss and debate an important issue, arguing the points and counterpoints, and converging on answers that accurately reflect their collective knowledge, wisdom, values, and sensibilities.</p><p>Now imagine that you convened this debate on <b>America’s 250</b><b><sup>th</sup></b><b> birthday</b> and asked 250 randomly selected Americans to come up with the <b>top three innovations </b>that America has contributed to the world over the last 250 years.<b> </b>What would they come up with?</p><p>I know – this all sounds impossible. </p><p>After all, you can’t get more than a dozen people to have a productive conversation on anything. At large scale, nobody would get enough airtime to express their views or respond to others. This is why typical business meetings or focus groups never have more than 8 to 10 people. Thoughtful real-time conversations just don’t scale.</p><p>To solve this, a new category of AI technology called <i>“hyper-communication</i>” is greatly expanding the size, scope, and efficiency of large-scale deliberations. It uses specialized <a href="https://venturebeat.com/technology/agentic-ai-solved-coding-and-exposed-every-other-problem-in-software-engineering">AI agents</a> to connect groups in real-time, allowing people to <a href="https://www.intechopen.com/chapters/1223362"><u>discuss and debate issues at any scale</u></a>. The goal is to enable hundreds or even thousands of participant to hold thoughtful discussions where they can express their views and argue the merits of any issue. </p><p>I first wrote about this emerging technology in VentureBeat two years ago in an article about “<a href="https://venturebeat.com/ai/can-we-use-generative-ai-to-build-a-global-hive-mind"><u>Collective Superintelligence</u></a>.” In that piece, I explain how large human groups can be hyper-connected by AI agents in ways that greatly <a href="https://arxiv.org/abs/2401.15109"><u>amplify the group’s collective intelligence</u></a>. You can check out the science behind hyper-communication in that prior VentureBeat piece. Here I am focusing on the debate among 250 Americans on America’s birthday.</p><p>To do this, I asked the team at Unanimous AI to field a randomly selected group of at least 250 Americans (with a broad distribution from every region in the country and diverse mix of political and social demographics) and invite them to a twenty-minute online debate inside a hyper-communication platform called <a href="https://www.thinkscape.ai/"><u>Thinkscape</u></a> that enables massively scalable discussion by text, voice, or video.   </p><p>Once connected, we asked the group to come up with the <b>top three contributions</b> that America has made to the world over the last 250 years – not a survey of opinions, but deliberation of ideas,  arguments, evidence, and reasoning. The group converged on a set of top answers that surprised me – but on reflection, they were sensible and well-reasoned. </p><p>Before getting into the answers, let me show you what the debate looks like behind the scenes. There were 277 people, each of them debating the issues with four or five other people in parallel discussion spaces. The magic is the <a href="https://unanimous.ai/hyperchat-ai/"><u>swarm of AI agents</u></a> that connect all the small groups together into a single real-time deliberation.This is what it looks like at high speed:</p><p>In the debate above, the group of 277 people came up with <b>94 different ideas</b> and then narrowed it down to a <b>top 10,</b> then a <b>top 3</b>. In the gif above, we  just plot the top ten ideas as they emerged and battle for support during the live conversational debate. </p><p>The most interesting part of a large debate like this is not the answers, but the reasons that emerge to justify the answers. Here is the group’s reasoning behind the “top three innovations” that America has given to the world over the last 250 years:</p><p><b>#1: The Internet:</b> <i>“Our collective perspective is that America’s greatest contribution to the world over the past 250 years is the internet. It was born exclusively in the U.S. through academic and government research and was scaled globally with profound impact. It transformed communication, democratized information and education, enabled commerce, medicine, research and cultural exchange, and amplified soft power and civic organizing. We also acknowledged significant harms (misinformation, addiction, privacy loss) and arguments that it’s recent, global, or not uniquely American.”</i></p><p><b>#2 Advances in medicine</b>: <i>“Our collective perspective is that the United States has saved and prolonged hundreds of millions of lives worldwide. American-developed vaccines have successfully eradicated or controlled once-deadly diseases, significantly extending life expectancy and enabling broader societal and technological progress. From major breakthroughs in cancer research and treatments to cutting-edge medical technologies that have revolutionized hospital safety and procedures, U.S. ingenuity has redefined healthcare. Ultimately, while the global diffusion of affordable medicines and vaccines has extended these benefits across borders, the U.S. remains a premier medical destination where people from around the world travel to receive the most advanced treatments.”</i></p><p><b>#3: Spreading democracy:</b>  “Our collective perspective is that one of America’s most significant global contributions is the nation's system of governance. The US has long demonstrated democracy in practice as an enduring global model. The U.S. Constitution provided a vital blueprint for representative government, inspiring democratic movements and revolutions worldwide while actively promoting human rights and individual liberties internationally. By empowering citizens with the fundamental power to vote and choose their own leaders, this framework has served as a foundational framework for broader societal advances and directly helped establish thriving democracies around the world.”</p><p>It’s important to remember, this is 100% human intelligence — a pure reflection of the collective knowledge, wisdom, and values of 277 randomly selected Americans. That’s because the role of the AI agents in a <a href="https://unanimous.ai/hyperchat-ai/"><u>hyper-communication system</u></a> is to <i>connect people, </i>not replace them. The agents work to enable scalable <i>human deliberation</i> in which every participant is given optimized ability to express their views, respond to others, and converge on solutions based on their merits. The only question left is — <b>what should we ask next? </b></p><p><i></i><a href="https://sites.google.com/view/louisrosenberg/bio"><i><u>Louis Rosenberg</u></i></a><i> earned his PhD from Stanford University, was a professor at California State University (Cal Poly) and has been awarded over 300 patents for his work in human-computer interaction, AI, and collective intelligence.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13840 | Google Chrome up to 149.0.7827.201 Canvas cross-domain policy (ID 514609)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Google Chrome. This impacts an unknown function of the component Canvas. Such manipulation leads to permissive cross-domain policy with untrusted domains.

This vulnerability is uniquely identified as CVE-2026-13840. The attack can be launche...]]></description>
<link>https://tsecurity.de/de/3645583/sicherheitsluecken/cve-2026-13840-google-chrome-up-to-14907827201-canvas-cross-domain-policy-id-514609/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645583/sicherheitsluecken/cve-2026-13840-google-chrome-up-to-14907827201-canvas-cross-domain-policy-id-514609/</guid>
<pubDate>Sat, 04 Jul 2026 18:09:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/google:chrome">Google Chrome</a>. This impacts an unknown function of the component <em>Canvas</em>. Such manipulation leads to permissive cross-domain policy with untrusted domains.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-13840">CVE-2026-13840</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Workspace Weekly Recap - July 3, 2026]]></title>
<description><![CDATA[Updated admin setting for improved video quality in Google MeetIn April 2026, we updated Meet to improve video quality on high-resolution displays. We’re now updating the way the Admin console setting that limits video bandwidth works to reduce data usage and improve call quality. | Learn more.Ed...]]></description>
<link>https://tsecurity.de/de/3644366/web-tipps/google-workspace-weekly-recap-july-3-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644366/web-tipps/google-workspace-weekly-recap-july-3-2026/</guid>
<pubDate>Fri, 03 Jul 2026 22:42:03 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Updated admin setting for improved video quality in Google Meet</h3><p>In April 2026, we updated Meet to improve video quality on high-resolution displays. We’re now updating the way the Admin console setting that limits video bandwidth works to reduce data usage and improve call quality. | <a href="https://workspaceupdates.googleblog.com/2026/06/updated-admin-setting-for-improved-video-quality-in-Google-Meet.html" target="_blank">Learn more</a>.</p><h3>Educators and students can now share Gemini Canvas creations directly to Google Classroom</h3><p>Educators and students of all ages can now seamlessly attach Gemini Canvas artifacts, like websites, quizzes, interactive games, infographics, and more, to Google Classroom assignments and posts. | <a href="https://workspaceupdates.googleblog.com/2026/06/educators-and-students-can-now-share-Gemini-Canvas-creations-directly-to-Google-Classroom.html" target="_blank">Learn more</a>.</p><h3>Assign mobile device management admin privileges based on organizational unit</h3><p>We’re giving admins more granular control over how mobile device management privileges are delegated. Specifically, admins can be assigned privileges for specific organizational units (OUs), adding another layer of security by scoping access only to necessary OUs. | <a href="https://workspaceupdates.googleblog.com/2026/06/assign-mobile-device-management-admin-privileges-based-on-organizational-unit.html" target="_blank">Learn more</a>.</p><h3>Data regions support for the Gemini app now available</h3><p>The Gemini app adheres to your organization’s data regionalization requirements. As with Google Workspace, admins have the flexibility to configure controls for EU storage and processing, US storage and processing, or both, including granular settings down to the organizational unit (OU) level. | <a href="https://workspaceupdates.googleblog.com/2026/06/gemini-app-data-regions-support.html" target="_blank">Learn more</a>.</p><h3>Create fully native and editable presentations with Gemini in Google Slides</h3><p>You can now create a full, multi-slide presentation using Gemini in Google Slides. With a single prompt, you can ground the presentation in existing content from Google Drive, match the style of another presentation, and build fully editable slides, allowing you to make any necessary adjustments. | <a href="https://workspaceupdates.googleblog.com/2026/06/create-fully-native-and-editable-presentations-with-Gemini-in-Google-Slides.html" target="_blank">Learn more</a>.</p><h3>Ask Gemini in Drive now available on mobile</h3><p>In April, we announced the general availability of Ask Gemini in Drive on the web. We’re now bringing this feature to the Drive Android and iOS apps. | <a href="https://workspaceupdates.googleblog.com/2026/06/ask-gemini-in-drive-now-available-on-mobile.html" target="_blank">Learn more</a>.</p><h3>Work with delegated Gmail accounts from mobile devices</h3><p>Previously, users could only work with delegated Gmail accounts through the web interface. We are updating the Gmail app for iOS and Android to allow delegates to read, manage, and compose emails on behalf of a delegator directly from their mobile devices. | <a href="https://workspaceupdates.googleblog.com/2026/06/work-with-delegated-gmail-accounts-from-mobile-devices.html" target="_blank">Learn more</a>.</p><h3>AI Overviews in Drive now available on mobile</h3><p>In April, we announced the general availability for Drive AI Overviews in Drive on the web. We’re now bringing this feature to the Drive Android and iOS apps. | <a href="https://workspaceupdates.googleblog.com/2026/06/ai-overviews-in-drive-now-available-on-mobile.html" target="_blank">Learn more</a>.</p><h3>Import 3D bar charts into Google Sheets</h3><p>Google Sheets now fully supports the import of 3D bar charts. Previously, when users imported files containing 3D bar charts into Sheets, they would be displayed as 2D bar charts. With this update, importing these types of files, including from Microsoft Excel, will yield a more seamless experience. | <a href="https://workspaceupdates.googleblog.com/2026/06/import-3d-bar-charts-into-google-sheets.html" target="_blank">Learn more</a>.</p><p><span>The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My canvas art TV gets endless compliments, and it's cheaper than Samsung's Frame TV]]></title>
<description><![CDATA[The Hisense Canvas Art TV is on sale for $350 off during July 4th weekend.]]></description>
<link>https://tsecurity.de/de/3643915/it-nachrichten/my-canvas-art-tv-gets-endless-compliments-and-its-cheaper-than-samsungs-frame-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643915/it-nachrichten/my-canvas-art-tv-gets-endless-compliments-and-its-cheaper-than-samsungs-frame-tv/</guid>
<pubDate>Fri, 03 Jul 2026 18:04:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Hisense Canvas Art TV is on sale for $350 off during July 4th weekend.]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. Secures Extradition of 19-Year-Old Linked to Scattered Spider]]></title>
<description><![CDATA[US authorities have intensified their pursuit of individuals linked to the financially motivated hacking collective Scattered Spider, and the extradition of a 19-year-old suspect marks another significant development.  Peter Stokes, who is a dual citizen of the United States and…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3642812/it-security-nachrichten/us-secures-extradition-of-19-year-old-linked-to-scattered-spider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642812/it-security-nachrichten/us-secures-extradition-of-19-year-old-linked-to-scattered-spider/</guid>
<pubDate>Fri, 03 Jul 2026 08:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>US authorities have intensified their pursuit of individuals linked to the financially motivated hacking collective Scattered Spider, and the extradition of a 19-year-old suspect marks another significant development.  Peter Stokes, who is a dual citizen of the United States and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/u-s-secures-extradition-of-19-year-old-linked-to-scattered-spider/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/u-s-secures-extradition-of-19-year-old-linked-to-scattered-spider/">U.S. Secures Extradition of 19-Year-Old Linked to Scattered Spider</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider hacker extradited to the United States]]></title>
<description><![CDATA[A dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. [...]]]></description>
<link>https://tsecurity.de/de/3640607/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-the-united-states/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640607/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-the-united-states/</guid>
<pubDate>Thu, 02 Jul 2026 11:09:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider Hacker Extradited to U.S. for 100+ Network Intrusions]]></title>
<description><![CDATA[A suspected member of the notorious hacking collective Scattered Spider has been taken into U.S. custody following an international extradition operation spanning Finland, Estonia, and the United States. The arrest marks a significant milestone in the ongoing crackdown against one of the most dis...]]></description>
<link>https://tsecurity.de/de/3640249/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-us-for-100-network-intrusions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640249/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-us-for-100-network-intrusions/</guid>
<pubDate>Thu, 02 Jul 2026 07:54:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A suspected member of the notorious hacking collective Scattered Spider has been taken into U.S. custody following an international extradition operation spanning Finland, Estonia, and the United States. The arrest marks a significant milestone in the ongoing crackdown against one of the most disruptive cybercriminal groups targeting American enterprises. Peter Stokes, 19, a dual U.S.-Estonian […]</p>
<p>The post <a href="https://cyberpress.org/alleged-scattered-spider-hacker-extradited/">Alleged Scattered Spider Hacker Extradited to U.S. for 100+ Network Intrusions</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider Member Extradited to the US for His Role in Hacking 100+ Networks]]></title>
<description><![CDATA[A dual U.S.-Estonian citizen accused of belonging to the notorious Scattered Spider hacking collective has been extradited from Finland to face federal charges in the Northern District of Illinois, the Department of Justice announced Tuesday. Peter Stokes, 19, was arrested…
Read more →
The post A...]]></description>
<link>https://tsecurity.de/de/3640138/it-security-nachrichten/alleged-scattered-spider-member-extradited-to-the-us-for-his-role-in-hacking-100-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640138/it-security-nachrichten/alleged-scattered-spider-member-extradited-to-the-us-for-his-role-in-hacking-100-networks/</guid>
<pubDate>Thu, 02 Jul 2026 06:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A dual U.S.-Estonian citizen accused of belonging to the notorious Scattered Spider hacking collective has been extradited from Finland to face federal charges in the Northern District of Illinois, the Department of Justice announced Tuesday. Peter Stokes, 19, was arrested…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/alleged-scattered-spider-member-extradited-to-the-us-for-his-role-in-hacking-100-networks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/alleged-scattered-spider-member-extradited-to-the-us-for-his-role-in-hacking-100-networks/">Alleged Scattered Spider Member Extradited to the US for His Role in Hacking 100+ Networks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider Member Extradited to the US for His Role in Hacking 100+ Networks]]></title>
<description><![CDATA[A dual U.S.-Estonian citizen accused of belonging to the notorious Scattered Spider hacking collective has been extradited from Finland to face federal charges in the Northern District of Illinois, the Department of Justice announced Tuesday. Peter Stokes, 19, was arrested by Finnish authorities ...]]></description>
<link>https://tsecurity.de/de/3640085/it-security-nachrichten/alleged-scattered-spider-member-extradited-to-the-us-for-his-role-in-hacking-100-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640085/it-security-nachrichten/alleged-scattered-spider-member-extradited-to-the-us-for-his-role-in-hacking-100-networks/</guid>
<pubDate>Thu, 02 Jul 2026 05:36:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A dual U.S.-Estonian citizen accused of belonging to the notorious Scattered Spider hacking collective has been extradited from Finland to face federal charges in the Northern District of Illinois, the Department of Justice announced Tuesday. Peter Stokes, 19, was arrested by Finnish authorities in April under an Interpol Red Notice and extradited to the United […]</p>
<p>The post <a href="https://cybersecuritynews.com/alleged-scattered-spider-member-extradited/">Alleged Scattered Spider Member Extradited to the US for His Role in Hacking 100+ Networks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Apple Security Update Review]]></title>
<description><![CDATA[We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS s...]]></description>
<link>https://tsecurity.de/de/3638963/it-security-nachrichten/the-june-2026-apple-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638963/it-security-nachrichten/the-june-2026-apple-security-update-review/</guid>
<pubDate>Wed, 01 Jul 2026 17:25:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. </p><p class="">For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS scores or other severity information, we’re left to speculate on which of these bugs is the most severe. The overwhelming majority (31 of 37) are WebKit/WebRTC bugs reachable through malicious web content. Most of those are crash/DoS bugs rather than code execution, so the real risk lives in the small set of kernel bugs and the handful of WebKit sandbox escapes. However, there are a couple that stand out.</p><p class="">-    <strong>CVE-2026-43724 (Kernel)</strong> – According to Apple, “An app may be able to cause unexpected system termination or write kernel memory.” A kernel memory write is the highest-value primitive here: it's the privilege-escalation half of a full exploit chain and leads to complete device control. The bug was credited to Hyunwoo Kim (@v4bel), who is known to be a serious kernel researcher. </p><p class="">-    <strong>CVE-2026-39868 (Kernel)</strong> – Another kernel bug, this one could “cause unexpected system termination or corrupt kernel memory.” This is kernel memory corruption, and notably credited to a roster of elite offensive researchers (STAR Labs, Positive Technologies, Baidu Security). This kind of attribution usually signals a weaponizable, possibly Pwn2Own-grade bug rather than a theoretical crash.</p><p class="">-    <strong>CVE-2026-43725 / CVE-2026-43701 (WebKit)</strong> – Apple states these bugs could allow a website to process restricted web content outside the sandbox. I'm flagging this sandbox-escape pair over the many WebKit crash bugs because a sandbox escape is the bridge that turns a web-content bug into a path toward the kernel issues above. It's the most dangerous remotely-triggered class in the release.</p><p class="">Here’s a look at all the bugs released by Apple this month:</p>





















  
  




  


  
    




<title>Apple Security Update – June 29, 2026</title>



  
    
      <span class="num">37</span><span class="lbl">Total CVEs</span>
      <span class="num">22</span><span class="lbl">Denial of Service</span>
      <span class="num">7</span><span class="lbl">Information Disclosure</span>
      <span class="num">3</span><span class="lbl">Memory Corruption</span>
      <span class="num">2</span><span class="lbl">Elevation of Privilege</span>
      <span class="num">2</span><span class="lbl">Sandbox Escape</span>
      <span class="num">1</span><span class="lbl">Spoofing</span>
    

    <table>
      <caption>Apple security release — June 29, 2026. "Yes/No" indicates whether each update is affected. CVE IDs link to NVD.</caption>
      <thead>
        <tr>
          <th>CVE ID</th>
          <th>Component</th>
          <th>Impact</th>
          <th class="center">iOS 26.5.2 / iPadOS 26.5.2</th>
          <th class="center">macOS Tahoe 26.5.2</th>
          <th class="center">Safari 26.5.2</th>
        </tr>
      </thead>
      <tbody>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43743" target="_blank" rel="noopener">CVE-2026-43743</a></td>
        <td>IOGPUFamily</td>
        <td class="impact">An app may be able to cause unexpected system termination</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39868" target="_blank" rel="noopener">CVE-2026-39868</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or corrupt kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43722" target="_blank" rel="noopener">CVE-2026-43722</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to leak sensitive kernel state</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43724" target="_blank" rel="noopener">CVE-2026-43724</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or write kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43703" target="_blank" rel="noopener">CVE-2026-43703</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43706" target="_blank" rel="noopener">CVE-2026-43706</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43704" target="_blank" rel="noopener">CVE-2026-43704</a></td>
        <td>Web Extensions</td>
        <td class="impact">A malicious web extension may be able to cause an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39872" target="_blank" rel="noopener">CVE-2026-39872</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43663" target="_blank" rel="noopener">CVE-2026-43663</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43676" target="_blank" rel="noopener">CVE-2026-43676</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43699" target="_blank" rel="noopener">CVE-2026-43699</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43700" target="_blank" rel="noopener">CVE-2026-43700</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43701" target="_blank" rel="noopener">CVE-2026-43701</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43705" target="_blank" rel="noopener">CVE-2026-43705</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43707" target="_blank" rel="noopener">CVE-2026-43707</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43708" target="_blank" rel="noopener">CVE-2026-43708</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43709" target="_blank" rel="noopener">CVE-2026-43709</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43712" target="_blank" rel="noopener">CVE-2026-43712</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43713" target="_blank" rel="noopener">CVE-2026-43713</a></td>
        <td>WebKit</td>
        <td class="impact">Visiting a website may leak sensitive data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43715" target="_blank" rel="noopener">CVE-2026-43715</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43716" target="_blank" rel="noopener">CVE-2026-43716</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43725" target="_blank" rel="noopener">CVE-2026-43725</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43726" target="_blank" rel="noopener">CVE-2026-43726</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43727" target="_blank" rel="noopener">CVE-2026-43727</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43731" target="_blank" rel="noopener">CVE-2026-43731</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43732" target="_blank" rel="noopener">CVE-2026-43732</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43734" target="_blank" rel="noopener">CVE-2026-43734</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43735" target="_blank" rel="noopener">CVE-2026-43735</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43740" target="_blank" rel="noopener">CVE-2026-43740</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may result in the disclosure of process memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43742" target="_blank" rel="noopener">CVE-2026-43742</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43745" target="_blank" rel="noopener">CVE-2026-43745</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43720" target="_blank" rel="noopener">CVE-2026-43720</a></td>
        <td>WebKit Canvas</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43721" target="_blank" rel="noopener">CVE-2026-43721</a></td>
        <td>WebKit Storage</td>
        <td class="impact">A malicious website may be able to silently hijack clipboard data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28979" target="_blank" rel="noopener">CVE-2026-28979</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43717" target="_blank" rel="noopener">CVE-2026-43717</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43718" target="_blank" rel="noopener">CVE-2026-43718</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43746" target="_blank" rel="noopener">CVE-2026-43746</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      </tbody>
    </table>
  



  
  






  <p class="">We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Chrome team is delighted to announce the promotion of Chrome 151 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.Chrome 150.0.7871.46 (Linux) 150.0.7871.46/.47 Windows/Mac contains a number of fixes and improvements -- a list of changes is avail...]]></description>
<link>https://tsecurity.de/de/3637049/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637049/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Wed, 01 Jul 2026 01:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The Chrome team is delighted to announce the promotion of Chrome 151 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.</span></p><p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">Chrome </span><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)">150.0.7871.46 (Linux) </span></span></span></span></span><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.46/.47 </span><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">Windows/Mac </span></span></span><span><span color="rgba(0, 0, 0, 0.87)">contains a number of fixes and improvements -- a list of changes is available in the</span><a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.201..150.0.7871.47?pretty=fuller&amp;n=10000"> log</a><span color="rgba(0, 0, 0, 0.87)">. Watch out for upcoming</span><a href="https://chrome.blogspot.com/"> </a><a href="https://chrome.blogspot.com/">Chrome</a> </span><span>and</span><a href="https://blog.chromium.org/"> Chromium</a><span> blog posts about new features and big efforts delivered in 151.</span></span></span></span></p><div><span>Security Fixes and Rewards<br></span><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.<br></span><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:0-M150"><span>382</span></a><span> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506558270"><span>506558270</span></a><span>]</span><span> Critical </span><span>CVE-2026-13774: Use after free in Extensions. </span><span>Reported by Google on 2026-04-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511766407"><span>511766407</span></a><span>]</span><span> Critical </span><span>CVE-2026-13775: Use after free in GPU. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513012139"><span>513012139</span></a><span>]</span><span> Critical </span><span>CVE-2026-13776: Type Confusion in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513128566"><span>513128566</span></a><span>]</span><span> Critical </span><span>CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513167952"><span>513167952</span></a><span>]</span><span> Critical </span><span>CVE-2026-13778: Use after free in WebUSB. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513222854"><span>513222854</span></a><span>]</span><span> Critical </span><span>CVE-2026-13779: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514769383"><span>514769383</span></a><span>]</span><span> Critical </span><span>CVE-2026-13780: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-05-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516457532"><span>516457532</span></a><span>]</span><span> Critical </span><span>CVE-2026-13781: Insufficient validation of untrusted input in Skia. </span><span>Reported by Google on 2026-05-25<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516683433"><span>516683433</span></a><span>]</span><span> Critical </span><span>CVE-2026-13782: Use after free in Browser. </span><span>Reported by Google on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516962178"><span>516962178</span></a><span>]</span><span> Critical </span><span>CVE-2026-13783: Use after free in Views. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516962715"><span>516962715</span></a><span>]</span><span> Critical </span><span>CVE-2026-13784: Use after free in Views. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517021684"><span>517021684</span></a><span>]</span><span> Critical </span><span>CVE-2026-13785: Use after free in Bluetooth. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/518007821"><span>518007821</span></a><span>]</span><span> Critical </span><span>CVE-2026-13786: Use after free in Ozone. </span><span>Reported by Google on 2026-05-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/522919313"><span>522919313</span></a><span>]</span><span> Critical </span><span>CVE-2026-13787: Use after free in Chromoting. </span><span>Reported by Google on 2026-06-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523119897"><span>523119897</span></a><span>]</span><span> Critical </span><span>CVE-2026-13788: Use after free in Fullscreen. </span><span>Reported by Google on 2026-06-12<br></span><span>[$36000][</span><a href="https://issues.chromium.org/issues/493847920"><span>493847920</span></a><span>]</span><span> High </span><span>CVE-2026-13789: Use after free in GPU. </span><span>Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-18<br></span><span>[$10000][</span><a href="https://issues.chromium.org/issues/457771782"><span>457771782</span></a><span>]</span><span> High </span><span>CVE-2026-13790: Side-channel information leakage in Scroll. </span><span>Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer on 2025-11-04<br></span><span>[$10000][</span><a href="https://issues.chromium.org/issues/503850012"><span>503850012</span></a><span>]</span><span> High </span><span>CVE-2026-13791: Insufficient validation of untrusted input in Downloads. </span><span>Reported by Ron Masas (Imperva) on 2026-04-17<br></span><span>[$4000][</span><a href="https://issues.chromium.org/issues/496012368"><span>496012368</span></a><span>]</span><span> High </span><span>CVE-2026-13792: Use after free in Touchbar. </span><span>Reported by Weipeng Jiang (@Krace) of VRI on 2026-03-25<br></span><span>[$3000][</span><a href="https://issues.chromium.org/issues/510829679"><span>510829679</span></a><span>]</span><span> High </span><span>CVE-2026-13793: Insufficient policy enforcement in SVG. </span><span>Reported by pakhunov.anton.n@gmail.com on 2026-05-07<br></span><span>[$2500][</span><a href="https://issues.chromium.org/issues/513893425"><span>513893425</span></a><span>]</span><span> High </span><span>CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Daniel Rodríguez on 2026-05-16<br></span><span>[$2000][</span><a href="https://issues.chromium.org/issues/476591032"><span>476591032</span></a><span>]</span><span> High </span><span>CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS. </span><span>Reported by maitai on 2026-01-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/491894115"><span>491894115</span></a><span>]</span><span> High </span><span>CVE-2026-13796: Integer overflow in Chromecast. </span><span>Reported by Google on 2026-03-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499025645"><span>499025645</span></a><span>]</span><span> High </span><span>CVE-2026-13797: Insufficient validation of untrusted input in Chromecast. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499048914"><span>499048914</span></a><span>]</span><span> High </span><span>CVE-2026-13798: Heap buffer overflow in Chromecast. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499252371"><span>499252371</span></a><span>]</span><span> High </span><span>CVE-2026-13799: Use after free in QUIC. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500108770"><span>500108770</span></a><span>]</span><span> High </span><span>CVE-2026-13800: Inappropriate implementation in Updater. </span><span>Reported by Google on 2026-04-06</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/500587568"><span>500587568</span></a><span>]</span><span> High </span><span>CVE-2026-13801: Integer overflow in Chromecast. </span><span>Reported by Google on 2026-04-08</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/501623322"><span>501623322</span></a><span>]</span><span> High </span><span>CVE-2026-13802: Use after free in Views. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501669642"><span>501669642</span></a><span>]</span><span> High </span><span>CVE-2026-13803: Type Confusion in Chrome Tabs. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501873032"><span>501873032</span></a><span>]</span><span> High </span><span>CVE-2026-13804: Use after free in Chromecast. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502282040"><span>502282040</span></a><span>]</span><span> High </span><span>CVE-2026-13805: Use after free in GFX. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503333798"><span>503333798</span></a><span>]</span><span> High </span><span>CVE-2026-13806: Insufficient validation of untrusted input in Accessibility. </span><span>Reported by Google on 2026-04-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504194494"><span>504194494</span></a><span>]</span><span> High </span><span>CVE-2026-13807: Use after free in Import. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504221510"><span>504221510</span></a><span>]</span><span> High </span><span>CVE-2026-13808: Insufficient data validation in Chrome for iOS. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504222227"><span>504222227</span></a><span>]</span><span> High </span><span>CVE-2026-13809: Side-channel information leakage in Safe Browsing. </span><span>eported by Google on 2026-04-19<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/504600482"><span>504600482</span></a><span>]</span><span> High </span><span>CVE-2026-13810: Inappropriate implementation in Input. </span><span>Reported by dilipsc03@gmail.com on 2026-04-20<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506149253"><span>506149253</span></a><span>]</span><span> High </span><span>CVE-2026-13811: Use after free in IME. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508293203"><span>508293203</span></a><span>]</span><span> High </span><span>CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508462149"><span>508462149</span></a><span>]</span><span> High </span><span>CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511712766"><span>511712766</span></a><span>]</span><span> High </span><span>CVE-2026-13814: Use after free in Views. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511722207"><span>511722207</span></a><span>]</span><span> High </span><span>CVE-2026-13815: Use after free in Blink. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511735715"><span>511735715</span></a><span>]</span><span> High </span><span>CVE-2026-13816: Insufficient validation of untrusted input in File Input. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511739631"><span>511739631</span></a><span>]</span><span> High </span><span>CVE-2026-13817: Insufficient validation of untrusted input in Glic. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511823182"><span>511823182</span></a><span>]</span><span> High </span><span>CVE-2026-13818: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512962749"><span>512962749</span></a><span>]</span><span> High </span><span>CVE-2026-13819: Out of bounds read in ANGLE. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512986879"><span>512986879</span></a><span>]</span><span> High </span><span>CVE-2026-13820: Out of bounds read in Skia. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513142445"><span>513142445</span></a><span>]</span><span> High </span><span>CVE-2026-13821: Use after free in Canvas. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513148038"><span>513148038</span></a><span>]</span><span> High </span><span>CVE-2026-13822: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513163011"><span>513163011</span></a><span>]</span><span> High </span><span>CVE-2026-13823: Use after free in Glic. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513177497"><span>513177497</span></a><span>]</span><span> High </span><span>CVE-2026-13824: Insufficient validation of untrusted input in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513209610"><span>513209610</span></a><span>]</span><span> High </span><span>CVE-2026-13825: Uninitialized Use in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513237800"><span>513237800</span></a><span>]</span><span> High </span><span>CVE-2026-13826: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513371963"><span>513371963</span></a><span>]</span><span> High </span><span>CVE-2026-13827: Use after free in Updater. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513399832"><span>513399832</span></a><span>]</span><span> High </span><span>CVE-2026-13828: Inappropriate implementation in Enterprise. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513490996"><span>513490996</span></a><span>]</span><span> High </span><span>CVE-2026-13829: Insufficient validation of untrusted input in Settings. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513727494"><span>513727494</span></a><span>]</span><span> High </span><span>CVE-2026-13830: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513781328"><span>513781328</span></a><span>]</span><span> High </span><span>CVE-2026-13831: Use after free in GPU. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513822378"><span>513822378</span></a><span>]</span><span> High </span><span>CVE-2026-13832: Use after free in Headless. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513920082"><span>513920082</span></a><span>]</span><span> High </span><span>CVE-2026-13833: Uninitialized Use in ANGLE. </span><span>Reported by Google on 2026-05-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513925114"><span>513925114</span></a><span>]</span><span> High </span><span>CVE-2026-13834: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-05-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514338102"><span>514338102</span></a><span>]</span><span> High </span><span>CVE-2026-13835: Inappropriate implementation in XML. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514420555"><span>514420555</span></a><span>]</span><span> High </span><span>CVE-2026-13836: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514429130"><span>514429130</span></a><span>]</span><span> High </span><span>CVE-2026-13837: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514445398"><span>514445398</span></a><span>]</span><span> High </span><span>CVE-2026-13838: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514449396"><span>514449396</span></a><span>]</span><span> High </span><span>CVE-2026-13839: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/514609778"><span>514609778</span></a><span>]</span><span> High </span><span>CVE-2026-13840: Insufficient policy enforcement in Canvas. </span><span>Reported by Binglin Song on 2026-05-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/515467789"><span>515467789</span></a><span>]</span><span> High </span><span>CVE-2026-13841: Integer overflow in Skia. </span><span>Reported by Google on 2026-05-21<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/516836297"><span>516836297</span></a><span>]</span><span> High </span><span>CVE-2026-13842: Incorrect security UI in Chrome for iOS. </span><span>Reported by Azza Tegar Naufal Ataullah on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516869032"><span>516869032</span></a><span>]</span><span> High </span><span>CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516926115"><span>516926115</span></a><span>]</span><span> High </span><span>CVE-2026-13844: Use after free in Updater. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516936863"><span>516936863</span></a><span>]</span><span> High </span><span>CVE-2026-13845: Use after free in DOM. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516999424"><span>516999424</span></a><span>]</span><span> High </span><span>CVE-2026-13846: Use after free in USB. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517073397"><span>517073397</span></a><span>]</span><span> High </span><span>CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517345069"><span>517345069</span></a><span>]</span><span> High </span><span>CVE-2026-13848: Use after free in Forms. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517351411"><span>517351411</span></a><span>]</span><span> High </span><span>CVE-2026-13849: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517610676"><span>517610676</span></a><span>]</span><span> High </span><span>CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/519692255"><span>519692255</span></a><span>]</span><span> High </span><span>CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-06-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/522560124"><span>522560124</span></a><span>]</span><span> High </span><span>CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-06-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523224019"><span>523224019</span></a><span>]</span><span> High </span><span>CVE-2026-13853: Use after free in Journeys. </span><span>Reported by Google on 2026-06-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523690961"><span>523690961</span></a><span>]</span><span> High </span><span>CVE-2026-13854: Use after free in Ozone. </span><span>Reported by Google on 2026-06-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/524395469"><span>524395469</span></a><span>]</span><span> High </span><span>CVE-2026-13855: Use after free in Ozone. </span><span>Reported by Google on 2026-06-16<br></span><span>[$8000][</span><a href="https://issues.chromium.org/issues/508092634"><span>508092634</span></a><span>]</span><span> Medium </span><span>CVE-2026-13856: Insufficient validation of untrusted input in Speech. </span><span>Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-30<br></span><span>[$5000][</span><a href="https://issues.chromium.org/issues/479203484"><span>479203484</span></a><span>]</span><span> Medium </span><span>CVE-2026-13857: Inappropriate implementation in Geometry. </span><span>Reported by Luan Herrera (@lbherrera_) on 2026-01-27<br></span><span>[$3000][</span><a href="https://issues.chromium.org/issues/507090179"><span>507090179</span></a><span>]</span><span> Medium </span><span>CVE-2026-13858: Out of bounds read in FFmpeg. </span><span>Reported by Wongi Lee (@_qwerty_po) of Theori with Xint Code, Jungwoo Lee (@physicube) on 2026-04-27<br></span><span>[$2000][</span><a href="https://issues.chromium.org/issues/484756087"><span>484756087</span></a><span>]</span><span> Medium </span><span>CVE-2026-13859: Inappropriate implementation in ANGLE. </span><span>Reported by Jason Villaluna on 2026-02-15<br></span><span>[$1000][</span><a href="https://issues.chromium.org/issues/417052041"><span>417052041</span></a><span>]</span><span> Medium </span><span>CVE-2026-13860: Incorrect security UI in Autofill. </span><span>Reported by Khalil Zhani on 2025-05-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495456765"><span>495456765</span></a><span>]</span><span> Medium </span><span>CVE-2026-13861: Use after free in Core. </span><span>Reported by Google on 2026-03-23<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495897416"><span>495897416</span></a><span>]</span><span> Medium </span><span>CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys &amp; Security Keys). </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496012495"><span>496012495</span></a><span>]</span><span> Medium </span><span>CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs. </span><span>Reported by Google on 2026-03-25<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496399913"><span>496399913</span></a><span>]</span><span> Medium </span><span>CVE-2026-13864: Insufficient policy enforcement in WebHID. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497090912"><span>497090912</span></a><span>]</span><span> Medium </span><span>CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497207698"><span>497207698</span></a><span>]</span><span> Medium </span><span>CVE-2026-13866: Insufficient validation of untrusted input in Input. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497345177"><span>497345177</span></a><span>]</span><span> Medium </span><span>CVE-2026-13867: Inappropriate implementation in Geolocation. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497453475"><span>497453475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13868: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497610642"><span>497610642</span></a><span>]</span><span> Medium </span><span>CVE-2026-13869: Use after free in Device. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497634837"><span>497634837</span></a><span>]</span><span> Medium </span><span>CVE-2026-13870: Use after free in WebView. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497961376"><span>497961376</span></a><span>]</span><span> Medium </span><span>CVE-2026-13871: Insufficient data validation in GuestView. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497977983"><span>497977983</span></a><span>]</span><span> Medium </span><span>CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-03-31<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498085466"><span>498085466</span></a><span>]</span><span> Medium </span><span>CVE-2026-13873: Out of bounds memory access in Layout. </span><span>Reported by Google on 2026-03-31<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498411773"><span>498411773</span></a><span>]</span><span> Medium </span><span>CVE-2026-13874: Inappropriate implementation in DataTransfer. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498721671"><span>498721671</span></a><span>]</span><span> Medium </span><span>CVE-2026-13875: Insufficient validation of untrusted input in GPU. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498722200"><span>498722200</span></a><span>]</span><span> Medium </span><span>CVE-2026-13876: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498820206"><span>498820206</span></a><span>]</span><span> Medium </span><span>CVE-2026-13877: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499007266"><span>499007266</span></a><span>]</span><span> Medium </span><span>CVE-2026-13878: Use after free in Bluetooth. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499022239"><span>499022239</span></a><span>]</span><span> Medium </span><span>CVE-2026-13879: Use after free in Bluetooth. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499025880"><span>499025880</span></a><span>]</span><span> Medium </span><span>CVE-2026-13880: Use after free in USB. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499100491"><span>499100491</span></a><span>]</span><span> Medium </span><span>CVE-2026-13881: Insufficient data validation in WebAppInstalls. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499162550"><span>499162550</span></a><span>]</span><span> Medium </span><span>CVE-2026-13882: Inappropriate implementation in USB. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500030250"><span>500030250</span></a><span>]</span><span> Medium </span><span>CVE-2026-13883: Type Confusion in ANGLE. </span><span>Reported by Google on 2026-04-06<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500077014"><span>500077014</span></a><span>]</span><span> Medium </span><span>CVE-2026-13884: Heap buffer overflow in Chromecast. </span><span>Reported by Google on 2026-04-06<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500474409"><span>500474409</span></a><span>]</span><span> Medium </span><span>CVE-2026-13885: Use after free in Skia. </span><span>Reported by Google on 2026-04-07<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500475136"><span>500475136</span></a><span>]</span><span> Medium </span><span>CVE-2026-13886: Policy bypass in Isolated Web Apps. </span><span>Reported by Google on 2026-04-07<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500508524"><span>500508524</span></a><span>]</span><span> Medium </span><span>CVE-2026-13887: Insufficient policy enforcement in NFC. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500566906"><span>500566906</span></a><span>]</span><span> Medium </span><span>CVE-2026-13888: Use after free in Extensions. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500588580"><span>500588580</span></a><span>]</span><span> Medium </span><span>CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500601345"><span>500601345</span></a><span>]</span><span> Medium </span><span>CVE-2026-13890: Out of bounds read in Chromecast. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501631475"><span>501631475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13891: Insufficient validation of untrusted input in Extensions. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501674841"><span>501674841</span></a><span>]</span><span> Medium </span><span>CVE-2026-13892: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501729582"><span>501729582</span></a><span>]</span><span> Medium </span><span>CVE-2026-13893: Insufficient validation of untrusted input in WebUI. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501741117"><span>501741117</span></a><span>]</span><span> Medium </span><span>CVE-2026-13894: Insufficient policy enforcement in Network. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501770542"><span>501770542</span></a><span>]</span><span> Medium </span><span>CVE-2026-13895: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501820076"><span>501820076</span></a><span>]</span><span> Medium </span><span>CVE-2026-13896: Insufficient policy enforcement in Glic. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501877896"><span>501877896</span></a><span>]</span><span> Medium </span><span>CVE-2026-13897: Insufficient policy enforcement in Chromecast. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501925480"><span>501925480</span></a><span>]</span><span> Medium </span><span>CVE-2026-13898: Use after free in Cast Receiver. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502109002"><span>502109002</span></a><span>]</span><span> Medium </span><span>CVE-2026-13899: Use after free in HTML. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502374993"><span>502374993</span></a><span>]</span><span> Medium </span><span>CVE-2026-13900: Insufficient validation of untrusted input in Chromecast. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503585173"><span>503585173</span></a><span>]</span><span> Medium </span><span>CVE-2026-13901: Insufficient validation of untrusted input in Serial. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503725717"><span>503725717</span></a><span>]</span><span> Medium </span><span>CVE-2026-13902: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503912196"><span>503912196</span></a><span>]</span><span> Medium </span><span>CVE-2026-13903: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-04-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504185807"><span>504185807</span></a><span>]</span><span> Medium </span><span>CVE-2026-13904: Incorrect security UI in Safe Browsing. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504192688"><span>504192688</span></a><span>]</span><span> Medium </span><span>CVE-2026-13905: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504613867"><span>504613867</span></a><span>]</span><span> Medium </span><span>CVE-2026-13906: Out of bounds read in Codecs. </span><span>Reported by Google on 2026-04-20<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505156685"><span>505156685</span></a><span>]</span><span> Medium </span><span>CVE-2026-13907: Inappropriate implementation in iOSWeb. </span><span>Reported by Google on 2026-04-22<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505242189"><span>505242189</span></a><span>]</span><span> Medium </span><span>CVE-2026-13908: Insufficient validation of untrusted input in Omnibox. </span><span>Reported by Google on 2026-04-22<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505933538"><span>505933538</span></a><span>]</span><span> Medium </span><span>CVE-2026-13909: Insufficient policy enforcement in DevTools. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507231605"><span>507231605</span></a><span>]</span><span> Medium </span><span>CVE-2026-13910: Insufficient policy enforcement in WebXR. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507239830"><span>507239830</span></a><span>]</span><span> Medium </span><span>CVE-2026-13911: Insufficient data validation in Spellcheck. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508259433"><span>508259433</span></a><span>]</span><span> Medium </span><span>CVE-2026-13912: Incorrect security UI in Safe Browsing. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508260619"><span>508260619</span></a><span>]</span><span> Medium </span><span>CVE-2026-13913: Insufficient policy enforcement in Autofill. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508273690"><span>508273690</span></a><span>]</span><span> Medium </span><span>CVE-2026-13914: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508275293"><span>508275293</span></a><span>]</span><span> Medium </span><span>CVE-2026-13915: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508283108"><span>508283108</span></a><span>]</span><span> Medium </span><span>CVE-2026-13916: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508286935"><span>508286935</span></a><span>]</span><span> Medium </span><span>CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/509712284"><span>509712284</span></a><span>]</span><span> Medium </span><span>CVE-2026-13918: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-05-05<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511249430"><span>511249430</span></a><span>]</span><span> Medium </span><span>CVE-2026-13919: Insufficient data validation in Extensions. </span><span>Reported by Google on 2026-05-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511722559"><span>511722559</span></a><span>]</span><span> Medium </span><span>CVE-2026-13920: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511738175"><span>511738175</span></a><span>]</span><span> Medium </span><span>CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511748106"><span>511748106</span></a><span>]</span><span> Medium </span><span>CVE-2026-13922: Side-channel information leakage in Paint. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511772034"><span>511772034</span></a><span>]</span><span> Medium </span><span>CVE-2026-13923: Uninitialized Use in GPU. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511784747"><span>511784747</span></a><span>]</span><span> Medium </span><span>CVE-2026-13924: Insufficient validation of untrusted input in WebView. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511802911"><span>511802911</span></a><span>]</span><span> Medium </span><span>CVE-2026-13925: Inappropriate implementation in Downloads. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511814550"><span>511814550</span></a><span>]</span><span> Medium </span><span>CVE-2026-13926: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511826446"><span>511826446</span></a><span>]</span><span> Medium </span><span>CVE-2026-13927: Insufficient validation of untrusted input in UI. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512162479"><span>512162479</span></a><span>]</span><span> Medium </span><span>CVE-2026-13928: Insufficient validation of untrusted input in Enterprise. </span><span>Reported by Google on 2026-05-11<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/512249559"><span>512249559</span></a><span>]</span><span> Medium </span><span>CVE-2026-13929: Insufficient validation of untrusted input in DevTools. </span><span>Reported by LegioSec on 2026-05-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512937764"><span>512937764</span></a><span>]</span><span> Medium </span><span>CVE-2026-13930: Insufficient policy enforcement in Actor. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512997441"><span>512997441</span></a><span>]</span><span> Medium </span><span>CVE-2026-13931: Inappropriate implementation in Media. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513001690"><span>513001690</span></a><span>]</span><span> Medium </span><span>CVE-2026-13932: Inappropriate implementation in Sharing. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513002625"><span>513002625</span></a><span>]</span><span> Medium </span><span>CVE-2026-13933: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513006636"><span>513006636</span></a><span>]</span><span> Medium </span><span>CVE-2026-13934: Insufficient validation of untrusted input in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513009005"><span>513009005</span></a><span>]</span><span> Medium </span><span>CVE-2026-13935: Side-channel information leakage in ComputePressure. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513044658"><span>513044658</span></a><span>]</span><span> Medium </span><span>CVE-2026-13936: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513046494"><span>513046494</span></a><span>]</span><span> Medium </span><span>CVE-2026-13937: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513143921"><span>513143921</span></a><span>]</span><span> Medium </span><span>CVE-2026-13938: Integer overflow in Fonts. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513149760"><span>513149760</span></a><span>]</span><span> Medium </span><span>CVE-2026-13939: Insufficient validation of untrusted input in WebShare. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513158425"><span>513158425</span></a><span>]</span><span> Medium </span><span>CVE-2026-13940: Uninitialized Use in Cast. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513183855"><span>513183855</span></a><span>]</span><span> Medium </span><span>CVE-2026-13941: Inappropriate implementation in SiteSettings. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513186670"><span>513186670</span></a><span>]</span><span> Medium </span><span>CVE-2026-13942: Insufficient validation of untrusted input in Video Capture. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513204116"><span>513204116</span></a><span>]</span><span> Medium </span><span>CVE-2026-13943: Uninitialized Use in CSS. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513224212"><span>513224212</span></a><span>]</span><span> Medium </span><span>CVE-2026-13944: Inappropriate implementation in DataTransfer. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513226551"><span>513226551</span></a><span>]</span><span> Medium </span><span>CVE-2026-13945: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513274039"><span>513274039</span></a><span>]</span><span> Medium </span><span>CVE-2026-13946: Inappropriate implementation in ScriptInjections. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513280648"><span>513280648</span></a><span>]</span><span> Medium </span><span>CVE-2026-13947: Uninitialized Use in XR. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513286820"><span>513286820</span></a><span>]</span><span> Medium </span><span>CVE-2026-13948: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513311569"><span>513311569</span></a><span>]</span><span> Medium </span><span>CVE-2026-13949: Insufficient policy enforcement in Payments. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513360781"><span>513360781</span></a><span>]</span><span> Medium </span><span>CVE-2026-13950: Uninitialized Use in GPU. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513394321"><span>513394321</span></a><span>]</span><span> Medium </span><span>CVE-2026-13951: Policy bypass in USB. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513401808"><span>513401808</span></a><span>]</span><span> Medium </span><span>CVE-2026-13952: Inappropriate implementation in PerformanceAPIs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513459192"><span>513459192</span></a><span>]</span><span> Medium </span><span>CVE-2026-13953: Inappropriate implementation in SplitView. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513504934"><span>513504934</span></a><span>]</span><span> Medium </span><span>CVE-2026-13954: Insufficient policy enforcement in XML. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513508305"><span>513508305</span></a><span>]</span><span> Medium </span><span>CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513515168"><span>513515168</span></a><span>]</span><span> Medium </span><span>CVE-2026-13956: Incorrect security UI in PageInfo. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513553557"><span>513553557</span></a><span>]</span><span> Medium </span><span>CVE-2026-13957: Incorrect security UI in Extensions. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513567306"><span>513567306</span></a><span>]</span><span> Medium </span><span>CVE-2026-13958: Uninitialized Use in Codecs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513609249"><span>513609249</span></a><span>]</span><span> Medium </span><span>CVE-2026-13959: Insufficient validation of untrusted input in Blink. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513714023"><span>513714023</span></a><span>]</span><span> Medium </span><span>CVE-2026-13960: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513719481"><span>513719481</span></a><span>]</span><span> Medium </span><span>CVE-2026-13961: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513721370"><span>513721370</span></a><span>]</span><span> Medium </span><span>CVE-2026-13962: Insufficient data validation in PDF. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513727626"><span>513727626</span></a><span>]</span><span> Medium </span><span>CVE-2026-13963: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513735096"><span>513735096</span></a><span>]</span><span> Medium </span><span>CVE-2026-13964: Insufficient policy enforcement in WebView. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513737952"><span>513737952</span></a><span>]</span><span> Medium </span><span>CVE-2026-13965: Use after free in Oilpan. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513741393"><span>513741393</span></a><span>] </span><span>Medium </span><span>CVE-2026-13966: Inappropriate implementation in History. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513751951"><span>513751951</span></a><span>] </span><span>Medium </span><span>CVE-2026-13967: Type Confusion in V8. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513762145"><span>513762145</span></a><span>] </span><span>Medium </span><span>CVE-2026-13968: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513762962"><span>513762962</span></a><span>] </span><span>Medium </span><span>CVE-2026-13969: Uninitialized Use in UI. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513779283"><span>513779283</span></a><span>]</span><span> </span><span>Medium </span><span>CVE-2026-13970: Uninitialized Use in Media. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513780208"><span>513780208</span></a><span>]</span><span> </span><span>Medium </span><span>CVE-2026-13971: Uninitialized Use in Skia. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513792140"><span>513792140</span></a><span>]</span><span> Medium </span><span>CVE-2026-13972: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513832989"><span>513832989</span></a><span>]</span><span> Medium </span><span>CVE-2026-13973: Inappropriate implementation in UI. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513850475"><span>513850475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13974: Integer overflow in Safe Browsing. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513857658"><span>513857658</span></a><span>] </span><span>Medium </span><span>CVE-2026-13975: Out of bounds read in ANGLE. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513858286"><span>513858286</span></a><span>] </span><span>Medium </span><span>CVE-2026-13976: Heap buffer overflow in Storage. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513859894"><span>513859894</span></a><span>] </span><span>Medium </span><span>CVE-2026-13977: Inappropriate implementation in HTMLParser. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513866949"><span>513866949</span></a><span>] </span><span>Medium </span><span>CVE-2026-13978: Insufficient policy enforcement in PageInfo. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513988889"><span>513988889</span></a><span>] </span><span>Medium </span><span>CVE-2026-13979: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513989973"><span>513989973</span></a><span>] </span><span>Medium </span><span>CVE-2026-13980: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513990408"><span>513990408</span></a><span>] </span><span>Medium </span><span>CVE-2026-13981: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514006829"><span>514006829</span></a><span>]</span><span> Medium </span><span>CVE-2026-13982: Incorrect security UI in Passwords. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514009910"><span>514009910</span></a><span>] </span><span>Medium </span><span>CVE-2026-13983: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514010404"><span>514010404</span></a><span>] </span><span>Medium </span><span>CVE-2026-13984: Incorrect security UI in TabStrip. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514013849"><span>514013849</span></a><span>] </span><span>Medium </span><span>CVE-2026-13985: Inappropriate implementation in MediaCapture. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514020959"><span>514020959</span></a><span>] </span><span>Medium </span><span>CVE-2026-13986: Inappropriate implementation in Media UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039122"><span>514039122</span></a><span>] </span><span>Medium </span><span>CVE-2026-13987: Incorrect security UI in Mobile. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514040614"><span>514040614</span></a><span>] </span><span>Medium </span><span>CVE-2026-13988: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514056221"><span>514056221</span></a><span>] </span><span>Medium </span><span>CVE-2026-13989: Insufficient policy enforcement in PageInfo. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514058439"><span>514058439</span></a><span>] </span><span>Medium </span><span>CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514061117"><span>514061117</span></a><span>] </span><span>Medium </span><span>CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514063409"><span>514063409</span></a><span>] </span><span>Medium </span><span>CVE-2026-13992: Inappropriate implementation in UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514064139"><span>514064139</span></a><span>] </span><span>Medium </span><span>CVE-2026-13993: Incorrect security UI in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514067416"><span>514067416</span></a><span>] </span><span>Medium </span><span>CVE-2026-13994: Inappropriate implementation in Credential Management. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514067524"><span>514067524</span></a><span>] </span><span>Medium </span><span>CVE-2026-13995: Insufficient validation of untrusted input in Autofill. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514068972"><span>514068972</span></a><span>] </span><span>Medium </span><span>CVE-2026-13996: Incorrect security UI in Permissions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514069689"><span>514069689</span></a><span>] </span><span>Medium </span><span>CVE-2026-13997: Incorrect security UI in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514070501"><span>514070501</span></a><span>] </span><span>Medium </span><span>CVE-2026-13998: Incorrect security UI in File Input. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514071697"><span>514071697</span></a><span>] </span><span>Medium </span><span>CVE-2026-13999: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514461552"><span>514461552</span></a><span>] </span><span>Medium </span><span>CVE-2026-14000: Inappropriate implementation in XML. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514481943"><span>514481943</span></a><span>] </span><span>Medium </span><span>CVE-2026-14001: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514489361"><span>514489361</span></a><span>] </span><span>Medium </span><span>CVE-2026-14002: Inappropriate implementation in Geolocation. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514503077"><span>514503077</span></a><span>] </span><span>Medium </span><span>CVE-2026-14003: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514538751"><span>514538751</span></a><span>] </span><span>Medium </span><span>CVE-2026-14004: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514740273"><span>514740273</span></a><span>] </span><span>Medium </span><span>CVE-2026-14005: Use after free in Omnibox. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515423596"><span>515423596</span></a><span>] </span><span>Medium </span><span>CVE-2026-14006: Use after free in Navigation. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516425999"><span>516425999</span></a><span>] </span><span>Medium </span><span>CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy. </span><span>Reported by Google on 2026-05-25</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516781007"><span>516781007</span></a><span>] </span><span>Medium </span><span>CVE-2026-14008: Uninitialized Use in WebXR. </span><span>Reported by Google on 2026-05-26</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516819850"><span>516819850</span></a><span>] </span><span>Medium </span><span>CVE-2026-14009: Insufficient data validation in Passwords. </span><span>Reported by Google on 2026-05-26</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516924151"><span>516924151</span></a><span>] </span><span>Medium </span><span>CVE-2026-14010: Uninitialized Use in Codecs. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516944556"><span>516944556</span></a><span>] </span><span>Medium </span><span>CVE-2026-14011: Out of bounds read in SurfaceCapture. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517110749"><span>517110749</span></a><span>] </span><span>Medium </span><span>CVE-2026-14012: Side-channel information leakage in CSS. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517114175"><span>517114175</span></a><span>] </span><span>Medium </span><span>CVE-2026-14013: Inappropriate implementation in SVG. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517155893"><span>517155893</span></a><span>] </span><span>Medium </span><span>CVE-2026-14014: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517207235"><span>517207235</span></a><span>] </span><span>Medium </span><span>CVE-2026-14015: Inappropriate implementation in WebRTC. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517234388"><span>517234388</span></a><span>] </span><span>Medium </span><span>CVE-2026-14016: Insufficient policy enforcement in SVG. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517241992"><span>517241992</span></a><span>] </span><span>Medium </span><span>CVE-2026-14017: Inappropriate implementation in Navigation. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517350251"><span>517350251</span></a><span>] </span><span>Medium </span><span>CVE-2026-14018: Use after free in Updater. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517455455"><span>517455455</span></a><span>] </span><span>Medium </span><span>CVE-2026-14019: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517598518"><span>517598518</span></a><span>] </span><span>Medium </span><span>CVE-2026-14020: Insufficient validation of untrusted input in WebXR. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517731924"><span>517731924</span></a><span>] </span><span>Medium </span><span>CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517791835"><span>517791835</span></a><span>] </span><span>Medium </span><span>CVE-2026-14022: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518063436"><span>518063436</span></a><span>] </span><span>Medium </span><span>CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518245882"><span>518245882</span></a><span>] </span><span>Medium </span><span>CVE-2026-14024: Use after free in Ozone. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[$2000][</span><a href="https://issues.chromium.org/issues/506482786"><span>506482786</span></a><span>]</span><span> Low </span><span>CVE-2026-14025: Use after free in Views. </span><span>Reported by asjidkalam on 2026-04-26<br></span><span>[$1000][</span><a href="https://issues.chromium.org/issues/507263861"><span>507263861</span></a><span>]</span><span> Low </span><span>CVE-2026-14026: Incorrect security UI in SplitView. </span><span>Reported by adisahilna35@gmail.com on 2026-04-28<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/361375787"><span>361375787</span></a><span>]</span><span> Low </span><span>CVE-2026-14027: Use after free in SignIn. </span><span>Reported by Sven Dysthe (@svn-dys) on 2024-08-21<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/401816601"><span>401816601</span></a><span>]</span><span> Low </span><span>CVE-2026-14028: Incorrect security UI in Chrome for iOS. </span><span>Reported by Ameen Basha M K on 2025-03-09<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/488762971"><span>488762971</span></a><span>]</span><span> Low </span><span>CVE-2026-14030: Incorrect security UI in SplitView. </span><span>Reported by Khalil Zhani on 2026-03-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495459838"><span>495459838</span></a><span>]</span><span> Low </span><span>CVE-2026-14031: Incorrect security UI in File Input. </span><span>Reported by Google on 2026-03-23<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495783474"><span>495783474</span></a><span>]</span><span> Low </span><span>CVE-2026-14032: Use after free in Bluetooth. </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495848160"><span>495848160</span></a><span>]</span><span> Low </span><span>CVE-2026-14033: Insufficient policy enforcement in Media. </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496368832"><span>496368832</span></a><span>]</span><span> Low </span><span>CVE-2026-14034: Inappropriate implementation in WebXR. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496371586"><span>496371586</span></a><span>]</span><span> Low </span><span>CVE-2026-14035: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496411061"><span>496411061</span></a><span>]</span><span> Low </span><span>CVE-2026-14036: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496522611"><span>496522611</span></a><span>]</span><span> Low </span><span>CVE-2026-14037: Insufficient policy enforcement in GPU. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497241148"><span>497241148</span></a><span>]</span><span> Low </span><span>CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497358012"><span>497358012</span></a><span>]</span><span> Low </span><span>CVE-2026-14039: Insufficient policy enforcement in GetUserMedia. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497488593"><span>497488593</span></a><span>]</span><span> Low </span><span>CVE-2026-14040: Use after free in BrowserTag. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497544822"><span>497544822</span></a><span>]</span><span> Low </span><span>CVE-2026-14041: Insufficient policy enforcement in Serial. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497558336"><span>497558336</span></a><span>]</span><span> Low </span><span>CVE-2026-14042: Inappropriate implementation in Isolated Web Apps. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497632232"><span>497632232</span></a><span>]</span><span> Low </span><span>CVE-2026-14043: Use after free in GetUserMedia. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497670996"><span>497670996</span></a><span>]</span><span> Low </span><span>CVE-2026-14044: Use after free in ANGLE. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497723649"><span>497723649</span></a><span>]</span><span> Low </span><span>CVE-2026-14045: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497959724"><span>497959724</span></a><span>]</span><span> Low </span><span>CVE-2026-14046: Inappropriate implementation in CustomTabs. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498864176"><span>498864176</span></a><span>]</span><span> Low </span><span>CVE-2026-14047: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499189601"><span>499189601</span></a><span>]</span><span> Low </span><span>CVE-2026-14048: Use after free in Chromecast. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501659888"><span>501659888</span></a><span>]</span><span> Low </span><span>CVE-2026-14049: Inappropriate implementation in GPU. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501708647"><span>501708647</span></a><span>]</span><span> Low </span><span>CVE-2026-14050: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501747804"><span>501747804</span></a><span>]</span><span> Low </span><span>CVE-2026-14051: Uninitialized Use in GamepadAPI. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501810874"><span>501810874</span></a><span>]</span><span> Low </span><span>CVE-2026-14052: Insufficient policy enforcement in FileSystem. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501836539"><span>501836539</span></a><span>]</span><span> Low </span><span>CVE-2026-14053: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501851312"><span>501851312</span></a><span>]</span><span> Low </span><span>CVE-2026-14054: Insufficient policy enforcement in Network. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501857663"><span>501857663</span></a><span>]</span><span> Low </span><span>CVE-2026-14055: Insufficient validation of untrusted input in Device Trust. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501888426"><span>501888426</span></a><span>]</span><span> Low </span><span>CVE-2026-14056: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502212647"><span>502212647</span></a><span>]</span><span> Low </span><span>CVE-2026-14057: Insufficient policy enforcement in FedCM. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502354038"><span>502354038</span></a><span>]</span><span> Low </span><span>CVE-2026-14058: Policy bypass in Parser. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502363986"><span>502363986</span></a><span>]</span><span> Low </span><span>CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502372527"><span>502372527</span></a><span>]</span><span> Low </span><span>CVE-2026-14060: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502434484"><span>502434484</span></a><span>]</span><span> Low </span><span>CVE-2026-14061: Inappropriate implementation in Dawn. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502448128"><span>502448128</span></a><span>]</span><span> Low </span><span>CVE-2026-14062: Inappropriate implementation in Views. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502473563"><span>502473563</span></a><span>]</span><span> Low </span><span>CVE-2026-14063: Out of bounds memory access in Chromecast. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502714977"><span>502714977</span></a><span>]</span><span> Low </span><span>CVE-2026-14064: Use after free in PageInfo. </span><span>Reported by Google on 2026-04-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503617508"><span>503617508</span></a><span>]</span><span> Low </span><span>CVE-2026-14065: Insufficient validation of untrusted input in PageInfo. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503779807"><span>503779807</span></a><span>]</span><span> Low </span><span>CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504069465"><span>504069465</span></a><span>]</span><span> Low </span><span>CVE-2026-14067: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-04-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504210171"><span>504210171</span></a><span>]</span><span> Low </span><span>CVE-2026-14068: Inappropriate implementation in Omnibox. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505136542"><span>505136542</span></a><span>]</span><span> Low </span><span>CVE-2026-14069: Integer overflow in WebNN. </span><span>Reported by Google on 2026-04-21<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505137978"><span>505137978</span></a><span>]</span><span> Low </span><span>CVE-2026-14070: Uninitialized Use in WebNN. </span><span>Reported by Google on 2026-04-21<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506143724"><span>506143724</span></a><span>]</span><span> Low </span><span>CVE-2026-14071: Side-channel information leakage in WebAudio. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507099867"><span>507099867</span></a><span>]</span><span> Low </span><span>CVE-2026-14072: Incorrect security UI in SplitView. </span><span>Reported by FARISSAL B on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507237563"><span>507237563</span></a><span>]</span><span> Low </span><span>CVE-2026-14073: Insufficient policy enforcement in WebXR. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511743480"><span>511743480</span></a><span>]</span><span> Low </span><span>CVE-2026-14074: Side-channel information leakage in WebAuthentication. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511808800"><span>511808800</span></a><span>]</span><span> Low </span><span>CVE-2026-14075: Policy bypass in Chrome for iOS. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511815165"><span>511815165</span></a><span>]</span><span> Low </span><span>CVE-2026-14076: Policy bypass in Network. </span><span>Reported by Google on 2026-05-10<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/511869411"><span>511869411</span></a><span>]</span><span> Low </span><span>CVE-2026-14077: Incorrect security UI in Select. </span><span>Reported by pwn.ai on 2026-05-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512953564"><span>512953564</span></a><span>]</span><span> Low </span><span>CVE-2026-14078: Policy bypass in WebRTC. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512971938"><span>512971938</span></a><span>]</span><span> Low </span><span>CVE-2026-14079: Policy bypass in Network. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512997517"><span>512997517</span></a><span>]</span><span> Low </span><span>CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513030698"><span>513030698</span></a><span>]</span><span> Low </span><span>CVE-2026-14081: Insufficient policy enforcement in DevTools. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513049578"><span>513049578</span></a><span>] </span><span>Low </span><span>CVE-2026-14082: Race in Storage. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513128322"><span>513128322</span></a><span>] </span><span>Low </span><span>CVE-2026-14083: Insufficient validation of untrusted input in HTML. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513138148"><span>513138148</span></a><span>] </span><span>Low </span><span>CVE-2026-14084: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513155863"><span>513155863</span></a><span>] </span><span>Low </span><span>CVE-2026-14085: Side-channel information leakage in CSS. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513169718"><span>513169718</span></a><span>] </span><span>Low </span><span>CVE-2026-14086: Insufficient policy enforcement in HID. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513177237"><span>513177237</span></a><span>] </span><span>Low </span><span>CVE-2026-14087: Insufficient validation of untrusted input in WebNN. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513178869"><span>513178869</span></a><span>] </span><span>Low </span><span>CVE-2026-14088: Uninitialized Use in Canvas. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513188254"><span>513188254</span></a><span>] </span><span>Low </span><span>CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513194241"><span>513194241</span></a><span>] </span><span>Low </span><span>CVE-2026-14090: Out of bounds read in CameraCapture. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513208773"><span>513208773</span></a><span>] </span><span>Low </span><span>CVE-2026-14091: Use after free in DevTools. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513212892"><span>513212892</span></a><span>] </span><span>Low </span><span>CVE-2026-14092: Insufficient policy enforcement in Privacy. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513240099"><span>513240099</span></a><span>] </span><span>Low </span><span>CVE-2026-14093: Use after free in Cast. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513264273"><span>513264273</span></a><span>] </span><span>Low </span><span>CVE-2026-14094: Use after free in Installer. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513271007"><span>513271007</span></a><span>] </span><span>Low </span><span>CVE-2026-14095: Insufficient validation of untrusted input in Browser. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513310821"><span>513310821</span></a><span>] </span><span>Low </span><span>CVE-2026-14096: Object lifecycle issue in Input. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513333529"><span>513333529</span></a><span>] </span><span>Low </span><span>CVE-2026-14097: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513375767"><span>513375767</span></a><span>] </span><span>Low </span><span>CVE-2026-14098: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513382161"><span>513382161</span></a><span>] </span><span>Low </span><span>CVE-2026-14099: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513383891"><span>513383891</span></a><span>] </span><span>Low </span><span>CVE-2026-14100: Insufficient data validation in NetworkCache. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513454805"><span>513454805</span></a><span>] </span><span>Low </span><span>CVE-2026-14101: Insufficient policy enforcement in Sandbox. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513455047"><span>513455047</span></a><span>] </span><span>Low </span><span>CVE-2026-14102: Use after free in Passwords. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513465245"><span>513465245</span></a><span>] </span><span>Low </span><span>CVE-2026-14103: Use after free in SSL. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513484193"><span>513484193</span></a><span>] </span><span>Low </span><span>CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513528117"><span>513528117</span></a><span>] </span><span>Low </span><span>CVE-2026-14105: Insufficient policy enforcement in Speech. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513532778"><span>513532778</span></a><span>] </span><span>Low </span><span>CVE-2026-14106: Insufficient validation of untrusted input in Text. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513544566"><span>513544566</span></a><span>] </span><span>Low </span><span>CVE-2026-14107: Use after free in Scheduling. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513689974"><span>513689974</span></a><span>] </span><span>Low </span><span>CVE-2026-14108: Use after free in PDFium. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513694957"><span>513694957</span></a><span>] </span><span>Low </span><span>CVE-2026-14109: Insufficient policy enforcement in Mojo. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513698452"><span>513698452</span></a><span>] </span><span>Low </span><span>CVE-2026-14110: Inappropriate implementation in DarkMode. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513710926"><span>513710926</span></a><span>] </span><span>Low </span><span>CVE-2026-14111: Use after free in WebProtect. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513713946"><span>513713946</span></a><span>] </span><span>Low </span><span>CVE-2026-14112: Inappropriate implementation in Enterprise. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513737335"><span>513737335</span></a><span>] </span><span>Low </span><span>CVE-2026-14113: Use after free in Updater. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513743129"><span>513743129</span></a><span>] </span><span>Low </span><span>CVE-2026-14114: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513745699"><span>513745699</span></a><span>] </span><span>Low </span><span>CVE-2026-14115: Insufficient validation of untrusted input in Cast. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513747800"><span>513747800</span></a><span>] </span><span>Low </span><span>CVE-2026-14116: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513751020"><span>513751020</span></a><span>] </span><span>Low </span><span>CVE-2026-14117: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513772764"><span>513772764</span></a><span>] </span><span>Low </span><span>CVE-2026-14118: Insufficient data validation in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513775483"><span>513775483</span></a><span>] </span><span>Low </span><span>CVE-2026-14119: Type Confusion in Bluetooth. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513777411"><span>513777411</span></a><span>] </span><span>Low </span><span>CVE-2026-14120: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513789382"><span>513789382</span></a><span>] </span><span>Low </span><span>CVE-2026-14121: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513824891"><span>513824891</span></a><span>] </span><span>Low </span><span>CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513856644"><span>513856644</span></a><span>] </span><span>Low </span><span>CVE-2026-14123: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513867710"><span>513867710</span></a><span>] </span><span>Low </span><span>CVE-2026-14124: Inappropriate implementation in CredentialProvider. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513918431"><span>513918431</span></a><span>] </span><span>Low </span><span>CVE-2026-14125: Uninitialized Use in ANGLE. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513992796"><span>513992796</span></a><span>] </span><span>Low </span><span>CVE-2026-14126: Incorrect security UI in UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514009654"><span>514009654</span></a><span>] </span><span>Low </span><span>CVE-2026-14127: Inappropriate implementation in Printing. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514015836"><span>514015836</span></a><span>] </span><span>Low </span><span>CVE-2026-14128: Insufficient data validation in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514018024"><span>514018024</span></a><span>] </span><span>Low </span><span>CVE-2026-14129: Incorrect security UI in PreviewTab. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514019522"><span>514019522</span></a><span>] </span><span>Low </span><span>CVE-2026-14130: Incorrect security UI in Omnibox. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514020982"><span>514020982</span></a><span>] </span><span>Low </span><span>CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039492"><span>514039492</span></a><span>] </span><span>Low </span><span>CVE-2026-14132: Inappropriate implementation in WebXR. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039947"><span>514039947</span></a><span>] </span><span>Low </span><span>CVE-2026-14133: Race in History Embeddings. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514055973"><span>514055973</span></a><span>] </span><span>Low </span><span>CVE-2026-14134: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514058566"><span>514058566</span></a><span>] </span><span>Low </span><span>CVE-2026-14135: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514068611"><span>514068611</span></a><span>] </span><span>Low </span><span>CVE-2026-14136: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514070067"><span>514070067</span></a><span>] </span><span>Low </span><span>CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514071775"><span>514071775</span></a><span>] </span><span>Low </span><span>CVE-2026-14138: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072495"><span>514072495</span></a><span>] </span><span>Low </span><span>CVE-2026-14139: Inappropriate implementation in TabStrip. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072607"><span>514072607</span></a><span>] </span><span>Low </span><span>CVE-2026-14140: Insufficient validation of untrusted input in Input. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072867"><span>514072867</span></a><span>] </span><span>Low </span><span>CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514073460"><span>514073460</span></a><span>] </span><span>Low </span><span>CVE-2026-14142: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514075028"><span>514075028</span></a><span>] </span><span>Low </span><span>CVE-2026-14143: Incorrect security UI in Passwords. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514079793"><span>514079793</span></a><span>] </span><span>Low </span><span>CVE-2026-14144: Incorrect security UI in Views. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514485825"><span>514485825</span></a><span>] </span><span>Low </span><span>CVE-2026-14145: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514550047"><span>514550047</span></a><span>] </span><span>Low </span><span>CVE-2026-14146: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514632767"><span>514632767</span></a><span>] </span><span>Low </span><span>CVE-2026-14147: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515426873"><span>515426873</span></a><span>] </span><span>Low </span><span>CVE-2026-14148: Type Confusion in CSS. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515427046"><span>515427046</span></a><span>] </span><span>Low </span><span>CVE-2026-14149: Use after free in Audio. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517376041"><span>517376041</span></a><span>] </span><span>Low </span><span>CVE-2026-14150: Insufficient validation of untrusted input in Speech. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517381770"><span>517381770</span></a><span>] </span><span>Low </span><span>CVE-2026-14151: Inappropriate implementation in AI. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517534944"><span>517534944</span></a><span>] </span><span>Low </span><span>CVE-2026-14152: Out of bounds write in ANGLE. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517684077"><span>517684077</span></a><span>] </span><span>Low </span><span>CVE-2026-14153: Inappropriate implementation in Glic. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517741170"><span>517741170</span></a><span>] </span><span>Low </span><span>CVE-2026-14154: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518246925"><span>518246925</span></a><span>] </span><span>Low </span><span>CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518247789"><span>518247789</span></a><span>] </span><span>Low </span><span>CVE-2026-14156: Policy bypass in StorageAccessAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span><br></span></div><div><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></div><p><span><br></span></p><p><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span><br></span></span></span></span></p><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google unveils Nano Banana 2 Lite aka Gemini 3.1 Flash-Lite for low cost, 4-second fast enterprise image generations]]></title>
<description><![CDATA[Google is upgrading its AI image generation capabilities today with the debut of Nano Banana 2 (NB2) Lite, an optimized model built for rapid execution and tight infrastructure budgets. Technically designated as Gemini 3.1 Flash-Lite Image on Google's application programming interface (API), NB2 ...]]></description>
<link>https://tsecurity.de/de/3636200/it-nachrichten/google-unveils-nano-banana-2-lite-aka-gemini-31-flash-lite-for-low-cost-4-second-fast-enterprise-image-generations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636200/it-nachrichten/google-unveils-nano-banana-2-lite-aka-gemini-31-flash-lite-for-low-cost-4-second-fast-enterprise-image-generations/</guid>
<pubDate>Tue, 30 Jun 2026 18:18:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google is upgrading its AI image generation capabilities today with the <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-omni-flash-nano-banana-2-lite/">debut</a> of <a href="https://x.com/googleaidevs/status/2071988366925521075">Nano Banana 2 (NB2) Lite</a>, an optimized model built for rapid execution and tight infrastructure budgets. </p><p>Technically designated as Gemini 3.1 Flash-Lite Image on Google's application programming interface (API), NB2 Lite is positioned as the fastest and most cost-effective option within Google's creative model family, capable of generating images in 4 seconds at a flat rate of $0.034 per 1,000 images. </p><p>It's available immediately to enterprise developers through Google AI Studio, the Gemini API, and the Gemini Enterprise Agent Platform (GEAP).</p><p>It's not quite as fast or customizable as startup <a href="https://venturebeat.com/ai/enterprise-grade-ai-image-generation-in-2-seconds-is-here-krea-2-raw-and-turbo-available-as-open-weights-under-custom-license">Krea's new, partially open licensed Krea 2 Turbo</a> (which allows for open modification and commercial usage by small enterprises), but the big selling point here is the low price and bundling with Google's larger Workplace and AI offerings. </p><p>This release lands alongside the public preview of Gemini Omni Flash, a multimodal conversational video generation and editing model. </p><p>However, while Omni Flash represents Google's long-term bet on agentic video manipulation, Nano Banana 2 Lite is the immediate infrastructure workhorse, tailored specifically for high-throughput commercial application, rapid programmatic prototyping, and automated asset generation workflows. </p><h3><b>The technology of speed</b></h3><p>At its core, Nano Banana 2 Lite is built directly upon the Gemini 3.1 Flash Lite architecture, engineered to solve the persistent tension between computational latency and operational overhead. </p><p>In high-velocity enterprise frameworks, traditional large-scale image models introduce significant friction due to multi-second processing delays and high per-token costs. Google's new lightweight model circumvents these bottlenecks by generating a standard 1k resolution image in under four seconds. </p><p>This represents a stark performance optimization over its legacy predecessor, Nano Banana (Gemini 2.5 Flash Image), achieved through targeted enhancements in core baseline capabilities. </p><p>According to internal documentation, the model features upgraded world knowledge for drafting rough data visualizations and contextual layouts, enhanced character consistency to preserve identity across continuous image streams, and localized typographic rendering capabilities. </p><p>The trade-offs inherent to this "Lite" designation are transparently outlined in Google’s technical data sheets. </p><p>Unlike the broader standard Nano Banana 2 (NB2) and Nano Banana Pro (NB Pro) lines, which support versatile multi-resolution scaling across 1k, 2k, and 4k outputs, Nano Banana 2 Lite restricts its resolution support exclusively to a 1k canvas. Yet, within this specialized operational boundary, the architectural tuning yields surprising competitive efficiencies. In standardized internal benchmarks, Nano Banana 2 Lite achieved a Text to Image arena Elo score of 1251. This score comfortably eclipses the legacy NB1 score of 1151 and remarkably edges out the bulkier, more expensive NB Pro, which sits at 1245 in the same text-to-image track. For specialized editing tasks, the model maintains a single-image editing Elo score of 1308 and a multiple-image editing score of 1294, providing a highly optimized sweet spot for real-time applications.</p><h2><b>A boost to rapid prototyping and marketing research</b></h2><p>From a product implementation perspective, Google is marketing Nano Banana 2 Lite not as an artistic engine, but as an invisible, high-throughput utility layer for automated workflows. T</p><p>he target demographic spans software engineers, programmatic ad platforms, and digital commerce applications where rapid iteration is crucial. </p><p>Think real-time A/B testing for thousands of targeted advertising variations or immediate layout adjustments on localized storefronts. Google highlights three specific production environments where the model excels. </p><p>First, its world knowledge allows systems to instantly draft accurate contextual scenes or location-specific mockups. </p><p>Second, its character consistency handles the rigorous demands of storyboarding tools and digital fashion try-ons, where keeping object fidelity static across sequential generations is historically difficult. </p><p>Finally, its text rendering improvements mean legible copy can be embedded directly into rapid ad generations, allowing teams to verify layout compatibility across various languages on the fly. </p><p>Developers should note, however, that while native image generation operates with lowest-latency profiles, conditional image editing tasks may experience marginally higher response times due to the secondary processing layers required to rewrite existing pixels. </p><h2><b>Licensing and acess</b></h2><p>The deployment mechanism of Nano Banana 2 Lite via proprietary APIs underscores an enterprise-first commercial licensing strategy. </p><p>Unlike open-weights models that developers can pull down to run locally under open-source frameworks like Apache 2.0 or modified OpenRAIL licenses, Google’s latest models remain tightly integrated into its managed cloud stack. </p><p>For enterprises, this eliminates the operational complexity of hosting hardware but binds usage strictly to Google’s metered pricing terms.Financially, this commercial strategy is highly aggressive. </p><p>At $0.034 per 1,000 images across both AI Studio and GEAP channels, the model undercuts the older, less capable NB1 model ($0.039) and slashes costs dramatically compared to standard NB2 ($0.067) and NB Pro ($0.134) tiers. Internal notes indicate that the model delivers roughly 60–70% of the general capability of NB2 and NB Pro while executing at significantly higher speeds and a fraction of the cost. </p><p>By lowering the fiscal barrier to high-frequency image generation, Google is making a direct play to lock enterprise developers into its commercial platform ecosystem.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Key Takeaways: Strengthening Public Safety Through Collective Defense]]></title>
<description><![CDATA[Here are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.]]></description>
<link>https://tsecurity.de/de/3636178/it-security-nachrichten/6-key-takeaways-strengthening-public-safety-through-collective-defense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636178/it-security-nachrichten/6-key-takeaways-strengthening-public-safety-through-collective-defense/</guid>
<pubDate>Tue, 30 Jun 2026 18:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Security Update Patches 30+ Vulnerabilities in iOS 26.5.2]]></title>
<description><![CDATA[The latest Apple Security Update brings fixes for more than 30 security vulnerabilities in iOS 26.5.2 and iPadOS 26.5.2, addressing flaws across the kernel, WebKit, WebRTC, libxslt, and IOGPUFamily. Released on June 29, Apple said the update includes security fixes that were previously introduced...]]></description>
<link>https://tsecurity.de/de/3634865/it-security-nachrichten/apple-security-update-patches-30-vulnerabilities-in-ios-2652/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634865/it-security-nachrichten/apple-security-update-patches-30-vulnerabilities-in-ios-2652/</guid>
<pubDate>Tue, 30 Jun 2026 09:53:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Apple Security Update" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Apple Security Update Patches 30+ Vulnerabilities in iOS 26.5.2 1"></p><div class="qMYqUG_convSearchResultHighlightRoot">
<div class="" data-turn-id-container="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-14" data-is-intersecting="true"><section class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn-id="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-14" data-turn-id-container="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-14" data-testid="conversation-turn-30" data-turn="assistant">
<div class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)">
<div class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content="">
<div class="flex max-w-full flex-col gap-4 grow">
<div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;]:mt-1" dir="auto" tabindex="0" data-message-author-role="assistant" data-message-id="e32e8865-0f23-42a7-b6d0-4c4a35a807ad" data-message-model-slug="gpt-5-5" data-turn-start-message="true">
<div class="flex w-full flex-col gap-1 empty:hidden">
<div class="markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling">
<p data-start="666" data-end="1125">The latest Apple Security Update brings fixes for more than 30 security <a href="https://thecyberexpress.com/?s=vulnerabilities" target="_blank" rel="noopener">vulnerabilities</a> in iOS 26.5.2 and iPadOS 26.5.2, addressing flaws across the kernel, WebKit, WebRTC, libxslt, and IOGPUFamily. Released on June 29, <a href="https://thecyberexpress.com/webkit-vulnerability-fixed-in-apple-update/" target="_blank" rel="noopener">Apple</a> said the update includes security fixes that were previously introduced in the iOS 26.6 and iPadOS 26.6 beta releases, strengthening protections for supported iPhone and iPad devices.</p>
<p data-start="1127" data-end="1417">The update is available for iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later).</p>

<h3 data-section-id="1a0l6c6" data-start="1419" data-end="1497"><strong><span role="text">Apple Security Update Addresses Kernel and System-Level Vulnerabilities</span></strong></h3>
<p data-start="1499" data-end="1742">Among the most significant Apple security fixes are several kernel <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28878">vulnerabilities</a> that could allow an application to trigger unexpected system termination, write to kernel memory, leak sensitive kernel state, or corrupt kernel memory.</p>
<p data-start="1744" data-end="1965">Apple <a href="https://support.apple.com/en-us/127594" target="_blank" rel="nofollow noopener">said</a> these issues were resolved through improved input sanitization and input validation. The patched vulnerabilities include CVE-2026-43724, CVE-2026-43722, and CVE-2026-39868.</p>
<p data-start="1967" data-end="2206">The update also resolves a flaw in IOGPUFamily (CVE-2026-43743) that could allow an application to cause an unexpected system termination. Apple addressed the issue through improved state handling.</p>

<h3 data-section-id="14loq5d" data-start="2208" data-end="2274"><strong><span role="text">Apple Security Update Delivers Extensive WebKit Protections</span></strong></h3>
<p data-start="2276" data-end="2412">A large portion of the update focuses on WebKit vulnerabilities, the browser engine that powers Safari and other <a href="https://thecyberexpress.com/new-apple-security-update/" target="_blank" rel="noopener">Apple applications</a>.</p>
<p data-start="2414" data-end="2681">According to Apple's advisory, the fixes address multiple security issues that could allow malicious web content to disclose sensitive user information, trigger unexpected crashes, corrupt memory, bypass browser restrictions, or enable cross-origin <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28880">data</a> exfiltration.</p>
<p data-start="2683" data-end="2914">The advisory also patches vulnerabilities that could allow malicious websites to process restricted web content outside the browser sandbox, disclose process memory, or leak sensitive information through permissions-related issues.</p>
<p data-start="2916" data-end="3099">Apple said the flaws were addressed through improved memory management, input validation, bounds checking, and stronger <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28881">security</a> origin tracking.</p>

<h3 data-section-id="1qo922l" data-start="3101" data-end="3162"><strong>Safari, WebRTC and Other Components Receive Security Fixes</strong></h3>
<p data-start="3164" data-end="3346">Beyond WebKit, the Apple Security Update includes fixes for vulnerabilities affecting <a href="https://thecyberexpress.com/safari-cybersecurity-best-practices-apples/" target="_blank" rel="noopener">Safari security</a>, WebRTC, libxslt, Web Extensions, WebKit Canvas, and WebKit Storage.</p>
<p data-start="3348" data-end="3367">According to Apple:</p>

<ul data-start="3369" data-end="3915">
 	<li data-section-id="1j06bn9" data-start="3369" data-end="3490">Two libxslt vulnerabilities could cause unexpected process crashes when processing maliciously crafted web content.</li>
 	<li data-section-id="1jsjmxm" data-start="3491" data-end="3597">A Web Extensions <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28879">vulnerability</a> could allow a malicious extension to trigger an unexpected process crash.</li>
 	<li data-section-id="lqi7at" data-start="3598" data-end="3698">A WebKit Storage vulnerability could enable a malicious website to silently hijack clipboard data.</li>
 	<li data-section-id="10t7ye7" data-start="3699" data-end="3915">Multiple WebRTC vulnerabilities could lead to Safari crashes or unexpected process termination after processing malicious web content.</li>
</ul>
<h3 data-section-id="6t6fw8" data-start="3917" data-end="3964"><strong>Apple Credits Researchers for Reporting CVEs</strong></h3>
<p data-start="3966" data-end="4358">Apple acknowledged dozens of security researchers and organizations that reported the patched <a href="https://thecyberexpress.com/cve-2026-20245-cisco-catalyst/" target="_blank" rel="noopener">CVE vulnerabilities</a>, including researchers from Positive Technologies, STAR Labs SG, DEVCORE Research Team, Talence Security, Calif.io, NVIDIA AI Red Team, Braze Security Team, <a href="https://thecyberexpress.com/lessons-from-autonomous-ai-cyberattack/" target="_blank" rel="noopener">Anthropic</a>, <a href="https://thecyberexpress.com/openai-daybreak-introduces-gpt-5-5/" target="_blank" rel="noopener">OpenAI Codex Security</a>, ThreatBook, and Baidu Security, among others.</p>
<p data-start="4360" data-end="4668">The company reiterated that it does not publicly disclose or discuss security issues until investigations have been completed and software updates have been released to customers. Apple also noted that its security advisories reference CVE identifiers whenever possible.</p>
<p data-start="4670" data-end="4962" data-is-last-node="" data-is-only-node="">The latest Apple Security Update delivers broad protections across core operating system components, reinforcing Apple's ongoing efforts to address security vulnerabilities affecting supported iPhone and iPad devices through regular software updates.</p>

</div>
</div>
</div>
</div>
</div>
</div>
</section></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Releases iOS and Android Companion Node Apps That Connect a Phone to a Self-Hosted AI Agent Gateway]]></title>
<description><![CDATA[OpenClaw's iOS and Android apps are companion nodes, not standalone chatbots. Each phone pairs to a self-hosted Gateway over WebSocket. This adds device hardware — camera, location, voice, and Canvas — to a local-first AI agent. Here is the architecture, the capabilities, and the trade-offs for b...]]></description>
<link>https://tsecurity.de/de/3634251/ai-nachrichten/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634251/ai-nachrichten/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/</guid>
<pubDate>Tue, 30 Jun 2026 01:48:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw's iOS and Android apps are companion nodes, not standalone chatbots. Each phone pairs to a self-hosted Gateway over WebSocket. This adds device hardware — camera, location, voice, and Canvas — to a local-first AI agent. Here is the architecture, the capabilities, and the trade-offs for builders.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/29/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/">OpenClaw Releases iOS and Android Companion Node Apps That Connect a Phone to a Self-Hosted AI Agent Gateway</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Educators and students can now share Gemini Canvas creations directly to Google Classroom]]></title>
<description><![CDATA[Educators and students of all ages can now seamlessly attach Gemini Canvas artifacts, like websites, quizzes, interactive games, infographics, and more, to Google Classroom assignments and posts. Right from Gemini Canvas, users can click on the “Share to to Classroom” button. This update allows u...]]></description>
<link>https://tsecurity.de/de/3633918/web-tipps/educators-and-students-can-now-share-gemini-canvas-creations-directly-to-google-classroom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633918/web-tipps/educators-and-students-can-now-share-gemini-canvas-creations-directly-to-google-classroom/</guid>
<pubDate>Mon, 29 Jun 2026 21:41:58 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Educators and students of all ages can now seamlessly attach Gemini Canvas artifacts, like websites, quizzes, interactive games, infographics, and more, to Google Classroom assignments and posts. Right from Gemini Canvas, users can click on the “Share to to Classroom” button. This update allows users to enrich their classroom communication and coursework by embedding interactive materials directly into their existing workflows.</p><p>By removing the friction of exporting or linking external files, this feature helps teachers diversify their lesson materials and enables students to share creative outputs more efficiently. The integration ensures that rich, interactive media is easily accessible to everyone in the class, supporting a more engaging and dynamic digital learning environment.</p><p><br></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKRMOyE9HCB_KsHRTFVCU1UN8Fz5K_UyEZHp9zbxzPmoNNUJ7NsWTnrc-96qMqt7L32JiDVKPyB-WXvYhQ_Kp9TYNQuIClbeWAQqhwomMdDkv7hcBW-_iwjb5aYSez4a4q8ARl24XM24K8omJ5_qsQXDvUhqdmolfWgCNbU1nzpm6MptmeBRNbsW74ucY/s1412/Educators%20and%20students%20can%20now%20share%20Gemini%20Canvas%20creations%20directly%20to%20Google%20Classroom.gif" imageanchor="1"><img border="0" data-original-height="861" data-original-width="1412" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKRMOyE9HCB_KsHRTFVCU1UN8Fz5K_UyEZHp9zbxzPmoNNUJ7NsWTnrc-96qMqt7L32JiDVKPyB-WXvYhQ_Kp9TYNQuIClbeWAQqhwomMdDkv7hcBW-_iwjb5aYSez4a4q8ARl24XM24K8omJ5_qsQXDvUhqdmolfWgCNbU1nzpm6MptmeBRNbsW74ucY/s16000/Educators%20and%20students%20can%20now%20share%20Gemini%20Canvas%20creations%20directly%20to%20Google%20Classroom.gif"></a></div><h3>Getting started</h3><p></p><ul><li><b>Admins:</b></li><ul><li>The ability to share Gemini Canvas artifacts will be ON by default and can be managed via a <a href="https://knowledge.workspace.google.com/admin/generative-ai/gemini-app/turn-conversation-sharing-on-or-off" target="_blank">new Admin console setting</a>. Additionally, sharing is governed by your organization’s existing Drive sharing policies. If Drive content is set to be shareable outside the organization, your Gemini assets will be as well. Visit the Help Center to <a href="https://knowledge.workspace.google.com/admin/gemini/turn-conversation-sharing-on-or-off" target="_blank">learn more</a>.</li><li>To share Gemini Canvas artifacts to Google Classroom, students and educators must also be in a group or OU with <a href="https://support.google.com/a/answer/14571493" target="_blank">Gemini</a> set to On. Visit the Help Center to learn more about <a href="https://knowledge.workspace.google.com/admin/gemini/turn-the-gemini-app-on-or-off" target="_blank">turning Gemini on or off for users</a>.</li></ul><li><b>End users:</b> There is no end user setting for this feature. If enabled by your admin, you can share your Gemini canvases and media to Classroom, select Share &gt; Share to Classroom &gt; select the class and/or assignment you want to share it with. Visit the Help Center to <a href="https://support.google.com/gemini/?hl=en#topic=15280100" target="_blank">learn more about Gemini</a>.</li></ul><p></p><h3>Rollout pace</h3><p></p><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains:</a> Available now</li></ul><p></p><h3>Availability</h3><p></p><ul><li><b>Education: </b>Education Fundamentals, Standard, and Plus</li></ul><p></p><h3>Resources</h3><p></p><ul><li>Google Workspace Updates Blog: <a href="https://workspaceupdates.googleblog.com/2026/04/share-chats-canvases-and-generated-media-from-the-Gemini-app-securely-via-Google-Drive.html" target="_blank">Share chats, canvases, and generated media from the Gemini app securely via Google Drive</a></li><li>Google Workspace Admin Help: <a href="https://knowledge.workspace.google.com/admin/gemini/turn-conversation-sharing-on-or-off" target="_blank">Turn conversation sharing on or off</a></li><li>Google Workspace Admin Help: <a href="https://knowledge.workspace.google.com/admin/gemini/turn-the-gemini-app-on-or-off" target="_blank">Turn the Gemini app on or off</a></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem]]></title>
<description><![CDATA[Written by: James Sadowski, Alden Wahlstrom

Introduction
Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we hav...]]></description>
<link>https://tsecurity.de/de/3633127/it-security-nachrichten/the-bear-necessities-a-look-at-the-drivers-dynamics-and-applications-of-the-pro-russia-influence-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633127/it-security-nachrichten/the-bear-necessities-a-look-at-the-drivers-dynamics-and-applications-of-the-pro-russia-influence-ecosystem/</guid>
<pubDate>Mon, 29 Jun 2026 16:07:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: James Sadowski, Alden Wahlstrom</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span></h3>
<p><span>Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/global-revival-of-hacktivism"><span>revitalization</span></a><span> of pro-Russia hacktivism at an unprecedented scale. While this threat activity initially adapted to encompass Ukraine-related priorities, it is gradually pivoting back to established Russian influence objectives for which the ecosystem was originally honed. This shift is significant because it likely signals increased focus outside of Ukraine, warning that pro-Russia influence activity targeting the European Union (EU), North Atlantic Treaty Organization (NATO), and other top targeting priorities may intensify. </span></p>
<p><span>Ultimately, the war in Ukraine has provided a critical feedback loop for Russia to refine its influence activity, lessons that we anticipate will be applied as the ecosystem continues to reorient toward global strategic objectives while maintaining focus on Ukraine. Further, recent pro-Russia IO indicates the continued expansion of already diverse tactics, and the increasing use of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"><span>generative AI tooling</span></a><span> for planning, research, and content creation marks a forward trend in pro-Russia IO. Meanwhile, new and different actors have adopted IO tactics to meet an increasingly diverse set of challenges, signaling growing Russian reliance on influence tactics. Together, these trends likely demonstrate the Kremlin's perception of these tactics as cost effective and successful. The interconnected nature of the ecosystem's disparate components makes it resilient to limited scope disruptions, which defenders must consider to effectively mitigate pro-Russia influence threats. </span></p>
<h3><span>The Ecosystem at a Glance: Objectives, Targeting, and Tactics</span></h3>
<p><span>Russia's modern approach to information operations is built on the conceptual foundation of Soviet-era "</span><a href="https://www.marshallcenter.org/en/publications/security-insights/active-measures-russias-covert-geopolitical-operations-0" rel="noopener" target="_blank"><span>active measures</span></a><span>" adapted for the digital age. Alongside disruptive cyberattacks dating back to the early 2000s, the Kremlin has increasingly harnessed internet-based platforms for espionage and information operations. Russia's approach has evolved from rudimentary, singular operations into a complex, self-sustaining environment intentionally curated by the Russian Government that blends overt, covert, and independent elements to advance Kremlin interests both at home and abroad.</span></p>
<h4><span>Core Influence Objectives </span></h4>
<p><span>GTIG’s observations suggest the primary strategic motivations driving the pro-Russia influence ecosystem fall into five categories, each aiming to achieve military and/or political objectives through psychological manipulation of the target audience (Figure 1). Collectively, these objectives informally depict a global influence strategy: through the furthest reach of its influence, the Kremlin seeks to diminish Western primacy and advance Russia's global position; within its surrounding region, it strives to retain and return Moscow's dominance; and at home, it works to ensure the stability of the political regime.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig1.max-1000x1000.png" alt="Core objectives of the pro-Russia influence ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="sfic5">Figure 1: Core objectives of the pro-Russia influence ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Targeting</span><span> </span></h5>
<p><span>Pro-Russia influence operations are pivoting from the </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>near singular focus on Ukraine</span></a><span> that dominated the ecosystem since 2022. We expect influence operations advancing Russia's war-specific interests to continue. However, as Russia seeks to reemerge from international isolation, we have increasingly observed a concurrent focus on pre-war pro-Russia influence objectives. </span></p>
<p><span>The current and historical targeting scope of each ecosystem component exposes both the Kremlin's global ambitions and the realistic limitations of its power projection. State-owned media organizations produce content intended to serve populations across six continents, but in recent years, sanctions and other factors have limited its production and distribution. Meanwhile, covert operations have appeared more limited in scope, primarily targeting the West and countries surrounding Russia, with intermittent operations targeting the Middle East and Africa, indicating that finite resources necessarily limit these operations (Figure 2).</span></p>
<h5><span>Top Regional Targets</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>The United States and Europe:</strong><span> The Kremlin has long viewed the West as a top adversary of Russia. Accordingly, the US and Europe are top targets of covert pro-Russia information operations, especially aimed at undermining political stability within these countries and the unity between them. </span><span>NATO and the EU embody the collective "West" and are Russia's perceived top adversaries</span><span>, second only to the US independently.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Russia's "Near Abroad":</strong><span> Since the dissolution of the Soviet Union, Moscow has asserted that the countries that formerly comprised part of the USSR now reside in Russia's so-called "sphere of influence." Covert influence targeting this region directly reflects Moscow's assertion that Russia is a world power entitled to special privileges within its neighborhood. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>The Middle East and Africa:</strong><span> Over the past decade, Russian efforts to reassert itself as a global power have included high-profile investments in cultivating Russia's standing in the Middle East and </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/io-campaigns-russian-prigozhin-persist"><span>Africa</span></a><span>. Covert pro-Russia influence activity is likely deployed in tandem as intended support for other Russian initiatives in these regions.  </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Russia Domestic:</strong><span> Internally targeted covert IO is a well-established component of pro-Russia influence activity, deployed by regime-aligned actors to promote Kremlin policies and repress opposition voices. </span></p>
</li>
</ul>
<h5><span>Targeted Entities and Global Events</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>The Olympics:</strong><span> Russia has long viewed Olympic participation as a point of national prestige, and GTIG has observed notable Russian influence activity targeting the </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-threats-2024-paris-olympics"><span>Olympics</span></a><span> in the face of Russian participation bans. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>War in Ukraine:</strong><span> The </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>war in Ukraine</span></a><span> has been a key driver of Russia's influence activity, including attempts to influence events on the ground as well as influence activity intended to advance Moscow's interests elsewhere vis-a-vis the war. GTIG expects that Ukraine will remain a priority in Russia's targeting calculus during the post-conflict phase following any future peace agreements.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Elections:</strong><span> Election targeting aligns with multiple Russian influence objectives, including attempting to undermine confidence in democratic institutions as well as internally weakening perceived Western adversaries. These operations regularly target elections in countries that are already prioritized by ongoing pro-Russia influence activity. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ad Hoc Geopolitical Flashpoints and Global Events:</strong><span> Russian influence actors have a history of pivoting activity to engage with emerging geopolitical developments and events, such as the </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/limited-shifts-cyber-threat-landscape-driven-covid-19?e=48754805"><span>COVID-19 </span></a><span>pandemic or the</span><a href="https://apnews.com/article/iran-war-images-misinformation-russia-israel-9e495017dc5c4bf24a0b6152863dbfb1" rel="noopener" target="_blank"><span> 2026 Middle East </span></a><span>conflict. This flexible target selection often overlaps or is aligned with other Russian priorities, making previously observed Russian influence activity helpful in anticipating which events may be appropriated.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig2.max-1000x1000.png" alt="Priority targets of the ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7460p">Figure 2: Priority targets of the ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Tactics</span><span> </span></h5>
<p><span>Converging geopolitical and technological developments make the evolution of pro-Russia influence tactics a particularly important space to monitor right now. The pro-Russia influence ecosystem expanded to support the war effort, bringing change across the spectrum of activity and providing operators the opportunity to hone their tactics, techniques, and procedures (TTPs) in the rapid feedback loop of war. Meanwhile, the emergence and increased democratization of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use"><span>generative AI</span></a><span> tooling has brought both promised and already realized opportunities to support all phases of the IO lifecycle. The following are a sample of key tactics that illustrate how pro-Russia actors currently blend well-tested methods with new technological developments to reach audiences through diverse means:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Generative AI: </strong><span>GTIG </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai"><span>has observed</span></a><span> pro-Russia influence actors increasingly leverage AI tooling to support different stages of their operations, including support for planning and general research as well as content creation.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Google Threat Intelligence Group (GTIG) is closely tracking the transition from nascent AI-enabled operations to the maturing, industrial-scale application of generative models within adversarial workflows across threats ranging from espionage and crime to IO. Please see our latest </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access"><span>AI threat tracker</span></a><span> for more information on how this threat is developing based on our insights, and what Google is doing to protect our customers. </span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Narrative Resonance:</strong><span> Hijacking existing ideological and emotional fissures within a society provides pro-Russia influence actors tailored narratives to target audiences and potentially increases potential engagement and impact. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cyber-Enabled IO:</strong><span> Influence campaigns frequently coincide with destructive cyberattacks, such as the deployment of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook?e=48754805"><span>wiper malware</span></a><span> alongside website defacements containing false surrender messages, or the historic use of "hack and leak" campaigns in which exfiltrated data, sometimes manipulated, is then publicized through an actor-controlled false persona. In some instances, Russian actors may even leverage direct cyber espionage targeting as a way to achieve psychological effects, intending to influence victims' behavior through intimidation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Media Mimicry:</strong><span> Pro-Russia actors have attempted to mimic legitimate media at scale and through a variety of means, including via the wholesale appropriation of legitimate media brands or developing inauthentic media brands that generally masquerade as independent news sources. These tactics are intended to add a veneer of legitimacy to the promoted narratives. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Direct Dissemination: </strong><span>Pro-Russia influence actors have used closed communication channels, such as emails, SMS text messages, and messenger apps, to disseminate various types of pro-Russia narratives as an adjunct to or outside typical social media-focused operations. </span></p>
</li>
</ul>
<h4><span>Core Ecosystem Components </span></h4>
<p><span>The current pro-Russia influence ecosystem operates across a spectrum from official government communications to deniable covert actions conducted by intelligence services and "patriotic" proxies. GTIG identified six core components that represent key activity types (Figure 3). While many elements are state-directed or state-affiliated, the ecosystem is also a cultivated, self-sustaining system: various actors, often without explicit direction, amplify Kremlin-friendly narratives and pursue actions that advance Russia's strategic interests. This fluidity provides resilience and complicates attribution, mirroring the longstanding Kremlin strategy to co-opt non-state actors, including criminal networks for </span><a href="https://www.rusi.org/explore-our-research/publications/commentary/operation-destabilise-russia-organised-crime-and-illicit-finance" rel="noopener" target="_blank"><span>finance</span></a><span> or </span><a href="https://www.bbc.com/news/articles/cz91dk0l50no" rel="noopener" target="_blank"><span>illicit logistics</span></a><span>, to achieve state objectives without direct attribution. Although each of the core ecosystem components serves as a unique lever the Russian Government can employ to achieve desired objectives, they are regularly used together. For instance, while the entire pro-Russia hacktivist landscape is not state-sponsored, the Russian intelligence services have used both genuine and fabricated hacktivist personas to launder stolen data as part of blended cyber espionage and IO hybrid operations.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig3.max-1000x1000.png" alt="Core components of the pro-Russia influence ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7460p">Figure 3: Core components of the pro-Russia influence ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>An Interconnected Ecosystem Enhances Influence Utility</span></h5>
<p><span>Figure 4 illustrates the complex, interconnected nature of the pro-Russia influence ecosystem by mapping relationships between a selection of key actors and organizations across five of the core components. The ecosystem functions as a cohesive unit, not only through shared objectives, but also through direct cross-component interactions. The Russian Government functions as the sixth core ecosystem component, setting the policy and talking points that inform the ecosystem’s promoted narratives and sponsoring overt and covert assets throughout the other five components diagrammed in Figure 4. Through these levers, the Kremlin fosters the cross-component links that underpin the ecosystem, enhancing its overall utility as a versatile tool of state influence.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig4.max-1000x1000.png" alt="Subset of actors that illustrate how different components of the ecosystem interact with each other">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="df0ri">Figure 4: Subset of actors that illustrate how different components of the ecosystem interact with each other</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>10 Key Dynamics for Understanding the Pro-Russia Influence Ecosystem</span></h4>
<p><span>The scope and diversity of activity in the pro-Russia influence ecosystem challenges defenders tasked with enumerating, tracking, and countering its threats. GTIG has distilled 10 key ecosystem dynamics based on our current understanding of its components and how they each enable covert influence activity. These dynamics frame critical aspects of how activity manifests within the ecosystem, providing a high-level guide to understand and track these threats.</span></p>
<p><strong>Large-scale IO campaigns are an integral element of the pro-Russia influence ecosystem. </strong><span>Major pro-Russia IO campaigns have been an enduring feature of the pro-Russia ecosystem, with new campaigns emerging as previous ones fall into inactivity. Maintaining extensive IO campaigns and their associated established influence infrastructure enables proactive </span><a href="https://home.treasury.gov/news/press-releases/jy0628" rel="noopener" target="_blank"><span>messaging</span></a><span> on strategic issues and underpins a capability that can be rapidly adapted for emerging domestic and global priorities.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Long-established IO campaigns, like Secondary Infektion, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>pivoted to meet</span></a><span> new strategic needs as Russia’s 2022 invasion of Ukraine began. New IO campaigns, such as “Operation Overload,” subsequently emerged to support the war effort; while Secondary Infektion has become dormant, these “successor” campaigns have since been leveraged to advance other global Russian influence objectives beyond the war itself. </span></p>
</li>
</ul>
<p><strong>Pro-Russia actors often prioritize persistence </strong><span>and the range of tactics they leverage reflects this. In the face of public exposure and disruption, pro-Russia actors and their infrastructure have often remained persistent, sometimes making tactical adjustments to mitigate the effects of detection and disruption and other times continuing operations unabated. </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>These persistence tactics include the Doppelganger campaign and overt </span><a href="https://www.bloomberg.com/news/articles/2023-11-23/ukraine-war-how-kremlin-propaganda-websites-dodge-disinformation-sanctions#xj4y7vzkg" rel="noopener" target="_blank"><span>Russian media</span></a><span>’s respective cycling of domain infrastructure and/or use of mirror domains to overcome exposure, platform bans and sanctions. Influence operators also frequently continue using compromised assets, sometimes mocking their exposure, as seen with the legacy US-targeted NAEBC campaign and the APT44-affiliated hacktivist persona XakNet Team.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig5.max-1000x1000.png" alt="NAEBC-linked persona account">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="df0ri">Figure 5: NAEBC-linked persona account mocking public exposure of influence assets (left), and GRU-sponsored XakNet Team persona mocking then-Mandiant (now part of Google Threat Intelligence Group) attribution of the group’s activities to the GRU (right)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Pro-Russia and Russian cyber espionage groups leverage IO tactics to support their operations and weaponize stolen data and/or illicit access</strong><span>. While less frequent, this </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/russian-espionage-influence-ukrainian-military-recruits-anti-mobilization-narratives"><span>hybrid activity</span></a><span> is a critical dynamic within the pro-Russia influence ecosystem. GTIG has previously observed operations used to shape narratives around </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook"><span>cyberattacks</span></a><span> and influence events on the ground and to conduct foreign political interference, including the repeated targeting of </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-threats-global-elections"><span>foreign elections</span></a><span>, reported in Spring 2024. We have attributed some observed instances of this to Russian government-sponsored threat actors.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Russian state sponsored or pro-Russia hacktivist groups have long relied on public advertisement of real or claimed data exfiltration to highlight their operations, intimidate targets, or sway public opinion. In 2022, UNC4057 (COLDRIVER) used data stolen from espionage targets in a high profile hack-and-leak operation seeking to exacerbate divisions in UK politics. More recently, the self-proclaimed hacktivist group </span><a href="https://cert.gov.ua/article/6287707" rel="noopener" target="_blank"><span>PalachPro</span></a><span> claimed in February 2026 to have gained unauthorized access to a Ukrainian government online portal and publicly posted </span><a href="https://caspianpost.com/regions/russian-hackers-target-ukraine-s-starlink-authorisation-service" rel="noopener" target="_blank"><span>screenshots</span></a><span> of the claimed compromise. The Ukrainian government has previously noted that the portal does not store the type of data the threat actor claimed to compromise, suggesting the public posting was likely intended as influence activity, attempting to create the illusion of a more serious threat.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig6.max-1000x1000.png" alt="UNC4057 leak website attempting to inflame public debate">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="df0ri">Figure 6: UNC4057 leak website attempting to inflame public debate</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Pro-Russia hacktivists serve a direct influence function. </strong><span>Modern pro-Russia hacktivism has evolved into an important component of the influence </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/global-revival-of-hacktivism"><span>ecosystem</span></a><span> that blends </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm"><span>state-backed actors</span></a><span> leveraging </span><a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal" rel="noopener" target="_blank"><span>hacktivist tactics</span></a><span> with an evolving cohort of likely third-party hacktivist actors that support Russia's geopolitical interests. Pro-Russia hacktivist groups gain domestic and foreign attention for strategic messaging via their </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/killnet-new-capabilities-older-tactics"><span>claimed threat activity</span></a><span>, amplify narratives directly seeded in overt ecosystem segments, and at times also support traditional IO activity or create a means of plausible deniability for state-sponsored espionage actors. </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The self-proclaimed hacktivist group NoName057(16) emerged following the Russian invasion of Ukraine in 2022, primarily targeting Ukraine and its partners and allies with DDoS attacks and various network intrusions. It has targeted high profile events, such as the Milano Cortina Winter Olympics, institutions like the French National Assembly, and critical infrastructure and transportation targets in Germany. Often their messaging cites grievances with overt acts of Western support for Kyiv, suggesting the group advances Russian interests not only through the targeting of perceived Russian adversaries but also in gaining attention for its pro-Russia messaging. </span></p>
</li>
</ul>
<p><strong>Established ecosystem components facilitate the cultivation of new assets and activity. </strong><span>Inter-ecosystem cross-promotion helps overcome challenges of audience building by directing traffic toward </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-2022-midterm-elections/"><span>new assets</span></a><span>, operations, and narratives, enabling rapid deployment of new and existing IO capabilities. This directly supports a self-sustaining cycle that maintains and expands the ecosystem. </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The hacktivist persona JokerDNR played a significant role in amplifying the APT44-linked persona Solntsepek when its doxxing-focused Telegram channel first launched and then again as it began claiming cyber espionage activity. </span></p>
</li>
</ul>
<p><strong>Domestic Russian audiences are a longstanding target of the pro-Russia influence ecosystem. </strong><span>Internally directed </span><a href="https://blog.google/threat-analysis-group/prigozhin-interests-and-russian-information-operations/" rel="noopener" target="_blank"><span>influence activity</span></a><span> has often involved the promotion of Kremlin policies and talking points and the denigration of opposition voices and ideas, conducted by both overt and covert segments of the ecosystem.</span><strong> </strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Ahead of Russia’s March 2024 presidential election, GTIG identified the hybrid espionage and influence actor UNC5101 register domains and conduct associated influence operations attempting to deceive Russian opposition voters about the timing of an anti-Putin protest.</span></p>
</li>
</ul>
<p><strong>Ecosystem actors respond to the same set of internal shifting circumstances and external geopolitical developments</strong><span>, often leading to seemingly similar, but ultimately distinct, activity. </span><span>These shared drivers and general motivational alignments encourage actors to "spontaneously" coalesce around a particular topic or narrative. While this can appear superficially similar, this phenomenon is distinct from instances of actor coordination and campaign linkages, which is less common. </span></p>
<p><strong>Systemic flexibility is a central feature, </strong><span>with influence assets able to mobilize both incrementally and at scale to advance Russian interests. The Russian Government is able to </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/information-operations-surrounding-ukraine"><span>mobilize assets</span></a><span> across the ecosystem to respond to strategic events. Meanwhile, individual or aligned actors can separately mobilize to address </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-information-operations-drone-incursions"><span>tactical needs</span></a><span>, allowing the ecosystem to concurrently message on multiple issues across different geographies (Figure 7). </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Russia demonstrated its ability to focus the ecosystem on a single strategic issue like the Russian invasion of Ukraine. Simultaneously, discrete assets have addressed tactical events, such as when Portal Kombat briefly </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-information-operations-drone-incursions"><span>promoted</span></a><span> narratives about a Russian drone incursion into Poland concurrently with other covert pro-Russia influence activity.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig7.max-1000x1000.png" alt="Tactical responses are executed by individual or coordinated/aligned clusters of actors to address emerging developments">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="pcu6e">Figure 7: Tactical responses are executed by individual or coordinated/aligned clusters of actors to address emerging developments</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Overt Russian media contributes to, and is connected with, multiple covert influence components. </strong><span>The overt components of Russia's influence infrastructure play a critical role within the broader Russian influence ecosystem beyond the commonly understood function of providing a public platform for government-aligned narratives and official talking points; overt media helps to drive (inform targeting) and amplify covert pro-Russia influence activity, seeding desirable narratives within the ecosystem and providing an indirect conduit between the Kremlin and a disparate array of influence actors. Overt media outlets have directly </span><a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"><span>coordinated</span></a><span> their activity with covert actors and have increasingly employed IO tactics to disseminate their own content in the face of sanctions and platform bans (Figure 8). </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>US Government </span><a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"><span>sanctions</span></a><span> in late 2024 indicated that Russian state media company Russia Today (RT) directly conducted covert influence operations, including on behalf of the Russian intelligence services. Further, RT employees reportedly interacted with members of the self-proclaimed hacktivist group RaHDit, which has claimed to collaborate with multiple other pro-Russia hacktivist groups, illustrating the layered connections between overt media, Russian intelligence services, and hacktivist groups.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig8.max-1000x1000.png" alt="Overt Russian media maintains multiple links with the covert segments of the ecosystem">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="pcu6e">Figure 8: Overt Russian media maintains multiple links with the covert segments of the ecosystem</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><strong>Outsourcing IO capability development and campaign execution to third-party organizations and proxies enables scaling and obfuscation. </strong><span>Outsourcing is used for developing </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-operations-russian-vulkan"><span>custom tooling</span></a><span> and bolstering both human and </span><a href="https://home.treasury.gov/news/press-releases/jy2559" rel="noopener" target="_blank"><span>organizational</span></a><span> </span><a href="https://home.treasury.gov/news/press-releases/jy2195" rel="noopener" target="_blank"><span>capacity</span></a><span>. While </span><a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal" rel="noopener" target="_blank"><span>custom tool</span></a><span> development facilitates operators in all phases of the IO lifecycle, Russian government actors can flexibly leverage different models for outsourcing campaign execution based on their specific needs. Proxy actors can also generate plausible deniability (Figure 9). </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>GTIG </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/cyber-operations-russian-vulkan"><span>reported</span></a><span> how Russian IT contractor NTC Vulkan (Russian: НТЦ Вулкан) worked with the Russian intelligence services, including providing tooling and support for the GRU unit that sponsors APT44 activity. Separately, US government </span><a href="https://home.treasury.gov/news/press-releases/jy2195" rel="noopener" target="_blank"><span>sanctions</span></a><span> detailed how the Doppelganger campaign is supported by multiple Russian contractors under the sponsorship of the Russian Presidential Administration.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/russia-io-fig9.max-1000x1000.png" alt="Outsourcing and proxies support capability development and campaign execution for covert influence activity">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6mos1">Figure 9: Outsourcing and proxies support capability development and campaign execution for covert influence activity</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Multiple factors are propelling the evolution of the pro-Russia influence ecosystem we have observed since Moscow’s full scale invasion of Ukraine four years ago. The Kremlin mobilized the entire ecosystem to support the ongoing conflict, which has provided rapid feedback and driven significant investment in new and established overt and covert influence assets. At the same time, pro-Russia actors are increasingly experimenting with generative AI to enhance their workflows. This condensed period of adaptation, alongside signals suggesting Russia's growing reliance on IO tactics to navigate new challenges, raises concerns regarding how a potentially diversifying pool of actors will leverage advancements in tradecraft and scalability. As Russia seeks to emerge from international isolation and reorients its influence ecosystem back toward global objectives, it is critical for defenders to understand how this ecosystem provides the Kremlin with a durable influence capability in order to better anticipate future Russian influence threats.</span></p>
<h3><span>Additional Tools and Resources</span></h3>
<p><span>For mitigation and hardening recommendations, please review the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span><a href="https://cloud.google.com/blog/topics/threat-intelligence/understand-action-intelligence-information-operations">How to Understand and Action Mandiant's Intelligence on Information Operations</a></span></p>
</li>
<li aria-level="1">
<p role="presentation"><span><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks">Proactive Preparation and Hardening to Protect Against Destructive Attacks</a></span></p>
</li>
<li aria-level="1">
<p role="presentation"><span><a href="https://services.google.com/fh/files/misc/linux-endpoint-hardening-wp-en.pdf" rel="noopener" target="_blank">Linux Endpoint Hardening to Protect Against Malware and Destructive Attacks</a></span></p>
</li>
<li aria-level="1">
<p role="presentation"><span><a href="https://services.google.com/fh/files/misc/ddos-protection-recommendations-wp-en.pdf" rel="noopener" target="_blank">Distributed Denial of Service (DDoS) Protection Recommendations</a></span></p>
</li>
</ul>
<p><span>Google offers a suite of free of cost tools to help protect high-risk users from the most pervasive digital attacks, to which politicians, journalists, and campaigns are often most vulnerable. Examples include protecting accounts from targeted attacks with </span><a href="https://landing.google.com/advancedprotection/" rel="noopener" target="_blank"><span>Advanced Protection Program</span></a><span> and safeguarding campaign websites from DDoS attacks with </span><a href="https://projectshield.withgoogle.com/landing" rel="noopener" target="_blank"><span>Project Shield</span></a><span>.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When software developers and AI agents share the learning]]></title>
<description><![CDATA[Before Tobi Lütke ran Shopify, he learned programming through Germany’s apprenticeship system⁠, the way people have learned trades forever: in a shared workshop, watching people who already knew what they were doing. More recently, describing Shopify’s River, he reached for a related word: Lehrwe...]]></description>
<link>https://tsecurity.de/de/3632384/ai-nachrichten/when-software-developers-and-ai-agents-share-the-learning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632384/ai-nachrichten/when-software-developers-and-ai-agents-share-the-learning/</guid>
<pubDate>Mon, 29 Jun 2026 11:04:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Before Tobi Lütke ran Shopify, he <a href="https://tobi.lutke.com/blogs/news/11280301-the-apprentice-programmer">learned programming</a> through Germany’s apprenticeship system⁠, the way people have learned trades forever: in a shared workshop, watching people who already knew what they were doing. More recently, <a href="https://x.com/tobi/status/2053121182044451016">describing Shopify’s River</a>, he reached for a related word: <em>Lehrwerkstatt</em>⁠, a teaching workshop where “the whole shop floor is the classroom.”</p>



<p>X has been agog by the numbers around <a href="https://shopify.engineering/under-the-river">River</a>⁠, Shopify’s Slack-native <a href="https://www.infoworld.com/article/3611465/how-ai-agents-will-transform-the-future-of-work.html">AI agent</a>. In total, 5,938 Shopify employees worked with River across 4,450 different Slack channels, and River now coauthors roughly one in eight merged pull requests across the company. It’s a big deal, but understanding <em>why</em> it works that way is the most important part.</p>



<p>River can read code, run tests, open pull requests, query the data warehouse, inspect production traces, and sometimes push back on a plan it thinks is bad. Great. Lots of companies will have clever coding agents someday soon. Some already do.</p>



<p>The interesting part is that River doesn’t work alone; it works where everyone can see it.</p>



<h2 class="wp-block-heading"><a></a>Betting on the workshop</h2>



<p>I’ve already <a href="https://www.infoworld.com/article/4142019/coding-for-agents.html">argued that agents reward explicit, consistent, well-documented software</a>. They like the “boring” stuff, such as schemas, tests, conventions, clean setup instructions, and codebases that don’t require a deep retrospective with the one engineer who remembers why the build script has to run twice. Dropping an agent into a messy repo is mostly an efficient audit of your engineering discipline. Agents hold up a mirror to our engineering practices.</p>



<p>This is where Shopify comes off looking good. Without all the engineering pre-work, River wouldn’t be a success. In early 2024⁠, the company says it had many repositories, bespoke development environments, and slow feedback loops. It then made two unpopular but critically important choices: moved to a monorepo called World and built dev environments, continuous integration, and production images on <a href="https://shopify.engineering/what-is-nix" data-type="link" data-id="https://shopify.engineering/what-is-nix">Nix</a> as one reproducible substrate.</p>



<p>Shopify recognized that “code is going to be increasingly written with AI, and our infrastructure needs to be the substrate for that.” But the company did more than insist on legible code: It started to create shared memory of that code across the company.</p>



<h2 class="wp-block-heading"><a></a>Collective coding</h2>



<p>River has one design constraint that every enterprise architect should pay attention to: It only works in public Slack channels. No direct messages. No private groups. You summon River where other people can watch, join, search, and learn. That sounds like a small product choice, but it’s not. It’s the operating model, kind of like open sourcing code development within Slack.</p>



<p>Because of this design constraint, every River session becomes a visible transcript. Shopify can then mine those transcripts, see recurring patterns, and feed them back into River’s skills, prompts, and defaults. One engineer’s hard-won fix at two o’clock becomes the next engineer’s starting point at four o’clock. The model doesn’t need to be retrained for the company to get smarter, and developers don’t need to go out of their way to document things. The work just has to leave a trace.</p>



<p>That’s the <em>Lehrwerkstatt</em>, productized. Everyone gets to watch the agent work.</p>



<p>Now compare that with how most enterprises are deploying AI. One developer works with a private chatbot in a private IDE in a private window that no one else will ever see. Multiply that by a few thousand. Each person discovers a clever way to investigate a flaky test, explain a troublesome service boundary, or avoid a migration trap. Then the session closes, and the discovery dies. Sure, the developer may go faster, but the company is no better off than it was yesterday.</p>



<h2 class="wp-block-heading"><a></a>The transcript is the artifact</h2>



<p>One mistake enterprises have made with knowledge management is treating documentation as something people write <em>after</em> the work. This rarely works. Few employees (developers or otherwise) want to undertake the tedium of documenting what they already did. Not unless someone is paying them to do it.</p>



<p>River suggests a better pattern: The work itself creates the documentation.</p>



<p>Not every transcript is useful, of course. Most probably aren’t. But the useful ones can become skills, defaults, examples, runbooks, repo instructions, or links that help the next person avoid starting from zero. Shopify says River sessions are searchable and reproducible, and the company feeds patterns from those sessions back into River’s skills, prompts, and defaults. That’s not a chatbot; it’s a learning loop.</p>



<p>This is where the usual “AI will make developers more productive” framing feels too small. The more interesting claim is that AI can make software organizations more teachable. However, this won’t happen by default. The shop floor needs to be institutionalized or the enterprise will remain an atomized collection of productivity silos.</p>



<h2 class="wp-block-heading">A magic memory file</h2>



<p>This is where <code><a href="https://agents.md/">agents.md</a>⁠</code> is useful, but only if properly used. <code>agents.md</code> describes itself as a README for agents and says it’s now used by more than 60,000 open source projects. How should a developer use it? GitHub, based on<a href="https://github.blog/ai-and-ml/github-copilot/how-to-write-a-great-agents-md-lessons-from-over-2500-repositories/"> analysis of more than 2,500 repositories</a>⁠, gives some clear guidance: Put commands early, be specific, provide real examples, and set explicit boundaries.</p>



<p>In other words, write down what matters.</p>



<p>But don’t mistake the file for the capability. ETH Zurich researchers recently<a href="https://arxiv.org/abs/2602.11988"> </a><a href="https://arxiv.org/abs/2602.11988">tested whether repository-level context files actually help coding agents</a>⁠ and found that they often reduce task success while increasing inference cost by more than 20%. InfoQ <a href="https://www.infoq.com/news/2026/03/agents-context-file-value-review/">summarized⁠</a> their finding this way: LLM-generated context files often hurt, and human-written ones should focus on non-inferable details, such as custom tools, unusual build commands, and highly specific project constraints.</p>



<p>That’s the enterprise opportunity.</p>



<p>Public GitHub projects often don’t have much non-inferable domain knowledge to encode, but enterprise software is filled with it: odd quirks such as why the pricing service can’t be called during checkout in a certain region, or which legacy API looks dead but still supports a major customer, or why the data model says one thing but revenue recognition says another. Etc., etc.</p>



<p>That’s the context worth preserving, rather than directory maps an agent can discover or generic coding preferences. That’s what the shop-floor version of <code>agents.md</code> looks like: Not a static file that someone auto-generates and forgets, but rather the residue of observed work. Agents struggle, humans correct, patterns emerge, and only the durable lessons become instructions.</p>



<h2 class="wp-block-heading"><a></a>You’re not Shopify</h2>



<p>If all this sounds great (and it should), then it’s worth a word of warning: You probably won’t be able to copy Shopify, any more than you could have (or should have) <a href="https://www.infoworld.com/article/2260708/no-you-dont-have-to-run-like-google.html">copied Google</a>. You’re not Shopify. Most companies shouldn’t wake up Monday and announce a monorepo migration, a Nix conversion, and a Slack-only agent because River sounds cool. That approach has worked for Shopify, but it doesn’t mean it will work for you.</p>



<p>The useful approach for any company that isn’t Shopify is to ask different questions: Where does <a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">agent</a> work happen in your company and who learns from it? If the answers are “in private” and “nobody,” you’ve got problems. I’m not saying that every agent session belongs in a public channel. You absolutely should <em>not </em>dump customer data, security incidents, HR issues, or privileged production context into a companywide AI water cooler. Boundaries still matter. In some cases, they matter more because agents can move faster and touch more systems than humans do, <a href="https://www.infoworld.com/article/4021238/why-llms-demand-a-new-approach-to-authorization.html">as I’ve warned</a>.</p>



<p>But the principle survives the caveats: Agent work should be inspectable, reusable, and improvable where appropriate. The organization should be able to see the path from question to tool call to failed attempt to correction to pull request to reusable knowledge.</p>



<h2 class="wp-block-heading"><a></a>Shared learning is the new (old) way</h2>



<p>For years, developer experience mostly meant removing friction for individuals: faster setup, better docs, nicer APIs, etc. Those are all still good. But agentic development adds a new requirement: shared learning.</p>



<p>A great developer experience now needs other things: Can the next developer benefit from the last agent session? Can the agent explain not just what it changed, but what it learned? Can a private breakthrough become a team asset without creating a surveillance nightmare? And no, visibility isn’t surveillance, and the goal is not to grade every keystroke or turn developers into content producers for the corporate memory machine. The goal is to make valuable work observable enough that it compounds.</p>



<p>This is a management problem as much as a tools problem. Developers will use agents because agents help them get work done. At this point, you’d struggle to get them to stop. Still, they won’t voluntarily produce beautiful organizational memory as a side effect unless the workflow makes it natural. You need to make the shared shop floor the golden path, as <a href="https://www.infoworld.com/article/4125409/ai-will-not-save-developer-productivity.html">I’ve applied in various ways for years</a>.</p>



<p>In the River story, humans are still the teachers. The organization is still responsible for deciding what counts as good work. The system still needs judgment, taste, security, cost control, and review. The magic happens when all this work is done in the open where the organization can learn from the teaching.</p>



<p>That’s the real promise of agentic coding inside enterprises. Not that every developer gets a private genius, but rather that every developer can tap into collective genius. Lütke learned his trade in a room where the craft was visible, and apprentices learned by watching the work. The companies that win the agent era will rebuild that room for software.</p>



<p>In short, the smartest thing your AI can do isn’t to code faster. It’s to work in public.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Visuelle PKM-Tools: Heptabase, Obsidian Canvas und Xmind im Vergleich]]></title>
<description><![CDATA[Visuelle PKM-Tools wie bringen Ordnung ins Ideenchaos. Der Ratgeber zeigt, welches Tool zur persönlichen Denkweise passt.]]></description>
<link>https://tsecurity.de/de/3630786/it-nachrichten/heise-visuelle-pkm-tools-heptabase-obsidian-canvas-und-xmind-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630786/it-nachrichten/heise-visuelle-pkm-tools-heptabase-obsidian-canvas-und-xmind-im-vergleich/</guid>
<pubDate>Sun, 28 Jun 2026 11:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Visuelle PKM-Tools wie bringen Ordnung ins Ideenchaos. Der Ratgeber zeigt, welches Tool zur persönlichen Denkweise passt.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Ebike Accessories You Need to Help You Haul the Most Stuff]]></title>
<description><![CDATA[An unadorned ebike is a blank canvas. Here, get tips for maximizing its cargo-hauling and person-carrying capabilities.]]></description>
<link>https://tsecurity.de/de/3630782/it-nachrichten/the-ebike-accessories-you-need-to-help-you-haul-the-most-stuff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630782/it-nachrichten/the-ebike-accessories-you-need-to-help-you-haul-the-most-stuff/</guid>
<pubDate>Sun, 28 Jun 2026 11:17:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An unadorned ebike is a blank canvas. Here, get tips for maximizing its cargo-hauling and person-carrying capabilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[MAHNMAL KEUPSTRASSE (fusion26)]]></title>
<description><![CDATA[Diese Veranstaltung beleuchtet zehn Jahre kritischer Praxis am Mahnmal Keupstraße in Köln, wo 2004 vom NSU ein Nagelbombenanschlag verübt wurde. KUTLU YURTSEVEN von Microphone Mafia und ein weiteres Mitglied der Initiative werden darüber berichten, wie die Nachbarschaft Infrastrukturen für kritis...]]></description>
<link>https://tsecurity.de/de/3629870/it-security-video/mahnmal-keupstrasse-fusion26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629870/it-security-video/mahnmal-keupstrasse-fusion26/</guid>
<pubDate>Sat, 27 Jun 2026 18:33:42 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Diese Veranstaltung beleuchtet zehn Jahre kritischer Praxis am Mahnmal Keupstraße in Köln, wo 2004 vom NSU ein Nagelbombenanschlag verübt wurde. KUTLU YURTSEVEN von Microphone Mafia und ein weiteres Mitglied der Initiative werden darüber berichten, wie die Nachbarschaft Infrastrukturen für kritisches Gedenken und kollektives Handeln aufgebaut hat, und wie Gemeinschaften sich erinnern, handeln und gestalten können – und so Erinnerung in eine lebendige, partizipative Infrastruktur der Resilienz und kulturellen Stärke verwandeln.

Fatoş Tuna, Gesine Schütt, Kutlu Yurtseven &amp; Ulf Aminde

Language: DE Translation: YES Video Recording: YES? Graphic Recording: YES

Ten years of critical practice at Mahnmal Keupstraße in Cologne, where memory, resistance, and community intersect and turning memory into a living, participatory infrastructure of resilience and cultural strength. Together with KUTLU YURTSEVEN from Microphone Mafia and another member of the initiative, we will share how the neighborhood has built infrastructures for critical remembrance and collective action.

Fatoş Tuna, Gesine Schütt, Kutlu Yurtseven &amp; Ulf Aminde

Language: DE Translation: YES Video Recording: YES? Graphic Recording: YES

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[It’s not about Anthropic vs. OpenAI anymore]]></title>
<description><![CDATA[AI models have progressed to the point where their capabilities have real political consequences. Dealing with those consequences will require collective action.]]></description>
<link>https://tsecurity.de/de/3628067/it-nachrichten/its-not-about-anthropic-vs-openai-anymore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628067/it-nachrichten/its-not-about-anthropic-vs-openai-anymore/</guid>
<pubDate>Fri, 26 Jun 2026 18:33:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI models have progressed to the point where their capabilities have real political consequences. Dealing with those consequences will require collective action.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mac Users Are Getting More Out of AI Creative Work]]></title>
<description><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't aban...]]></description>
<link>https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</guid>
<pubDate>Fri, 26 Jun 2026 16:22:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't abandoned their existing workflows. But something is changing in how people approach the early, messier stages of creative work — ideation, iteration, rapid visual exploration — and AI tools are filling a gap that native apps never really addressed.



The Friction Nobody Talks About



The real challenge with AI-assisted creative work isn't capability. The models are impressive. The friction is operational: too many platforms, too many tabs, too much manual handoff between steps.



A typical session might involve generating an image in one tool, downloading it, uploading it somewhere else for background removal, switching to another service for video conversion, and then losing track of which version came from which prompt. This kind of tool-hopping breaks the focused state that creative work depends on.



Mac users feel this acutely, because the platform has always rewarded deep, single-environment focus. The friction isn't a technical problem — it's a workflow problem.



What's Actually Changing







The most useful AI tools emerging right now aren't necessarily the ones with the most powerful models. They're the ones that minimize context-switching.



This is showing up in a few different ways:



Unified canvas environments. Some tools are moving toward a visual, node-based interface — where discrete AI tasks (image generation, background swap, video conversion) connect to each other on an infinite canvas, with outputs flowing directly from one step to the next. For Mac users who think spatially and work across large or multiple displays, this approach fits naturally. 



Multi-model access in one place. Rather than holding separate subscriptions to GPT Image 2, Seedance, Kling, Midjourney, or other services, users increasingly want a single interface where different models can be called on for different tasks within the same session. Banana Pro AI is one platform taking this direction — the model becomes a tool choice, not a platform commitment.



Reusable workflow templates. Once a pipeline is built — say, a product photo → model integration → short video sequence — it can be saved and rerun with new inputs. Tools like Workflow Studio make this possible without rebuilding from scratch each time. The setup cost is paid once, which matters most to anyone managing a content catalog or running regular production cycles.



The Mac Advantage in This Context



None of this is Mac-exclusive. But there are reasons Mac users tend to adopt these kinds of tools quickly.



The platform's culture has always favored deep tool mastery over constant app-switching. When a creative environment reduces friction and rewards learning its structure, Mac users lean in. The spatial thinking that makes tools like Figma, Miro, or even Xcode feel natural translates well to canvas-based AI workflows.



The device ecosystem matters too. Heavy work happens at a desk — MacBook Pro, external display, the full setup. But review, approval, and light adjustment increasingly happen on an iPhone. Tools that sync across both contexts fit into how Mac users already move through their day.



The Shift in Creative Roles



What AI actually changes isn't the final output — it's who can generate a first draft, and how quickly.



A solo designer can now run product photography variations, motion concepts, and visual alternates in a single session that would have previously required a photographer, a video editor, and several rounds of back-and-forth. The creative direction still comes from the person. The labor-intensive middle steps increasingly don't.



This doesn't collapse the value of craft. If anything, it raises the bar for creative judgment — because the bottleneck is no longer production capacity, it's the quality of decisions made at each step. Mac users who treat these tools as leverage for their existing skills, rather than replacements for them, tend to get the most out of them.



A Practical Reality



The honest version of this story isn't that AI has transformed creative work overnight. Most professionals are still figuring out where it fits and where it doesn't.



What has changed is that the experimentation cost has dropped. Trying a visual direction, running a quick motion test, exploring a product presentation format — these used to require either significant time or significant budget. They increasingly don't.



For Mac users with an existing creative practice, that's not a disruption. It's an expansion of what's possible in a single afternoon's work.]]></content:encoded>
</item>
<item>
<title><![CDATA[Role of community radio (fusion26)]]></title>
<description><![CDATA[Eine partizipative Live-Radiosendung, die das Freie Radio als Raum für vergessene Geschichten, Stimmen von Minderheiten und alternative Perspektiven erkundet. Das Publikum ist eingeladen, Auszüge aus einem Hörspiel über die Widerstandskämpferin Lore Wolf sowie Texte über die Besetzung des O-Platz...]]></description>
<link>https://tsecurity.de/de/3627430/it-security-video/role-of-community-radio-fusion26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627430/it-security-video/role-of-community-radio-fusion26/</guid>
<pubDate>Fri, 26 Jun 2026 14:48:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine partizipative Live-Radiosendung, die das Freie Radio als Raum für vergessene Geschichten, Stimmen von Minderheiten und alternative Perspektiven erkundet. Das Publikum ist eingeladen, Auszüge aus einem Hörspiel über die Widerstandskämpferin Lore Wolf sowie Texte über die Besetzung des O-Platzes durch People On The Move im Jahr 2016 in Berlin vorzulesen. Durch gemeinsames Vorlesen und Performances werden Archive wiederbelebt und Geschichten des Widerstands in einen Dialog gebracht.

Language: EN Translation: YES Video Recording: YES Graphic Recording: YES

A live participatory radio broadcast exploring community radio as a space for lost histories, minority voices and alternative perspectives. Audiences are invited to read excerpts from a radio play about antifascist resistance fighter Lore Wolf and texts on the 2016 O-Platz migrant occupation in Berlin. Through collective readings and performances, archives are reactivated and stories of resistance brought into dialogue.

Language: EN Translation: YES Video Recording: YES Graphic Recording: YES

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Canvas breach hit 160 UK unis but caused limited damage]]></title>
<description><![CDATA[The April 2026 ShinyHunters breach of the Canvas learning management system caused downstream impacts at more than 150 higher education institutions in the UK, but the damage appears to have been limited]]></description>
<link>https://tsecurity.de/de/3626990/it-nachrichten/canvas-breach-hit-160-uk-unis-but-caused-limited-damage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626990/it-nachrichten/canvas-breach-hit-160-uk-unis-but-caused-limited-damage/</guid>
<pubDate>Fri, 26 Jun 2026 12:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The April 2026 ShinyHunters breach of the Canvas learning management system caused downstream impacts at more than 150 higher education institutions in the UK, but the damage appears to have been limited]]></content:encoded>
</item>
<item>
<title><![CDATA[CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach]]></title>
<description><![CDATA[The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents This article has been indexed from www.infosecurity-magazine.com Read the original article: CMC Releases Analysis and Guidance for…
Read m...]]></description>
<link>https://tsecurity.de/de/3626721/it-security-nachrichten/cmc-releases-analysis-and-guidance-for-education-sector-after-canvas-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626721/it-security-nachrichten/cmc-releases-analysis-and-guidance-for-education-sector-after-canvas-data-breach/</guid>
<pubDate>Fri, 26 Jun 2026 10:20:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents This article has been indexed from www.infosecurity-magazine.com Read the original article: CMC Releases Analysis and Guidance for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cmc-releases-analysis-and-guidance-for-education-sector-after-canvas-data-breach/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cmc-releases-analysis-and-guidance-for-education-sector-after-canvas-data-breach/">CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach]]></title>
<description><![CDATA[The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents]]></description>
<link>https://tsecurity.de/de/3626688/it-security-nachrichten/cmc-releases-analysis-and-guidance-for-education-sector-after-canvas-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626688/it-security-nachrichten/cmc-releases-analysis-and-guidance-for-education-sector-after-canvas-data-breach/</guid>
<pubDate>Fri, 26 Jun 2026 10:08:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents]]></content:encoded>
</item>
<item>
<title><![CDATA[A $2.5 Billion Whodunit: The Hack That Dented the U.K. Economy]]></title>
<description><![CDATA[A loose collective of cybercriminals initially took credit for crippling Jaguar Land Rover last year. Investigators now see Russian hands behind the ransomware attack.]]></description>
<link>https://tsecurity.de/de/3626272/it-security-nachrichten/a-25-billion-whodunit-the-hack-that-dented-the-uk-economy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626272/it-security-nachrichten/a-25-billion-whodunit-the-hack-that-dented-the-uk-economy/</guid>
<pubDate>Fri, 26 Jun 2026 06:22:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A loose collective of cybercriminals initially took credit for crippling Jaguar Land Rover last year. Investigators now see Russian hands behind the ransomware attack.]]></content:encoded>
</item>
<item>
<title><![CDATA[Easy Clip Studio on Linux!!]]></title>
<description><![CDATA[The 2d artist that want to escape windows and still use clip studio. this youtube channel https://youtu.be/iYhEm32Lr4Y?si=MiyHFBUm9yfaoe1U has a very simple install script and method for clip studio 5.0. full access to login,3d assets, cloud sync, icons for app menu and no brush lag. you dont hav...]]></description>
<link>https://tsecurity.de/de/3626182/linux-tipps/easy-clip-studio-on-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626182/linux-tipps/easy-clip-studio-on-linux/</guid>
<pubDate>Fri, 26 Jun 2026 04:26:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The 2d artist that want to escape windows and still use clip studio. this youtube channel <a href="https://youtu.be/iYhEm32Lr4Y?si=MiyHFBUm9yfaoe1U">https://youtu.be/iYhEm32Lr4Y?si=MiyHFBUm9yfaoe1U</a> has a very simple install script and method for clip studio 5.0. full access to login,3d assets, cloud sync, icons for app menu and no brush lag. you dont have to mess with bottles,wine any of it .</p> <p>The only thing i had to do was change the 3d render to normal instead of fast so that the 3d assets didnt freak out when dropping on to the canvas. </p> <p>my setup is linux mint on a geekom a9 max. hx370 w/890m 96gb ddr5. Wacom 16 (2025) and tested with xp pen artist pro 19 gen 2also. Not sure of other distros tho. Definitely check it out.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Prior_Outside_6397"> /u/Prior_Outside_6397 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ufh76l/easy_clip_studio_on_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ufh76l/easy_clip_studio_on_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Foundation Launches Akrites To Coordinate AI-Driven Open Source Security]]></title>
<description><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA...]]></description>
<link>https://tsecurity.de/de/3625881/it-security-nachrichten/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625881/it-security-nachrichten/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security/</guid>
<pubDate>Thu, 25 Jun 2026 23:23:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA, IBM, Cisco, JPMorganChase, and others. Akrites will provide a shared Security Incident Response Team (SIRT), a standardized coordinated vulnerability disclosure process, and act as a "maintainer of last resort" for abandoned but widely used packages.
 
The goal is to reduce duplicate reports, avoid conflicting patches, and help upstream maintainers address vulnerabilities before they can be exploited. As AI makes it easier to find security flaws, can a coordinated industry effort help protect open source, or does it risk giving large corporations too much influence over the ecosystem? "Akrites is the largest coordinated effort in history to create systems and deploy tooling that leverages the collective power of the community to make everyone safer," the Linux Foundation said in an open letter. "Akrites participants will contribute engineering resources; work to build and ship fixes; or fund the engineers who do. Some companies have contributed mightily already. The reality is, collectively, we need to contribute more."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Foundation+Launches+Akrites+To+Coordinate+AI-Driven+Open+Source+Security%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F06%2F25%2F2031228%2Flinux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/06/25/2031228/linux-foundation-launches-akrites-to-coordinate-ai-driven-open-source-security?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Moodle vs. Canvas LMS: Welche Lernplattform passt besser?]]></title>
<description><![CDATA[Moodle und Canvas LMS gehören zu den bekanntesten Lernplattformen, setzen aber unterschiedliche Schwerpunkte. Moodle punktet mit hoher Flexibilität, offenem Plugin-Ökosystem und starker Anpassbarkeit. Canvas LMS ist ebenfalls Open Source und wird häufig als professionell betreute Plattform von In...]]></description>
<link>https://tsecurity.de/de/3623728/server/moodle-vs-canvas-lms-welche-lernplattform-passt-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623728/server/moodle-vs-canvas-lms-welche-lernplattform-passt-besser/</guid>
<pubDate>Thu, 25 Jun 2026 10:00:16 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/Moodle_vs._Canvas.png" width="1698" height="926" alt=""><br>Moodle und Canvas LMS gehören zu den bekanntesten Lernplattformen, setzen aber unterschiedliche Schwerpunkte. Moodle punktet mit hoher Flexibilität, offenem Plugin-Ökosystem und starker Anpassbarkeit. Canvas LMS ist ebenfalls Open Source und wird häufig als professionell betreute Plattform von Instructure genutzt. Wo liegen die Unterschiede und welche Lösung passt zu welchem Use Case?]]></content:encoded>
</item>
<item>
<title><![CDATA[Updates to Gemini in Google Classroom]]></title>
<description><![CDATA[We are introducing several updates to the Gemini tab in Google Classroom designed to make its tools even more helpful for teachers. These changes make it easier for educators to collaborate with AI and create visual aids from any device, while expanding options for refining lesson plans.Mobile av...]]></description>
<link>https://tsecurity.de/de/3622850/web-tipps/updates-to-gemini-in-google-classroom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622850/web-tipps/updates-to-gemini-in-google-classroom/</guid>
<pubDate>Wed, 24 Jun 2026 23:11:02 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We are introducing several updates to the Gemini tab in Google Classroom designed to make its tools even more helpful for teachers. These changes make it easier for educators to collaborate with AI and create visual aids from any device, while expanding options for refining lesson plans.<div><br></div><div><b>Mobile availability</b></div><div>We know educators and students use Google Classroom on the go on their mobile devices, so we are excited to announce that the Gemini tab is now available in the Classroom Android and iOS apps, making these features more accessible to teachers and higher education students. For educators, the following features are available in the Classroom mobile app: Generate a quiz, Brainstorm project ideas, Craft a compelling hook, Tackle common misconceptions, and starter prompts for the Gemini app. All Gemini starter prompts and personal class notebooks in the student Gemini tab are available in the Classroom mobile app.</div><div><br></div><div><b>Tools to generate visual resources</b></div><div>Powered by Nano Banana 2, Google’s newest image generation model, these starter prompts help teachers create visuals that illustrate complex topics for students:</div><div><br></div><div><ul><li>Create an infographic</li><li>Draw a comic strip</li><li>Visualize a concept</li></ul></div><div><br></div><div>Teachers can also personalize three new starter prompts to generate a slide deck for a given concept and grade level using Gemini’s Canvas tool:</div><div><br></div><div><ul><li>Create a presentation</li><li>Create an interactive activity</li><li>Convert a file to Google slides</li></ul><div><br></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXdbvdkkpDDa8PQoInhl-3-dh6wS5IPbLiNXxV5chyS2ZRvSvg_C4hSV0Atj7_JXFDxNQ7NpwdlSA2TvU6tx0k8ZupIIizM5KO_epnEGoc96WQ4WyvfJPLG14jGoahFXo3quF9PSzz4nTlVZ75SRe-14b4MPhsoHPgo0EoxZ-Yj2gTlxkrj44fI_zaBI/s3984/Updates%20to%20Gemini%20in%20Google%20Classroom.png" imageanchor="1"><img border="0" data-original-height="3984" data-original-width="2560" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYXdbvdkkpDDa8PQoInhl-3-dh6wS5IPbLiNXxV5chyS2ZRvSvg_C4hSV0Atj7_JXFDxNQ7NpwdlSA2TvU6tx0k8ZupIIizM5KO_epnEGoc96WQ4WyvfJPLG14jGoahFXo3quF9PSzz4nTlVZ75SRe-14b4MPhsoHPgo0EoxZ-Yj2gTlxkrj44fI_zaBI/s16000/Updates%20to%20Gemini%20in%20Google%20Classroom.png"></a></div></div><h3>Getting started</h3><div><ul><li><b>Admins:</b> As an administrator of your organization's Google Accounts, you can control who is allowed to use Gemini in Google Classroom to generate content and resources. These capabilities are only available to users who are <a href="https://support.google.com/edu/classroom/answer/6071551?hl=en&amp;ref_topic=11987113&amp;sjid=5080632148063304179-NC#zippy=" target="_blank">verified as teachers</a> and as 18 years of age or older in your institution’s <a href="https://support.google.com/a/answer/10651918" target="_blank">age-based access settings</a>. Visit the Help Center to learn about <a href="http://support.google.com/a/answer/16291887" target="_blank">managing access to Gemini in Classroom and the option to turn the service on or off for users in your Admin console</a>.</li><li><b>End users: </b>Navigate to the Gemini tab in the navigation bar in Google Classroom. When using generated content, you should always review the outputs as AI can make mistakes and refine the output so that it fits your context and local policies before assigning to students. Visit the Help Center to learn more about <a href="https://support.google.com/edu/classroom/answer/15410566" target="_blank">Gemini in Classroom</a>, and check out these <a href="https://docs.google.com/presentation/d/1MTyP-BBusYw2rHKE_lQ2QVDA7uT7ngYaGfBy9HypQdY/edit?slide=id.g39a340b9584_1285_8915#slide=id.g39a340b9584_1285_8915" target="_blank">resources for teachers, including this resource with tips and best practices for trying Gemini in Classroom</a>.</li></ul></div><h3>Rollout pace</h3><div><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains:</a> Available now</li></ul></div><h3>Availability</h3><div><ul><li><b>Education: </b>Education Fundamentals, Standard, and Plus</li></ul></div><h3>Resources</h3><div><ul><li>Google Workspace Admin Help: <a href="http://support.google.com/a/answer/16291887" target="_blank">Manage access to Gemini in Classroom</a></li><li>Google Classroom Help: <a href="https://support.google.com/edu/classroom/answer/15410566" target="_blank">Learn about Gemini in Classroom</a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Computer says no. Troubles with fixing algorithmic decision-making. (tdf2026)]]></title>
<description><![CDATA[Algorithmic predictions are used to allocate social goods such as healthcare, job training, and education. Despite efforts to apply fairness frameworks and participatory approaches, practical outcomes remain problematic as recent investigations have shown. This talk examines standard approaches t...]]></description>
<link>https://tsecurity.de/de/3622545/it-security-video/computer-says-no-troubles-with-fixing-algorithmic-decision-making-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622545/it-security-video/computer-says-no-troubles-with-fixing-algorithmic-decision-making-tdf2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:00 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Algorithmic predictions are used to allocate social goods such as healthcare, job training, and education. Despite efforts to apply fairness frameworks and participatory approaches, practical outcomes remain problematic as recent investigations have shown. This talk examines standard approaches to ‘fair machine learning’ through three cases: (1) health programs, (2) long-term unemployment, and (3) school dropout. It critically assesses their limitations and normative assumptions. Two key distinctions clarify the debates: fairness-focused versus welfare-focused methods on the one hand, and whether predictions are instrumentally or communicatively rational on the other. The latter distinction stresses whether algorithms serve effective implementation or facilitate collective evaluation of policy goals.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/SBXZNK/]]></content:encoded>
</item>
<item>
<title><![CDATA[KeepKarlsruheBoring: collective agendas, boredom and maintenance (gpn24)]]></title>
<description><![CDATA[[KeepKarlsruheBoring](https://keepkarlsruheboring.org/) is an agenda for Karlsruhe using [gancio](https://gancio.org/) to allow users, with or without registration, to add events that will be displayed in a web and in the Fediverse. In this talk, we will have an overview on the maintenance of the...]]></description>
<link>https://tsecurity.de/de/3622506/it-security-video/keepkarlsruheboring-collective-agendas-boredom-and-maintenance-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622506/it-security-video/keepkarlsruheboring-collective-agendas-boredom-and-maintenance-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:12 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[[KeepKarlsruheBoring](https://keepkarlsruheboring.org/) is an agenda for Karlsruhe using [gancio](https://gancio.org/) to allow users, with or without registration, to add events that will be displayed in a web and in the Fediverse. In this talk, we will have an overview on the maintenance of the system beyond the software.

Some people complain about how boring Karlsruhe can be (literally, the name of the city can be translated as the calm or dream of Carl). Yet, having a more in-depth look, there are many people and collectives doing astonishing things: maybe the issue was never the lack of activity, but not having a shared agenda to get an overview on that is going on, especially if you refuse to use Instagram or other (a)social media. Under this premise, KeepKarlsruheBoring was launched in 2025 and since them have been collecting events.

Contrary to what most of the people think, technical set up and maintenance is almost effortless and what really requires work is the social maintenance: reaching out to people and helping them to put their events, moderation and correction of events. After having a brief look and the technical set-up, we will have an overview on what we have been doing in this first year to let people know and use this agenda.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/DLSLS7/]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixel Bureaucracy At The Scale Of Chaos - or: Torturing 286 People By Pretending To Be The Government (gpn24)]]></title>
<description><![CDATA[This talk could be described as "pixelebbe Wrapped", except that it is at a different time of the year, has better jokes, provides more technical and moral insights and is not personalized. So erm it probably isn't a "pixelebbe Wrapped" at all, but hey, learn how we built and hosted pixelebbe, ac...]]></description>
<link>https://tsecurity.de/de/3622494/it-security-video/pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-government-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622494/it-security-video/pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-government-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:48:56 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This talk could be described as "pixelebbe Wrapped", except that it is at a different time of the year, has better jokes, provides more technical and moral insights and is not personalized. So erm it probably isn't a "pixelebbe Wrapped" at all, but hey, learn how we built and hosted pixelebbe, achieved better uptime than GitHub and spent only a reasonable amount of effort on this shitpost-turned-project (that's what we tell ourselves at night).

In the history of human kind, there is a set of unfortunate innovations that have caused a lot of suffering and destroyed many lives. One might think of the nuclear bomb, or the internet. One could also think of pixelebbe. At least if one were to be untroubled by accusations of exaggeration and over-dramatising.

Well what is pixelebbe? It's a pixel-setting experience designed to frustrate the player using everyones' favorite thing: ✨ excessive bureaucracy ✨. The idea is very simple: we provide a 40x30 canvas, everyone can then tell us to set a specific pixel to a specific colour from our limited colourset, which we then do and so a picture will be created. Just add on top of that large amounts of red tape, such as limited office hours, a dedicated queueing system, having to use an official government form, very strict formality control and stamps.

In this talk, we want to lift the curtains and give a backoffice tour through pixelebbe. We'll talk about the technology abused to build and host pixelebbe, how we made professional software designed to look like it was put together in 2 hours. We'll even leak official secrets and risk going to pixeljail. There'll be time for a Q&amp;A and a rare live-pixel-setting-session. Rumour has it, that even our agency lead might appear on stage, which had been notoriously always-absent during 39c3.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/VJDF8H/]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider duo convicted over $38M Transport for London attack]]></title>
<description><![CDATA[Two members of the Scattered Spider cybercrime collective have admitted launching a cyberattack against Transport for London (TfL) that caused millions in damages.



Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were due to stand trial for computer hacki...]]></description>
<link>https://tsecurity.de/de/3622323/it-security-nachrichten/scattered-spider-duo-convicted-over-38m-transport-for-london-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622323/it-security-nachrichten/scattered-spider-duo-convicted-over-38m-transport-for-london-attack/</guid>
<pubDate>Wed, 24 Jun 2026 19:54:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Two members of the <a href="https://www.csoonline.com/article/4020567/anatomy-of-a-scattered-spider-attack-a-growing-ransomware-threat-evolves.html">Scattered Spide</a>r cybercrime collective have admitted launching a cyberattack against Transport for London (TfL) that caused millions in damages.</p>



<p>Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were due to stand trial for computer hacking offences at Woolwich Crown Court on Monday but changed their pleas to guilty on the first day of what was scheduled to be a six-week trial.</p>



<p>Sentencing for the pair is due to take place in the same outer London court on July 22.</p>



<h2 class="wp-block-heading">Mind the gap</h2>



<p><a href="https://www.bbc.co.uk/news/articles/czx5yp9qy0do">Jubair and Flowers</a> compromised TfL’s network between Aug. 31 and Sept. 3, 2024, in an attack that disrupted in-station services such as information boards, and online services such as TfL’s refunds portal and Oyster photocard application systems for young people.</p>



<p>The same attack also meant all 28,000 employees of the London transport network were obliged to attend a TfL office for a password reset. A BBC investigation in March 2026 revealed that the hack had exposed the names, email addresses, mobile phone numbers and physical addresses of <a href="https://www.bbc.co.uk/news/articles/cz0ggkr2g77o">an estimated 10 million people</a>.</p>



<p>TfL suffered a reported £29 million ($38.2 million) in losses, incident response, and other recovery costs.</p>



<p>The attack was investigated by the UK’s National Crime Agency and City of London Police. Police investigators quickly identified Flowers as a suspect prior to his arrest at his home on Sept. 6, 2024.</p>



<p>Forensic analysis on the laptops, tower computers, hard drives, and USB sticks seized at the time of Flower’s arrest uncovered evidence that he had also broken into the systems of US healthcare companies SSM Health Care and Sutter Health.</p>



<p>One Acer laptop seized during the arrest held videos showing Jubair accessing TfL systems during the attack, according to a <a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted">police statement on the case</a>. The pair were messaging each other through the Telegram messaging service as well as using a common workspace that they shared with other cybercriminals.</p>



<h2 class="wp-block-heading">Web of destruction</h2>



<p>The <a href="https://www.csoonline.com/article/3994369/how-cisos-can-defend-against-scattered-spider-ransomware-attacks.html">Scattered Spider group</a> burst onto the scene with <a href="https://www.csoonline.com/article/563507/what-is-ransomware-how-it-works-and-how-to-remove-it.html">ransomware</a> attacks against Caesars Entertainment and <a href="https://www.csoonline.com/article/654846/mgm-ransomware-attack-costs-100-million-in-busy-month-for-breaches.html">MGM Resorts</a> in 2023. Attacks against a wide variety of targets across multiple industries, including <a href="https://www.csoonline.com/article/3977688/warning-issued-to-retailers-cisos-worldwide-after-three-attacks-in-uk.html">retail</a>, hospitality, telecoms, and aviation, followed.</p>



<p>UK attacks linked to Scattered Spider include high-profile attacks on <a href="https://www.csoonline.com/article/4065991/dont-drink-or-drive-say-cyberattackers.html">Jaguar Land Rover</a> and retailer <a href="https://www.csoonline.com/article/3986579/aggressive-creative-hackers-behind-uk-breaches-now-eyeing-us-retailers.html">Marks and Spencer</a>.</p>



<p>Scattered Spider is best viewed as an overlapping network of largely English-speaking crews and affiliates rather than a tightly knit organisation.</p>



<p>The group’s tradecraft is characterised by social engineering, help-desk impersonation, SIM swapping in the furtherance of ransomware-enabled extortion, and other scams. In particular, Scattered Spider targeted outsourced IT support and help-desk providers to reset credentials and bypass multi-factor authentication controls to expand their access into victim’s networks.</p>



<p>A loose alliance or collective of cybercrime groups including Scattered Spider, <a href="https://en.wikipedia.org/wiki/Lapsus%24">Lapsus$</a>, and <a href="https://en.wikipedia.org/wiki/ShinyHunters">ShinyHunters</a> was established last year.</p>



<p>Jubair and Flowers are among a growing number of members of the group to be convicted for computer crime offences.</p>



<p><a href="https://www.csoonline.com/article/4163328/scattered-spider-co-conspirator-pleads-guilty.html">Tyler Buchanan</a>, a senior figure in the group, was arrested at a Spanish airport in June 2024.</p>



<p>Buchanan, 24, of Dundee, Scotland, was extradited to the US and <a href="https://www.justice.gov/usao-cdca/pr/british-national-pleads-guilty-hacking-companies-and-stealing-least-8-million-virtual">pleaded guilty in April 2026 to a scam that aimed to steal $8 million in virtual currency</a> from at least a dozen companies as well as numerous individuals.</p>



<p>Co-conspirator <a href="https://www.justice.gov/usao-mdfl/pr/palm-coast-hacker-sentenced-10-years-prison">Noah Michael Urban of Palm Coast, Florida, was jailed for 10 years</a> in April 2025 after pleading guilty to aggravated identity theft and wire fraud offences.</p>



<p>Other prosecutions remain pending.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Every College Student Needs a Trusty Laptop. Here Are the 4 I'd Buy]]></title>
<description><![CDATA[In the age of Blackboard and Canvas, every student needs a good computer and the right accessories to succeed. Here's what to get before the next school year.]]></description>
<link>https://tsecurity.de/de/3622232/it-nachrichten/every-college-student-needs-a-trusty-laptop-here-are-the-4-id-buy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622232/it-nachrichten/every-college-student-needs-a-trusty-laptop-here-are-the-4-id-buy/</guid>
<pubDate>Wed, 24 Jun 2026 19:03:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In the age of Blackboard and Canvas, every student needs a good computer and the right accessories to succeed. Here's what to get before the next school year.]]></content:encoded>
</item>
<item>
<title><![CDATA[Figma bets on human judgment at Config 2026 while the AI powering its canvas belongs to someone else]]></title>
<description><![CDATA[At Config 2026, Figma turned its canvas into a full workspace with code, animation, shaders, and AI agents. But the intelligence powering all of it is rented from API providers, squeezing margins. And one of those providers is now building competing design tools.
The article Figma bets on human j...]]></description>
<link>https://tsecurity.de/de/3622190/ai-nachrichten/figma-bets-on-human-judgment-at-config-2026-while-the-ai-powering-its-canvas-belongs-to-someone-else/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622190/ai-nachrichten/figma-bets-on-human-judgment-at-config-2026-while-the-ai-powering-its-canvas-belongs-to-someone-else/</guid>
<pubDate>Wed, 24 Jun 2026 18:49:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://the-decoder.com/wp-content/uploads/2026/06/Config_2026_product_overview.jpg" class="attachment-full size-full wp-post-image" alt='A montage of several Figma features on a black background, including a Risograph effect with sliders for Dither Size, Offset, and Noise Scale; a prompt field for a circular image array plugin; a "Build with code" menu item; and a compass display showing "355°".' decoding="async" fetchpriority="high"></p>
<p>        At Config 2026, Figma turned its canvas into a full workspace with code, animation, shaders, and AI agents. But the intelligence powering all of it is rented from API providers, squeezing margins. And one of those providers is now building competing design tools.</p>
<p>The article <a href="https://the-decoder.com/figma-bets-on-human-judgment-at-config-2026-while-the-ai-powering-its-canvas-belongs-to-someone-else/">Figma bets on human judgment at Config 2026 while the AI powering its canvas belongs to someone else</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Figma now has AI motion graphics and shader tools]]></title>
<description><![CDATA[Figma has unveiled some new design and coding product updates at its annual Config conference that aim to help creatives "push their ideas further" and automate tedious tasks with AI. Part of this is a reimagined canvas that's now optimized for full-stack development, according to Figma, bringing...]]></description>
<link>https://tsecurity.de/de/3622127/ai-nachrichten/figma-now-has-ai-motion-graphics-and-shader-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622127/ai-nachrichten/figma-now-has-ai-motion-graphics-and-shader-tools/</guid>
<pubDate>Wed, 24 Jun 2026 18:19:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Figma has unveiled some new design and coding product updates at its annual Config conference that aim to help creatives "push their ideas further" and automate tedious tasks with AI. Part of this is a reimagined canvas that's now optimized for full-stack development, according to Figma, bringing teams, AI agents, tools, and materials "together in […]]]></content:encoded>
</item>
<item>
<title><![CDATA[TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million]]></title>
<description><![CDATA[Two alleged members of the cybercrime collective Scattered Spider have pleaded guilty to their roles in the Transport for London cyberattack, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport a...]]></description>
<link>https://tsecurity.de/de/3620296/it-security-nachrichten/tfl-hackers-plead-guilty-after-breach-exposed-customer-data-and-cost-29-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620296/it-security-nachrichten/tfl-hackers-plead-guilty-after-breach-exposed-customer-data-and-cost-29-million/</guid>
<pubDate>Wed, 24 Jun 2026 07:38:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Transport for London cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million 1"></p>Two alleged members of the cybercrime collective <a href="https://thecyberexpress.com/scattered-spider-teens-plead-not-guilty/" target="_blank" rel="noopener">Scattered Spider </a>have pleaded guilty to their roles in the <a href="https://thecyberexpress.com/transport-for-london-addressing-cyberattack/" target="_blank" rel="noopener">Transport for London cyberattack</a>, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport authority.

The guilty pleas were entered by Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, on the opening day of proceedings at Woolwich Crown Court. The pair had been due to stand trial on June 22 but changed their pleas to guilty.
<h3><strong>Transport for London Cyberattack Led to Major Disruption</strong></h3>
According to the National Crime Agency (NCA) and City of London Police, TfL's network was infiltrated between August 31 and September 3, 2024. The breach forced all 28,000 employees to attend TfL offices for <a href="https://thecyberexpress.com/top-password-managers-for-digital-safety/" target="_blank" rel="noopener">password</a> resets and caused significant operational disruption across the organization.

The TfL cyberattack also resulted in unauthorized access to <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28805">data</a> held within TfL's Oyster refunds system. The incident affected the authority's customer refund process, delaying reimbursements for some customers. In addition, the application system for Oyster photocards used by children and young people was temporarily shut down.

Authorities <a href="https://nca-newsroom.prgloo.com/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="nofollow noopener">said</a> the attack caused substantial financial damage, with TfL reporting losses and recovery costs totaling approximately £29 million.
<h3><strong>Investigation Linked Attackers to Scattered Spider</strong></h3>
Jubair and Flowers were arrested at their homes on September 16, 2024, following a joint investigation conducted by the <a href="https://thecyberexpress.com/nca-arrests-4-for-retail-cyberattacks/" target="_blank" rel="noopener">NCA</a> and City of London Police.

Investigators identified both individuals as members of Scattered Spider, a cybercriminal collective that has been linked to a number of high-profile intrusions.

During searches of Flowers' residence, officers recovered laptops, desktop computers, hard drives, and USB storage devices. Evidence recovered from one Acer laptop included a screenshot showing connectivity to TfL infrastructure.

[caption id="attachment_112868" align="aligncenter" width="600"]<img class="wp-image-112868 size-full" src="https://thecyberexpress.com/wp-content/uploads/TFL-cyberattack-e1782278063737.webp" alt="Transport for London cyberattack" width="600" height="900"> Source: NCA[/caption]

Authorities also found evidence indicating Flowers had accessed an online marketplace that sold breached credentials. Investigators further discovered videos recorded by Flowers that allegedly showed Jubair accessing TfL systems during the attack.

The investigation revealed that the two communicated through <a href="https://thecyberexpress.com/telegram-ban-in-india-ahead-of-neet-re-exam/" target="_blank" rel="noopener">Telegram</a> and collaborated using an online workspace platform that allowed multiple participants to work remotely on shared systems.
<h3><strong>Additional Allegations Involving US Healthcare Networks</strong></h3>
The investigation extended beyond the Transport for London <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28806">cyberattack</a>. When Flowers was first arrested on September 6, 2024, NCA officers identified evidence suggesting unauthorized activity targeting the networks of SSM Health Care Corporation and Sutter Health in the United States.

Court records show Flowers pleaded guilty to charges related to a conspiracy to conduct unauthorized acts against SSM Health Care Corporation's computer systems with intent to impair operations. He also admitted attempting unauthorized acts against Sutter Health's systems with the same intent.

Jubair additionally faced a charge for failing to disclose PINs or passwords associated with devices seized during the investigation.

Authorities noted that Flowers breached bail conditions on two occasions in March and May 2025.
<h3><strong>Law Enforcement Highlights Impact of Cybercrime</strong></h3>
Paul Foster, Deputy Director and head of the NCA's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Cyber Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28803">Cyber Crime</a> Unit, described the case as a lengthy and highly complex investigation. He said the attack demonstrated that <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28804">cybercrime</a> has significant real-world consequences, affecting public services and causing millions of pounds in losses to critical national infrastructure.

Foster also highlighted the growing threat posed by cybercriminal groups operating from the UK and other English-speaking countries, citing Scattered Spider as a notable example.

Deputy Commissioner Nik Adams of the City of London Police said the cyberattack had a significant impact on essential public services and daily operations. He emphasized that individuals responsible for targeting critical organizations and causing financial harm would be pursued through coordinated law enforcement efforts.

The investigation received support from the West Midlands Regional Organised Crime Unit and British Transport Police.

Jubair and Flowers are scheduled to be sentenced at Woolwich Crown Court on July 16.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sustainability Needs Solidarity: Lessons from Ebola - Table.Briefings]]></title>
<description><![CDATA[It is a pragmatic investment in collective security. Every dollar spent ... While emphasizing global health security as a pillar of its security ...]]></description>
<link>https://tsecurity.de/de/3619579/it-security-nachrichten/sustainability-needs-solidarity-lessons-from-ebola-tablebriefings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619579/it-security-nachrichten/sustainability-needs-solidarity-lessons-from-ebola-tablebriefings/</guid>
<pubDate>Tue, 23 Jun 2026 22:53:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>It</b> is a pragmatic investment in collective <b>security</b>. Every dollar spent ... While emphasizing global health <b>security</b> as a pillar of its <b>security</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise-grade AI image generation in 2 seconds is here: Krea 2 Raw and Turbo available as open weights under custom license]]></title>
<description><![CDATA[While many enterprises have already begun integrating AI-generated images, visuals, graphics and videos into their production workflows — there is also a growing pool of data and subjective commentary indicating AI imagery ultimately looks non-distinct, monotonous, and too unoriginal to ensure a ...]]></description>
<link>https://tsecurity.de/de/3619526/it-nachrichten/enterprise-grade-ai-image-generation-in-2-seconds-is-here-krea-2-raw-and-turbo-available-as-open-weights-under-custom-license/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619526/it-nachrichten/enterprise-grade-ai-image-generation-in-2-seconds-is-here-krea-2-raw-and-turbo-available-as-open-weights-under-custom-license/</guid>
<pubDate>Tue, 23 Jun 2026 22:31:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>While many enterprises have already begun integrating AI-generated images, visuals, graphics and videos into their production workflows — there is also a<a href="https://gizmodo.com/ai-image-generators-default-to-the-same-12-photo-styles-study-finds-2000702012"> growing pool of data</a> and subjective commentary indicating AI imagery ultimately looks non-distinct, monotonous, and too unoriginal to ensure a brand and its assets stand out from the pack. That it's "AI slop," in other words. </p><p>AI creative tools startup Krea is hoping to change that trend by<a href="https://x.com/krea_ai/status/2069435590995812396"> opening up the weights</a> to its new frontier AI image model Krea 2 as two versions, "<a href="https://huggingface.co/krea/Krea-2-Raw">Krea 2 Raw</a>" and "<a href="https://huggingface.co/krea/Krea-2-Turbo">Krea 2 Turbo</a>," under a <a href="https://huggingface.co/krea/Krea-2-Raw/blob/main/LICENSE.pdf">custom license </a>that requires firms with more than 50 seats to pay for Enterprise usage, and mandates all users of any size to implement technical safeguards to <!-- -->prevent the generation of illegal materials, non-consensual intimate imagery (NCII), child sexual abuse material (CSAM), or defamatory assets.</p><p>Both models are available for public download on <a href="https://huggingface.co/krea">Hugging Face</a>. The company says the models provide more visual variety than typical AI generators, while maintaining high prompt accuracy, fidelity, and quality. Importantly, they also offer enterprises and users the ability to customize the generative outputs much more than typical proprietary or even other open source models. </p><p>And, for those seeking to generate imagery at high-throughput, <a href="https://www.krea.ai/blog/krea-2-turbo">Krea 2 Turbo's generation speed is only 2 seconds</a>, making it among the fastest now available across open and proprietary AI image generation models.</p><h2><b>AI Image Generator API Speed &amp; Licensing Benchmarks (Mid-2026)</b></h2><table><tbody><tr><td><p><b>Model / Generator</b></p></td><td><p><b>Developer / Platform</b></p></td><td><p><b>Avg. Generation Time</b></p></td><td><p><b>Licensing &amp; Commercial Use</b></p></td><td><p><b>Key Characteristics</b></p></td></tr><tr><td><p>FLUX.1 [schnell] (fast)</p></td><td><p>Prodia</p></td><td><p>0.5 seconds</p></td><td><p>Open Weights (Apache 2.0).</p><p> Fully permissive for free commercial use.</p></td><td><p>Highly optimized endpoint utilizing step distillation to deliver sub-second generation times, representing the absolute floor for current API latency.</p></td></tr><tr><td><p>Z-Image Turbo</p></td><td><p>Replicate / fal.ai</p></td><td><p>1.8 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights require active API usage contracts.</p></td><td><p>Designed for instantaneous inference bursts. Both Replicate and fal.ai achieve identical 1.8-second median times on this model.</p></td></tr><tr><td><p><b>Krea 2 Turbo</b></p></td><td><p><b>Krea</b></p></td><td><p><b>2.0 seconds</b></p></td><td><p><b>Open Weights / Proprietary Hybrid.</b></p><p><b> Available via platform trial or API.</b></p></td><td><p><b>Maintains the base model's compatibility with style references and LoRAs while utilizing Trajectory Distribution Matching (TDM) to accelerate the creative ideation loop.</b></p></td></tr><tr><td><p>Midjourney v8.1 (Turbo Mode)</p></td><td><p>Midjourney</p></td><td><p>3 – 6 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>Delivers generation speeds "three times faster than v8" while maintaining the model's signature "painterly realism with sophisticated lighting," though it requires a "higher credit cost". </p></td></tr><tr><td><p>FLUX.2 [klein] 4B</p></td><td><p>Black Forest Labs</p></td><td><p>3.9 seconds</p></td><td><p>Open Weights.</p><p> Permissive commercial use.</p></td><td><p>The lightweight 4-billion parameter variant of the FLUX.2 architecture, balancing prompt adherence with high-speed generation.</p></td></tr><tr><td><p>FLUX.2 [klein] 9B</p></td><td><p>Black Forest Labs</p></td><td><p>4.6 seconds</p></td><td><p>Open Weights.</p><p> Permissive commercial use.</p></td><td><p>The medium-weight 9-billion parameter open model. It scales up compositional intelligence while keeping generation firmly under the 5-second barrier.</p></td></tr><tr><td><p>MAI Image 2 Efficient</p></td><td><p>Microsoft</p></td><td><p>4 – 7 seconds </p></td><td><p>Proprietary. Commercial use requires consumption-based API billing via Azure AI Foundry. </p></td><td><p>A throughput-optimized variant explicitly designed to "out-pace Google’s Imagen Flash". It makes a slight trade-off in detail for "substantially lower latency" that suits "automated pipelines" perfectly. </p></td></tr><tr><td><p>Midjourney v8.1 (Fast Mode)</p></td><td><p>Midjourney</p></td><td><p>5 – 9 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>The standard operational mode for v8.1. Average wait times "consistently lands below 10 seconds for most prompts" while offering "excellent handling of complex multi-element scenes". </p></td></tr><tr><td><p>FLUX.2 [dev]</p></td><td><p>fal.ai / DeepInfra</p></td><td><p>6.1 – 6.4 seconds</p></td><td><p>Open Weights (Non-Commercial).</p><p> Strictly for research and non-commercial development.</p></td><td><p>The developer-focused research model. API endpoint optimizations cause slight variance, with fal.ai operating at 6.1 seconds and DeepInfra at 6.4 seconds.</p></td></tr><tr><td><p>Midjourney v8.1 (Relax Mode)</p></td><td><p>Midjourney</p></td><td><p>8 – 14 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>Processes standard 1024x1024 resolution images without consuming fast GPU hours. The model retains "strong compositional instincts" and "consistent color grading and mood". </p></td></tr><tr><td><p>FLUX.2 [pro]</p></td><td><p>Black Forest Labs</p></td><td><p>11.1 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights require paid API consumption.</p></td><td><p>The closed, professional-grade tier. It drops extreme step-distillation to prioritize high-fidelity commercial rendering and strict spatial alignments.</p></td></tr><tr><td><p>Seedream 4.0</p></td><td><p>BytePlus</p></td><td><p>11.6 seconds</p></td><td><p>Proprietary.</p><p> Commercial use via BytePlus enterprise contracts.</p></td><td><p>The base commercial generation model for the Seedream architecture, focused on reliable, standard-resolution outputs.</p></td></tr><tr><td><p>MAI Image 2 Standard</p></td><td><p>Microsoft</p></td><td><p>12 – 20 seconds </p></td><td><p>Proprietary. Commercial use requires consumption-based API billing via Azure AI Foundry. </p></td><td><p>Operates as a "full-quality output optimized for photorealism". It acts as a literal renderer, delivering "high-fidelity skin tones and material textures" and "strong literal prompt adherence". </p></td></tr><tr><td><p>Nano Banana Pro (Gemini 3 Pro Image)</p></td><td><p>Google DeepMind</p></td><td><p>17.7 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights granted via Gemini API terms.</p></td><td><p>Prioritizes exact semantic accuracy and prompt adherence through an extended reasoning phase, trading raw speed for complex contextual execution.</p></td></tr><tr><td><p>Seedream 4.5</p></td><td><p>BytePlus</p></td><td><p>18.2 seconds</p></td><td><p>Proprietary.</p><p> Commercial use via BytePlus enterprise contracts.</p></td><td><p>The upgraded high-fidelity variant, requiring an additional 6.6 seconds of compute time over the 4.0 version to refine complex textures and text rendering.</p></td></tr><tr><td><p>Krea 2 Large</p></td><td><p>Krea</p></td><td><p>23.7 seconds</p></td><td><p>Proprietary / Open Weights.</p><p> Commercial rights depend on deployment.</p></td><td><p>The un-distilled foundation model. It ignores the speed-focused Trajectory Distribution Matching of the Turbo variant to maximize aesthetic polish and structural stability.</p></td></tr><tr><td><p>FLUX.2 [max]</p></td><td><p>Black Forest Labs</p></td><td><p>25.6 seconds</p></td><td><p>Proprietary.</p><p> Closed enterprise API.</p></td><td><p>The heaviest parameter model in the FLUX lineup. It operates exclusively as a deep reasoning renderer for complex commercial assets.</p></td></tr><tr><td><p>GPT-Image-2</p></td><td><p>OpenAI</p></td><td><p>200.8 seconds</p></td><td><p>Proprietary.</p><p> Full commercial usage under standard OpenAI terms.</p></td><td><p>A massive outlier in the latency landscape. It dedicates over three minutes to complex, multi-step semantic reasoning, likely utilizing an expansive chain-of-thought process prior to finalizing pixel outputs.</p></td></tr></tbody></table><p><i>Sources: </i><a href="https://artificialanalysis.ai/image/models"><i>Artificial Analysis</i></a><i>, </i><a href="https://www.krea.ai/blog/krea-2-turbo"><i>Krea</i></a><i>, </i><a href="https://www.mindstudio.ai/blog/midjourney-v8-1-vs-microsoft-mai-image-2"><i>MindStudio.AI</i></a><i></i></p><h2><b>Architectural bifurcation and the 12B parameter Transformer</b></h2><p>At the <a href="https://www.krea.ai/blog/krea-2-technical-report">technical core</a> of the release sits an architectural framework built entirely from scratch: a Diffusion Transformer scaled to 12 billion parameters. </p><p>Rather than deploying a single, heavily fine-tuned model for all downstream tasks, Krea open-sources two highly differentiated checkpoints captured at distinct milestones of the model's training lifecycle.</p><p>Departing from multi-stream configurations for structural clarity, the core engine standardizes on a single-stream transformer block architecture wherein attention and MLP layers are shared natively between text and image tokens. </p><p>To maximize computational efficiency, Krea incorporates a SwiGLU MLP layer operating at a 4x expansion factor alongside Grouped-Query Attention (GQA) combined with gated sigmoid attention layers to stabilize training dynamics. </p><p>Timestep conditioning is heavily optimized; the network replaces traditional per-block MLP modules with a lightweight, per-block tunable bias term, successfully cutting total block modulation parameters by 20% to 30% and reallocating that parameter budget directly into core layers. </p><p>Positional encoding is managed via a 3D Axial Rotary Position Embedding (RoPE) scheme mapping across individual frame, height, and width coordinate</p><p><b>Krea 2 Raw </b>represents an undistilled base release checkpoint taken directly from the mid-training stage of the larger Krea 2 Medium development cycle. </p><p>Because it lacks post-training alignment, reinforcement learning from human feedback (RLHF), or final aesthetic distillation, Krea 2 Raw functions as a blank canvas. </p><p>It retains a vast, uncurated latent space that makes it poorly suited for immediate out-of-the-box prompting, but highly optimized for structural training. </p><p>Operating this model via the Hugging Face `diffusers` library requires a heavy compute footprint, executing via `Krea2Pipeline` in `torch.bfloat16` precision across 52 inference steps with a guidance scale of 3.5.</p><p>To accelerate early-stage architectural convergence during the first epoch of this 256px baseline training phase, Krea applied internal Representation Alignment (iREPA) techniques before decoupling them to let the underlying model develop independent structural representations.</p><p>The second checkpoint, <b>Krea 2 Turbo,</b> represents the opposite end of the optimization spectrum. </p><p>It is a distilled, post-trained variant derived from Krea 2 Medium. Through knowledge distillation, the network's complex multi-step generation sequence is compressed into an incredibly lean operational profile. </p><p>Krea 2 Turbo slashes the required generation cycle down to just 8 inference steps with a guidance scale of 0.0, enabling it to render native 2k resolution imagery on standard consumer-grade hardware in <b>approximately 2 seconds.</b></p><p>The underlying latent representations for both models are optimized through the integration of the Qwen Image VAE and the FLUX 2 VAE to guarantee rapid convergence while maintaining high reconstruction fidelity.</p><h2><b>Data and training</b></h2><p>The underlying dataset strategy for the Krea 2 family relies on a hybrid blend of publicly harvested data, third-party licensed image repositories, and highly curated synthetic datasets built via proprietary generation methods. </p><p>Prior to final training, Krea processed these collections through rigorous algorithmic filters designed to strip out duplicative frames, low-resolution media, and explicit or harmful material, ensuring high fidelity and strong prompt compliance across both models.</p><p>Krea enforces a <i>zero-synthetic data policy</i> within its primary pretraining mix. </p><p>To prevent the upper-bound quality limitations and output biases induced by AI-generated data, the engineering team deployed custom in-house filtering classifiers built on top of DINOv3 and SigLIP-2 architectures to completely purge synthetic images at scale. </p><p>Furthermore, rather than using traditional model-based aesthetic filters that inadvertently strip away artistic intents like motion blur, Krea preserves wide stylistic boundaries. </p><p>The team trained a Sparse Autoencoder (SAE) on SigLIP-2 embeddings to isolate and filter out genuine visual artifacts using an unsupervised tagging framework. </p><h2><b>Krea 2 Raw vs. Krea 2 Turbo: Distinctions and use cases</b></h2><p>The release establishes a highly deliberate operational paradigm for professional studios and independent creators: "train on Raw, generate with Turbo." This workflow leverages the unique architectural properties of both open-weight files to optimize both training accuracy and rendering speed.</p><p>In creative production pipelines, engineers can use Krea 2 Raw to train custom Low-Rank Adaptations (LoRAs) or domain-specific fine-tunes. </p><p>Because the Raw checkpoint contains no baked-in stylistic opinions or aggressive post-training constraints, it absorbs unique aesthetic directions—such as architectural drafting styles, specific brand assets, or complex lighting designs—with high fidelity and zero stylistic interference. </p><p>Once the training phase is complete, creators can port those exact LoRAs directly over to Krea 2 Turbo.</p><p>This methodology is reflected in Krea's own development ecosystem, which hosts an in-house collection of custom LoRAs trained entirely on the Raw foundation model but optimized for execution within Turbo workflows. </p><p>On the user-facing application layer, Krea integrates this dual-engine setup with a powerful style transfer system. Rather than relying on erratic text descriptions to achieve an artistic look, users can feed multiple style reference images directly into the system. </p><p>Krea 2 maps these references across its latent space, allowing creators to isolate individual aesthetic components, combine distinct moodboards, adjust style strength via generative sliders, and fine-tune batch variation levels to maintain visual cohesion across large-scale design iterations.</p><p>To address the gap between raw textual training captions and brief user inputs, Krea paired this suite with an advanced LLM Prompt Expander. Refined via Generalized Deep Q-Network Preference Optimization (GDPO) and trained on synthetic thinking traces to preserve intent reconstruction, the expander applies a photographic-medium bias to photorealistic requests and integrates an active DINOv3 embedding diversity score across rollout groups to prevent automated prompting routines from collapsing into a singular house style.</p><p>While Krea 2 Medium and Krea 2 Large remain the company's flagship models for high-fidelity composition and absolute stylistic adherence, Turbo fills the critical role of rapid visual ideation. </p><p>It serves as an interactive scratchpad for early concept creation, quick prompt experimentation, and iterative art direction where near-instantaneous feedback loops are required to maintain creative momentum.</p><h2><b>The custom license and its particulars</b></h2><p>The open-weight assets deploy under the <a href="https://huggingface.co/krea/Krea-2-Raw/blob/main/LICENSE.pdf">Krea 2 Community License Agreemen</a>t operating alongside an official Acceptable Use Policy. </p><p>At a macro level, this legal framework mirrors recent industry trends toward commercial-use permissions that target small businesses while restricting large enterprise exploitation. </p><p>The license explicitly permits individuals, independent creators, and <i>small</i> commercial companies to build applications, monetize generated imagery, and integrate the open weights directly into commercial software products without royalty obligations. </p><p>Furthermore, Krea states that it "does not claim copyright or other intellectual property rights over content generated by users of this model," leaving output ownership entirely in the hands of the operator.</p><p>For organizations scaling beyond this baseline, the ecosystem shifts into a paid, custom-tier structure. </p><p>While Krea's official documentation lacks a rigid revenue threshold defining a "large enterprise," the company structurally demarcates the boundary based on organizational footprint: standard commercial usage caps at a "Business" tier accommodating up to 50 seats. </p><p>Therefore, any entity requiring more than 50 seats, Single Sign-On (SSO) integrations, guaranteed Service Level Agreements (SLAs), or custom Data Processing Agreements (DPAs) qualifies as an Enterprise. </p><p>These larger entities fall outside the free Community License scope and must pay for a custom commercial license—operating under "Custom Terms of Service"—negotiated directly with Krea's sales team. </p><p>Additionally, developer access to Krea's official API remains entirely decoupled from the open-weights release; API usage operates as a distinct, paid service billed dynamically on a per-generation basis (measured in microdollars) and requires a prepaid USD balance independent of standard monthly compute subscriptions.</p><p>However, a close examination reveals a significant structural shift regarding legal and behavioral compliance for all self-hosted deployments. </p><p>Unlike traditional open-source permissions like the MIT or Apache 2.0 licenses—which grant unconditional usage rights and completely waive liability—the Krea 2 Community License implements strict downstream behavioral guardrails.</p><p>Because Krea relinquishes centralized control over the downstream deployment of its open weights, the contract legally binds deployers to enforce content moderation protocols at the infrastructure layer. </p><p>Under the terms of the agreement, any developer or platform hosting Krea 2 models must implement active input/output classifiers or equivalent content filtering mechanisms to actively prevent the generation of illegal materials, non-consensual intimate imagery (NCII), child sexual abuse material (CSAM), or defamatory assets. </p><p>Developers who fail to deploy these defensive safety layers stand in immediate breach of contract, giving Krea the explicit right to update model weights or revoke access to the model family entirely.</p><h2><b>Background on Krea</b></h2><p>Founded in 2022 by audiovisual systems engineering dropouts Víctor Perez and Diego Rodriguez Prado, San Francisco-based Krea initially captured market traction as a highly fluid user interface layer built to orchestrate disparate, third-party AI generative engines. </p><p>The startup's rapid scaling via product-led adoption culminated in an aggregate<a href="https://techcrunch.com/2025/04/07/kreas-founders-snubbed-postgrad-grants-from-the-king-of-spain-to-build-their-ai-startup-now-its-valued-at-500m/"> $83 million </a>in disclosed venture capital funding from major VCs including Andreessen Horowitz and Bain Capital Ventures, as well as early-stage institutional backers including Pebblebed, Abstract Ventures, and Gradient Ventures.</p><p>The company's user base surpassed <a href="https://www.krea.ai/">30 million individuals across 191 countries as of June 2026</a>, according to its website. </p><p>The open-weights launch of the Krea 2 model family represents the culmination of Krea’s deliberate evolution from a multi-model SaaS aggregator into a self-sustaining media research lab. </p><p>Early in its lifecycle, Krea focused on building workflow tools, editing systems, and a node-based automation pipeline that allowed digital artists to unify models from competitors like Runway, Midjourney, and Adobe under a single subscription. </p><p>However, to insulate itself against upstream platform dependencies and supplier margin pressures, the company aggressively shifted toward developing proprietary architectures. This transition began taking public shape in July 2025 with the open-weights release of the custom-curated FLUX.1 Krea checkpoint, followed in October 2025 by Krea Realtime 14B—an autoregressive video model distilled from Wan 2.1 capable of rendering 11 frames per second on localized enterprise hardware.</p><p>This underlying technical maturation parallels Krea's accelerating push into high-end enterprise workflows. Large-scale creative production operations have shifted toward treating Krea as core creative infrastructure; for example, the digital creative services platform </p><p><a href="https://www.youtube.com/watch?v=OLNbn4L2fUM">Superside reported migrating workflows</a> from fragmented open-source setups to route roughly 80 percent of its total AI generative production through Krea. </p><p>Furthermore, Krea established a strategic co-development partnership with Copenhagen-headquartered architecture firm <a href="https://henninglarsen.com/news/we-re-partnering-with-krea">Henning Larsen</a> to build highly restricted, domain-specific design tools tuned to meet the compliance frameworks mandated by the EU AI Act. </p><p>By releasing Krea 2 Raw and Turbo as open weights, Krea is continuing its expansion from an AI tools provider to being a model provider in its own right.</p><h2><b>An alternative to typical rigid AI imagery APIs?</b></h2><p>Creators are focusing heavily on the structural freedom offered by the unaligned Raw checkpoint, viewing it as an important alternative to the locked-down APIs provided by closed-source models.</p><p>Through the<a href="https://x.com/krea_ai/status/2069435590995812396"> official announcement on X,</a> Krea emphasized the foundational shift this launch represents for open AI workflows.</p><p>Developers note that by treating AI as an "actual creative medium" that feels "raw, flexible, unopinionated, and unconstrained," Krea is intentionally providing an infrastructure that creators can "break if [they] want to," moving far away from the rigid safety guardrails that frequently limit the visual range of competing enterprise tools.</p><p>As independent model builders begin compiling the Hugging Face repositories, the practical value of the release will be determined by how effectively the open-source community can scale customized LoRAs using Krea 2 Raw.</p><p>By providing clear commercial terms and lowering hardware entry barriers via Turbo's 8-step inference pipeline, Krea has introduced a highly competitive alternative to the open-weights market, challenging dominant models by prioritizing artistic control over centralized corporate alignment.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat USA 2026 | Welcome Video]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 1x - Views:15 As the cybersecurity landscape grows more complex and rapidly evolving, threats continue to multiply, artificial intelligence is reshaping the foundations of security, and the stability of our digital infrastructure is more at risk than ever before.

B...]]></description>
<link>https://tsecurity.de/de/3619116/it-security-video/black-hat-usa-2026-welcome-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619116/it-security-video/black-hat-usa-2026-welcome-video/</guid>
<pubDate>Tue, 23 Jun 2026 19:18:25 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 1x - Views:15 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OXsKQ8qPYjE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>As the cybersecurity landscape grows more complex and rapidly evolving, threats continue to multiply, artificial intelligence is reshaping the foundations of security, and the stability of our digital infrastructure is more at risk than ever before.<br />
<br />
Black Hat brings together a global community of experts, innovators, and leaders united by one shared mission: to outpace emerging threats through collaboration, preparation, and real-world innovation.<br />
<br />
This welcome video offers a glimpse into what to expect during your time onsite, from world-class programming to opportunities for discovery, connection, and meaningful exchange.<br />
<br />
Whether you are here for the first time or returning as part of the community, you are part of a collective effort driving the future of cybersecurity.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK tribunal greenlights $4 billion) class action lawsuit against Apple over iCloud ‘Lock-In’]]></title>
<description><![CDATA[The UK's Competition Appeal Tribunal has given the green light to a landmark collective lawsuit against Apple. The case, valued at…
The post UK tribunal greenlights $4 billion) class action lawsuit against Apple over iCloud ‘Lock-In’ appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3618374/ios-mac-os/uk-tribunal-greenlights-4-billion-class-action-lawsuit-against-apple-over-icloud-lock-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618374/ios-mac-os/uk-tribunal-greenlights-4-billion-class-action-lawsuit-against-apple-over-icloud-lock-in/</guid>
<pubDate>Tue, 23 Jun 2026 15:10:39 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The UK's Competition Appeal Tribunal has given the green light to a landmark collective lawsuit against Apple. The case, valued at…</p>
<p>The post <a href="https://macdailynews.com/2026/06/23/uk-tribunal-greenlights-4-billion-class-action-lawsuit-against-apple-over-icloud-lock-in/">UK tribunal greenlights $4 billion) class action lawsuit against Apple over iCloud ‘Lock-In’</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Risk Assumptions Are Becoming Obsolete Due to AI, Warn Five Eyes]]></title>
<description><![CDATA[AI Cyber Risk is evolving faster than many organizations can adapt, prompting a joint warning from the Five Eyes cyber security agencies. The agencies have called on business leaders, executives, and boards to act now, warning that advances in artificial intelligence are rapidly transforming the ...]]></description>
<link>https://tsecurity.de/de/3617483/it-security-nachrichten/cyber-risk-assumptions-are-becoming-obsolete-due-to-ai-warn-five-eyes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617483/it-security-nachrichten/cyber-risk-assumptions-are-becoming-obsolete-due-to-ai-warn-five-eyes/</guid>
<pubDate>Tue, 23 Jun 2026 09:35:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="AI Cyber Risk" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk.webp 1376w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-1140x636.webp 1140w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk.webp 1376w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/AI-Cyber-Risk-1140x636.webp 1140w" sizes="(max-width: 1376px) 100vw, 1376px" title="Cyber Risk Assumptions Are Becoming Obsolete Due to AI, Warn Five Eyes 1"></p>AI Cyber Risk is evolving faster than many organizations can adapt, prompting a joint warning from the Five Eyes cyber security agencies. The agencies have called on business leaders, executives, and boards to act now, warning that advances in artificial intelligence are rapidly transforming the cyber threat landscape and shortening the time available to respond to emerging risks.

In a coordinated statement, the leaders of the Five Eyes cyber security partnership said that while AI has the potential to improve defensive capabilities, it is also accelerating the speed, scale, and sophistication of cyber attacks. They cautioned that developments in Frontier AI are expected to exceed current industry expectations and could fundamentally change both offensive and defensive <a class="wpil_keyword_link" title="cyber" href="https://thecyberexpress.com/cyber-news/" data-wpil-keyword-link="linked" data-wpil-monitor-id="28797">cyber</a> operations within months rather than years.
<h3><strong>AI Cyber Risk Demands Immediate Attention</strong></h3>
The agencies stressed that AI is no longer a future consideration. According to the statement, AI is already lowering barriers for malicious actors and increasing the complexity of attacks. At the same time, it is reducing the gap between the discovery of <a class="wpil_keyword_link" title="vulnerabilities" href="https://thecyberexpress.com/what-are-vulnerabilities/" data-wpil-keyword-link="linked" data-wpil-monitor-id="28798">vulnerabilities</a> and their exploitation.

As a result, organizations are being urged to assess their readiness, understand accountability structures, and strengthen foundational <a href="https://thecyberexpress.com/8-cybersecurity-best-practices-in-2024/" target="_blank" rel="noopener">Cyber Security practices</a>. The agencies emphasized that cyber resilience should be viewed as a critical component of business continuity, market confidence, and long-term organizational value.

Leaders were encouraged to remain actively engaged as threats continue to evolve and new guidance emerges.
<h3 data-section-id="czm6ul" data-start="99" data-end="141"><strong>Frontier AI Is Accelerating Cyber Risk</strong></h3>
<p data-start="143" data-end="481">The Five Eyes agencies warned that <a href="https://www.cyber.gov.au/about-us/view-all-content/news/five-eyes-cyber-security-agencies-statement" target="_blank" rel="nofollow noopener">Frontier AI models</a> are advancing faster than many organizations anticipate and could fundamentally reshape both cyber attacks and cyber defence within months. As these systems evolve, long-standing assumptions about cyber <a class="wpil_keyword_link" title="risk" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" data-wpil-keyword-link="linked" data-wpil-monitor-id="28796">risk</a>, threat detection, and vulnerability management may quickly become outdated.</p>
<p data-start="483" data-end="1007" data-is-last-node="" data-is-only-node="">The agencies cautioned that organizations that fail to adapt could face growing operational and strategic disadvantages. They emphasized that leaders should not view AI-driven cyber risk as a future challenge but as an immediate business concern requiring proactive planning, continuous assessment, and investment in cyber resilience. As AI capabilities expand, the agencies said organizations must remain prepared for rapidly changing threats and emerging vulnerabilities that may challenge traditional <a class="wpil_keyword_link" title="security" href="https://thecyberexpress.com/" data-wpil-keyword-link="linked" data-wpil-monitor-id="28802">security</a> approaches.</p>

<h3><strong>Cyber Resilience Is a Leadership Responsibility</strong></h3>
The Five Eyes agencies stated that <a href="https://thecyberexpress.com/cyber-resilience-act-eu-adopts-new-law/" target="_blank" rel="noopener">Cyber Resilience </a>can no longer be treated solely as a technical issue. Instead, it should be considered a core <a href="https://thecyberexpress.com/artificial-intelligence-top-6-business-risks/" target="_blank" rel="noopener">Business Risk </a>and a leadership responsibility.

<a href="https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now" target="_blank" rel="nofollow noopener">According to the statement</a>, boards and executives must ensure that cyber resilience measures are not only implemented but are capable of functioning effectively during real-world incidents. The agencies noted that having security controls in place is not enough. Organizations must be confident those controls will perform under pressure.

They also called on leaders to reassess long-standing trade-offs and adopt AI deliberately to strengthen defensive capabilities rather than focusing exclusively on operational efficiency.
<h3><strong>Key Cyber Security Principles Highlighted</strong></h3>
The agencies identified several principles organizations should adopt to address evolving AI Threats.

They stated that <a href="https://thecyberexpress.com/google-2024-zero-day-exploitation-analysis/" target="_blank" rel="noopener">Secure-by-Design </a>and secure-by-default approaches should become standard practice rather than long-term goals. They also warned against relying on a single security solution, emphasizing that layered security remains essential.

The statement further noted that as AI systems continue to evolve, organizations should expect new and previously unknown vulnerabilities to emerge, including <a href="https://thecyberexpress.com/litecoin-network-zero-day-bug/" target="_blank" rel="noopener">Zero-Day Vulnerabilities</a>.

The agencies acknowledged that breaches are likely to occur and emphasized that preparedness is essential for containing incidents quickly and preventing them from escalating into larger operational and financial crises.
<h3><strong>Practical Actions for Organizations</strong></h3>
To reduce technical, operational, financial, and reputational exposure, the Five Eyes agencies outlined several practical actions.

Organizations were advised to reduce their attack surface by limiting unnecessary system access and external connectivity. They were also encouraged to accelerate patching processes, warning that AI is shortening the time available between <a class="wpil_keyword_link" title="vulnerability" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" data-wpil-keyword-link="linked" data-wpil-monitor-id="28800">vulnerability</a> disclosure and exploitation.

The agencies highlighted unsupported legacy systems as strategic liabilities that can become easy targets for attackers.

They also urged organizations to review and strengthen Identity and Access Controls, limit access to critical systems, enforce strong authentication, and regularly assess permissions.

In addition, they recommended testing <a class="wpil_keyword_link" title="Incident Response" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="28799">Incident Response</a> plans, training teams, and preparing for breaches before they occur, with a focus on rapid containment and recovery.
<h3><strong>Using AI to Strengthen Defense</strong></h3>
The agencies noted that threat actors are already using AI to improve their capabilities and increase operational speed.

As a result, defenders must also embrace AI-driven security tools. According to the statement, organizations that integrate AI into security operations can improve vulnerability detection, enhance software quality, identify unusual activity, and accelerate response efforts.

The agencies emphasized that success will not depend on having the largest number of security tools. Instead, it will come from strong fundamentals, rapid action, and integrating <a class="wpil_keyword_link" title="cyber security" href="https://thecyberexpress.com/what-is-cybersecurity/" data-wpil-keyword-link="linked" data-wpil-monitor-id="28801">cyber security</a> into core business strategy.
<h3><strong>Five Eyes Call for Collective Action</strong></h3>
The Five Eyes leaders concluded that assumptions about cyber threats can become outdated within months due to the rapid pace of <a href="https://thecyberexpress.com/study-of-ai-assisted-cyberattacks/" target="_blank" rel="noopener">AI development</a>. They urged organizations, including technology vendors, to act now, strengthen resilience, and remain prepared to adapt to changing threats.

The agencies said leaders who move quickly can reduce exposure, strengthen resilience, and build trust among customers, partners, and investors. Those who delay, they warned, face growing and avoidable risk.]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider Hackers Behind London Transport Network Breach Identified]]></title>
<description><![CDATA[Two members of the notorious Scattered Spider cybercriminal collective have pleaded guilty to orchestrating a devastating cyberattack against Transport for London (TfL), one of the UK’s most critical pieces of national infrastructure. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Wa...]]></description>
<link>https://tsecurity.de/de/3617468/it-security-nachrichten/scattered-spider-hackers-behind-london-transport-network-breach-identified/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617468/it-security-nachrichten/scattered-spider-hackers-behind-london-transport-network-breach-identified/</guid>
<pubDate>Tue, 23 Jun 2026 09:22:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two members of the notorious Scattered Spider cybercriminal collective have pleaded guilty to orchestrating a devastating cyberattack against Transport for London (TfL), one of the UK’s most critical pieces of national infrastructure. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, West Midlands, admitted their roles on June 22, 2026, at Woolwich […]</p>
<p>The post <a href="https://cyberpress.org/scattered-spider-london-transport-network-breach/">Scattered Spider Hackers Behind London Transport Network Breach Identified</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Scattered Spider Hackers Convicted Over Transport for London Cyber Attack]]></title>
<description><![CDATA[Two alleged members of the notorious Scattered Spider cybercrime collective have pleaded guilty to orchestrating a disruptive cyber attack against Transport for London (TfL). This marks a significant law enforcement victory against a group known for targeting large enterprises and…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3617331/it-security-nachrichten/two-scattered-spider-hackers-convicted-over-transport-for-london-cyber-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617331/it-security-nachrichten/two-scattered-spider-hackers-convicted-over-transport-for-london-cyber-attack/</guid>
<pubDate>Tue, 23 Jun 2026 08:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two alleged members of the notorious Scattered Spider cybercrime collective have pleaded guilty to orchestrating a disruptive cyber attack against Transport for London (TfL). This marks a significant law enforcement victory against a group known for targeting large enterprises and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/two-scattered-spider-hackers-convicted-over-transport-for-london-cyber-attack/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/two-scattered-spider-hackers-convicted-over-transport-for-london-cyber-attack/">Two Scattered Spider Hackers Convicted Over Transport for London Cyber Attack</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Scattered Spider Hackers Convicted Over Transport for London Cyber Attack]]></title>
<description><![CDATA[Two alleged members of the notorious Scattered Spider cybercrime collective have pleaded guilty to orchestrating a disruptive cyber attack against Transport for London (TfL). This marks a significant law enforcement victory against a group known for targeting large enterprises and critical infras...]]></description>
<link>https://tsecurity.de/de/3617312/it-security-nachrichten/two-scattered-spider-hackers-convicted-over-transport-for-london-cyber-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617312/it-security-nachrichten/two-scattered-spider-hackers-convicted-over-transport-for-london-cyber-attack/</guid>
<pubDate>Tue, 23 Jun 2026 07:53:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two alleged members of the notorious Scattered Spider cybercrime collective have pleaded guilty to orchestrating a disruptive cyber attack against Transport for London (TfL). This marks a significant law enforcement victory against a group known for targeting large enterprises and critical infrastructure. The UK National Crime Agency and City of London Police confirmed that Thalha […]</p>
<p>The post <a href="https://gbhackers.com/two-scattered-spider-hackers-convicted/">Two Scattered Spider Hackers Convicted Over Transport for London Cyber Attack</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Android Tablet I'd Recommend to Most People in 2026]]></title>
<description><![CDATA[Author: Shannon Morse - Bewertung: 32x - Views:149 📱 Looking for a budget Android tablet that doesn't feel cheap? The OnePlus Pad Go 2 might be one of the best values of 2026.

Buy via my affiliate links:
https://onepluscom.pxf.io/VO23rO  *
https://bestbuycreators.7tiv.net/WO23jA *
https://amzn.t...]]></description>
<link>https://tsecurity.de/de/3616896/videos/the-android-tablet-id-recommend-to-most-people-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616896/videos/the-android-tablet-id-recommend-to-most-people-in-2026/</guid>
<pubDate>Tue, 23 Jun 2026 01:47:56 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Shannon Morse - Bewertung: 32x - Views:149 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/E2-GYBeBoDU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>📱 Looking for a budget Android tablet that doesn't feel cheap? The OnePlus Pad Go 2 might be one of the best values of 2026.<br />
<br />
Buy via my affiliate links:<br />
https://onepluscom.pxf.io/VO23rO  *<br />
https://bestbuycreators.7tiv.net/WO23jA *<br />
https://amzn.to/3SFHhxD *<br />
<br />
In this review, I take a look at the OnePlus Pad Go 2, a tablet designed for streaming, multitasking, note-taking, productivity, and everyday use. With a 12.1-inch 2.8K display, 120Hz refresh rate, MediaTek Dimensity 7300 Ultra processor, Open Canvas multitasking, AI-powered features, and support for the Stylo pen, this tablet packs a surprising amount into a very affordable package.<br />
<br />
But is it worth buying, especially with questions surrounding OnePlus' North American roadmap? Let's find out!<br />
 <br />
Chapters:<br />
 Intro<br />
00:42 OnePlus Pad Go 2 Overview<br />
01:30 Display & Audio Quality<br />
03:09 Performance & Multitasking<br />
04:36 Patreon Shoutouts<br />
05:15 Ecosystem Features & Connectivity<br />
06:02 Battery Life Test Results<br />
07:30 OnePlus Stylo Pen Features<br />
08:35 AI Features & Productivity Tools<br />
10:25 Design & Build Quality<br />
11:13 Cameras & Software Support<br />
12:02 Should You Buy the OnePlus Pad Go 2?<br />
13:15 North America Availability Discussion<br />
14:02 Final Thoughts & Patreon Credits<br />
<br />
#OnePlus #OnePlusPadGo2 #AndroidTablet #TabletReview #TechReview<br />
<br />
<br />
Becoming a Morse Code Member by checking out the perks linked here!:<br />
https://www.youtube.com/channel/UCNofX8wmSJh7NTklvMqueOA/join<br />
<br />
Editor: @ColleenEdits <br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
SUBSCRIBE! 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
SUPPORT MY WORK<br />
PATREON 💛 https://www.patreon.com/ShannonMorse<br />
BUY ME A COFFEE 💛 https://www.buymeacoffee.com/snubs<br />
MY SHOP 💛 https://shannonrmorse.com/shop<br />
SPRING SHOP 💛 https://morsecode.creator-spring.com/<br />
ACTIVE COUPON CODES 💛 https://shannonrmorse.com/support<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
FOLLOW THE SOCIALS THINGS<br />
THREADS 🌸  https://www.threads.net/@snubs<br />
INSTAGRAM 🌸  http://www.instagram.com/snubs<br />
TIKTOK 🌸  https://tiktok.com/@snubsie<br />
YOUTUBE 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1<br />
WEBSITE 🌸 https://www.morsecodecreative.com/<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
TECH I USE AND RECOMMEND<br />
My Kits, Builds, and Must Haves ✨ https://kit.co/ShannonMorse<br />
My Amazon Influencer Page ✨ https://www.amazon.com/shop/shannonmorse<br />
My LiveStreaming Software ✨ https://streamyard.com/pal/d/6029725427957760<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
MY OTHER SHOWS<br />
Shannon Travels The World 🌙 https://www.youtube.com/@ShannonTravelsTheWorld/featured <br />
Sailor Snubs 🌙 https://www.youtube.com/@SailorSnubs/featured <br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
GET IN TOUCH<br />
Mail ✈ <br />
https://shannonrmorse.com/contact <br />
<br />
Email for Business and Sponsorship Inquiries ✈ Shannon@ShannonRMorse.com<br />
My Media Kit ✈ https://shannonrmorse.com/work-with-me <br />
Sponsor This Channel ✈ https://shannonrmorse.com/shannon-morse <br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
😍 FTC DISCLAIMER 😍<br />
Affiliate links listed above allow me to receive a small commission. Any sponsorships for videos are noted in video and listed in descriptions. Any products provided as gifts are listed above. Thank you for your support!<br />
<br />
Comment section code of conduct policy:<br />
Constructive feedback is appreciated, but please leave unproductive, divisive and harmful conversation at the door. Hateful comments are not tolerated, and these kinds of messages will be automatically removed. Thank you for making this community a welcoming experience for all viewers :)<br />
https://shannonrmorse.com/code-of-conduct<br />
<br />
Code of Ethics:<br />
https://www.morsecodecreative.com/code-of-ethics<br />
<br />
FTC: Links marked with * are affiliate links, which means I make a small commission off any sales.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[No Claude Fable 5? No problem: Sakana achieves frontier performance with new Fugu multi-model, auto synthesis system]]></title>
<description><![CDATA[Last night, the increasingly enterprise-focused AI startup Sakana launched Fugu, a multi-agent orchestration system that delivers frontier-level AI performance through a single, OpenAI-compatible API. Designed for developers, enterprises, and nations seeking resilience against vendor lock-in and ...]]></description>
<link>https://tsecurity.de/de/3616186/it-nachrichten/no-claude-fable-5-no-problem-sakana-achieves-frontier-performance-with-new-fugu-multi-model-auto-synthesis-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616186/it-nachrichten/no-claude-fable-5-no-problem-sakana-achieves-frontier-performance-with-new-fugu-multi-model-auto-synthesis-system/</guid>
<pubDate>Mon, 22 Jun 2026 19:03:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last night, the increasingly enterprise-focused AI startup <a href="https://sakana.ai/fugu/">Sakana launched Fugu</a>, a multi-agent orchestration system that delivers frontier-level AI performance through a single, OpenAI-compatible API. </p><p>Designed for developers, enterprises, and nations seeking resilience against vendor lock-in and geopolitical export controls, Fugu (Japanese for "pufferfish"), bypasses the traditional monolithic model structure by dynamically routing queries to a swappable pool of specialized AI agents. </p><p>Sakana CEO and co-founder David Ha, formerly of Google Brain, positioned Fugu as a more reliable option for enterprise workflows than any single AI model provider in the wake of<a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do"> Anthropic's move on June 12 to revoke public access</a> to its most powerful models, Claude Mythos 5 and Claude Fable 5, in the wake of a U.S. government export control order. As <a href="https://x.com/hardmaru/status/2068884466056225025">Ha wrote in a post today on X:</a></p><blockquote><p>"Fugu dynamically orchestrates the world’s best models to tackle complex tasks. We are proving that a well-orchestrated pool of swappable agents can match restricted frontier models like Fable and Mythos.

But Fugu is about more than just performance. I believe that Orchestration Models are the next frontier, beyond bigger models.

Relying on a single company’s model for national infrastructure is a massive risk. As recent export controls have shown, access to top models can disappear overnight.

Collective intelligence is the practical hedge against this concentration of power. Fugu simply routes around vendor restrictions by relying on an entirely swappable agent pool."</p></blockquote><p>Sakana AI explicitly states that the specific models Fugu selects and how it coordinates them are proprietary, meaning this routing information is hidden from the user by design. The documentation only refers generally to a "diverse pool of powerful models," "multiple LLMs," or "specialized models" without providing a specific count.</p><p>By acting as a sophisticated coordinator rather than a standalone foundation model, Fugu matches the output quality of top-tier models like Fable and Mythos on third-party benchmarks of agentic tasks, while fundamentally altering how developers deploy critical AI infrastructure.</p><h2><b>How Sakana Fugu works and where it beats Anthropic's Claude Fable 5</b></h2><p>At its core, Sakana Fugu operates like a master general contractor. When presented with a complex request, Fugu does not attempt to execute every step itself. </p><p>Instead, it breaks the problem down, delegates sub-tasks to a pool of expert foundation models, verifies their work, and synthesizes the final output.</p><p>"Fugu is itself an LLM, trained to call various LLMs in an agent pool, including instances of itself recursively," the Sakana AI team noted in their technical release. </p><p>Grounded in two of Sakana's 2026 research papers, <a href="https://sakana.ai/trinity/">TRINITY</a> and the <a href="https://sakana.ai/learning-to-orchestrate/">Conductor</a>, the system autonomously manages the entire lifecycle of model selection and verification using learned coordination strategies rather than hand-designed workflows. To the end user, this multi-agent swarm is entirely abstracted behind a standard API endpoint.</p><p>Sakana AI is offering two variants of the system to cater to different operational workloads:</p><ul><li><p><b>Fugu:</b> A high-speed, low-latency model optimized for everyday tasks. It is designed to act as the default engine for interactive chatbots and integrates directly into coding environments like Codex.</p></li><li><p><b>Fugu Ultra:</b> The flagship tier engineered for complex, high-stakes tasks such as AI research, cybersecurity analysis, and multi-step patent investigations. According to Sakana, Fugu Ultra coordinates a deeper pool of experts and matches industry-leading monolithic models across rigorous scientific and reasoning benchmarks.</p></li></ul><p>Additionally, on the pay-as-you-go plan, standard Fugu charges a dynamic rate based on the specific underlying models activated, whereas Fugu Ultra utilizes a fixed pricing structure starting at $5 per million input tokens and $30 per million output tokens.</p><p>As indicated by benchmark charts shared by Sakana, Fugu actually exceeds the performance of Anthropic's Claude Fable 5 on <a href="https://huggingface.co/blog/leaderboard-livecodebench">LiveCodeBench</a>, an open source benchmark testing coding performance on regularly refreshed, software problem-solving tasks (Fugu Ultra: 93.2, Fugu: 92.9, Fable: 89.8), and beats the prior Claude Mythos Preview model on <a href="https://epoch.ai/benchmarks/gpqa-diamond">GPQA-D (Diamond)</a> , a test of 198 graduate-level multiple-choice questions in biology, physics, and chemistry (Fugu Ultra: 95.5, Fugu: 95.5, Mythos Preview: 94.6).</p><p>By orchestrating multiple models from different providers, Fugu essentially builds native redundancy into the AI stack. If one provider suffers an outage or faces sudden regulatory restrictions, Fugu routes around the disruption to maintain uptime.</p><h2><b>Licensing and availability</b></h2><p>Fugu is offered as a commercial, proprietary API service, not an open-source framework. </p><p>Because Sakana’s core intellectual property lies in its non-obvious collaboration patterns, the specific routing information—meaning exactly which underlying models Fugu selects for a given query—remains proprietary and is intentionally hidden from the user.</p><p>However, Sakana offers critical controls for enterprise data compliance. Developers can explicitly opt specific models or providers out of their Fugu routing pool to maintain strict corporate privacy standards. </p><p>Additionally, users can opt out of having their prompts used for future training data. Geographically, Fugu is restricted from operating within the European Union (EU) and European Economic Area (EEA) while Sakana works to align its black-box data routing architecture with GDPR regulations.</p><h2><b>Pricing is fairly steep</b></h2><p>Fugu is available immediately in most regions—with the temporary exception of the EU and EEA—at subscription tiers and pay-as-you-go pricing.</p><p>Teams can opt for monthly <a href="https://sakana.ai/fugu/">subscription allowances </a>designed for individual or hands-on use: a Standard tier at $20/month for lightweight workflows, a Pro tier at $100/month providing 10x standard usage, and a Max tier at $200/month offering 20x usage for continuous, long-running tasks. I wasn't able to find the actual amount of tokens covered under these plans, but I've reached out to Ha on X for more information.</p><p>As part of the initial rollout, Sakana is offering a free second month for users who subscribe to any tier by July 31, 2026.</p><p>For enterprise scaling and production deployments, Sakana offers an elastic pay-as-you-go plan. Crucially for high-stakes environments, requests made under this consumption-based model are served at a higher priority than those from monthly subscription plans. </p><p>Under this framework, the standard Fugu engine charges the single rate of the highest-tier underlying model involved in a query, without ever stacking multi-agent fees. The flagship Fugu Ultra tier (fugu-ultra-20260615) utilizes a fixed pricing structure per one million tokens: $5 for input, $30 for output, and $0.50 for cached input. These rates increase to $10, $45, and $1.00 respectively for extreme workloads utilizing context windows above 272K tokens. That puts it among the more expensive options compared to single AI models via provider APIs:</p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p>DeepSeek</p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p>DeepSeek</p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p>MiniMax</p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p>Google</p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p>Alibaba Cloud</p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p>xAI</p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p>Moonshot</p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p>Z.ai</p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p>xAI</p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p>Alibaba Cloud</p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p>Google</p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p>Google</p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p>OpenAI</p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p>Google</p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p>Anthropic</p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p>OpenAI</p></td></tr><tr><td><p><b>Sakana Fugu Ultra</b></p></td><td><p><b>$5.00</b></p></td><td><p><b>$30.00</b></p></td><td><p><b>$35.00</b></p></td><td><p><b>Sakana AI</b></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p>Anthropic</p></td></tr></tbody></table><p>Developers modeling operational costs should also note a significant architectural caveat in how Fugu bills for its multi-agent capabilities. According to the developer documentation, Fugu Ultra’s API responses include detailed usage fields that separate user-visible token generation from internal orchestration work. The background tokens consumed and generated when Fugu delegates sub-tasks, verifies code, or routes between underlying agents are not absorbed by the provider; they represent real token usage and are counted toward the final price of the request at standard rates.</p><h2><b>The Orchestration landscape: Fugu vs. The Field and notable benchmark performance</b></h2><p>To understand Fugu’s position in the mid-2026 AI ecosystem, it is critical to distinguish between <i>model routing</i> and <i>multi-agent orchestration</i>. </p><p>Over the past year, enterprise adoption of standard routing platforms—such as Not Diamond, Martian, and the open-source RouteLLM framework—has skyrocketed. These systems act as intelligent air traffic controllers; using semantic classifiers or meta-models, they analyze an incoming prompt and predict which single foundation model will yield the highest quality or most cost-effective response, dispatching the query accordingly.</p><p>Fugu operates on a fundamentally different paradigm. Rather than making a one-shot routing decision, Fugu aligns more closely with complex multi-round systems like Router-R1 (a framework introduced at NeurIPS 2025). It breaks a query down, interleaves reasoning with delegation, and dynamically assigns sub-tasks to multiple models in parallel or sequence before synthesizing a final output.</p><p>While frameworks like LangGraph, CrewAI, and Microsoft AutoGen offer developers the tools to build similar multi-agent systems, they require immense manual configuration—defining roles, setting up conditional edges, and managing state across long-running loops. </p><p>Fugu abstracts this operational overhead entirely. It is essentially a LangGraph-style workflow packaged as a single, black-box API endpoint.</p><p>An orchestration system is ultimately bounded by the raw capabilities of the underlying models in its pool, a reality reflected in Sakana’s own benchmark testing against standalone frontier models.</p><p>On rigorous coding and agentic tasks, collective intelligence shows a distinct advantage over standard models. Fugu Ultra posted a <b>73.7 on SWE-Bench Pro</b>, significantly outperforming Anthropic's Claude Opus 4.8 (69.2) and OpenAI's GPT-5.5 (58.6). </p><p>However, Fugu is not a silver bullet, and its performance is not a clean sweep across the board. When compared to highly specialized or restricted-access monolithic models, Fugu occasionally trails:</p><ul><li><p><b>SWE-Bench Pro:</b> While Fugu Ultra (73.7) beat most accessible models, it was comfortably eclipsed by Anthropic’s limited-access Fable 5 (80.0), which is currently absent from Fugu's swappable pool due to the U.S. government's export control order and Anthropic's subsequent response to remove the model entirely from global usage. </p></li><li><p><b>Humanity's Last Exam:</b> Fugu Ultra (50.0) narrowly edged out Opus 4.8 (49.8), but again fell short of Fable 5 (53.3).</p></li><li><p><b>Long-Context and Security:</b> On the MRCRv2 long-context-recall test, OpenAI's GPT-5.5 maintained the lead (94.8 vs Fugu Ultra's 93.6), and Opus 4.8 remained the top performer on the CTI-REALM cybersecurity benchmark (69.6 vs Fugu Ultra's 69.4).</p></li></ul><p>The quantitative data points to a clear conclusion: Fugu is highly effective at boosting performance on messy, multi-step tasks (like writing a complex HTML5 game from scratch) by leaning on the combined strengths of multiple mid-tier and high-tier models. </p><p>However, for sheer brute-force reasoning within a single, highly constrained domain, the industry's largest standalone models still hold the edge—provided an enterprise can maintain uninterrupted access to them.</p><h2><b>Background on Sakana's formation and noteworthy achievements to date</b></h2><p><a href="https://venturebeat.com/ai/what-you-need-to-know-about-sakana-ai-the-new-startup-from-a-transformer-paper-co-author">Sakana AI was formed in Tokyo in 2023 </a>by Llion Jones, a co-author of Google’s foundational 2017 "Attention Is All You Need" paper, and David Ha, the former head of research at Stability AI. </p><p>Disillusioned by large tech company bureaucracy and the industry's hyper-fixation on scaling single, massive foundational models, the founders built Sakana around principles of biomimicry and evolutionary computing.</p><p>The company's name, derived from the Japanese word for fish, reflects its core technical thesis: utilizing collective "swarm" intelligence rather than brute-force compute. Following a $2.6 billion Series B valuation in late 2025 and <a href="https://venturebeat.com/technology/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours">the recent June 2026 launch of Marlin</a>—an autonomous, eight-hour research agent for the B2B sector—Fugu represents the commercialization of Sakana's multi-agent routing technology for everyday developers.</p><h2><b>A mixed reception among the broader AI community online</b></h2><p>The developer community has responded to Fugu by rigorously testing its practical tradeoffs, weighing its routing efficiencies against the sheer power of monolithic foundation models.</p><p>AI observer, developer and influencer <a href="https://x.com/ChrissGPT/status/2068904825685787083?s=20">Chris (@ChrissGPT on X)</a> highlighted the specific utility of Fugu over raw foundational AI. </p><p>"For a single clean prompt, you probably would [use Fable 5, Mythos, or GPT-5.5 directly]," he noted, but argued that Fugu's true value emerges in messy, multi-step environments. "...whether it involves delegation, verification, synthesis, code review, research loops, security analysis... the more it would make sense to use this," he wrote.</p><p>Chris also pointed out the strategic geopolitical advantage of Fugu's architecture, noting that if frontier AI access is abruptly revoked due to regulation or export controls, an orchestrator can dynamically swap models to prevent a total system failure.</p><p>Creative agency owner <a href="https://x.com/markksantos/status/2068962823007285628?s=20">Mark Santos (@markksantos) </a>of Mark Studios provided a direct, real-world comparison by tasking both Fugu Ultra and Claude Opus 4.8 with building a "Crossy Road" game clone using Three.js. The results underscored the operational differences between an orchestrator and a monolithic giant:</p><ul><li><p><b>Sakana Fugu Ultra:</b> Completed the task in 22 minutes using ~89,000 tokens for roughly $7.32. However, the final game suffered from minor logic errors, such as inverted directional turns and wonky camera angles.</p></li><li><p><b>Claude Opus 4.8:</b> Took 79 minutes, burned ~940,000 tokens for nearly $37.85, and got stuck in a retry loop requiring human intervention. Despite the inefficiency, it ultimately produced superior application design and functionality.</p></li></ul><p>Santos concluded the experiment by stating, "In terms of application functionality, quality, and design, Opus won. In terms of model speed and performance, Fugu... won".</p><p>Elie Bakouch, a research engineer at cloud-based, open AI infrastructure and systems provider <a href="https://www.primeintellect.ai/">Prime Intellect</a>, <a href="https://x.com/eliebakouch/status/2068939729811468503">pointed out on X</a> that "to be clear, this is a closed source orchestrator on top of closed source models. if before you didn't control the models, now you don't even control which ones are used or how much. this is not 'AI sovereignty'..."</p><div></div><p>These early tests and reactions mirror the sentiment summarized by <a href="https://www.reddit.com/r/LLMDevs/comments/1uca8e3/comment/ot2k0kx/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button">Reddit user GreedyWorking1499</a> in initial platform discussions: "<i>Until proven otherwise, this is just a highly advanced router/wrapper, not a fundamental not a fundamental leap in intelligence like Mythos/Fable was.</i>"</p><p>Yet, as enterprises increasingly demand fail-safes against single-vendor reliance, Sakana is proving that packaging collective intelligence into a single API endpoint is a highly viable commercial path.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why agentic enterprises need to become learning systems]]></title>
<description><![CDATA[Presented by SplunkEvery day, organizations learn things their AI systems never get to use.A security analyst corrects an AI-generated investigation. A network engineer identifies the root cause of a recurring outage. An observability team discovers that a pattern of latency, logs and infrastruct...]]></description>
<link>https://tsecurity.de/de/3616012/it-nachrichten/why-agentic-enterprises-need-to-become-learning-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616012/it-nachrichten/why-agentic-enterprises-need-to-become-learning-systems/</guid>
<pubDate>Mon, 22 Jun 2026 17:48:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Splunk</i></p><hr><p>Every day, organizations learn things their AI systems never get to use.</p><p>A security analyst corrects an AI-generated investigation. A network engineer identifies the root cause of a recurring outage. An observability team discovers that a pattern of latency, logs and infrastructure changes predicts service degradation. A customer operations team learns which signals indicate an escalation is likely.</p><p>Each moment contains valuable organizational knowledge. But in most enterprises, that knowledge disappears into tickets, dashboards, chat threads, post-incident reviews and the minds of individual experts. It may help solve the immediate problem, but it rarely becomes part of a reusable system that improves future AI-driven decisions.</p><p>That is the next challenge for the agentic enterprise.</p><p>The future will not be defined simply by who has the most capable model or the most autonomous agents. Many organizations will have access to similar frontier models. Many will deploy agents across security, IT, engineering, customer service, and business operations.</p><p>The real differentiator will be whether those agents can learn from the organization around them.</p><p>Not by constantly retraining the underlying model, but by capturing operational experience, converting it into institutional knowledge and making that knowledge available to future agents, workflows, and decisions.</p><p>The agentic enterprise is not just an enterprise that uses AI. It is an enterprise that learns through AI.</p><h2>Agentic enterprises allow AI systems to learn from them</h2><p>The AI conversation has been dominated by model capability: larger context windows, better reasoning, faster inference, stronger tool use, and more sophisticated agentic behavior.</p><p>Those advances matter. But in the enterprise, a model is only one part of the system.</p><p>A model does not automatically know how a specific organization operates. It does not inherently know which remediation step solved last month’s outage, which analyst correction improved a threat investigation, which network signal preceded a service disruption, or which internal policy should override an otherwise plausible recommendation.</p><p>That knowledge belongs to the enterprise.</p><p>For agentic systems to improve, organizations need a way to capture that knowledge and make it reusable. In many cases, that does not require changing the model itself. It requires changing the ecosystem around the model: the knowledge base, retrieval layer, prompts, policies, guardrails, routing logic and workflows that shape how agents behave.</p><p>The model may remain the same. The learning system around it becomes smarter.</p><h2>Feedback loops turn every outcome into a teachable moment for agents</h2><p>Every agentic workflow creates signals.</p><p>An agent receives a request. It retrieves context, reasonsthrough possible actions, calls tools, and generates answers. A human accepts, rejects, or modifies that answer. Downstream systems reveal whether the action worked.</p><p>That entire chain is valuable.</p><p>AI observability gives organizations visibility into what happened: the prompt, response, reasoning path, tool calls, data sources, intermediate steps, failure modes and outcomes. Without that visibility, organizations cannot understand why an agent behaved the way it did, let alone improve it.</p><p>But observability alone is not enough.</p><p>The larger opportunity is to turn observed behavior into institutional knowledge. A trace should not only help a developer and operators debug an agent. It should help the enterprise understand what the agent learned, what the human corrected, what outcome followed, and what should change before the next similar event.</p><p>That is the shift from monitoring AI to teaching AI.</p><p>In the agentic enterprise, feedback loops connect action to outcome, outcome to knowledge and knowledge back to future action.</p><h2>A learning system in practice across security, observability and the network</h2><p>Consider a service experiencing intermittent degradation.</p><p>An observability agent detects unusual latency and error rates. A network agent identifies packet loss across a specific path. A security agent notices that the same time window includes suspicious authentication behavior and unusual traffic from a previously unseen source.</p><p>Individually, each agent has only a partial view. Together, they create a richer operational picture.</p><p>The first time this incident occurs, human experts may need to intervene. A network engineer confirms that packet loss was caused by a misconfigured routing change. A security analyst determines that the suspicious traffic was not an attack, but a side effect of a misrouted internal service. An SRE connects the network event to the application degradation.</p><p>That resolution contains knowledge the organization should not have to relearn.</p><p>A mature agentic learning system would capture the traces, human corrections, topology context, security findings, observability signals and final remediation steps. It would preserve the relationship between those signals: latency pattern, network path, identity behavior, routing change and remediation.</p><p>The next time a similar pattern appears, agents would not start from zero. They could retrieve the prior case, compare current conditions, recommend the proven diagnostic path and escalate with better context.</p><p>The underlying frontier model did not need to be retrained.</p><p>The enterprise learned.</p><h2>The architecture of the learning agentic enterprise</h2><p>A learning-oriented agentic enterprise needs more than a model or chatbot. It needs an architecture that can capture experience, turn it into usable knowledge, connect that knowledge to operational context, and govern how it changes future agent behavior.</p><p><b>Memory </b>preserves what happened: what the agent saw, what it did, where humans intervened, and what outcomes followed.</p><p><b>Knowledge bases</b> turn that experience into reusable guidance, including playbooks, examples, policies, procedures, and evidence.</p><p>A <b>data fabric </b>connects the operational environment. The signals agents need live across logs, metrics, traces, tickets, identity systems, security tools, network telemetry, collaboration platforms, and business applications. A data fabric makes those signals discoverable, correlated, governed, and usable in context.</p><p><b>AI observability </b>explains how agents behave by capturing prompts, tool calls, intermediate steps, responses, feedback, and outcomes. That visibility helps organizations understand where agents succeed, where they fail, and what should improve.</p><p>The <b>control plane</b> governs how learning becomes change: what knowledge is promoted, which prompts or policies are updated, which agents can use new information, what approvals are required, and how changes are audited.</p><p>Together, these capabilities allow AI systems to improve over time in a controlled, trustworthy way that allows the enterprise to learn from its own operations.</p><h2>The organizations that learn fastest will win </h2><p>The next era of AI will not be won by models alone. It will be won by organizations that can capture what they learn from every workflow, expert correction, incident, investigation, and outcome.</p><p>The most advanced agentic enterprises will not simply deploy more agents. They will build systems that allow every agent to benefit from the collective knowledge of the organization.</p><p>That means connecting operational data through a data fabric. It means observing agent behavior deeply enough to understand it. It means preserving experience in memory and institutionalizing it in knowledge bases. It means using a control plane to govern how learning changes agent behavior.</p><p>The future of AI is not a single autonomous agent acting alone. It is an ecosystem of agents, humans, data and controls that learns over time.</p><p>The organizations that build that ecosystem will create AI systems that get better with every interaction. Not because the model is constantly changing, but because the enterprise itself is becoming more intelligent.</p><p><i>Learn more about how </i><a href="https://www.splunk.com/ciscodatafabric"><i>Cisco Data Fabric powered by the Splunk Platform</i></a><i> is accelerating agentic operations.</i></p><p><i>Hao Yang is Vice President AI at Splunk, a Cisco Company.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canvas-Hack legt Hochschulen lahm – Risiken für EdTech und Daten - it boltwise]]></title>
<description><![CDATA[KALIFORNIEN / LONDON (IT BOLTWISE) – Ein Hackerangriff auf Canvas hat in Kalifornien zeitweise den Zugriff auf Lernmaterial, Tests und ...]]></description>
<link>https://tsecurity.de/de/3615418/hacking/canvas-hack-legt-hochschulen-lahm-risiken-fuer-edtech-und-daten-it-boltwise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615418/hacking/canvas-hack-legt-hochschulen-lahm-risiken-fuer-edtech-und-daten-it-boltwise/</guid>
<pubDate>Mon, 22 Jun 2026 14:25:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KALIFORNIEN / LONDON (IT BOLTWISE) – Ein <b>Hacker</b>angriff auf Canvas hat in Kalifornien zeitweise den Zugriff auf Lernmaterial, Tests und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[When trust becomes the attack surface]]></title>
<description><![CDATA[Following the ransomware attack involving stolen student data, the company behind Canvas has now confirmed it paid the hackers in exchange for the return of the information.]]></description>
<link>https://tsecurity.de/de/3615066/it-nachrichten/when-trust-becomes-the-attack-surface/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615066/it-nachrichten/when-trust-becomes-the-attack-surface/</guid>
<pubDate>Mon, 22 Jun 2026 12:02:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Following the ransomware attack involving stolen student data, the company behind Canvas has now confirmed it paid the hackers in exchange for the return of the information.]]></content:encoded>
</item>
<item>
<title><![CDATA[Canvas-Hack legt Hochschulen lahm – Risiken für EdTech und Daten]]></title>
<description><![CDATA[KALIFORNIEN / LONDON (IT BOLTWISE) – Ein Hackerangriff auf Canvas hat in Kalifornien zeitweise den Zugriff auf Lernmaterial, Tests und Kommunikation zwischen Studierenden und Lehrenden gekappt. Betroffen waren laut Berichten mehrere Hochschulsysteme mit insgesamt potenziell mehr als einer Million...]]></description>
<link>https://tsecurity.de/de/3614563/it-security-nachrichten/canvas-hack-legt-hochschulen-lahm-risiken-fuer-edtech-und-daten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614563/it-security-nachrichten/canvas-hack-legt-hochschulen-lahm-risiken-fuer-edtech-und-daten/</guid>
<pubDate>Mon, 22 Jun 2026 07:38:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-canvas-outage-cybersecurity.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-canvas-outage-cybersecurity.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-canvas-outage-cybersecurity-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-canvas-outage-cybersecurity-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-canvas-outage-cybersecurity-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-canvas-outage-cybersecurity-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-canvas-outage-cybersecurity-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">KALIFORNIEN / LONDON (IT BOLTWISE) – Ein Hackerangriff auf Canvas hat in Kalifornien zeitweise den Zugriff auf Lernmaterial, Tests und Kommunikation zwischen Studierenden und Lehrenden gekappt. Betroffen waren laut Berichten mehrere Hochschulsysteme mit insgesamt potenziell mehr als einer Million Lernenden. Inzwischen meldet der Betreiber eine Einigung mit der Angreifergruppe und verweist auf unkritische Beeinträchtigungen zentraler […]</p>
<div><a href="https://www.it-boltwise.de/canvas-hack-legt-hochschulen-lahm-risiken-fuer-edtech-und-daten.html">... den vollständigen Artikel <strong>»Canvas-Hack legt Hochschulen lahm – Risiken für EdTech und Daten«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/canvas-hack-legt-hochschulen-lahm-risiken-fuer-edtech-und-daten.html">Canvas-Hack legt Hochschulen lahm – Risiken für EdTech und Daten</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Is Closing Three US Stores Today Amid Mall Decline and Union Dispute]]></title>
<description><![CDATA[Apple is permanently closing three retail stores in the United States on Saturday, June 20, after citing weaker mall conditions and the departure of major retailers from those shopping centers.



The affected stores are:




Apple Towson Town Center in Towson, Maryland, closing at 8 p.m.



Appl...]]></description>
<link>https://tsecurity.de/de/3612701/ios-mac-os/apple-is-closing-three-us-stores-today-amid-mall-decline-and-union-dispute/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612701/ios-mac-os/apple-is-closing-three-us-stores-today-amid-mall-decline-and-union-dispute/</guid>
<pubDate>Sat, 20 Jun 2026 21:53:26 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is permanently closing three retail stores in the United States on Saturday, June 20, after citing weaker mall conditions and the departure of major retailers from those shopping centers.



The affected stores are:




Apple Towson Town Center in Towson, Maryland, closing at 8 p.m.



Apple North County in Escondido, California, closing at 9 p.m.



Apple Trumbull in Trumbull, Connecticut, closing at 9 p.m.




Apple said in April that it had decided after reviewing conditions at Trumbull Mall, the Shops at North County, and Towson Town Center. The company said these malls have seen retail exits and declining conditions, which affected its ability to serve customers well at those locations.



The Towson closure has drawn the most attention because employees at that store became Apple’s first unionized retail workers in the United States in 2022. The staff later signed a collective bargaining agreement with Apple in 2024.



The union has criticized Apple because workers at the non-union Trumbull and North County stores can transfer to nearby Apple locations, while Towson employees must follow the terms of their union agreement and apply for open roles.



Apple says the agreement provides transfers or rehiring only if the company opens a new store within 50 miles of Towson Town Center. Since Apple has no current plan for a new nearby store, the company says affected workers will receive severance.



The closures also reflect broader pressure on struggling malls, but the Towson case has turned the decision into a larger labor issue for Apple.]]></content:encoded>
</item>
<item>
<title><![CDATA[US should take 50% stake in major AI firms, says Bernie Sanders]]></title>
<description><![CDATA[With the market capitalization of AI companies soaring, US Senator Bernie Sanders is looking to give the American people a piece of the action.



The veteran senator for Vermont has introduced the American AI Sovereign Wealth Fund Bill, aiming to give the public a 50 percent ownership in the lar...]]></description>
<link>https://tsecurity.de/de/3610952/it-nachrichten/us-should-take-50-stake-in-major-ai-firms-says-bernie-sanders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610952/it-nachrichten/us-should-take-50-stake-in-major-ai-firms-says-bernie-sanders/</guid>
<pubDate>Fri, 19 Jun 2026 18:48:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With the market capitalization of AI companies soaring, US Senator Bernie Sanders is looking to give the American people a piece of the action.</p>



<p>The veteran senator for Vermont has introduced the <a href="https://www.sanders.senate.gov/wp-content/uploads/AmericanAIWealthFundTextv618.pdf" target="_blank" rel="noreferrer noopener">American AI Sovereign Wealth Fund Bill</a>, aiming to give the public a 50 percent ownership in the largest AI companies in the US. It’s a timely move with both OpenAI and Anthropic preparing for the imminent IPOs.</p>



<p>Sanders is not the only one pondering such a move. As the bill notes, <a href="https://www.computerworld.com/article/4155108/openai-wants-a-four-day-workweek-and-a-robot-tax.html">OpenAI has proposed the creation of a “Public Wealth Fund”</a> giving citizens a stake in “AI-driven economic growth,” while Anthropic has proposed a sovereign wealth fund to “shape the sector’s behavior.” President Trump’s advisors are also contemplating the possibility of the government grabbing a stake in major AI corporations, according to <a href="https://www.semafor.com/article/06/17/2026/trump-advisers-weigh-structure-of-potential-ai-stakes" target="_blank" rel="noreferrer noopener">media reports</a>.</p>



<p>Sovereign wealth funds are not a new idea: Many administrations across the world have implemented them, notably Norway which has <a href="https://fortune.com/europe/2025/07/30/how-sparsely-populated-norway-amassed-1-8-trillion-sovereign-wealth-fund/">about $2 trillion in its wealth fund</a>.</p>



<p>Sanders’ proposal would give the public a direct ownership stake in the largest AI companies, but, he said, it wasn’t just about the wealth. “The foundation of AI is based on the collective knowledge of humanity and the creative work of tens of millions of people. The American people must have the ability to slow it down and make sure that AI benefits humanity, not just the richest people on the planet. That’s precisely what this legislation does,” he said.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s Fable and the State of AI]]></title>
<description><![CDATA[On June 9th, Anthropic released its Fable generative AI model. Three days later, the US government classified it as a dangerous munition, and used its export-control authority to prohibit any foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, the compan...]]></description>
<link>https://tsecurity.de/de/3610146/it-security-nachrichten/anthropics-fable-and-the-state-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610146/it-security-nachrichten/anthropics-fable-and-the-state-of-ai/</guid>
<pubDate>Fri, 19 Jun 2026 13:08:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>On June 9th, Anthropic <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">released</a> its Fable generative AI model. Three days later, the US government <a href="https://www.explainx.ai/blog/us-government-bans-fable-5-mythos-5-anthropic-export-control-2026">classified</a> it as a dangerous munition, and used its export-control authority to <a href="https://www.theguardian.com/technology/2026/jun/13/anthropic-disable-advanced-ai-models-us-government-order">prohibit</a> any foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, the company <a href="https://www.anthropic.com/news/fable-mythos-access">shut off</a> access for everyone.</p>
<p>The government’s actions <a href="https://freefable.org/">won’t help</a>. The problem isn’t any one particular model; it’s the general trend of increasing AI capabilities. And any real solution requires the sort of collective action that just isn’t possible right now...</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's Claude Code Artifacts update brings live, shared dashboards and interactive workspaces to enterprises]]></title>
<description><![CDATA[Anthropic announced a potentially game-changing new feature for users of Claude Code on the Claude Team and Enterprise subscription plans: Artifacts. This update turns a Claude Code session's work into a live, interactive, and shareable, custom HTML webpage, allowing a Claude Code user to plug in...]]></description>
<link>https://tsecurity.de/de/3609186/it-nachrichten/anthropics-claude-code-artifacts-update-brings-live-shared-dashboards-and-interactive-workspaces-to-enterprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609186/it-nachrichten/anthropics-claude-code-artifacts-update-brings-live-shared-dashboards-and-interactive-workspaces-to-enterprises/</guid>
<pubDate>Fri, 19 Jun 2026 02:47:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic announced a potentially game-changing new feature for users of Claude Code on the Claude Team and Enterprise subscription plans: <a href="https://claude.com/blog/artifacts-in-claude-code">Artifacts</a>. </p><p>This update turns a Claude Code session's work into a live, interactive, and shareable, custom HTML webpage, allowing a Claude Code user to plug in live code, multiple data sources, and have it surface on an interactive URL that they can send to other teammates — be it a dashboard, an app design, or some other product meant for internal usage. </p><div></div><p>These teammates and the original user can watch the webpage it update in real-time as Claude Code goes about its work autonomously or under the user's guidance, and as the connected data sources and codebases change. </p><p>While Anthropic first introduced Artifacts to its consumer web chatbot in the summer of 2024—where it evolved from a manual toggle feature to a generally available tool for publishing code snippets and games to the web—integrating this capability directly into the Claude Code command-line interface (CLI) and desktop app bridges the gap between deep, back-end engineering and the non-technical stakeholders who need to understand it.</p><h2><b>Product and Technology: The End of the Status Update</b></h2><p>At its core, Claude Code Artifacts acts as a dynamic translation layer. Built directly from the unbroken context of a user’s session, the agent uses the local repository codebase, connected monitoring tools, and conversational reasoning to spin up specialized web pages. </p><p>Engineers no longer need to wire up external data sources or stand up temporary infrastructure; the AI builds the UI from what already exists.</p><p>Crucially, these web pages are not static exports. As the AI works through a terminal session, the open webpage refreshes in-place, updating charts and text instantly at the exact same URL. Every update publishes a new version history, allowing teammates to roll back or track the agent's progress securely on desktop or mobile.</p><h2><b>The Battle of Live, Interactive, Shared AI Work Surfaces: Anthropic's Claude Code Artifacts vs. OpenAI's Codex Sites</b></h2><p>Anthropic's update comes more than <a href="https://venturebeat.com/orchestration/openais-codex-update-lets-agents-build-interactive-enterprise-workspaces-via-sites-and-role-specific-plugins">two weeks after OpenAI released a massive update to its own Codex platform</a>, introducing a strikingly similar enterprise hosting feature called "Sites". </p><p>This tit-for-tat product cadence highlights a rapidly escalating battle over the enterprise workspace across functions and beyond developers themselves, though there are some important technical and philosophical distinctions worth pointing out for enterprises considering either.  </p><p>As revealed in their respective developer documentation webpages, <a href="https://developers.openai.com/codex/sites">OpenAI</a> is building a platform-as-a-service; <a href="https://code.claude.com/docs/en/artifacts#share-session-output-as-artifacts">Anthropic</a> is building a stateless canvas.</p><p>OpenAI’s Sites is designed to generate durable, full-stack web applications. According to the platform's documentation, Codex Sites hosts projects that output as Cloudflare Worker-compatible ES modules. </p><p>Crucially, Sites supports persistent backend infrastructure: agents can automatically wire up "D1" relational databases for structured data (like user progress or saved records) and "R2" object storage for file uploads. An OpenAI Site can support public sign-ins, integrate with external identity providers, and allows for highly specific access controls tailored to specific workspace groups. </p><p>It utilizes a two-stage publishing process—saving a reviewable candidate linked to a Git commit before officially deploying to production. In short, it is a production environment designed to replace functional internal SaaS tools.</p><p>Anthropic’s Claude Code Artifacts, by contrast, deliberately avoids the backend. The newly released documentation is blunt about its limitations: "An artifact is a capture of work, not an application". </p><p>Each Artifact is a single, self-contained HTML page capped at a rendered size of 16 MiB. To guarantee organizational security, Claude wraps the published file in a strict Content Security Policy (CSP) that blocks all external network requests. T</p><p>his means the page cannot load external scripts, fonts, or stylesheets, and <code>fetch</code>, XHR, and WebSocket calls are completely blocked. All CSS and JavaScript must be inlined, and images must be embedded as data URIs. Artifacts cannot store form input, call an API at view time, or serve multiple routes.</p><p>This technical limitation is actually Anthropic's deliberate philosophical position: While OpenAI wants to spin up persistent software portals for the whole company, Anthropic is keeping Claude Code firmly anchored in ephemeral, highly secure technical workflows. Claude Artifacts are <i>not</i> meant to be software; they are meant to replace whiteboard diagrams, manual bug walkthroughs, and status reports with secure, self-updating visual tools that never leak live data outside the corporate boundary.</p><h2><b>Licensing and Enterprise Security: Keeping the Codebase Private</b></h2><p>Because these agents sit at the nexus of proprietary company data and live codebases, licensing and access controls are a primary concern. </p><p>Both Anthropic and OpenAI have opted for closed, proprietary licensing models for these new visual workspaces. For end users and developers, the distinction is critical. Unlike permissive open-source software (such as MIT or Apache 2.0) or strict copyleft licenses (like GPL)—which grant developers the legal freedom to inspect, modify, and self-host the underlying code—neither Claude Code Artifacts nor Codex Sites can be independently forked or hosted. </p><p>Enterprise clients do not maintain code-level ownership over Anthropic's rendering engine or Codex’s integration nodes; both operate strictly within their <i>respective creators' managed infrastructures.</i></p><p>To make this vendor-managed approach palatable to enterprise compliance teams, both companies have heavily prioritized organizational security. Anthropic ensures every artifact is private to its author by default and strictly cannot be made public to the broader internet. When an engineer chooses to share a link, it is viewable exclusively by authenticated members of their specific organization. System administrators retain ultimate authority, managing access through org-level toggles, role-based scoping, and explicit retention policies, while maintaining oversight through a centralized compliance API.</p><p>OpenAI takes a similarly gated approach with Codex Sites, rolling the feature out primarily for ChatGPT Business and Enterprise workspaces. Like Anthropic, OpenAI relies on system administrators to manage deployment through centralized workspace settings, requiring an admin to explicitly enable Sites via role-based access control (RBAC) for Enterprise tiers.</p><p>However, because Codex Sites functions more like a hosted web application, its access controls are slightly more granular. When an engineer prepares to share a deployed URL, they can apply specific access modes: restricting the site to just themselves and workspace admins, opening it to all active users in the workspace, or limiting access to custom user groups. </p><p>Furthermore, to prevent sensitive data leaks, OpenAI provides a dedicated Sites panel to manage runtime environment variables and secrets securely, ensuring those keys do not have to be committed to local source files.</p><h2><b>Reactions and Reflections</b></h2><p>The introduction of visual, self-updating UI layers to command-line agents is fundamentally altering how developers view their own workflows. As AI handles the raw syntax and automates the reporting, the friction of communicating technical work to stakeholders is vanishing.</p><p>Boris Cherny, the Lead and creator of Claude Code, highlighted the sheer utility of the update in a <a href="https://x.com/bcherny/status/2067700226669060207?s=20">post on X earlier today</a>: </p><p>"I've been using Artifacts in Claude Code for everything: visual explanations of tricky code, system diagrams, quick previews of a few animation options, data analyses and dashboards I share with the team," Cherny wrote. "They are a game changer for how I work with Claude. Can't wait to hear what you think!"</p><p>This sentiment is practically demonstrated in Anthropic’s launch materials. In one scenario, an engineer prompts Claude Code to investigate user drop-offs since a previous software release. </p><p>In a matter of seconds, the agent executes an SQL read, builds an interactive drop-off funnel dashboard, and diagnoses that "Pro accounts stall at the export sheet". The AI then proposes UI fixes, updates the live charts as the code is refactored, and generates a secure link that a manager can instantly open via mobile.</p><p>By turning the terminal into a live, collaborative canvas, Anthropic is proving that the most valuable output of an AI coding assistant isn't just the code itself—it is the context, the reasoning, and the ability to share that work instantly.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Adds Brand Controls, Code Sync to Claude Design]]></title>
<description><![CDATA[Anthropic updated Claude Design with design system imports, Claude Code syncing, canvas editing, and more export options for enterprise teams.
The post Anthropic Adds Brand Controls, Code Sync to Claude Design appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3608227/it-nachrichten/anthropic-adds-brand-controls-code-sync-to-claude-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608227/it-nachrichten/anthropic-adds-brand-controls-code-sync-to-claude-design/</guid>
<pubDate>Thu, 18 Jun 2026 17:19:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic updated Claude Design with design system imports, Claude Code syncing, canvas editing, and more export options for enterprise teams.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-anthropic-claude-design-overhaul-enterprise-teams/">Anthropic Adds Brand Controls, Code Sync to Claude Design</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adobe embeds agentic AI workflows across Creative Cloud, shifting from media generation to production orchestration]]></title>
<description><![CDATA[Adobe has announced a major expansion of its "creative agent" across its flagship Creative Cloud suite and upgraded Firefly AI studio. Available in public beta starting today across Premiere Pro, Photoshop, Illustrator, InDesign, and Frame.io, the agent is designed to serve everyone from individu...]]></description>
<link>https://tsecurity.de/de/3608158/it-nachrichten/adobe-embeds-agentic-ai-workflows-across-creative-cloud-shifting-from-media-generation-to-production-orchestration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608158/it-nachrichten/adobe-embeds-agentic-ai-workflows-across-creative-cloud-shifting-from-media-generation-to-production-orchestration/</guid>
<pubDate>Thu, 18 Jun 2026 17:08:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blog.adobe.com/en/publish/2026/06/18/adobe-firefly-introduces-new-agentic-capabilities-and-an-upgraded-creative-ai-studio-built-for-the-way-you-work">Adobe has announced</a> a major expansion of its "creative agent" across its flagship Creative Cloud suite and upgraded Firefly AI studio. </p><p>Available in public beta starting today across Premiere Pro, Photoshop, Illustrator, InDesign, and Frame.io, the agent is designed to serve everyone from individual creators to enterprise marketing teams. </p><p>Unlike first-generation generative AI tools that simply output flat media from a chat interface, Adobe’s embedded assistant acts as an orchestration layer. </p><p>It interprets natural language prompts and directly accesses the underlying software's APIs to execute complex, multi-step production workflows—from batch-renaming video sequences to dynamically updating brand assets across print layouts—while leaving the final aesthetic decisions entirely in the hands of the human designer. </p><h3><b>Technology: Contextual Memory and DOM Manipulation</b></h3><p>At the core of this release is a significant technical upgrade to how Adobe's AI handles persistent memory and context window management. In its upgraded Firefly creative AI studio—currently in private beta—Adobe has introduced two foundational architectural components: "Elements" and "Projects". </p><ul><li><p><b>Elements</b> functions as a visual variables library, allowing users to save and reuse specific characters, locations, and objects across multiple generations to ensure strict visual consistency as campaigns scale. </p></li><li><p><b>Projects</b> acts as the contextual memory layer, storing assets, generations, and session history in a unified space so users can pick up where they left off without rebuilding their prompt context. </p></li></ul><p>Beyond pixel generation, the system's most critical technological leap is its ability to operate seamlessly within the complex document structures of desktop applications. "Our Adobe Creative Agent can leverage the decades of powerful features, workflows, APIs that we've brought into our application and exposed through tooling that can now be invoked through a creative agent," an Adobe representative explained. </p><h3><b>Product: Automating the Tedious, Expanding the Canvas</b></h3><p>The practical application of this technology fundamentally alters standard production workflows. Adobe is positioning the human user as a "creative director" capable of delegating repetitive, labor-intensive tasks to the AI. The rollout introduces highly specific specialist agents tailored to the logic of each application: </p><ul><li><p><b>Premiere Pro:</b> The agent handles tedious project setup, analyzing and sorting source media into bins, batch renaming clips, identifying interview questions, and assembling a rough working starting point. </p></li><li><p><b>Illustrator:</b> The assistant automates mathematical and multi-step design tasks, such as generating 50 versioned files from a spreadsheet or running pre-flight checks to flag color mode errors before printing. It can even programmatically duplicate a vector shape 100 times, randomize its position, and change its size based on its z-depth and transparency. </p></li><li><p><b>Photoshop &amp; InDesign:</b> The agent executes batch background removals, dynamic layer organization, and applies brand updates across multi-page layouts. </p></li></ul><p>Furthermore, Adobe is actively integrating its creative agent into major third-party enterprise platforms, including OpenAI's ChatGPT, Anthropic's Claude, Microsoft 365 Copilot, and soon, Google Gemini and Slack. </p><h3><b>Licensing: Commercial SaaS and Enterprise Implications</b></h3><p>Unlike open-source orchestration frameworks or models released under MIT or Apache licenses, Adobe's creative agent operates strictly within a proprietary, commercial SaaS ecosystem. For enterprise decision-makers, this carries specific implications. Because the agent relies on Adobe's proprietary APIs to manipulate project files, it requires an active Creative Cloud commercial license. Additionally, by bringing the "Adobe for creativity connector" to platforms like Slack and Microsoft Copilot , enterprise IT and systems architects must consider how internal chat tools will interface with Adobe's cloud processing environments to support enterprise creative and marketing teams securely. </p><h3><b>The Enterprise Unknowns: APIs, Governance, and Architecture</b></h3><p>While Adobe’s announcements highlight a powerful user interface and deep integration within its own flagship applications, several critical questions remain for enterprise technical decision-makers tasked with building bespoke AI systems. VentureBeat has reached out to Adobe for clarification on these infrastructure-level details and will update this coverage as we learn more.</p><p>For AI system architects, the value of a creative agent lies not just in a native application UI, but in its extensibility. It remains unclear if Adobe plans to expose these new agentic capabilities via API, or if the company will support the Model Context Protocol (MCP). Without MCP support or direct API access, enterprise teams will face friction integrating Adobe's tools into their own custom task-routing frameworks and internal LLM pipelines.</p><p>Adobe’s new "Elements" feature promises to solve the generative AI consistency problem by anchoring characters and objects across generations. </p><p>However, the backend architecture driving this persistent memory is not yet detailed. Whether Adobe is leveraging on-the-fly Low-Rank Adaptation (LoRA) based on user uploads or utilizing a form of visual Retrieval-Augmented Generation (RAG) is a critical distinction for technology leaders managing compute costs, model evaluations, and enterprise-grade inference pipelines.</p><p>As organizations build out "Projects" and define brand-specific "Elements", security and data decision-makers require strict guarantees regarding data provenance and storage. It is currently unknown exactly where this contextual workflow and vector data lives—specifically, whether it remains strictly sandboxed within the customer's enterprise Creative Cloud instance on Adobe servers, and how role-based permissions apply to these new agentic workflows.</p><p>Finally, as lightning-fast, developer-first, multi-model AI creative platforms like <a href="https://www.linkedin.com/posts/toddj0_running-out-of-new-ways-to-describe-just-share-7356718780363796481-zREK/">fal.ai gain significant traction</a> among enterprises and developers, Adobe’s position in the broader developer ecosystem remains a point of interest. </p><p>Whether Adobe views these infrastructure-level API providers as direct competitors to its Firefly AI studio or as potential integration points for bespoke enterprise environments has yet to be seen.</p><h3><b>Community Reactions: The Tension Between Automation and Craft</b></h3><p>The integration of agentic AI touches on the tension between eliminating drudgery and surrendering creative control. According to Adobe's recent Creators' Toolkit Report, which surveyed over 16,000 creators globally, the market is highly receptive to AI as an operational assistant rather than an autonomous creator. </p><ul><li><p>75 percent of surveyed creators describe creative AI as integrated or essential to their current workflows. </p></li><li><p>85 percent emphasized that the final creative decision must always remain in human hands. </p></li></ul><p>This sentiment is central to Adobe's messaging. By focusing the agent's capabilities on file organization, layer management, and brand compliance, Adobe aims to automate what a spokesperson called the "tedious parts of their workflow". The goal, according to Adobe executive David Wadhwani, is to let creatives focus on the craft so they can "apply their taste and make the calls that only they can". </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Splash Canvas: Create abstract art (with an attitude)]]></title>
<description><![CDATA[Splash Canvas lets you create abstract art using unconventional, highly opinionated sea creatures.]]></description>
<link>https://tsecurity.de/de/3607290/it-nachrichten/splash-canvas-create-abstract-art-with-an-attitude/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607290/it-nachrichten/splash-canvas-create-abstract-art-with-an-attitude/</guid>
<pubDate>Thu, 18 Jun 2026 12:01:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/splash-canvas-hero.max-600x600.format-webp.webp">Splash Canvas lets you create abstract art using unconventional, highly opinionated sea creatures.]]></content:encoded>
</item>
<item>
<title><![CDATA[Explainer video: Powering every moment in football]]></title>
<description><![CDATA[Football thrives on split-second decisions, passion, and the collective energy of millions of fans worldwide. Lenovo Hybrid AI is reimagining how the game is played, managed, and experienced. By combining real-time intelligence, innovative connectivity, and advanced infrastructure, Lenovo’s techn...]]></description>
<link>https://tsecurity.de/de/3607275/it-security-nachrichten/explainer-video-powering-every-moment-in-football/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607275/it-security-nachrichten/explainer-video-powering-every-moment-in-football/</guid>
<pubDate>Thu, 18 Jun 2026 11:52:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Football thrives on split-second decisions, passion, and the collective energy of millions of fans worldwide. Lenovo Hybrid AI is reimagining how the game is played, managed, and experienced. By combining real-time intelligence, innovative connectivity, and advanced infrastructure, Lenovo’s technology powers smarter experiences both on and off the pitch. From broadcasters capturing every angle to fans engaging with live content, discover how Hybrid AI is redefining the future of football at every level.</p>



<p>Watch the video to find out more</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mastering the chess of IT leadership today]]></title>
<description><![CDATA[In today’s AI-driven world, every decision a CIO makes is a pivotal move, with outcomes that ripple across the enterprise. Business performance, investor confidence, and the organization’s ability to compete are all influenced by these moves. It’s why Salumeh Companieh, chief digital and informat...]]></description>
<link>https://tsecurity.de/de/3607222/it-nachrichten/mastering-the-chess-of-it-leadership-today/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607222/it-nachrichten/mastering-the-chess-of-it-leadership-today/</guid>
<pubDate>Thu, 18 Jun 2026 11:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In today’s AI-driven world, every decision a CIO makes is a pivotal move, with outcomes that ripple across the enterprise. Business performance, investor confidence, and the organization’s ability to compete are all influenced by these moves. It’s why Salumeh Companieh, chief digital and information officer at Cushman &amp; Wakefield, says leadership in this environment feels a lot more like chess than checkers.</p>



<p>As the margin for error shrinks, expectations are rising, and <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">the role of CIO is evolving</a>, from technology leader to enterprise operator at the highest levels. Across the board, IT leaders are facing hard decisions with no easy answers. It demands clarity of intent, discipline in execution, and the ability to anticipate not just the next move but the downstream impact of every decision.</p>



<p>In a recent episode of the <a href="https://linktr.ee/techwhisperers" rel="nofollow">Tech Whisperers podcast</a>, we explored how Companieh leads where speed, transparency, and human impact collide. In the Q&amp;A that follows, edited for length and clarity, she builds on that conversation, sharing how her perspective, intentionality, and leadership approach ensure every move counts.</p>



<p><strong>Dan Roberts: You’ve compared leadership today to chess, where second-order consequences are real. What has changed in the CIO role that makes that level of precision and foresight so critical now, and how do you help your team keep up?</strong></p>



<p><strong>Salumeh Companieh:</strong> What’s changed is the pace of change and velocity of delivery. You now have far more opportunities to make missteps at an accelerated pace if you do not understand the broader chessboard. One way we set our teams up to go faster is through clarity. The clearer the outcome, the faster you can go. So that means drawing clear accountability lines and having a really clear vision. And then it’s about real-time recognition, real-time pivots, and the awareness to slow down when needed — making course corrections in the moment and celebrating wins, both small and significant — because then you continue to fuel the flywheel. You fuel this sense of impact.</p>



<p>We host a team town hall after every earnings call, and one of the things we do very clearly is translate the earnings call to the work that they’re doing, drawing clear lineage between the amount of hours you’re spending away from your family doing work and the outcome of when your CEO is on an earnings call speaking to enterprise outcomes. The momentum that has built within our organization has been awe-inspiring. Feedback on the employee engagement survey statement ‘I can clearly align my work to the outcomes of the company’ continues to go up, and that’s where your sense of belonging continues to rise. You understand impact, so you can go faster.</p>



<p><strong>You played a visible role in Cushman &amp; Wakefield’s recent </strong><a href="https://ir.cushmanwakefield.com/events-and-presentations/2025-Investor-Day/default.aspx" rel="nofollow"><strong>Investor Day</strong></a><strong>. Not long ago, it would have been unusual to see a CIO in that spotlight. What was your role, and what did you want investors to understand about technology, AI, and the business?</strong><strong></strong></p>



<p>The core message was, it’s inseparable from the strategy. There isn’t a separate AI strategy from the business strategy. It’s a cohesive, co-created strategy, and we are at the forefront of the new way of working for a professional services firm. We’re looking to redefine not just commercial real estate but professional services in whole. How do you move knowledge? How do you elevate colleagues? How do you shape different ways of working, with human-first and AI-augmented. So that was the core message.</p>



<p>My role in that is also to gain trust. It’s to clearly articulate the integral role that technology and data will continue to play in professional services, and we are making bold moves to shape it. </p>



<p><strong>Your leadership style is grounded in consistency, clarity, and generosity, qualities that often come from lived experience. How have your early influences and upbringing shaped the way you lead and make decisions today?</strong></p>



<p>My No. 1 and No. 2 role models are my parents. They made incredibly bold decisions when we were younger. They had to pivot multiple times in their lives and re-create from scratch. There was this real grounding of grit that I experienced day in and day out. And I genuinely believe that every single step I’ve taken, regardless of how hard, is not even remotely in the realm of the difficult decisions that they’ve made. For that to be your north star of what difficult looks like, candidly, everything else is benign. They taught me consistently showing up will pay dividends at an outsized return. They taught me that in your darkest days you never lose empathy for others. Most importantly, they taught me to keep myself humble.</p>



<p>That’s the true start of where my ‘operating system,’ if you will, was. For their decisions, for their sacrifice, I will always be grateful. And for the lessons in my life. I don’t think I’d be where I am today without that. And not just physically in a different country, but the growth that I’ve both witnessed and experienced wouldn’t have been possible otherwise. Whether it’s their decisions or my dad’s constant challenge of, ‘Well, of course you could do it,’ there was never a doubt in the forefront of the discussion. There was always a center of, ‘Why <em>not</em> you?’ And that same kind of leadership in a familial sense is what we hope that we’ve given to our sons. Why not you? You’ve just got to keep opening your mind space of, somebody’s going to crack this code, it might as well be you.</p>



<p><strong>You’re known for your ability to see situations through multiple points of view across the business, your teams, and your clients. How does that perspective shape the moves you make, especially in moments of uncertainty?</strong></p>



<p>I look at each of those lenses as their own data points, if you will, and depending on both external factors and internal factors, you dial up a particular decision criterion or you dial it down. It’s no different than, historically, we would have done this for risk mitigation. We would have looked at the risk profile of aging technology and tech debt and cybersecurity protocols and made risk-based decisions. It’s almost like mentally pivoting that to rewards-based decisions. What are the biggest rewards you’re going to get, both from a cultural perspective as well as a revenue optimization perspective?</p>



<p>Sometimes you might make a move just to start building the culture, and the next move on top of that will be an accelerated business and revenue outcome. But the more informed you are with all the data points, the better investment portfolio manager you are, because that’s really this job, right? Whether it’s your people’s capacity or genuine capital, it’s an investment portfolio. And there are risks and rewards against every investment portfolio.</p>



<p>Sometimes you’re going to be in a position to take higher-risk/higher-reward decisions, and sometimes you want to tone it down a little bit. To do that in totality, you need to know all the component parts you can make a decision on. You can’t put a blinder on. You have to provide transparency to the entire canvas. Then you can make really, really good decisions.</p>



<p><strong>At enterprise scale, clarity, speed, cost, and people don’t always align. When those forces are pulling in different directions, how do you stay intentional about the moves you make?</strong></p>



<p>The thing I lean on the most is to remove the definitive no’s quickly from the table. There might be different forces, some of which you know based on either context, intellect, or gut, that you’re immediately going to say no to. Remove that noise and put it to the side. Then it’s the ability to roll back through the others and draw on the proximity to your team and get their voices in the room and understand context with greater depth. You remove the noise, you draw clarity from those with deep proximity to the opportunity, you balance with enterprise context, and you make bold decisions, always centered on client outcomes. Key to all of this is that you maintain accountability for the entire decision cycle.</p>



<p>At this accelerated pace of decision-making, with imperfect data, it’s getting comfortable in that ambiguity but knowing that there’s no one that’s going to try harder to make the best enterprise decision. And that lets me sleep at night.</p>



<p><strong>You care deeply about your people, but you also hold a high bar. How do you push your team to take ownership and deliver without stepping in and doing it for them?</strong></p>



<p>One, you have to model the leadership and commitment you seek from others. If you’re asking for really high quality, you better be putting in really high quality. Whether it’s from talent management — I’m not going to ask them are you having really hard conversations with your team unless I’m having really hard conversations with them — or it’s curiosity and learning. I have to show and model that behavior.</p>



<p>I also think there’s something about this whole concept of <a href="https://www.cio.com/article/4120226/rethinking-it-leadership-to-unlock-the-agility-of-teamship.html">teamship</a>, and I think Keith [Ferrazzi, author and Ferrazzi Greenlight founder] does a great job of bringing light to that. We model that every single day. If I am clear on the fact that we will win or lose as a team, and not individuals, and I continue to reiterate that, not in words, but in actions, then what happens is, when I’m not there, they hold each other accountable. And they model that behavior for their team. You start going down this tree of action where everybody is cohesively holding each other accountable for both behavioral and technological outcomes. It’s magical. You’ve created a construct where people have the autonomy and desire to do great work and an accountability construct to ensure best-in-class outcomes.</p>



<p>It takes a long time, because if people have not been led in this manner previously, there’s a genuine lack of trust of the process and learning that is required. But I do believe deeply in the way that Keith puts it on this concept of teamship and this cohesive outcome.</p>



<p><em>As </em><em>Sal Companieh’s chess analogy reveals, the modern CIO’s remit goes beyond running technology to shaping business outcomes, culture, and the future operating model of the enterprise, often without the luxury of slowing down. Her ability to play aggressively without losing sight of the human side of the board proves that, in this environment, the leaders who win aren’t just the fastest movers. They’re the ones thinking several moves ahead while bringing their people with them. For more from Companieh on leading through the tension of today’s environment, </em><a href="https://linktr.ee/techwhisperers" rel="nofollow"><em>tune in to the Tech Whisperers</em></a><em>.</em></p>



<p><strong>See also:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4176073/developing-a-customer-first-culture-for-it.html">Developing a customer-first culture for IT</a></li>



<li><a href="https://www.cio.com/article/4166851/coherence-where-leadership-and-ai-success-intersect.html">Coherence: Where leadership and AI success intersect</a></li>



<li><a href="https://www.cio.com/article/4159277/cio-sanjay-shringarpure-invites-you-to-reimagine-the-event-experience.html">CIO Sanjay Shringarpure invites you to reimagine the event experience</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Ukraine’s Entry Into the EU Cybersecurity Reserve Means]]></title>
<description><![CDATA[Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities.

The decision allows Ukraine to activate suppo...]]></description>
<link>https://tsecurity.de/de/3607084/it-security-nachrichten/what-ukraines-entry-into-the-eu-cybersecurity-reserve-means/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607084/it-security-nachrichten/what-ukraines-entry-into-the-eu-cybersecurity-reserve-means/</guid>
<pubDate>Thu, 18 Jun 2026 10:38:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Ukraine Joins EU Cybersecurity Reserve" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Ukraine-Joins-EU-Cybersecurity-Reserve-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="What Ukraine's Entry Into the EU Cybersecurity Reserve Means 1"></p>Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities.

The decision allows <a href="https://thecyberexpress.com/account-theft-scheme-ukraine-cyber-police/" target="_blank" rel="noopener">Ukraine</a> to activate support from the<a href="https://thecyberexpress.com/enisa-and-commission/" target="_blank" rel="noopener"> EU Cybersecurity Reserve</a>, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity providers. The move reflects ongoing EU-Ukraine cooperation on digital security and resilience amid evolving cyber threats.
<h3><strong>Ukraine Joins EU Cybersecurity Reserve Under EU Cyber Solidarity Framework</strong></h3>
The EU <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="Cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28747">Cybersecurity</a> Reserve was established under the Cyber Solidarity Act to help participating countries respond to significant cybersecurity incidents. Through the reserve, nations can request specialized assistance when their own <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28751">incident response</a> resources are overwhelmed.

<a href="https://digital-strategy.ec.europa.eu/en/news/eu-provides-cyber-support-ukraine-against-major-attacks" target="_blank" rel="nofollow noopener">According to the European Commission</a>, Ukraine will now be able to officially seek emergency European support if a cyberattack surpasses the capacity of its domestic response teams. This would allow cybersecurity experts from across the European Union to assist in incident containment and recovery efforts.

The Commission described the decision as part of broader efforts to strengthen preparedness, improve rapid response capabilities, and encourage cooperation against growing <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28752">cyber</a> threats.
<h3><strong>EU Highlights Digital Security Cooperation</strong></h3>
Commenting on the development, Henna Virkkunen, Executive Vice-President for Tech Sovereignty, <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28748">Security</a> and Democracy, said Ukraine's inclusion strengthens collective cyber defenses and reflects the principle of solidarity at the core of Europe's digital future.

The Commission noted that cyberattacks continue to present a persistent challenge and emphasized the importance of coordinated responses and shared expertise among partner nations.

Ukraine's inclusion also aligns with the EU's strategic digital partnership agenda, which focuses on strengthening cybersecurity cooperation with neighboring countries.
<h3><strong>Moldova Previously Granted Access</strong></h3>
Ukraine becomes the second non-EU country to gain access to the reserve. Moldova <a href="https://digital-strategy.ec.europa.eu/en/news/eu-and-moldova-enhance-digital-cooperation-better-resilience-strategic-areas" target="_blank" rel="nofollow noopener">was granted access in 2024</a> following an increase in Moscow-linked Cyber Threats and influence operations targeting the country.

The Council's authorization for Moldova to use the reserve was described as a major step forward in regional cybersecurity cooperation. The arrangement was implemented under the Cyber Solidarity Act and formed part of broader EU-Moldova efforts to improve digital resilience.

The European Commission stated that enhancing cybersecurity cooperation remains a key component of its partnership with Moldova.
<h3><strong>Broader EU-Moldova Digital Cooperation Expands</strong></h3>
Alongside cybersecurity initiatives, the European Union has expanded digital cooperation with Moldova in several strategic areas.

The Commission welcomed a political agreement that will allow Moldova to join the EU Roaming Area under the "Roam Like at Home" framework following formal adoption. Once implemented, Moldovan citizens and EU travelers will be able to call, text, and use mobile <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28749">data</a> without additional roaming charges.

Moldova has also joined the EU Third Countries' Trusted List, enabling easier validation of electronic signatures and seals between EU and Moldovan organizations, businesses, and citizens.

To strengthen resilience against Disinformation and foreign interference, a new hub of the European Digital Media Observatory (EDMO) known as FACT has also been established with support from the European Commission.
<h3><strong>Cyber Cooperation Advances as EU Membership Talks Progress</strong></h3>
The cybersecurity <a class="wpil_keyword_link" href="https://cyble.com/announcement/" target="_blank" rel="noopener" title="announcement" data-wpil-keyword-link="linked" data-wpil-monitor-id="28750">announcement</a> comes shortly after EU member states agreed to launch formal accession negotiations with both Ukraine and Moldova.

European Commission President Ursula von der Leyen <a href="https://x.com/vonderleyen/status/2065481649077317692" target="_blank" rel="nofollow noopener">described</a> the decision as a major milestone, stating that all member states had agreed to open the first accession negotiations cluster with the two countries. She said the move recognizes the reforms undertaken by Ukraine and Moldova despite significant challenges and reinforces the EU's commitment to peace, security, and stability across the region.

With access to the EU Cybersecurity Reserve, Ukraine now gains an additional layer of support to strengthen its cyber resilience and coordinate responses to major cybersecurity incidents alongside European partners.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic ships major Claude Design overhaul with design system imports, code round-trips, and a fix for its token-burning problem]]></title>
<description><![CDATA[When Anthropic quietly released Claude Design in April as a "research preview," it generated the kind of instant traction most product teams dream about: more than one million users in its first week. It also generated a problem. The tool consumed tokens so voraciously that a PCWorld reviewer bur...]]></description>
<link>https://tsecurity.de/de/3605936/it-nachrichten/anthropic-ships-major-claude-design-overhaul-with-design-system-imports-code-round-trips-and-a-fix-for-its-token-burning-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605936/it-nachrichten/anthropic-ships-major-claude-design-overhaul-with-design-system-imports-code-round-trips-and-a-fix-for-its-token-burning-problem/</guid>
<pubDate>Wed, 17 Jun 2026 21:31:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When <a href="https://www.anthropic.com/">Anthropic</a> quietly released <a href="https://claude.ai/design">Claude Design</a> in April as a "<a href="https://www.anthropic.com/news/claude-design-anthropic-labs">research preview</a>," it generated the kind of instant traction most product teams dream about: more than one million users in its first week. It also generated a problem. The tool consumed tokens so voraciously that a PCWorld reviewer <a href="https://www.pcworld.com/article/3117811/i-tried-claude-design-for-half-an-hour-im-already-locked-out-for-a-week.html">burned through 80 percent</a> of his weekly Claude Pro allowance in roughly 25 minutes, producing just three variations of a single webpage prototype. "We're talking another token-hungry Claude product here," the reviewer wrote, "one that Pro users in particular will barely be able to use before burning through their usage limits."</p><p>Two months later, Anthropic is shipping a substantially overhauled version of <a href="https://claude.ai/design">Claude Design</a> that attempts to fix the consumption issue while simultaneously repositioning the product from a flashy demo into something far more strategically important: a design system compliance layer that connects to code, connects to the tools enterprises already use, and — critically — keeps everything on brand.</p><p>The update, announced Wednesday, arrives at a moment when Anthropic is executing one of the most aggressive product expansions in the AI industry's brief history. In the past ten weeks alone, the company has launched <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8</a>, released (and then suspended) the Mythos-class <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Fable 5 model</a>, shipped ten agent templates for financial services, announced a <a href="https://investors.dxc.com/investor-news/news-details/2026/DXC-and-Anthropic-Announce-Multi-Year-Global-Alliance-to-Bring-AI-into-Mission-Critical-Enterprise-Systems/default.aspx">multi-year alliance</a> with DXC Technology to embed Claude inside the IT infrastructure of the world's largest banks and airlines, rolled out <a href="https://www.anthropic.com/news/claude-for-small-business">Claude for Small Business</a> with integrations into QuickBooks and PayPal, and published research showing that Claude Code users now average <a href="https://www.anthropic.com/research/claude-code-expertise?lang=us">20 hours per week on the tool</a>. </p><p>Claude Design's transformation from prototype toy to enterprise platform is the latest move in a company-wide strategy to make Claude not just an assistant people talk to, but a worker embedded in the systems where work actually happens.</p><h2><b>How design system imports make Claude Design an enterprise brand-compliance tool</b></h2><p>The headline feature in Wednesday's update is not the new drag-and-resize editor, nor the expanded list of export destinations, though both matter. The feature that signals where Anthropic is heading is the rebuilt design system import.</p><p>Users can now bring one or several design systems into Claude Design from a <a href="https://github.com/">GitHub</a> repository, design files, or raw uploads. Once imported, Claude builds with those components, checks its output against the design system, and auto-corrects before the user ever sees the result. For larger organizations, a new admin role can approve a single standard system and lock down edits, ensuring that every asset Claude produces conforms to company guidelines.</p><p>This is a meaningful departure from the tool's original positioning. In April, <a href="https://claude.ai/design">Claude Design</a> was a blank canvas: give it a prompt, and it would generate something visually impressive but stylistically arbitrary. Business Insider tested it against Canva AI for a photography workshop slide deck and found that Claude Design "<a href="https://www.businessinsider.com/claude-design-canva-ai-test-compare-create-presentation-saas-2026-5">anticipated my needs</a>" and "identified its own errors and corrected them without prompting." But the output reflected Claude's aesthetic judgment, not the user's brand. For an individual freelancer or a startup founder sketching ideas, that was fine. For a 10,000-person enterprise with a 200-page brand standards document, it was a non-starter.</p><p>The design system import changes that equation. By ingesting a company's actual components — its buttons, typography, color tokens, spacing rules — and then validating output against them before surfacing results, Claude Design is attempting something that most human designers struggle with: consistent brand compliance at speed and scale. The admin lockdown feature, which prevents individual users from overriding the approved system, is a direct play for the enterprise procurement conversation, where "can we control what it produces?" is often the first question.</p><h2><b>Why the Claude Code round-trip could end the design-to-engineering handoff problem</b></h2><p>The second major update is the bidirectional integration between <a href="https://claude.ai/design">Claude Design</a> and <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>. Users can now run /design-sync in Claude Code to import their local codebase's design system into Claude Design, ensuring that prototypes start from real components rather than approximations. When a design is ready to ship, it hands off to Claude Code, which picks up exactly where the designer left off — no screenshot, no rebuild. The integration works in reverse, too. From a Claude Code terminal, the /design command lets developers create, edit, and sync design projects without leaving their workflow.</p><p>This matters because the handoff between design and engineering has been one of the most persistent friction points in software development for decades. Tools like Figma's Dev Mode and Zeplin have tried to bridge the gap by generating specifications and code snippets from design files, but the translation has always been lossy. A designer's prototype and an engineer's implementation inevitably diverge, creating a cycle of visual QA, redlines, and "that's not what the mockup looked like" conversations.</p><p>Anthropic is betting that if the same AI system both designs and codes — and if both modes share the same underlying component library — the gap disappears. It is, in effect, arguing that the design-to-code problem was never really about better specification formats or smarter handoff tools. It was about the fact that two different humans (or two different tools) were interpreting the same intent. A single AI system that operates on both sides of the workflow doesn't need to interpret; it just continues.</p><p>The timing of this integration is also significant in light of Anthropic's own research. Just yesterday, the company published an analysis of <a href="https://www.anthropic.com/research/claude-code-expertise">roughly 400,000 Claude Code sessions </a>showing that domain expertise — not coding proficiency — is the primary driver of successful outcomes. Every major occupation succeeded at coding tasks at nearly the same rate as software engineers. If designers can now move fluidly between visual prototyping and code implementation through a single AI system, the research suggests they will succeed not because they learned to code, but because they deeply understand the design problems they are solving.</p><h2><b>Token consumption gets a fix, but the economics of generative design remain tight</b></h2><p>The token consumption issue that dogged Claude Design's launch was not just a user experience annoyance — it was a structural threat to the product's viability. If a <a href="https://support.claude.com/en/articles/11049762-choose-a-claude-plan">$20-per-month Pro subscriber</a> could exhaust their entire weekly allowance in a single 30-minute session, the tool was effectively inaccessible to the individual users and small teams who drove its initial viral adoption.</p><p>Anthropic's response is twofold. First, <a href="https://claude.ai/design">Claude Design</a> now shares usage limits with chat, <a href="https://www.anthropic.com/product/claude-cowork">Claude Cowork</a>, and <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, rather than drawing from a separate, smaller pool. This gives most users significantly more headroom. Second, the company says it has reduced the average token consumption per turn while maintaining output quality, and that error rates have dropped sharply.</p><p>Whether this is enough remains an open question. The fundamental tension is architectural: generative design is inherently token-expensive. Every variation Claude produces requires the model to reason about layout, typography, color, spacing, responsiveness, and content simultaneously, then generate a complete, functional artifact. That is a fundamentally different workload than answering a question in chat, and it consumes tokens accordingly. Anthropic's efficiency improvements may push the breaking point further out, but they do not eliminate the underlying economics. For enterprise customers on Team and Enterprise plans with higher limits, this may be a non-issue. For Pro subscribers, the math is still likely to be tight.</p><p>The new editor helps mitigate this somewhat by giving users direct control over individual elements — drag, resize, and align — without burning a model turn for every small adjustment. Hundreds of stability fixes also mean fewer wasted turns on errors and regenerations, which were a significant source of token drain in the original release. These are not glamorous improvements, but they are the kind of grind work that separates a research preview from a daily-use tool.</p><h2><b>Nine new export partners position Claude Design as a creative hub, not a destination</b></h2><p>The update's third pillar is an expanded set of export destinations. Claude Design now sends work to <a href="https://www.adobe.com/">Adobe</a>, <a href="https://base44.com/">Base44</a>, <a href="https://www.canva.com/">Canva</a>, <a href="https://gamma.app/">Gamma</a>, <a href="https://lovable.dev/">Lovable</a>, <a href="https://miro.com/">Miro</a>, <a href="https://replit.com/">Replit</a>, <a href="https://vercel.com/">Vercel</a>, and <a href="https://www.wix.com/">Wix</a>, in addition to PDF and PowerPoint. The breadth of this list reveals a deliberate positioning strategy: Anthropic is building Claude Design not as a place where work is finished, but as the place where it begins.</p><p>The partner quotes tell the story. Replit's president Michele Catasta frames the integration as meeting "builders wherever ideas begin." Canva's Anwar Haneef describes the flow from Claude Design as turning "a first draft" into "a finished asset — kept on-brand, personalized for the moment." Vercel's Andrew Qu talks about pushing a concept "straight to Vercel to ship." In each case, Claude Design is the origin point, and the partner tool is where polish, collaboration, and deployment happen.</p><p>This hub-and-spoke model also serves as a defensive moat against the open-source alternative that has emerged with surprising speed. <a href="https://github.com/nexu-io/open-design">Open Design</a>, a community-built project tracked by <a href="https://www.augmentcode.com/learn/open-design-claude-design-alternative">Augment Code</a>, reached 57,400 GitHub stars and 310 contributors in just eight weeks after Claude Design's launch. It offers local-first operation, model flexibility supporting 16 different coding agents, and 259 skills with 142 design systems — all without cloud lock-in. Augment Code's Paula Hingel noted that for "teams that need to self-host, use their own API keys, or swap models, Open Design is currently the only local-first option with this level of skill and design system coverage."</p><p>Anthropic's answer to this competitive pressure is not to match <a href="https://www.augmentcode.com/learn/open-design-claude-design-alternative">Open Design</a> on self-hosting or model flexibility — those are philosophical concessions the company is unlikely to make. Instead, it is building an integration ecosystem that open-source projects cannot easily replicate. A native Adobe Express connector, a verified Canva export pipeline, a first-party Vercel deployment path — these are partnerships, not features, and they require business relationships that community projects cannot forge at the same pace.</p><h2><b>Claude Design fits into Anthropic's broader push to embed AI across the entire enterprise stack</b></h2><p>To understand why Claude Design's evolution matters, it helps to zoom out. Anthropic is building a product surface that now spans creative work (<a href="https://claude.ai/design">Design</a>), code (<a href="https://www.anthropic.com/product/claude-code">Code</a>), knowledge work (<a href="https://www.anthropic.com/product/claude-cowork">Cowork</a>), and enterprise operations (<a href="https://platform.claude.com/docs/en/managed-agents/overview">Managed Agents</a>) — all unified by the same underlying models and, increasingly, by shared context that carries across tools.</p><p>The trajectory of the past quarter makes the pattern unmistakable. In May, Anthropic launched Claude for Small Business with connectors to QuickBooks, PayPal, and HubSpot, putting Claude inside the tools that small business owners already use for payroll, invoicing, and marketing. The same month, the company released ten agent templates for financial services covering everything from pitchbook creation to KYC screening, with connectors to FactSet, S&amp;P Capital IQ, and Morningstar. Claude Opus 4.8 shipped on May 28 with a "dynamic workflows" feature enabling hundreds of parallel sub-agents in a single Claude Code session. Then came the Fable 5 and Mythos 5 launch on June 9, followed almost immediately by a US government export control directive that suspended access to both. DXC Technology announced a multi-year alliance to train tens of thousands of Claude-certified engineers to embed Claude inside the systems it operates for major banks, airlines, and insurers.</p><p>The design system you import into Claude Design is the same component library that Claude Code uses to implement. The financial model you build in Claude for Excel can flow into a pitchbook created in Claude Design and exported to PowerPoint. The brand assets a small business owner creates through Claude Design can be pushed directly to Canva for team collaboration. This is not a chatbot strategy. It is a platform strategy, and the Claude Design update — with its design system imports, code round-trips, and export ecosystem — is one of the clearest expressions of it yet.</p><p>Anthropic also published an engineering deep-dive last month detailing how it contains Claude across products using sandboxes, virtual machines, and egress controls — infrastructure that becomes more critical as tools like Claude Design gain access to proprietary design systems and brand assets. The containment architecture reveals both the ambition and the risk: the more deeply Claude embeds into enterprise workflows, the higher the stakes when something goes wrong, and the more sophisticated the security envelope must become.</p><p>Three questions will determine whether Wednesday's update delivers on its ambitions. First, whether the token economics actually work for the broadest user base — shared limits and efficiency gains help, but generative design remains expensive. Second, whether the design system import proves robust enough for real enterprise use, because ingesting a GitHub repository of React components and faithfully using them across dozens of design variations is a genuinely hard technical problem. And third, whether the Claude Code round-trip actually eliminates the design-engineering gap or merely shifts it.</p><p>Claude Design launched two months ago as a thing people tried once and marveled at. Anthropic is now trying to make it a thing people use every day — and more than that, a thing their entire team trusts to stay on brand while they do. In the AI industry, the distance between a viral demo and an indispensable tool has swallowed more products than it has produced. Anthropic just bet that design systems, not just design prompts, are the bridge across.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adobe: New Firefly Graph can turn creative workflows into reusable assets]]></title>
<description><![CDATA[Adobe’s Firefly Graph is now available to Creative Cloud customers, offering a node-based workflow tool designed to help business create content at scale with generative AI (genAI). 



With Firefly Graph, users can connect multiple tools in visual workflow, with each “node” performing a specific...]]></description>
<link>https://tsecurity.de/de/3605819/ai-nachrichten/adobe-new-firefly-graph-can-turn-creative-workflows-into-reusable-assets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605819/ai-nachrichten/adobe-new-firefly-graph-can-turn-creative-workflows-into-reusable-assets/</guid>
<pubDate>Wed, 17 Jun 2026 20:34:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Adobe’s <a href="https://business.adobe.com/blog/meet-firefly-graph" data-type="link" data-id="https://business.adobe.com/blog/meet-firefly-graph" target="_blank" rel="noreferrer noopener">Firefly Graph is now available to Creative Cloud customers</a>, offering a node-based workflow tool designed to help business create content at scale with generative AI (genAI). </p>



<p>With Firefly Graph, users can connect multiple tools in visual workflow, with each “node” performing a specific task before passing its output to the next node. This <a href="https://www.computerworld.com/article/4163220/adobe-bets-on-ai-agents-to-stay-at-the-center-of-marketing-workflows.html" data-type="link" data-id="https://www.computerworld.com/article/4163220/adobe-bets-on-ai-agents-to-stay-at-the-center-of-marketing-workflows.html">gives creative professionals more control over generated outputs</a>, according to Adobe, and makes it easier to try out ideas by swapping, adjusting or adding components.</p>



<p>For example, a user could start with a text prompt box that connects to a node that generates an image using an AI model from Adobe or third-parties such as Google and OpenAI. Further along the chain, the user could add nodes to remove a background or upscale an image, for instance, before producing an image, video or other asset ready for use.</p>



<p>Changing one aspect, such as adding a reference image or adapting the text prompt, would change the final output.</p>



<p>It’s an approach similar to node-based workflow tools such as ComfyUI — a startup valued at $500 million which <a href="https://techcrunch.com/2026/04/24/comfyui-hits-500m-valuation-as-creators-seek-more-control-over-ai-generated-media/" target="_blank" rel="noreferrer noopener">claims more than 4 million users</a>. Others include Weavy, <a href="https://www.calcalistech.com/ctechnews/article/byyrqlbjwg" target="_blank" rel="noreferrer noopener">acquired by Figma last year for a reported $200 million</a>. </p>



<p>With so many AI tools available to creative professionals, workflows can get complex and hard to replicate, said Elliot Sedegah, senior product marketing manager at Adobe. Firefly Graph provides access to more than 300 different node types, including images, video editing and AI generation tools across Adobe’s portfolio and third-party tools. </p>



<p>“Whether you’re working at a mom-and-pop shop or a larger enterprise, you’re looking for consistency and then bringing that into a workflow so that you’re not hopping in and out of different tools,” he said. “Putting all that together takes massive amount of time, and sometimes it’s very difficult to even know what you did.”</p>



<p>Once created, workflows can be shared across an organization as repeatable processes for other individuals or teams to use. “Think of that rock star creative that you have and the recipes they create: those are now canonized as workflows, as assets, that the rest of the organization can take and reuse over and over again,” said Sedegah.</p>



<p>In addition, while creative professionals are needed to created high quality assets, reusable workflows can be put into the hands of broader teams to create content for large audiences, said Sedegah.</p>



<p>Firefly Graph addresses a challenge that most large creative organizations face, said Lisa Gately, principal analyst at Forrester — namely that their best creative workflows “live inside the heads of a few experts.</p>



<p>“Teams can generate images and video with AI, but reproducing the exact sequences of creative decisions, model selections, edits, and refinements that lead to a high-quality result is difficult and inconsistent. Firefly Graph turns those workflows into reusable assets,” she said.<br></p>



<p>While other node-based workflows aim to address similar problems, Adobe’s pitch is that Firefly Graph provides customers with the benefit of integration into its product suite. </p>



<p>“Firefly is a full, broader AI creative studio, not just a node-based tool, so [Firefly Graph] is a part of a bigger picture,” said Sedegah. “The strength is having everything in one place with the tools that people know.” </p>



<p>“Where Adobe differentiates is in enterprise integration,” said Gately, with Adobe connecting Firefly Graph to a range of other Adobe tools. Those include Creative Cloud applications; Firefly Boards for ideation; and Firefly Creative Production. </p>



<p>“The workflow becomes part of a broader content supply chain instead of a standalone creation tool,” she said. ”Organizations committed to other tools are unlikely to migrate for a node-based canvas — making a change is about the broader content supply chain.”</p>



<p>Project Firefly is available now to Adobe Creative Cloud for Enterprise subscribers (pricing details were not immediately available), and in a public beta for individual users; the wait list sign up is <a href="https://survey.adobe.com/jfe/form/SV_7VXFxdaIe7JlGOa" target="_blank" rel="noreferrer noopener">available here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Jeetu Patel Cisco bis zur Unkenntlichkeit verändert hat]]></title>
<description><![CDATA[width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">Ciscos Chief Product Officer Jeetu Patel auf der Cisco Live US 2026Cisco



Auf der Cisco Live 2026 war es Zeit für Jeetu Patel, Chief Product Officer von Cisco, ein vor 24 Monaten gegebenes Versprechen einzulösen. Zwei Jah...]]></description>
<link>https://tsecurity.de/de/3602096/it-security-nachrichten/wie-jeetu-patel-cisco-bis-zur-unkenntlichkeit-veraendert-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602096/it-security-nachrichten/wie-jeetu-patel-cisco-bis-zur-unkenntlichkeit-veraendert-hat/</guid>
<pubDate>Tue, 16 Jun 2026 16:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Ciscos Chief Product Officer Jeetu Patel auf der Cisco Live US 2026</p><br></figcaption></figure><p class="imageCredit">Cisco</p></div>



<p>Auf der <a href="https://www.ciscolive.com/" target="_blank" rel="noreferrer noopener">Cisco Live 2026</a> war es Zeit für <a href="https://www.linkedin.com/in/jeetupatel" target="_blank" rel="noreferrer noopener">Jeetu Patel</a>, Chief Product Officer von Cisco, ein vor 24 Monaten gegebenes Versprechen einzulösen. Zwei Jahre zuvor hatte der Manager versprochen, dass <a href="https://www.cisco.com/">Cisco</a> in zwei Jahren  kaum wiederzuerkennen sein würde – im positiven Sinne, versteht sich.</p>



<p>Die auf der Veranstaltung vorgestellten Innovationen lassen darauf schließen, dass er sein Versprechen tatsächlich weitgehend eingelöst hat. Cisco positioniert sich neu: weg von einer Holding-Gesellschaft für Produkte und Dashboards hin zu einer einheitlichen, KI-nativen Infrastrukturplattform. Dabei fungiert Cloud Control als Steuerungsebene, Cisco IQ als CX-Zentrum und Secure Networking als verbindendes Element.</p>



<p>Dieser Wandel betrifft nicht nur neue Funktionen, sondern ein völlig neues Betriebsmodell. Cisco schafft eine Umgebung, in der sich menschliche Administratoren und KI-Agenten dieselben Daten, denselben Kontext und dieselben Handlungsmöglichkeiten teilen, wobei die Menschen die Kontrolle behalten.</p>



<h2 class="wp-block-heading">Vom Dashboard-Wust zu Cloud Control</h2>



<p>Der sichtbarste Beweis für das „neue“ Cisco ist <strong>Cloud Control</strong>, eine einheitliche Management-Plattform für Networking, Security, Compute, Observability, Collaboration und ein wachsendes Ökosystem von Drittanbieter-Tools. Cisco betont, dass es sich hierbei nicht nur um eine weitere zentrale Übersicht handelt. Stattdessen ist es  eine aktive Ausführungsumgebung, in der Richtlinien und Identitäten direkt in den Steuerungsprozess integriert sind. Die Plattform wurde von Grund auf dafür konzipiert, dass Menschen und KI-Agenten die Infrastruktur gemeinsam betreiben.</p>



<p>Wenn sich Betreiber in Cloud Control anmelden, sehen sie eine vertraute, ChatGPT-ähnliche Oberfläche mit drei Modi:</p>



<ul class="wp-block-list">
<li><strong>„Assistant“</strong> ermöglicht es Betreibern, mit der Plattform in natürlicher Sprache zu kommunizieren.</li>



<li><strong>„Canvas“</strong> bietet einen Arbeitsbereich für mehrere Nutzer, in dem Menschen und Agenten gemeinsam Probleme untersuchen und lösen können.</li>



<li><strong>„Actions“</strong> fungiert als Leitstelle zur Überwachung dessen, was Agenten vorschlagen und ausführen.</li>
</ul>



<p>Cloud Control stellt zudem gemeinsame Plattformdienste wie Bestands- und Topologieinformationen über die gesamte Cisco-Infrastruktur hinweg bereit. Meraki, Intersight, Sicherheitsdienste, Splunk, Webex Control Hub und Cisco IQ sind alle mit einem einzigen Login zugänglich. Damit entfällt der Wechsel zwischen mehreren Dashboards und Authentifizierungsdomänen, stattdessen können sich die Betreiber nahtlos zwischen Plattformdiensten und Produkterfahrungen innerhalb derselben Umgebung bewegen.</p>



<h2 class="wp-block-heading">Cloud Control als „KI-Harness“, nicht als Konsole</h2>



<p>Technisch basiert Cloud Control auf einer gemeinsamen Datenstruktur, die Telemetriedaten aus Benutzern, Geräten, Anwendungen, Netzwerken und Bedrohungen korreliert. Diese Datenbasis dient sowohl menschlichen Entscheidungen als auch agentengestützter Automatisierung.</p>



<p>Cisco beschreibt diesen Wandel als Übergang von „Infrastructure as Code“ zu „Infrastructure as a Harness“. Anstatt ausschließlich von Menschen geschriebene Skripte und Playbooks zu verwenden, wird Cloud Control zur kontrollierten Umgebung, in der KI-Agenten Systeme beobachten, analysieren und sicher steuern können.</p>



<p>Drei zentrale Komponenten prägen diesen Ansatz:</p>



<ul class="wp-block-list">
<li><strong>„AI Canvas“</strong> bildet den Arbeitsbereich, in dem Menschen und Agenten gemeinsam Vorfälle untersuchen, wobei der Kontext über Schichten und Eskalationen hinweg erhalten bleibt.</li>



<li>Das „<strong>Cloud Control Studio“</strong> ermöglicht Kunden und Partnern, mit Agent Builder und App Buildermithilfe natürlicher Sprache und integrierter Programmierassistenten ihre eigenen Agenten und Anwendungen auf Basis der Daten, Richtlinien und der Steuerungsebene von Cisco zu erstellen .</li>



<li>Der<strong> „Cloud Control Marketplace“</strong> stellt Eigenentwicklungen und Partnerlösungen über einen zentralen Marktplatz zur Verfügung.</li>
</ul>



<p>Aus Sicht von Unternehmen wandelt sich Cloud Control damit von einer Plattform „zum Durchklicken von Einstellungen“ zu einer sicheren Plattform für agentengestützte IT-Prozesse: Eine geregelte Umgebung, in der KI-Agenten durchgängig bereitgestellt, überwacht, eingeschränkt und geprüft werden können. Dies ist ein ganz anderes Konzept als die herkömmliche Netzwerkmanagement-Konsole.</p>



<h2 class="wp-block-heading">Ein gemeinsames „Gehirn“ für Customer Experience und Produkte</h2>



<p>Unter der Leitung von <a href="https://www.linkedin.com/in/lizcentoni/" target="_blank" rel="noreferrer noopener">Liz Centoni</a>, Executive Vice President und General Manager, hat Cisco zudem seine Customer-Experience-Organisation (CX) grundlegend umgebaut. Lange Zeit wirkten die CX- und Produktorganisationen wie zwei Parallelwelten: Services wurden auf Produkte aufgesetzt, statt eng mit deren Funktionsweise verzahnt zu sein. Um diese Lücke zu schließen, arbeitete Centoni eng mit Patel zusammen, um sicherzustellen, dass Produktentwicklung und CX vollständig aufeinander abgestimmt sind.</p>



<p><strong>Cisco IQ</strong> verändert diese Dynamik, indem die modernisierten CX-Funktionen direkt in die gleiche Cloud-Control-Umgebung integriert werden, in der auch die Produkte betrieben werden. Zudem werden die CX-Workflows an dieselbe Telemetrie- und Policy-Ebene angebunden. Bemerkenswert ist dabei, dass Cisco IQ nicht einfach ein weiteres Dashboard ist, sondern ein integraler Bestandteil von Cloud Control.</p>



<p>Cisco IQ ist als KI-gestützte Plattform für Support und Professional Services positioniert. Ziel ist es, Kunden vollständige Transparenz über die gesamte IT-Landschaft, proaktive Ausfallsicherheit, schnellere Problemlösungen und kontextbezogene Services zu bieten. Die Lösung wird als SaaS-Plattform bereitgestellt, kann aber für Kunden mit strengen Anforderungen an Datenhoheit auch On-Premises betrieben werden.</p>



<p>Durch die Nutzung der gemeinsamen Data Fabric kann Cisco:</p>



<ul class="wp-block-list">
<li><strong>IQ Assets</strong> inventarisieren, unabhängig davon, ob sie bereits im Einsatz sind oder sich noch im Lager befinden,</li>



<li>Risiken kennzeichnen, bevor Kunden Probleme erleben, und</li>



<li>die Sicherheitslage eines Unternehmens anhand anonymisierter Vergleichswerte nach Branche, Marktsegment oder Region benchmarken.</li>
</ul>



<p>Neue Funktionen unterstreichen die enge Verzahnung von CX und Produktentwicklung weiter:</p>



<ul class="wp-block-list">
<li>„<strong>Resilient Infrastructure Services</strong>“ nutzt ein dreistufiges Framework aus Expositionsbewertung, Infrastrukturmodernisierung und Verteidigungsresilienz, um Kunden bei der Vorbereitung auf Bedrohungen nach dem „Frontier-Modell“ zu unterstützen.</li>



<li><strong>„Quantum Ready Assessments“</strong>, die über Cisco IQ bereitgestellt werden, identifizieren Systeme, die besonders anfällig für sogenannte „Harvest Now, Decrypt Later“-Angriffe sind, und zeigen einen Weg zu einer quantensicheren Infrastruktur auf.</li>
</ul>



<p>Die Verlagerung des „CX-Gehirns“ in Cloud Control und dessen Anbindung an dieselben Daten- und KI-Modelle, die auch den operativen Betrieb steuern, stellt sowohl kulturell als auch architektonisch einen grundlegenden Wandel dar.</p>



<h2 class="wp-block-heading">Secure Networking als Beweis für die Integration</h2>



<p>Wer verstehen möchte, wie stark das neue Cisco inzwischen integriert ist, sollte sich den Bereich Secure Networking ansehen.</p>



<p>Ciscos Vision besteht darin, Sicherheit direkt in die Infrastruktur einzubetten – vom Silizium über das Netzwerk bis hin zum operativen Betrieb –, statt sie als separaten Technologie-Stack zu behandeln.</p>



<p>Diese Strategie manifestiert sich auf verschiedene, konkrete Weisen.</p>



<p><strong>Live Protect</strong>, intern als „digitales Immunsystem“ bezeichnet, wendet präzise Ausgleichskontrollen auf Cisco-Produkte im Betrieb an, um diese vor neu entdeckten Schwachstellen zur Laufzeit zu schützen. Dies geschieht ohne Neustarts, Upgrades oder Wartungsfenster. Die Kontrollen sind zielgerichtet eingesetzt, um Leistungseinbußen zu vermeiden und Fehlalarme zu minimieren.</p>



<p>Live Protect ist bereits auf Nexus-9000-Switches verfügbar und wird auf das gesamte Portfolio ausgeweitet, einschließlich Campus-Switches, wodurch die Rückkopplungsschleife zwischen der Entdeckung von Schwachstellen und deren Behebung von Wochen auf Minuten verkürzt wird.</p>



<p>Die <strong>Hybrid Mesh Firewall</strong> erweitert einheitliche Sicherheitsrichtlinien über Netzwerke, Anwendungen sowie Firewalls von Cisco und Drittanbietern hinweg und begrenzt so den Schadensumfang, wenn etwas schiefgeht.</p>



<p>Gleichzeitig integriert Cisco Post-Quantum-Krypto-Bibliotheken, Secure Boot und Trust Anchors in sein Kernportfolio und hat sich verpflichtet, bis Dezember 2026 quantensichere Kommunikationsfunktionen für die meisten Kernprodukte bereitzustellen. Neue Router-, Switch- und Firewall-Serien für Unternehmen und Rechenzentren werden als „standardmäßig quantensicher“ auf den Markt gebracht.</p>



<p>All dies wird über Cloud Control orchestriert, laut Cisco die Sicherheitsleitstelle für die Zeit nach Mythos. Dabei stellt Splunk das Telemetrie-Backbone sowie agentenbasierte SOC- und SRE-Funktionen bereit. Auf diese Weise soll es möglich sein, Vorfälle mit maschineller Geschwindigkeit zu erkennen, zu priorisieren und darauf zu reagieren.</p>



<p>Secure Networking ist damit mehr als klassische Firewalls oder SD-WAN. Es bildet das Rückgrat, das Ciscos Netzwerk-, Sicherheits-, Observability- und KI-Ressourcen zu einer einheitlichen Plattform verbindet.</p>



<h2 class="wp-block-heading">Multicloud Fabric: Networking as a Service für KI</h2>



<p>Ein weiteres Kennzeichen des neuen Cisco ist die Bereitschaft, Netzwerke als vollständig verwaltete Fabric bereitzustellen, anstatt Kunden lediglich Werkzeuge in die Hand zu drücken, die selbst zusammenstellen müssen.</p>



<p><strong>„Multicloud Fabric“</strong> veranschaulicht diesen Wandel. Die Lösung wird als Network-as-a-Service-Angebot über Cloud Control bereitgestellt und bietet Unternehmen eine einheitliche Struktur für sicheres Site-to-Cloud- und Cloud-to-Cloud-Networking. Cisco betreibt hierfür virtuelle Points of Presence (PoPs) bei den wichtigsten Cloud-Anbietern und in verschiedenen Regionen.</p>



<p>Kunden können dadurch Standorte und Cloud-Umgebungen einbinden, absichtsbasierte Konnektivität definieren, Sicherheitsrichtlinien zuweisen und die Leistung „mit einem Klick“ über Cloud Control überwachen, anstatt eigene Hub-and-Spoke-Architekturen aufzubauen und zu warten.</p>



<p>Sicherheit und Observability sind integriert – in Form von Zero-Trust-Routing, Cloud-Firewall-Service-Chaining sowie über in jeden Point of Presence eingebettete ThousandEyes-Agenten. Das Netzwerk ist somit nicht länger eine passive Leitung, sondern Teil des KI-Intelligence-Stacks.</p>



<p>Dies gewinnt an Bedeutung, da AI-First-Anwendungen zunehmend Inferenzprozesse über mehrere Clouds und Datenquellen hinweg ausführen. Cisco-eigene Untersuchungen zeigen, dass diese agentenbasierten Workflows ein Vielfaches an Netzwerkverkehr generieren können als manuelle Entsprechungen, wobei es sich bei einem Großteil um latenzempfindliche Inferenz handelt. Multicloud Fabric, das als Service betrieben und in dieselbe Cloud Control-Umgebung integriert ist, ist Ciscos Antwort auf diese neue Realität.</p>



<h2 class="wp-block-heading">Was bedeutet das für Kunden?</h2>



<p>Cisco hat vier Jahrzehnte damit verbracht, branchenführende Produkte zu entwickeln, von Meraki und Nexus bis hin zu Webex und ThousandEyes. Die größte Chance des Unternehmens lag jedoch schon immer darin, wie diese Komponenten zusammenwirken. Nämlich, wie es Patel formuliert, „eng integriert und dennoch lose gekoppelt“.</p>



<p>Cloud Control, Cisco IQ, Multicloud Fabric und Secure Networking deuten darauf hin, dass Cisco diese Lücke zunehmend schließt. Einzelne Dashboards werden zu agentischen Workflows und isolierte Produkte verwandeln sich in ein sicheres Gerüst für das KI-Zeitalter.</p>



<p>Für Kunden ist die Transformation von Cisco von Bedeutung, da sie nicht nur die Produktpalette, sondern auch das Betriebsmodell verändert. Cloud Control bietet IT-Teams eine einheitliche Verwaltungsebene für Netzwerke, Sicherheit, Observability, Zusammenarbeit und Dienste und ersetzt damit die fragmentierte Dashboard-Erfahrung, die für Cisco-Umgebungen lange Zeit eine Bürde waren. Dies dürfte den Betrieb schneller und einfacher machen, setzt aber auch höhere Anforderungen an die Kunden.</p>



<p>Da Cisco AgenticOps, AI Canvas, Live Protect und Cisco IQ in den Mainstream bringt, verschiebt sich die Rolle der IT von der manuellen Bedienung einzelner Werkzeuge hin zur Überwachung von KI-Agenten. Dieser Wandel erfordert neue Kompetenzen in den Bereichen Prompt-Design, Richtlinienmodellierung, Risikobewertung und Governance. Insbesondere, weil Agenten immer mehr Änderungen vorschlagen und testen, bevor Menschen überhaupt auf „Genehmigen“ klicken.</p>



<p>Für Kunden bedeutet dies auch einen Perspektivwechsel: Cisco sollte künftig weniger als Sammlung einzelner Best-of-Breed-Produkte betrachtet werden, sondern vielmehr als integrierte Plattform.</p>



<p>Je mehr der Cisco-Umgebung mit Cloud Control verknüpft ist, desto mehr Nutzen sollten Kunden aus gemeinsamer Telemetrie, einheitlichen Workflows, integrierter Sicherheit und domänenübergreifender Automatisierung ziehen – insbesondere in Bereichen wie Secure Networking und Multicloud-Betrieb.</p>



<p>Umgekehrt benötigen Kunden, deren Umgebungen weiterhin stark heterogen sind, klare Integrationsstrategien und Governance-Modelle, um sicherzustellen, dass Tools von Drittanbietern sicher in das System eingebunden werden können.</p>



<p>Der vielleicht größte Nutzen des neuen Cisco liegt in der Reduzierung von Komplexität – einem der größten Schmerzpunkte vieler Unternehmenskunden. Wenn das Unternehmen diese Vision umsetzen kann, werden Kunden möglicherweise feststellen, dass Cisco nicht nur auf positive Weise nicht wiederzuerkennen ist. Sondern auch einfacher zu kaufen, zu implementieren und zu betreiben ist als jemals zuvor. (mb)</p>



<p><em>Dieser Artikel basiert auf einem </em><a href="https://www.networkworld.com/article/4184554/how-jeetu-patel-made-cisco-unrecognizable.html"><em>Beitrag</em></a><em> der Network World.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Anthropic ‘Fable’ saga proves: we have opened the AI Pandora’s box. What now? | Nathan E Sanders and Bruce Schneier]]></title>
<description><![CDATA[We have opened the AI Pandora’s box. Now we have to make the best of itOn 9 June, Anthropic released its Fable generative AI model. Three days later, the US government classified it as a dangerous munition, and used its export-control authority to prohibit any foreign nationals from accessing it....]]></description>
<link>https://tsecurity.de/de/3601722/ai-nachrichten/the-anthropic-fable-saga-proves-we-have-opened-the-ai-pandoras-box-what-now-nathan-e-sanders-and-bruce-schneier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601722/ai-nachrichten/the-anthropic-fable-saga-proves-we-have-opened-the-ai-pandoras-box-what-now-nathan-e-sanders-and-bruce-schneier/</guid>
<pubDate>Tue, 16 Jun 2026 14:02:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> We have opened the AI Pandora’s box. Now we have to make the best of it</p><p>On 9 June, Anthropic <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">released</a> its Fable generative AI model. Three days later, the US government <a href="https://www.explainx.ai/blog/us-government-bans-fable-5-mythos-5-anthropic-export-control-2026">classified</a> it as a dangerous munition, and used its export-control authority to <a href="https://www.theguardian.com/technology/2026/jun/13/anthropic-disable-advanced-ai-models-us-government-order">prohibit</a> any foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, the company <a href="https://www.anthropic.com/news/fable-mythos-access">shut off</a> access for everyone.</p><p>The government’s actions <a href="https://freefable.org/">won’t help</a>. The problem isn’t any one particular models; it’s the general trend of increasing AI capabilities. And any real solution requires the sort of collective action that just isn’t possible right now.</p><p>Bruce Schneier is a security technologist who teaches at the Harvard Kennedy School at Harvard University</p> <a href="https://www.theguardian.com/commentisfree/2026/jun/16/anthropic-fable-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Want to get a data center online quickly? Give it some flex.]]></title>
<description><![CDATA[At the end of a tense and scoreless first half of a soccer match between the English men’s team and rival Germany, millions of Brits let out a collective sigh and did what they so often do in moments of stress: They made tea. That wave of electric kettles clicking on, however, caused a different…]]></description>
<link>https://tsecurity.de/de/3601360/ai-nachrichten/want-to-get-a-data-center-online-quickly-give-it-some-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601360/ai-nachrichten/want-to-get-a-data-center-online-quickly-give-it-some-flex/</guid>
<pubDate>Tue, 16 Jun 2026 12:04:01 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At the end of a tense and scoreless first half of a soccer match between the English men’s team and rival Germany, millions of Brits let out a collective sigh and did what they so often do in moments of stress: They made tea. That wave of electric kettles clicking on, however, caused a different…]]></content:encoded>
</item>
<item>
<title><![CDATA[The Art of Taking Notes]]></title>
<description><![CDATA[How To Effectively Take Notes That Not Only Boost Your Memory But Also Make Others Worth ReadingWhether you are in any technical, non-technical, financial, or medical field, you must have taken notes, whether for your career or yourself.And if you haven’t created your own notes, believe me, after...]]></description>
<link>https://tsecurity.de/de/3600901/hacking/the-art-of-taking-notes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600901/hacking/the-art-of-taking-notes/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qn1U1UFVOPnskJ2tSYULYg.png"></figure><h4>How To Effectively Take Notes That Not Only Boost Your Memory But Also Make Others Worth Reading</h4><p>Whether you are in any technical, non-technical, financial, or medical field, you must have taken notes, whether for your career or yourself.</p><p>And if you haven’t created your own notes, believe me, after this blog, you will surely start making your own notes.</p><h3>Why Take Notes?</h3><p>Before understanding <strong>“<em>How to Take Notes Effectively</em>”,</strong> we have to understand “<strong><em>Why Even Take Notes in the First Place?”</em></strong></p><p>The main objective of taking any notes depends upon your own intentions.</p><ul><li>Whether you want to publish them</li><li>Whether you want to share them with your friends, colleagues, classmates or professors</li><li>Whether you keep them private for yourself</li><li>Whether you want to keep remembering specific details and topics</li><li>Whether you want to make a summary or brief point downs</li></ul><p><strong>[ One Thing will be common ]</strong></p><p>Which is your intention/objective. This small thing can even increase your notes' effectiveness from 2x to 4x times.</p><blockquote>Your Objective Answers “Why Your Notes Exist”</blockquote><h3>How to Improve Your Notes? (Avoid common mistakes)</h3><p>Let’s go straight forward towards improving your notes.</p><p>To improve your notes, the first step is</p><h4>[1] Identify What to Note?</h4><ul><li>Not every word, every line should be noted in the notes. It’s just like if you were highlighting almost every line on a page while reading a book.</li><li><strong>Solution</strong>: You should select specific line or words that gives the meaning or fulfils the purpose of the concept you are making notes on.</li></ul><h4><strong>[2] How to Note?</strong></h4><ul><li>Many people don’t really fully understand the concept. They read or understand one line and write a note, and then another line and so on.</li><li><strong>Solution</strong>: You first have to learn the whole concept, and then should abstract it and make notes.</li></ul><h4>[3] Avoid Common Mistake</h4><ul><li><strong>Avoid Unstructured Notes: </strong>Always make notes in a structured way. (i.e. Index, Aim, Concept, Description, Summary). It depends on the objective of the note.</li><li><strong>Avoid Too Many Highlights in Notes: </strong>Not many words need to be highlighted or bold from each line. Highlighting many words makes it hard to grasp concepts.</li><li><strong>Avoid Copy/Paste:</strong> Many of you have at least “<strong><em>copy and paste</em></strong>” as it is in the notes. Instead, you should take notes in your own language as you were explaining it to someone. This will make your notes highly understandable and help you retain information in the long term.</li><li><strong>Avoid Taking Notes on Note-Taking Apps: </strong>If you were taking notes on simple applications (i.e. Google Notes, Notepad, Notepad++, Sticky Notes, etc). It’s time to move on to other applications.</li></ul><h3>Note-Taking Applications</h3><p>The Note-Taking applications are specifically designed to make the note-taking process faster, easier and more effective.</p><p>Google Notes is quite good, but only for making short notes. If you are making very large notes, you should avoid Google Notes, as there are some better options available.</p><p>There are plenty of applications available in the market. And I have used many applications to test whether they’re user-friendly and convenient.</p><p>I won’t assume that you only use laptops and desktops for taking notes. Instead, I will assume that you can take and review your notes whenever you want, whether you only have your laptop, your computer, or your mobile.</p><p>So, once you make notes, you can also access them from different devices.</p><p>Some of the best tools I have used,</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/817/1*XzcegPk0YpLQf2MOAYvoXA.png"></figure><h4><a href="https://www.notion.com/">[1] Notion</a></h4><p>The reason I put Notion on no. 1 is simple. Its features, UI, and Integrations.</p><ul><li>Notion’s beginner-friendly UI makes the note-taking process easy.</li><li>Notion’s suite helps you map your activity and notes synchronizly. (i.e. Notion, Notion Calendar, Notion Mail)</li><li>It integrates with many applications.</li><li>It also supports integrated Notion AI.</li><li>It is cross-platform.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0eJ4OS3AcJJsb4kE1MMahQ.png"></figure><h4><a href="https://obsidian.md/">[2] Obsidian</a></h4><p>Obsidian is also very popular among note-taking apps. It is known for</p><ul><li>Its awesome UI and theme.</li><li>cross-platform.</li><li>Canvas, Graphs and Links.</li><li>Publications.</li><li>Integrated features and plugins.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1hvdnc9wGYpOcYFPKPwCwQ.png"></figure><h4><a href="https://www.microsoft.com/en-in/microsoft-365/onenote/digital-note-taking-app">[3] OneNote from Microsoft</a></h4><p>OneNote is one of the most popular for</p><ul><li>Cross-platform</li><li>Cloud storing notes</li><li>Integrated Copilot</li><li>Collaboration</li><li>Advanced Features (i.e. Sketch, voice transcription)</li></ul><p>You may use any of these tools as per your convenience.</p><h3>Conclusion</h3><p>Making good and effective notes helps you recall things, tracking your progress, day-to-day activity, planning and preparation.</p><p>Using good software helps you increase your efficiency &amp; effectiveness of the notes. Not only softwares, but how you make notes decides how deeply you understan the concept and how effectively you can explain it to other (Skilling up: Grasping + Presentation).</p><p>Like and share this to your friends and colleagues. Help them improve because the better you make notes, the better you will understand the concept.</p><p>Also let me know in the comments,</p><ul><li><strong>Have you used or currently using one of these applications before for taking notes?</strong></li><li><strong>What features of them do you like the most?</strong></li><li><strong>What other note-taking app do you use?</strong></li></ul><p>See you in the next blog.</p><p><strong><em>Keep Learning — Keep Growing</em></strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ff5208fa13eb" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-art-of-taking-notes-ff5208fa13eb">The Art of Taking Notes</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DocLang aims to make documents readable by AI, not humans]]></title>
<description><![CDATA[AIs struggle to understand documents designed for humans; the DocLang working group seeks to flip that imbalance with its specification for machine-readable business documents “built from the ground up for LLM tokenizers.”



The working group, founded by IBM, Nvidia, and Red Hat and hosted by th...]]></description>
<link>https://tsecurity.de/de/3600883/ai-nachrichten/doclang-aims-to-make-documents-readable-by-ai-not-humans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600883/ai-nachrichten/doclang-aims-to-make-documents-readable-by-ai-not-humans/</guid>
<pubDate>Tue, 16 Jun 2026 09:04:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AIs struggle to understand documents designed for humans; the DocLang working group seeks to flip that imbalance with its specification for machine-readable business documents “built from the ground up for LLM tokenizers.”</p>



<p>The working group, founded by IBM, Nvidia, and Red Hat and hosted by the Linux Foundation’s LF AI &amp; Data project, aims to create an open, universal, AI-native document format designed to improve how enterprises prepare, exchange, and govern document data for AI systems. ABBYY and Human Signal will also be involved in its development, and other contributors are welcome.</p>



<p>“Enterprises today work across a fragmented landscape of document formats, including PDFs, JPEGs, and other file types built primarily for human consumption rather than AI interpretation,” the group said in its launch <a href="https://www.linuxfoundation.org/press/lf-ai-data-foundation-launches-doclang-specification-working-group-to-advance-an-open-standard-for-ai-native-documents" target="_blank" rel="noreferrer noopener">announcement</a>.</p>



<p>“This disconnect can introduce complexity, raise costs, and reduce reliability when extracting meaning from business documents,” as organizations increasingly rely on generative AI and agentic systems, it said.</p>



<p><a href="https://www.linkedin.com/in/markcollier/" target="_blank" rel="noreferrer noopener">Mark Collier</a>, executive director of LF AI &amp; Data, said the goal of the <a href="https://doclang.ai/">DocLang Specification</a> Working Group is to “develop a vendor-neutral, interoperable standard that helps organizations prepare document data for AI more reliably, transparently, and at scale.”</p>



<p>DocLang defines a structured, machine-readable format for documents of any type, like JSON for data, that any tool can implement and any pipeline can consume. It builds on <a href="https://www.infoworld.com/article/3997240/docling-an-open-source-tool-kit-for-advanced-document-processing.html">DocLing</a>, a document processing toolkit hosted by LF AI &amp; Data that can transform human-readable PDFs, word processor documents or spreadsheets into structured data.</p>



<h2 class="wp-block-heading">Standards must evolve for AI</h2>



<p>Something like DocLang is needed, said independent technology analyst <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>. “Existing document standards have done an admirable job allowing global stakeholders to confidently collaborate for decades, but it’s becoming increasingly clear that they are in desperate need of an update as AI reshapes the rules around how work gets done,” he explained.</p>



<p>Largely static document types, he said, “can be somewhat limiting when AI is redefining the very word, ‘document.’ In many ways. AI-age documents are far more iterative and dynamic than what they once were, and the definitions need to evolve with the times. The documents we currently live with simply weren’t designed for the AI age.”</p>



<p>Within that context, Levy said, “DocLang represents an early, best hope of achieving some kind of foundational baseline for document standards, one that will hopefully allow more intelligent, more efficient, lower-risk workflows than is currently the case.”</p>



<p>Taking an open-source, vendor-agnostic approach to the process ensures the collective will take precedence over the needs of specific vendors, he said, adding, “earlier standards-setting efforts around networking, documentation, the web, and the cloud powered the free-flowing digital landscape that defines modern life.”</p>



<p>An AI-centric documentation standard will carry that reality into the next generation of technology, said Levy.</p>



<h2 class="wp-block-heading">A question of governance</h2>



<p>The entire concept of LLMs, <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy said, “involves using natural human languages. The computer is supposed to understand us without us changing our syntax or language. Forcing a syntax on users is exactly what we have today with SEO and more advanced programming languages.”</p>



<p>With something like DocLang, where the standard can be applied to content ingestion, he said, “I would be OK with that being automated, which seems to be the intent. The use case I envision is that when I upload a document to an agent, a skill can be run to preprocess the document into the DocLang standard format, saving tokens.”</p>



<p>That makes sense, he said, adding that he thinks it’s good “if it can help generate outputs, like a visualization, that can be shared outside an AI tool. On that front, that is also why I am liking Web MCP, since you are just adding some code to the page, like CSS or JavaScript, and the consumer, in this case, an AI browser or skill, is better equipped to handle the site.”</p>



<p>The point, he said, is, “these standards need to preserve the fact that humans can still do what they want, and do not need to know any coding to be proficient. In terms of governance, I am not sure if it matters.”</p>



<p>But one analyst did foresee governance problems arising from DocLang’s use.</p>



<p><a href="https://www.infotech.com/profiles/yaz-palanichamy" target="_blank" rel="noreferrer noopener">Yaz Palanichamy</a>, senior research analyst at Info-Tech Research Group, said DocLang adoption will require organizations to implement and review controls in order to scale its use accountably and securely.</p>



<p><em>This article first appeared <em>on <a href="https://www.cio.com/article/4183187/doclang-aims-to-make-documents-readable-by-ai-not-humans.html">CIO</a></em>, <em>on June 10, 2026</em>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Ordered to Pay Nearly $10 Million in Brazil Over Loot Boxes Accessible to Minors]]></title>
<description><![CDATA[A Brazilian court has ordered Apple and several other major gaming and tech companies to pay nearly $60 million in damages over loot boxes in games accessible to minors, with Apple alone ordered to pay about $9.8 million.



Times Brasil reported that the 1st Court for Children and Youth of Brazi...]]></description>
<link>https://tsecurity.de/de/3600579/ios-mac-os/apple-ordered-to-pay-nearly-10-million-in-brazil-over-loot-boxes-accessible-to-minors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600579/ios-mac-os/apple-ordered-to-pay-nearly-10-million-in-brazil-over-loot-boxes-accessible-to-minors/</guid>
<pubDate>Tue, 16 Jun 2026 05:39:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Brazilian court has ordered Apple and several other major gaming and tech companies to pay nearly $60 million in damages over loot boxes in games accessible to minors, with Apple alone ordered to pay about $9.8 million.



Times Brasil reported that the 1st Court for Children and Youth of Brazil’s Federal District ordered the companies to pay R$298 million, or about $58.7 million, in collective moral damages after finding that loot boxes expose children and teenagers to gambling-like mechanics.



According to the ruling, loot boxes can encourage compulsive behavior because players spend money without knowing exactly what reward they will receive. The court said Brazil already protects minors through its Constitution, Child and Adolescent Statute, and Consumer Protection Code, even without a later law focused only on loot boxes.



Apple, Microsoft, and Tencent were each ordered to pay R$50 million, which equals about $9.8 million. Google, Sony, Electronic Arts, Riot Games, Ubisoft, Valve, Konami, and Nintendo received smaller penalties ranging from about $7.8 million to $1 million.



The damages will go to the Federal District’s Fund for the Rights of Children and Adolescents. The court also said minors who bought, opened, or accessed loot boxes can seek individual compensation, but each claimant must prove their link to the practice and show the harm suffered.



The companies must also change how loot boxes work in Brazil. The court ordered refund systems for unauthorized purchases by minors, stronger age checks, clearer warnings about random rewards, and full disclosure of the odds for each item.]]></content:encoded>
</item>
<item>
<title><![CDATA[When deep research isn't enough for your business: Sakana AI launches 'ultra deep research' agent for 100+ page reports in 8 hours]]></title>
<description><![CDATA[Tokyo-based AI startup Sakana AI has officially launched its first commercial product, Sakana Marlin. Billed as a "Virtual CSO" (Chief Strategy Officer), Marlin is an autonomous, B2B research agent that deliberately abandons the instantaneous text generation of modern chatbots in favor of deep, l...]]></description>
<link>https://tsecurity.de/de/3600172/it-nachrichten/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600172/it-nachrichten/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tokyo-based AI startup Sakana AI has officially launched its first commercial product, <a href="https://sakana.ai/marlin/">Sakana Marlin</a>. </p><p>Billed as a "<a href="https://sakana.ai/marlin-release/#English">Virtual CSO</a>" (Chief Strategy Officer), Marlin is an autonomous, B2B research agent that deliberately abandons the instantaneous text generation of modern chatbots in favor of deep, long-horizon reasoning. </p><p>What sets Marlin apart from the current ecosystem of AI tools is its temporal scale: instead of returning an answer in seconds, it runs continuous, self-governing reasoning loops for up to eight hours at a time to deliver deeply researched, well cited, 100-page strategy reports and executive slides. The company posted sample reports generated my Marlin on its product website <a href="https://sakana.ai/marlin/">here</a>.</p><p>Available immediately via the company’s website with pricing starting at a pay-as-you-go tier, the platform is designed strictly for enterprise use—specifically targeting corporations, financial institutions, and think tanks. </p><p>The generative AI hype cycle has largely been defined by speed. For the past two years, the industry standard has been the ability to generate a poem, a line of code, or a surface-level summary in mere milliseconds. But the enterprise frontier is rapidly shifting from shallow, rapid generation to deep, methodical reasoning. </p><p>With Marlin, major businesses are no longer asking how fast an AI can answer, but how deeply it can think.</p><h2><b>The Product: A Virtual CSO</b></h2><p>What exactly is a business getting when they deploy Sakana Marlin? The workflow is fundamentally different from typical large language model (LLM) interactions. Rather than engaging in a tedious back-and-forth prompt engineering session, the user simply provides a core research topic. Following a brief initial exchange to sharpen the scope and direction of the investigation, the human steps away entirely.</p><p>For the next several hours, Marlin operates as a self-contained digital strategy team. It formulates its own initial hypotheses, navigates the web to gather data, cross-references sources to verify findings, and maps the causal dynamics within complex business environments. It is effectively searching for the "winning formula" within a sea of noise.</p><p>Think of it less like a search engine and more like a junior strategy consultant locked in a room with a whiteboard and an internet connection. You provide the strategic prompt in the morning, and by the end of the workday, the system delivers a comprehensive, professional-grade portfolio. </p><p>In Marlin's case, the final output is not a generic text blob; it is a structured set of strategic options, complete with executive summary slides, appendices, references, and a deeply researched report. </p><p>The company highlighted several real-world use cases to demonstrate Marlin's capacity for complex synthesis, including generating detailed resolution scenarios for a theoretical blockade of the Strait of Hormuz, mapping out the fragmented global AI regulation patchwork, and analyzing macroeconomic trends like the return of "bond vigilantes".</p><p>Sakana says Marlin relies on multiple AI models, but did not provide specific model names or providers. I've reached out on X to find out more and will update when I receive a repsonse.</p><h2><b>The Engine of Long-Horizon Reasoning</b></h2><p>Under the hood, Marlin is the commercial culmination of Sakana AI’s extensive laboratory breakthroughs over the past two years. </p><p>The product is powered by an exploration engine relying on Sakana's own prior research breakthrough, <a href="https://sakana.ai/ab-mcts/">Adaptive Branching Monte Carlo Tree Search (AB-MCTS)</a>, and leverages frameworks derived from "The AI Scientist," an earlier Sakana AI research project featured in the journal <i>Nature</i> that successfully automated the scientific discovery process from ideation to peer review.</p><p>To understand how this works in practice, consider a real-world analogy: modern chess engines. When a computer plays chess, it doesn't just look at the board and guess; it plays out thousands of potential future moves, evaluating the strength of each resulting position before committing to an action. </p><p>Marlin’s AB-MCTS engine does something similar for research. </p><h2><b>Inside the Engine: The Mechanics of AB-MCTS</b></h2><p>The chronology of this technology traces back to June 2025, when Sakana AI first introduced the framework to the public alongside the research paper <i>“</i><a href="https://arxiv.org/pdf/2503.04412"><i>Wider or Deeper? Scaling LLM Inference-Time Compute with Adaptive Branching Tree Search</i></a><i>”</i>. </p><p>At that time, to encourage developer experimentation with collective AI intelligence, the company released the underlying algorithm as an open-source software library called <b>TreeQuest</b>, distributed under the permissive <b>Apache 2.0 license</b>. This open-source milestone laid the technical foundation for what would eventually evolve into the proprietary, enterprise-grade Marlin product a year later.</p><p>Traditionally, when developers attempt to extract higher-quality reasoning from large language models, they rely on a brute-force method called "repeated sampling"—essentially running the model dozens of times in parallel and hoping one of the answers is correct. However, repeated sampling operates blindly; it cannot evaluate its own intermediate steps or pivot based on external feedback.</p><p>AB-MCTS replaces this paradigm with a principled, multi-turn approach driven by a Bayesian decision framework. As the AI constructs a strategy report, the system treats the research process as a branching tree of possibilities. At each node of the tree, the algorithm dynamically balances two distinct behaviors based on external feedback signals:</p><ul><li><p><b>Going Wider (Exploration):</b> Spawning entirely new, alternative hypotheses or candidate responses when the current path yields diminishing returns or unresolved contradictions.</p></li><li><p><b>Going Deeper (Exploitation):</b> Methodically refining, auditing, and building upon an existing candidate solution that shows high strategic promise.</p></li></ul><p>What transforms this from a laboratory experiment into a commercial engine is its extension into <b>Multi-LLM AB-MCTS</b>. </p><p>Sakana AI’s architecture introduces a critical third dimension to the search tree: the ability to dynamically choose <i>which</i> model to invoke for a specific sub-task, treating the industry’s leading frontier models as a plug-and-play collective intelligence network.</p><p>According to technical documentation published by the company, the engine can coordinate highly heterogeneous models—allowing an orchestration model to delegate initial ideation to one LLM, while utilizing a reasoning-heavy model to audit, verify, and correct intermediate errors generated earlier in the search tree.</p><p>By scaling up compute at inference time—leveraging the distinct "personalities" and strengths of multiple foundation models over thousands of automated cycles—AB-MCTS provides the mathematical guardrails Marlin requires. It ensures that the resulting 100-page strategy reports are not merely long-winded AI generations, but the highly vetted product of systemic, automated trial-and-error.</p><h2><b>Licensing, Data, and Enterprise Implications</b></h2><p>It is crucial to note that Sakana Marlin is distinctly not a general consumer tool; it is a commercial software-as-a-service (SaaS) offering restricted to corporate entities, organizations, and sole proprietors.</p><p>For enterprises, licensing and data handling terms are often the determining factors in software adoption. Unlike many consumer-grade AI tools that silently harvest user inputs and proprietary data to train future foundational models, Sakana Marlin operates under a strict, enterprise-grade data policy. </p><p>Neither Sakana AI nor its external AI service providers will use customer data or inputs for model training or fine-tuning unless the client provides explicit opt-in consent. </p><p>Even with consent, data is heavily processed to remove personally identifiable information. This closed-loop security is absolutely vital for companies handling sensitive M&amp;A research, unreleased product strategies, or proprietary market analyses.</p><p>The commercial licensing is structured into tiered pricing models that reflect its enterprise nature:</p><ul><li><p><b>Pay-as-you-go:</b> Users can purchase credits on demand, with a single run costing 100 credits, and add-on credits priced at ¥98 ($0.61 USD) each.</p></li><li><p><b>Pro Plan:</b> At ¥150,000 ($935.68 USD) per month, businesses receive 2,000 credits, bringing down the cost of add-on credits to ¥90 ($0.56 USD).</p></li><li><p><b>Team Plan:</b> Geared toward larger departments, this ¥400,000 ($2,495.14 USD) per month tier includes 6,000 credits, lowering add-on costs to ¥85 ($0.53 USD) per credit.</p></li><li><p><b>Enterprise:</b> Fully custom quotes with dedicated support and customized credit allocations.</p></li></ul><h2><b>Why Sakana Is Worth Watching</b></h2><p>Sakana AI’s transition into a commercial enterprise powerhouse is rooted in the pedigree of its founders, who famously helped spark the current generative AI boom. </p><p><a href="https://venturebeat.com/ai/what-you-need-to-know-about-sakana-ai-the-new-startup-from-a-transformer-paper-co-author">Formed in Tokyo in 2023</a>, the startup was co-founded by Llion Jones—a co-author of Google’s seminal 2017 “Attention Is All You Need” paper who coined the term “transformer”—and David Ha, a former Google Brain researcher and head of research at Stability AI. </p><p>The decision to build a new laboratory outside the Silicon Valley bubble was a deliberate rejection of the current AI ecosystem. At a TED AI conference in late 2025, <a href="https://venturebeat.com/technology/sakana-ais-cto-says-hes-absolutely-sick-of-transformers-the-tech-that-powers">Jones candidly expressed that he was "absolutely sick" of transformers</a>, warning that the intense pressure from investors and the hyper-fixation on scaling single, monolithic models had calcified the industry's creativity and blinded researchers to the next major breakthrough.</p><p>To break free from this "big company-itis," Jones and Ha structured Sakana AI around principles of biomimicry and evolutionary computing. </p><p>The company's name, derived from the Japanese word for fish, reflects its core technical philosophy: leveraging collective intelligence similar to schools of fish, ant colonies, or insect swarms. Rather than attempting to build one massive, do-it-all foundation model, Sakana’s research has consistently focused on deploying networks of smaller, specialized models that collaborate dynamically to adapt to complex environments. </p><p>This philosophy posits that by treating individual AI models as members of a "dream team" with complementary strengths, systems can achieve more robust and cost-effective reasoning than relying on sheer scale alone.</p><p>This nature-inspired approach quickly yielded dividends in rigorous, competitive testing. Sakana AI has made significant strides in "inference-time scaling"—allocating computational resources during the problem-solving phase to allow models to think, iterate, and refine their own answers over extended periods. </p><p>In early 2026, the company’s<a href="https://sakana.ai/ahc058/"> ALE-Agent took first place in the highly complex AtCoder Heuristic Contest (AHC058),</a> a combinatorial optimization challenge, outperforming over 800 top-tier human programmers by autonomously rebuilding and testing hundreds of solutions over a four-hour window. </p><p>Similarly,<a href="https://venturebeat.com/orchestration/how-sakana-trained-a-7b-model-to-orchestrate-gpt-5-claude-sonnet-4-and-gemini-2-5-pro"> Sakana introduced "RL Conductor,"</a> a small 7-billion-parameter model trained via reinforcement learning specifically to orchestrate and delegate tasks among a diverse pool of worker models—ranging from GPT-5 to Claude Sonnet 4—achieving state-of-the-art results on reasoning benchmarks at a fraction of traditional computing costs.</p><p>Sakana's rapid evolution from a disruptive research lab to a commercial software provider has attracted intense attention from global financial heavyweights. </p><p>By late 2025, the Tokyo-based startup secured a massive <a href="https://techcrunch.com/2025/11/17/sakana-ai-raises-135m-series-b-at-a-2-65b-valuation-to-continue-building-ai-models-for-japan/">Series B funding round that pushed its post-money valuation past $2.6 billion</a>, cementing its status as one of Japan’s most highly valued private tech companies. The firm boasts a sprawling roster of strategic investors, including early venture backers Khosla Ventures, Lux Capital, and New Enterprise Associates (NEA), alongside industry titans like Nvidia and Google. </p><p>As Sakana has expanded its focus toward mission-critical sectors like defense and finance, it has also drawn investments from major global banking institutions like Mitsubishi UFJ Financial Group (MUFG) and Citi, as well as enterprise tech giant Salesforce, positioning the startup to actively reshape corporate AI infrastructure from the ground up.</p><h2><b>Community Reactions and Field Testing</b></h2><p>Sakana AI’s shift toward commercial, long-horizon agents did not happen in a vacuum. The company ran a rigorous closed beta test beginning in April 2026, putting the tool in the hands of approximately 300 professionals across financial institutions, consulting firms, and think tanks. The feedback underscores a stark qualitative difference between standard generative chatbots and Marlin’s autonomous, fact-driven approach.</p><p>A senior consultant at a major Tokyo consulting firm noted that the tool "exceeded expectations by discovering angles we hadn't even imagined," praising its ability to match human comprehensiveness while stripping away human bias. Meanwhile, a cybersecurity division at a major Japanese IT system integrator lauded the system for providing "a highly convincing report driven by high-quality, primary research," rather than relying on recycled secondary sources.</p><p>On social media, the company’s announcement resonated with the broader tech community's growing appetite for autonomous agents. </p><p>As the AI industry matures, the value proposition is clearly shifting. Tools that act as fast, conversational encyclopedias are becoming commoditized. With Sakana Marlin, the focus moves entirely to separating the heavy lifting of thinking from the final act of deciding. By delegating the exhaustive mapping of causal dynamics to an agent capable of sustained reasoning, human executives are free to do what they do best: take action.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/87ceb3fbef7fbc34d98350587fd2584a615c6dfc: [DTensor] Support _StridedShard to Shard through all-to-all (#170915)]]></title>
<description><![CDATA[(AI generated commit description)
[DTensor] Support _StridedShard to Shard through all-to-all
Summary
This PR adds support for redistributing tensors from _StridedShard placement to Shard placement using the all-to-all collective operation.
The key challenge is that _StridedShard produces non-con...]]></description>
<link>https://tsecurity.de/de/3597974/downloads/trunk87ceb3fbef7fbc34d98350587fd2584a615c6dfc-dtensor-support-stridedshard-to-shard-through-all-to-all-170915/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597974/downloads/trunk87ceb3fbef7fbc34d98350587fd2584a615c6dfc-dtensor-support-stridedshard-to-shard-through-all-to-all-170915/</guid>
<pubDate>Mon, 15 Jun 2026 06:16:03 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>(AI generated commit description)</p>
<h2>[DTensor] Support _StridedShard to Shard through all-to-all</h2>
<h3>Summary</h3>
<p>This PR adds support for redistributing tensors from <code>_StridedShard</code> placement to <code>Shard</code> placement using the all-to-all collective operation.</p>
<p>The key challenge is that <code>_StridedShard</code> produces non-contiguous (interleaved) shards, so converting to a regular <code>Shard</code> placement requires:</p>
<ol>
<li>Properly computing padding for both the source strided dimension and target dimension</li>
<li>Reordering elements after the all-to-all to restore contiguous layout</li>
</ol>
<h3>Example: Converting <code>_StridedShard(0, split_factor=2)</code> to <code>Shard(1)</code></h3>
<p>Consider the following setup:</p>
<ul>
<li><strong>Mesh shape</strong>: <code>(4,)</code> — 4 ranks on a single mesh dimension</li>
<li><strong>Original tensor shape</strong>: <code>(9, 4)</code></li>
<li><strong>Source placement</strong>: <code>(_StridedShard(0, split_factor=2),)</code></li>
<li><strong>Target placement</strong>: <code>(Shard(1),)</code></li>
</ul>
<h4>Step 1: Understand the _StridedShard distribution</h4>
<p>With <code>_StridedShard(0, split_factor=2)</code>, the tensor is conceptually split in two levels on dimension 0:</p>
<ol>
<li><strong>First level</strong>: Split into <code>split_factor=2</code> pieces → chunks of size ⌈9/2⌉ = 5, giving pieces <code>[0:5]</code> and <code>[5:9]</code></li>
<li><strong>Second level</strong>: Each piece is split into <code>num_chunks=4</code> pieces (mesh size)</li>
</ol>
<p>The shards are then interleaved so each rank gets one slice from each first-level piece:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Original tensor (9x4):            Strided sharding on dim 0:
┌─────────────────────┐
│ row 0               │  ─┐
│ row 1               │   ├─ First piece [0:5], split into 4 chunks
│ row 2               │   │  → chunks: [0:2], [2:4], [4:5], []
│ row 3               │   │
│ row 4               │  ─┘
│ row 5               │  ─┐
│ row 6               │   ├─ Second piece [5:9], split into 4 chunks
│ row 7               │   │  → chunks: [5:6], [6:7], [7:8], [8:9]
│ row 8               │  ─┘
└─────────────────────┘

Interleaved distribution to ranks:
  Rank 0: rows [0,1] + [5]     = rows [0,1,5]     (3 rows)
  Rank 1: rows [2,3] + [6]     = rows [2,3,6]     (3 rows)
  Rank 2: rows [4]   + [7]     = rows [4,7]       (2 rows)
  Rank 3: []         + [8]     = rows [8]         (1 row)"><pre class="notranslate"><code>Original tensor (9x4):            Strided sharding on dim 0:
┌─────────────────────┐
│ row 0               │  ─┐
│ row 1               │   ├─ First piece [0:5], split into 4 chunks
│ row 2               │   │  → chunks: [0:2], [2:4], [4:5], []
│ row 3               │   │
│ row 4               │  ─┘
│ row 5               │  ─┐
│ row 6               │   ├─ Second piece [5:9], split into 4 chunks
│ row 7               │   │  → chunks: [5:6], [6:7], [7:8], [8:9]
│ row 8               │  ─┘
└─────────────────────┘

Interleaved distribution to ranks:
  Rank 0: rows [0,1] + [5]     = rows [0,1,5]     (3 rows)
  Rank 1: rows [2,3] + [6]     = rows [2,3,6]     (3 rows)
  Rank 2: rows [4]   + [7]     = rows [4,7]       (2 rows)
  Rank 3: []         + [8]     = rows [8]         (1 row)
</code></pre></div>
<h4>Step 2: Pad for uniform all-to-all</h4>
<p>Before all-to-all, we pad so all ranks have uniform chunk sizes:</p>
<ul>
<li><strong>Old dimension (dim 0)</strong>: <code>max_chunk_size = 3</code>, pad ranks 2 and 3</li>
<li><strong>New dimension (dim 1)</strong>: size 4 with 4 chunks → already uniform (chunk size 1 each)</li>
</ul>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="After padding dim 0:
  Rank 0: [0,1,5] (no padding)    → shape (3, 4)
  Rank 1: [2,3,6] (no padding)    → shape (3, 4)
  Rank 2: [4,7,P] (+1 padding)    → shape (3, 4)
  Rank 3: [8,P,P] (+2 padding)    → shape (3, 4)"><pre class="notranslate"><code>After padding dim 0:
  Rank 0: [0,1,5] (no padding)    → shape (3, 4)
  Rank 1: [2,3,6] (no padding)    → shape (3, 4)
  Rank 2: [4,7,P] (+1 padding)    → shape (3, 4)
  Rank 3: [8,P,P] (+2 padding)    → shape (3, 4)
</code></pre></div>
<h4>Step 3: All-to-all on dim 0 → dim 1</h4>
<p>The all-to-all exchanges slices: each rank sends dim-1 slices to other ranks and receives dim-0 slices:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Before A2A (each rank has 3x4):     After A2A (each rank has 12x1):
  Rank 0: rows [0,1,5] cols [0,1,2,3]  →  col 0 from all ranks
  Rank 1: rows [2,3,6] cols [0,1,2,3]  →  col 1 from all ranks
  Rank 2: rows [4,7,P] cols [0,1,2,3]  →  col 2 from all ranks
  Rank 3: rows [8,P,P] cols [0,1,2,3]  →  col 3 from all ranks"><pre class="notranslate"><code>Before A2A (each rank has 3x4):     After A2A (each rank has 12x1):
  Rank 0: rows [0,1,5] cols [0,1,2,3]  →  col 0 from all ranks
  Rank 1: rows [2,3,6] cols [0,1,2,3]  →  col 1 from all ranks
  Rank 2: rows [4,7,P] cols [0,1,2,3]  →  col 2 from all ranks
  Rank 3: rows [8,P,P] cols [0,1,2,3]  →  col 3 from all ranks
</code></pre></div>
<h4>Step 4: Unpad and reorder</h4>
<p>After all-to-all, each rank has interleaved rows from the strided pattern with padding. We use <code>index_select</code> to:</p>
<ol>
<li>Extract only the valid (non-padded) elements</li>
<li>Reorder from strided order <code>[0,1,5,2,3,6,4,7,8]</code> back to natural order <code>[0,1,2,3,4,5,6,7,8]</code></li>
</ol>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Final result - Shard(1) distribution:
  Rank 0: all 9 rows, col 0  → shape (9, 1)
  Rank 1: all 9 rows, col 1  → shape (9, 1)
  Rank 2: all 9 rows, col 2  → shape (9, 1)
  Rank 3: all 9 rows, col 3  → shape (9, 1)"><pre class="notranslate"><code>Final result - Shard(1) distribution:
  Rank 0: all 9 rows, col 0  → shape (9, 1)
  Rank 1: all 9 rows, col 1  → shape (9, 1)
  Rank 2: all 9 rows, col 2  → shape (9, 1)
  Rank 3: all 9 rows, col 3  → shape (9, 1)
</code></pre></div>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3749201916" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/170915" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/170915/hovercard" href="https://github.com/pytorch/pytorch/pull/170915">#170915</a><br>
Approved by: <a href="https://github.com/weifengpy">https://github.com/weifengpy</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TDF 2026 - Computer says no. Troubles with fixing algorithmic decision-making.]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:12 https://media.ccc.de/v/tdf5-125-computer-says-no-troubles-with-fixing-algorithmic-decision-making-

Algorithmic predictions are used to allocate social goods such as healthcare, job training, and education. Despite efforts to apply fairness framewor...]]></description>
<link>https://tsecurity.de/de/3597585/it-security-video/tdf-2026-computer-says-no-troubles-with-fixing-algorithmic-decision-making/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597585/it-security-video/tdf-2026-computer-says-no-troubles-with-fixing-algorithmic-decision-making/</guid>
<pubDate>Sun, 14 Jun 2026 22:05:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:12 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/BbqcVwvNjbI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/tdf5-125-computer-says-no-troubles-with-fixing-algorithmic-decision-making-<br />
<br />
Algorithmic predictions are used to allocate social goods such as healthcare, job training, and education. Despite efforts to apply fairness frameworks and participatory approaches, practical outcomes remain problematic as recent investigations have shown. This talk examines standard approaches to ‘fair machine learning’ through three cases: (1) health programs, (2) long-term unemployment, and (3) school dropout. It critically assesses their limitations and normative assumptions. Two key distinctions clarify the debates: fairness-focused versus welfare-focused methods on the one hand, and whether predictions are instrumentally or communicatively rational on the other. The latter distinction stresses whether algorithms serve effective implementation or facilitate collective evaluation of policy goals.<br />
<br />
Sebastian Zezulka<br />
<br />
https://cfp.cttue.de/tdf5/talk/SBXZNK/<br />
<br />
#tdf2026 #EthicsPoliticsandSociety<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Computer says no. Troubles with fixing algorithmic decision-making. (tdf2026)]]></title>
<description><![CDATA[Algorithmic predictions are used to allocate social goods such as healthcare, job training, and education. Despite efforts to apply fairness frameworks and participatory approaches, practical outcomes remain problematic as recent investigations have shown. This talk examines standard approaches t...]]></description>
<link>https://tsecurity.de/de/3597557/it-security-video/computer-says-no-troubles-with-fixing-algorithmic-decision-making-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597557/it-security-video/computer-says-no-troubles-with-fixing-algorithmic-decision-making-tdf2026/</guid>
<pubDate>Sun, 14 Jun 2026 21:49:08 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Algorithmic predictions are used to allocate social goods such as healthcare, job training, and education. Despite efforts to apply fairness frameworks and participatory approaches, practical outcomes remain problematic as recent investigations have shown. This talk examines standard approaches to ‘fair machine learning’ through three cases: (1) health programs, (2) long-term unemployment, and (3) school dropout. It critically assesses their limitations and normative assumptions. Two key distinctions clarify the debates: fairness-focused versus welfare-focused methods on the one hand, and whether predictions are instrumentally or communicatively rational on the other. The latter distinction stresses whether algorithms serve effective implementation or facilitate collective evaluation of policy goals.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/SBXZNK/]]></content:encoded>
</item>
<item>
<title><![CDATA[fedora's default fontconfig made my browser fingerprint worse than windows, not better]]></title>
<description><![CDATA[Honestly did not expect this. Ran an open source 8 surface scanner (TypeScript, on GitHub, checks run locally, I read the source first) on the same Firefox across both. Windows: 38/100. Fedora: 23/100. Font enumeration was Critical because of wqy zenhei and xorg x11 fonts misc. Stripped to Noto, ...]]></description>
<link>https://tsecurity.de/de/3597454/linux-tipps/fedoras-default-fontconfig-made-my-browser-fingerprint-worse-than-windows-not-better/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597454/linux-tipps/fedoras-default-fontconfig-made-my-browser-fingerprint-worse-than-windows-not-better/</guid>
<pubDate>Sun, 14 Jun 2026 20:12:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Honestly did not expect this. Ran an open source 8 surface scanner (TypeScript, on GitHub, checks run locally, I read the source first) on the same Firefox across both. Windows: 38/100. Fedora: 23/100. Font enumeration was Critical because of wqy zenhei and xorg x11 fonts misc.</p> <p>Stripped to Noto, Liberation, DejaVu. Font enumeration flipped to Safe, composite hit 61.</p> <p>Canvas and WebGL still Critical on both. No idea what to do about Mesa.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/No-Fact-8828"> /u/No-Fact-8828 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u5qr4z/fedoras_default_fontconfig_made_my_browser/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u5qr4z/fedoras_default_fontconfig_made_my_browser/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9629 | codesupplyco Canvas Plugin up to 2.5.2 on WordPress day cross site scripting (EUVD-2026-36648)]]></title>
<description><![CDATA[A vulnerability was found in codesupplyco Canvas Plugin up to 2.5.2 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument day results in cross site scripting.

This vulnerability is cataloged as CVE-2026-9629. The attack may b...]]></description>
<link>https://tsecurity.de/de/3596097/sicherheitsluecken/cve-2026-9629-codesupplyco-canvas-plugin-up-to-252-on-wordpress-day-cross-site-scripting-euvd-2026-36648/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596097/sicherheitsluecken/cve-2026-9629-codesupplyco-canvas-plugin-up-to-252-on-wordpress-day-cross-site-scripting-euvd-2026-36648/</guid>
<pubDate>Sat, 13 Jun 2026 21:21:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/codesupplyco:canvas_plugin">codesupplyco Canvas Plugin up to 2.5.2</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code. The manipulation of the argument <em>day</em> results in cross site scripting.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-9629">CVE-2026-9629</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[ciflow/trunk/187140: Add _single c10d::Backend methods and migrate backends to them (#187140)]]></title>
<description><![CDATA[Summary:
Introduce the torchcomms _single collective names on the C++ c10d::Backend and migrate the in-tree backends to define them, while keeping the old names fully working for backward compatibility.
Backend now declares all_gather_single, all_gather_single_coalesced, reduce_scatter_single, re...]]></description>
<link>https://tsecurity.de/de/3594766/downloads/ciflowtrunk187140-add-single-c10dbackend-methods-and-migrate-backends-to-them-187140/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594766/downloads/ciflowtrunk187140-add-single-c10dbackend-methods-and-migrate-backends-to-them-187140/</guid>
<pubDate>Sat, 13 Jun 2026 02:16:42 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Summary:</p>
<p>Introduce the torchcomms <code>_single</code> collective names on the C++ <code>c10d::Backend</code> and migrate the in-tree backends to define them, while keeping the old names fully working for backward compatibility.</p>
<p><code>Backend</code> now declares <code>all_gather_single</code>, <code>all_gather_single_coalesced</code>, <code>reduce_scatter_single</code>, <code>reduce_scatter_single_coalesced</code>, and <code>all_to_all_single</code> alongside the existing <code>_allgather_base</code>, <code>allgather_into_tensor_coalesced</code>, <code>_reduce_scatter_base</code>, <code>reduce_scatter_tensor_coalesced</code>, and <code>alltoall_base</code>, which are kept as overridable, forwarding aliases.</p>
<p>Backward compatibility is preserved in both directions: each new method and its old-name alias forward to each other, so a <code>Backend</code> subclass may override EITHER name and a caller may invoke EITHER name. The old aliases simply forward to the canonical <code>_single</code> method; each canonical method opens with the <code>C10D_BACKEND_FORWARDING_GUARD()</code> macro, which installs a function-local thread-local re-entry flag using <code>__func__</code> for the message. If a backend overrides neither name the mutual forwarding re-enters the canonical method, the flag trips, and it reports "does not support " instead of recursing forever. As a result, existing callers of the old names (first-party and out-of-tree) and existing out-of-tree backends that override the old names both keep working unchanged. Removing the old overrides outright would have broken out-of-tree backends on the dispatch path, and dropping the old caller-facing names would have broken direct callers; the bidirectional forwarding avoids both.</p>
<p>The old names are intentionally NOT marked <code>C10_DEPRECATED_MESSAGE</code> in this change. PyTorch's open-source build compiles the bundled <code>third_party/torch-xpu-ops</code> submodule with <code>-Werror -Wdeprecated</code>, and its XPU collective op registration (<code>xccl/Register.cpp</code>) still calls the old <code>Backend</code> names, so a compile-time deprecation turns into a hard build error there. The deprecation will be reintroduced in a follow-up once those callers (and any other out-of-tree backends that are built in-tree) are migrated to the <code>_single</code> names and the submodule pin is bumped.</p>
<p>The in-tree backends are migrated to define the new names: <code>ProcessGroupNCCL</code>, <code>ProcessGroupGloo</code>, <code>ProcessGroupMPI</code>, <code>ProcessGroupUCC</code>, <code>ProcessGroupWrapper</code>, <code>FakeProcessGroup</code>, <code>NCCLXStub</code>, and the <code>torch_openreg</code> (<code>ProcessGroupOCCL</code>) test backend. The dispatcher op implementations in <code>Ops.cpp</code>, <code>ProcessGroupWrapper</code>'s forwarders, and the <code>Backend</code> pybind bindings in <code>init.cpp</code> use the new names.</p>
<p>The underlying aten / c10d dispatcher op names (<code>c10d::_allgather_base_</code>, <code>c10d::alltoall_base_</code>, etc.), their schema strings, the <code>IMPL_*</code> macro names in <code>Ops.cpp</code>, and the <code>OpType</code> enum values are intentionally left unchanged for backward compatibility.</p>
<p>Suggested review order: <code>Backend.hpp</code> (the new/old method pairs and the bidirectional forwarding + <code>ForwardingGuard</code>), then the per-backend subclass renames, then the <code>Ops.cpp</code> / <code>ProcessGroupWrapper</code> / <code>init.cpp</code> call sites.</p>
<p>This diff was authored with the assistance of an AI coding agent (Claude).</p>
<p>Test Plan:<br>
This revision only removes the compile-time deprecation annotations (<code>C10_DEPRECATED_MESSAGE</code>), their <code>-Wdeprecated-declarations</code> suppressions, and the now-unused <code>&lt;c10/util/Deprecated.h&gt;</code> include. The <code>_single</code> rename and the bidirectional forwarding/recursion guard are unchanged, so there is no runtime or codegen change -- dropping the annotations only removes deprecation warnings.</p>
<p>Verified by open-source CI on the exported commit: the full libtorch build across platforms, the <code>linux-noble-xpu-n-py3.10 / build-osdc</code> job (which compiles the bundled <code>torch-xpu-ops</code> <code>xccl/Register.cpp</code> with <code>-Werror -Wdeprecated</code> and previously failed on <code>-Werror=deprecated-declarations</code>), and the <code>lintrunner-clang</code> format jobs.</p>
<p>Reviewed By: kapilsh</p>
<p>Differential Revision: D108364288</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inspect and live-edit 3D WebGL elements]]></title>
<description><![CDATA[Author: Google for Developers - Bewertung: 0x - Views:17 See how the HTML-in-Canvas API  keeps your UI completely accessible, searchable, and inspectable with the tools you use every day. 

Subscribe to Google for Developers → https://goo.gle/developers 

Products Mentioned: Google AI  
Speakers:...]]></description>
<link>https://tsecurity.de/de/3594711/videos/inspect-and-live-edit-3d-webgl-elements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594711/videos/inspect-and-live-edit-3d-webgl-elements/</guid>
<pubDate>Sat, 13 Jun 2026 01:17:27 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Google for Developers - Bewertung: 0x - Views:17 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/PquqdRi8I18?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>See how the HTML-in-Canvas API  keeps your UI completely accessible, searchable, and inspectable with the tools you use every day. <br />
<br />
Subscribe to Google for Developers → https://goo.gle/developers <br />
<br />
Products Mentioned: Google AI  <br />
Speakers: Thomas Nattestad<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google unveils DiffusionGemma, an AI model that breaks free of left-to-right processing]]></title>
<description><![CDATA[Extremely powerful large language models (LLMs) still operate as though they’re typing on a keyboard, processing workloads in a simple left-to-right fashion. But in locally-run, single-user scenarios, this sequential processing can leave graphics processing units (GPUs) and tensor processing unit...]]></description>
<link>https://tsecurity.de/de/3594592/it-nachrichten/google-unveils-diffusiongemma-an-ai-model-that-breaks-free-of-left-to-right-processing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594592/it-nachrichten/google-unveils-diffusiongemma-an-ai-model-that-breaks-free-of-left-to-right-processing/</guid>
<pubDate>Fri, 12 Jun 2026 23:39:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Extremely powerful <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">large language models</a> (LLMs) still operate as though they’re typing on a keyboard, processing workloads in a simple left-to-right fashion. But in locally-run, single-user scenarios, this sequential processing can leave graphics processing units (GPUs) and <a href="https://www.networkworld.com/article/4093957/what-are-tpus-your-guide-to-tensor-processing-units-and-ai-acceleration.html" target="_blank">tensor processing units</a> (TPUs) underutilized.</p>



<p>Google is betting that <a href="https://deepmind.google/models/gemma/diffusiongemma/" target="_blank" rel="noreferrer noopener">DiffusionGemma</a> can get around this bottleneck. The new experimental open model generates text “exceptionally fast,” creating entire blocks of text simultaneously through diffusion techniques rather than through token-by-token processing. The company says this technique results in 4x faster inference compared to auto-regressive models that rely on sequential processing.</p>



<p>It can also save users money. Technology analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a> noted that existing pay-per-token monetization models “penalize the use of less than optimally efficient AI solutions.”</p>



<p>But DiffusionGemma “could herald a new generation of task-defined, efficient solutions that can enable expanded compute capacity without draining the operations budget,” he said.</p>



<h2 class="wp-block-heading">A contrast to left-to-right processing</h2>



<p>Built on Google’s Gemma 4 family and its <a href="https://deepmind.google/models/gemini-diffusion/" target="_blank" rel="noreferrer noopener">Gemini Diffusion</a> research, DiffusionGemma is a 26B mixture-of-experts (MoE) model designed to maximize text output generation.</p>



<p>It essentially shifts <a href="https://www.infoworld.com/article/4169605/21-llms-tuned-for-special-domains.html" target="_blank">how models use hardware</a>, giving processors a larger hunk of work each cycle so it can draft full 256-token paragraphs in sequence. This allows the model to generate text up to 4x faster on GPUs, Google claims. It activates only 3.8B parameters during inference, and, when quantized, can fit within 18GB VRAM on high-end consumer GPUs like Nvidia RTX 5090.</p>



<p>“It upgrades your model inference from a single, sequential typewriter to a massive printing press that stamps the entire block of text simultaneously,” Google research scientists Brendan O’Donoghue and Sebastian Flennerhag wrote in a <a href="https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>AI image generators begin with pure, random ‘visual noise’ and iteratively refine that into a finalized picture (what’s known as ‘diffusion’); DiffusionGemma applies this same process to text. It does not generate tokens in order, but begins with a “canvas of random placeholder tokens” that it processes in multiple passes, identifying the context tokens it feels are most relevant and using those to refine the rest.</p>



<p>The model has the ability to self-correct, using confidence scoring to re-evaluate tokens in the next pass. “The model iteratively refines its own output, allowing it to evaluate the entire text block at once to fix mistakes in real-time,” O’Donoghue and Flennerhag explained.</p>



<p>DiffusionGemma also has bidirectional attention, they wrote. “Generating 256 tokens in parallel with each forward pass allows every token to attend to all others.” This can be particularly helpful in domains that are non-linear in nature, such as mathematical graphs, code infilling, and in-line editing, they said.</p>



<p>DiffusionGemma is optimized across Nvidia’s hardware stack, making it compatible with consumer setups as well as with high-performance enterprise systems like Hopper and Blackwell.</p>



<p>Because it is released under the Apache 2.0 license, developers can freely use, modify, distribute, and commercialize the software using their preferred tools. It can be run on GPUs or in the cloud through <a href="https://console.cloud.google.com/agent-platform/publishers/google/model-garden/diffusiongemma" target="_blank" rel="noreferrer noopener">Google Cloud Model Garden</a> or <a href="https://catalog.ngc.nvidia.com/orgs/nim/teams/google/containers/diffusiongemma-26b-a4b-it?version=latest" target="_blank" rel="noreferrer noopener">Nvidia NIM</a>, and is available on <a href="https://huggingface.co/collections/mlx-community/diffusiongemma" target="_blank" rel="noreferrer noopener">Hugging Face</a>, <a href="https://github.com/google-gemma" target="_blank" rel="noreferrer noopener">GitHub</a>, and <a href="https://vllm-project.github.io/2026/06/10/diffusion-gemma" target="_blank" rel="noreferrer noopener">vLLM</a>, with support for the open-source library <a href="https://github.com/ggml-org/llama.cpp" target="_blank" rel="noreferrer noopener">llama.cpp</a> coming soon.</p>



<h2 class="wp-block-heading">Key use cases</h2>



<p>The model is particularly useful in local workflows that are “speed critical,” such as generation of non-linear text structures, and unlocks what Google calls “new patterns of model behavior” like multimodal understanding and generating and rendering code in near real-time.</p>



<p>Levy explained, “DiffusionGemma is particularly well suited for interactive coding and editing where its efficiency allows rapid processing and iterations,” noting that its ability to fit within 18GB of VRAM and its deployability on commonly available local GPUs can potentially benefit customer service-related workloads that lean heavily on real-time interaction and local processing.</p>



<p>“DiffusionGemma also incorporates a thinking mode that is especially adept at problem solving,” he said. For instance, the model was fine-tuned to play Sudoku, a typically challenging task for autoregressive models because each token depends on future tokens. This “rather handily” illustrates the model’s capability to solve more complex problems, Levy noted.</p>



<h2 class="wp-block-heading">Limitations</h2>



<p>Google freely admits that DiffusionGemma is geared to specific workflows, and there are “key trade-offs.”</p>



<p>The model is engineered for small batch size inferencing and low-latency, high-speed generation low-to-medium batch sizes on a “single capable accelerator.”</p>



<p>In high-QPS cloud serving environments, (where infrastructure is designed to handle tens or hundreds of thousands of requests per second with ultra-low latency), DiffusionGemma’s parallel coding “offers diminishing returns,” and can even result in higher serving costs, Google conceded. In addition, its overall output quality is lower than that of standard Gemma 4, which is built for apps demanding maximum quality.</p>



<p>However, Levy noted that while DiffusionGemma “can be less precise than other models in certain workloads,” subsequent refinement cycles could overcome this limitation.</p>



<p>While Google isn’t sharing runtime costs, it’s clear that this is an efficiency play, he added. “When deployed across the kinds of workloads that would optimally benefit from its architecture, DiffusionGemma seems to have the potential to reduce processing overhead and related costs,” he said.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4184668/google-unveils-diffusiongemma-an-ai-model-that-breaks-free-of-left-to-right-processing.html" target="_blank">InfoWorld</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google unveils DiffusionGemma, an AI model that breaks free of left-to-right processing]]></title>
<description><![CDATA[Extremely powerful large language models (LLMs) still operate as though they’re typing on a keyboard, processing workloads in a simple left-to-right fashion. But in locally-run, single-user scenarios, this sequential processing can leave graphics processing units (GPUs) and tensor processing unit...]]></description>
<link>https://tsecurity.de/de/3594561/ai-nachrichten/google-unveils-diffusiongemma-an-ai-model-that-breaks-free-of-left-to-right-processing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594561/ai-nachrichten/google-unveils-diffusiongemma-an-ai-model-that-breaks-free-of-left-to-right-processing/</guid>
<pubDate>Fri, 12 Jun 2026 23:19:28 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Extremely powerful <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">large language models</a> (LLMs) still operate as though they’re typing on a keyboard, processing workloads in a simple left-to-right fashion. But in locally-run, single-user scenarios, this sequential processing can leave graphics processing units (GPUs) and <a href="https://www.networkworld.com/article/4093957/what-are-tpus-your-guide-to-tensor-processing-units-and-ai-acceleration.html" target="_blank">tensor processing units</a> (TPUs) underutilized.</p>



<p>Google is betting that <a href="https://deepmind.google/models/gemma/diffusiongemma/" target="_blank" rel="noreferrer noopener">DiffusionGemma</a> can get around this bottleneck. The new experimental open model generates text “exceptionally fast,” creating entire blocks of text simultaneously through diffusion techniques rather than through token-by-token processing. The company says this technique results in 4x faster inference compared to auto-regressive models that rely on sequential processing.</p>



<p>It can also save users money. Technology analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a> noted that existing pay-per-token monetization models “penalize the use of less than optimally efficient AI solutions.”</p>



<p>But DiffusionGemma “could herald a new generation of task-defined, efficient solutions that can enable expanded compute capacity without draining the operations budget,” he said.</p>



<h2 class="wp-block-heading">A contrast to left-to-right processing</h2>



<p>Built on Google’s Gemma 4 family and its <a href="https://deepmind.google/models/gemini-diffusion/" target="_blank" rel="noreferrer noopener">Gemini Diffusion</a> research, DiffusionGemma is a 26B mixture-of-experts (MoE) model designed to maximize text output generation.</p>



<p>It essentially shifts <a href="https://www.infoworld.com/article/4169605/21-llms-tuned-for-special-domains.html" target="_blank">how models use hardware</a>, giving processors a larger hunk of work each cycle so it can draft full 256-token paragraphs in sequence. This allows the model to generate text up to 4x faster on GPUs, Google claims. It activates only 3.8B parameters during inference, and, when quantized, can fit within 18GB VRAM on high-end consumer GPUs like Nvidia RTX 5090.</p>



<p>“It upgrades your model inference from a single, sequential typewriter to a massive printing press that stamps the entire block of text simultaneously,” Google research scientists Brendan O’Donoghue and Sebastian Flennerhag wrote in a <a href="https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>AI image generators begin with pure, random ‘visual noise’ and iteratively refine that into a finalized picture (what’s known as ‘diffusion’); DiffusionGemma applies this same process to text. It does not generate tokens in order, but begins with a “canvas of random placeholder tokens” that it processes in multiple passes, identifying the context tokens it feels are most relevant and using those to refine the rest.</p>



<p>The model has the ability to self-correct, using confidence scoring to re-evaluate tokens in the next pass. “The model iteratively refines its own output, allowing it to evaluate the entire text block at once to fix mistakes in real-time,” O’Donoghue and Flennerhag explained.</p>



<p>DiffusionGemma also has bidirectional attention, they wrote. “Generating 256 tokens in parallel with each forward pass allows every token to attend to all others.” This can be particularly helpful in domains that are non-linear in nature, such as mathematical graphs, code infilling, and in-line editing, they said.</p>



<p>DiffusionGemma is optimized across Nvidia’s hardware stack, making it compatible with consumer setups as well as with high-performance enterprise systems like Hopper and Blackwell.</p>



<p>Because it is released under the Apache 2.0 license, developers can freely use, modify, distribute, and commercialize the software using their preferred tools. It can be run on GPUs or in the cloud through <a href="https://console.cloud.google.com/agent-platform/publishers/google/model-garden/diffusiongemma" target="_blank" rel="noreferrer noopener">Google Cloud Model Garden</a> or <a href="https://catalog.ngc.nvidia.com/orgs/nim/teams/google/containers/diffusiongemma-26b-a4b-it?version=latest" target="_blank" rel="noreferrer noopener">Nvidia NIM</a>, and is available on <a href="https://huggingface.co/collections/mlx-community/diffusiongemma" target="_blank" rel="noreferrer noopener">Hugging Face</a>, <a href="https://github.com/google-gemma" target="_blank" rel="noreferrer noopener">GitHub</a>, and <a href="https://vllm-project.github.io/2026/06/10/diffusion-gemma" target="_blank" rel="noreferrer noopener">vLLM</a>, with support for the open-source library <a href="https://github.com/ggml-org/llama.cpp" target="_blank" rel="noreferrer noopener">llama.cpp</a> coming soon.</p>



<h2 class="wp-block-heading">Key use cases</h2>



<p>The model is particularly useful in local workflows that are “speed critical,” such as generation of non-linear text structures, and unlocks what Google calls “new patterns of model behavior” like multimodal understanding and generating and rendering code in near real-time.</p>



<p>Levy explained, “DiffusionGemma is particularly well suited for interactive coding and editing where its efficiency allows rapid processing and iterations,” noting that its ability to fit within 18GB of VRAM and its deployability on commonly available local GPUs can potentially benefit customer service-related workloads that lean heavily on real-time interaction and local processing.</p>



<p>“DiffusionGemma also incorporates a thinking mode that is especially adept at problem solving,” he said. For instance, the model was fine-tuned to play Sudoku, a typically challenging task for autoregressive models because each token depends on future tokens. This “rather handily” illustrates the model’s capability to solve more complex problems, Levy noted.</p>



<h2 class="wp-block-heading">Limitations</h2>



<p>Google freely admits that DiffusionGemma is geared to specific workflows, and there are “key trade-offs.”</p>



<p>The model is engineered for small batch size inferencing and low-latency, high-speed generation low-to-medium batch sizes on a “single capable accelerator.”</p>



<p>In high-QPS cloud serving environments, (where infrastructure is designed to handle tens or hundreds of thousands of requests per second with ultra-low latency), DiffusionGemma’s parallel coding “offers diminishing returns,” and can even result in higher serving costs, Google conceded. In addition, its overall output quality is lower than that of standard Gemma 4, which is built for apps demanding maximum quality.</p>



<p>However, Levy noted that while DiffusionGemma “can be less precise than other models in certain workloads,” subsequent refinement cycles could overcome this limitation.</p>



<p>While Google isn’t sharing runtime costs, it’s clear that this is an efficiency play, he added. “When deployed across the kinds of workloads that would optimally benefit from its architecture, DiffusionGemma seems to have the potential to reduce processing overhead and related costs,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Jeetu Patel made Cisco unrecognizable]]></title>
<description><![CDATA[Cisco Live 2026 is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that Cisco would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely ...]]></description>
<link>https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</guid>
<pubDate>Fri, 12 Jun 2026 17:29:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.ciscolive.com/">Cisco Live 2026</a> is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that <a href="https://www.cisco.com/">Cisco</a> would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely delivered on that pledge. Cisco is repositioning itself from a holding company of products and dashboards to a unified, AI-native infrastructure platform, with Cloud Control as the control plane, Cisco IQ as the CX brain, and Secure Networking as the glue binding it all together.</p>



<p>The shift is not just about new features; it is about a new operating model. Instead of humans clicking through a sprawl of consoles, Cisco is building an environment where human operators and AI agents share the same data, context, and system of action, with humans staying in control. For longtime Cisco customers, the result is a company that, in fact, looks and feels very different from the one Patel inherited.</p>



<h2 class="wp-block-heading">From dashboard sprawl to Cloud Control</h2>



<p>The most visible proof point of the new Cisco is <a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">Cloud Control</a>, the unified management plane that now spans networking, security, compute, observability, collaboration, and an expanding ecosystem of third-party tools. Cisco is careful to note that this is not just another single pane of glass but an active execution environment with policy and identity embedded in the control path, designed from the ground up for humans and AI agents to operate infrastructure together.</p>



<p>Patel’s demo underscores how far Cisco has come from its historical dashboard sprawl. When operators land in Cloud Control, they see a familiar, ChatGPT‑style interface with three modes: Assistant, Canvas, and Actions. Assistant lets operators converse with the platform in natural language. Canvas provides a multiplayer workspace where humans and agents can investigate and resolve issues together. Actions become the mission control for supervising what agents propose and execute.</p>



<p>Crucially, Cloud Control surfaces shared platform services such as inventory and topology across the entire Cisco estate and exposes product tiles for Meraki, Intersight, security services, Splunk, Webex Control Hub, and Cisco IQ, all accessible with a single login. Instead of bouncing between multiple dashboards and authentication domains, operators can move seamlessly between platform services and product experiences within the same environment. For customers who have lived with overlapping portals and inconsistent workflows, this alone makes Cisco feel fundamentally different.</p>



<h2 class="wp-block-heading">Cloud Control as an AI harness, not a console</h2>



<p>Under the hood, Cloud Control is built on a shared data fabric that correlates telemetry across users, devices, applications, networks, and threats. That fabric fuels both human decision-making and agentic automation. Cisco describes this evolution as moving from “infrastructure as code” to “infrastructure as a harness.” Rather than relying solely on scripts and playbooks written by humans, Cloud Control becomes the governed substrate where AI agents can safely observe, reason, and act on real systems.</p>



<p>That harness appears in three visible dimensions. First, AI Canvas provides the workspace where humans and agents co-investigate incidents, with context persisting across shifts and escalations so nothing is lost. Second, Cloud Control Studio offers Agent Builder and App Builder, which let customers and partners build their own agents and applications on top of Cisco’s data, policy, and control plane using natural language and embedded coding assistants. Third, everything built in Studio—plus partner solutions—flows into the Cloud Control Marketplace, where integrations from dozens of ecosystem partners are already available.</p>



<p>For enterprises, the net effect is that Cloud Control shifts from a place to click through settings to the “secure harness” for agentic operations: a governed environment where AI agents can be deployed, monitored, constrained, and audited end-to-end. That is a very different proposition from the traditional network management console.</p>



<h2 class="wp-block-heading">CX and products finally share a brain</h2>



<p>Historically, <a href="https://www.cisco.com/site/us/en/services/support">Cisco’s Customer Experience (CX)</a> organization (services) and product groups have often felt like parallel universes. Services were layered on top of products rather than tightly integrated into how those products operated. Cisco IQ changes that dynamic by placing CX capabilities directly within the same Cloud Control environment where the products themselves live and by wiring CX workflows into the same telemetry and policy plane. This is notable as Cisco IQ isn’t yet another dashboard but an integrated part of Cloud Control.</p>



<p>Cisco IQ is positioned as the AI‑powered delivery vehicle for support and professional services. The goal is to give customers “complete landscape clarity,” proactive resilience, rapid resolution, and contextualized services. It runs as a SaaS platform, with an on‑premises deployment option for customers with strict data sovereignty requirements. By tapping the shared data fabric, Cisco IQ can inventory assets whether they are deployed or still in the warehouse, flag risks before customers experience issues, and benchmark an organization’s posture against anonymized peers by vertical, market segment or geography.</p>



<p>New capabilities, including Resilient Infrastructure Services and Quantum Ready Assessments, further underscore the integration of CX and product engineering. Resilient Infrastructure Services uses a three-step framework: Exposure Assessment, Infrastructure Modernization, and Defense Resiliency to help customers prepare for frontier-model threats. Quantum Ready Assessments, delivered through Cisco IQ, identify assets most exposed to “harvest now, decrypt later” attacks and map a path to quantum-safe infrastructure. Putting CX’s “brain” into Cloud Control and connecting it to the same data and AI models that drive operations is both a cultural and an architectural shift.</p>



<h2 class="wp-block-heading">Secure Networking as the integration proof point</h2>



<p>If you want a single domain that illustrates how integrated the new Cisco has become, look at Secure Networking. Cisco’s stated vision is to embed security directly into the fabric of the infrastructure, from silicon through the network to operations, rather than treating it as a separate stack. That strategy manifests in several concrete ways.</p>



<p>Live Protect, described internally as a “digital immune system,” applies precise compensating controls to Cisco products in production to protect them from newly discovered vulnerabilities at runtime. It does so without reboots, upgrades, or maintenance windows. The controls are narrowly targeted to avoid performance impact and minimize false positives. Live Protect is already shipping on Nexus 9000 switches and expanding across the portfolio, including campus switches, tightening the feedback loop between vulnerability discovery and mitigation from weeks to minutes.</p>



<p>Hybrid Mesh Firewall extends a unified security policy across networks, applications, and both Cisco and third-party firewalls, limiting the blast radius when something goes wrong. At the same time, Cisco is embedding post-quantum crypto libraries, secure boot, and trust anchors across its core portfolio, and has committed to enabling quantum-safe communications capabilities across most core products by December 2026. New enterprise and data center routers, switches, and firewall series are launching as “quantum-safe by default.”</p>



<p>All of this is orchestrated through Cloud Control, the security command center for a post-Mythos era, with Splunk providing the telemetry backbone and agentic SOC and SRE capabilities to detect, triage, and respond at machine speed. Secure Networking is no longer just about point firewalls and SD-WAN; it has become the spine that ties Cisco’s networking, security, observability, and AI assets into a coherent platform.</p>



<h2 class="wp-block-heading">Multicloud Fabric: networking as a service for AI</h2>



<p>Another hallmark of the new Cisco is a willingness to deliver networking as a managed fabric rather than a toolkit that customers must stitch together themselves. Multicloud Fabric, introduced as a network‑as‑a‑service offering delivered through Cloud Control, illustrates this shift.</p>



<p>Multicloud Fabric gives enterprises a single fabric for secure site-to-cloud and cloud-to-cloud networking, with Cisco operating virtual points of presence across major cloud providers and regions. Customers can onboard sites and cloud environments, define intent-based connectivity, attach security policies, and monitor performance “with one button” from Cloud Control, instead of building and maintaining their own hub-and-spoke architectures. Security and observability are built in—Zero Trust routing, cloud firewall service chaining, and ThousandEyes agents embedded in each point of presence—so the network is no longer a passive pipe but part of the AI intelligence stack.</p>



<p>This matters because AI-first applications increasingly chain inference across multiple clouds and data sources. Cisco’s own research shows that these agentic workflows can generate many times more network traffic than manual equivalents, with much of it being latency-sensitive inference. Multicloud Fabric, operated as a service and integrated into the same Cloud Control environment, is Cisco’s answer to this new reality.</p>



<h2 class="wp-block-heading">What this means for customers</h2>



<p>Cisco has spent four decades building category-leading products, from Meraki and Nexus to Webex and ThousandEyes. But the company’s biggest opportunity has always been in how those pieces work together. As Patel has said, tightly integrated and loosely coupled. Cloud Control, Cisco IQ, Multicloud Fabric, and Secure Networking suggest the product organization is finally closing that gap, turning dashboards into agentic workflows and discrete boxes into a secure harness for the AI era.</p>



<p>For customers, Cisco’s transformation matters because it changes the operating model, not just the product lineup. Cloud Control gives IT teams a single management plane across networking, security, observability, collaboration, and services, replacing the fragmented dashboard experience that has long complicated Cisco environments. That should make operations faster and simpler, but it also raises the bar for customers.</p>



<p>As Cisco pushes AgenticOps, AI Canvas, Live Protect, and Cisco IQ into the mainstream, IT teams will need to shift from manually managing tools to supervising agents, setting policy guardrails, and validating machine-speed actions. That shift will demand new skills in prompt design, policy modeling, risk scoring, and governance, especially as agents propose and test more changes before humans ever click “approve.”</p>



<p>It also means customers should view Cisco less as a best-of-breed product and more as an integrated platform. The more of the Cisco estate that is tied to Cloud Control, the more value customers should derive from shared telemetry, unified workflows, embedded security, and cross-domain automation—especially in areas like Secure Networking and multicloud operations. Conversely, customers that remain heavily heterogeneous will need clear integration strategies and governance models to ensure third-party tools plug safely into the harness.</p>



<p>Finally, this new Cisco has the potential to reduce one of the biggest pain points enterprise buyers have faced for years: complexity. If the company can deliver on its vision of one login, one view, tighter product integration, and CX services finally aligned with the product groups, customers may find that Cisco is not only unrecognizable in a positive way but also easier to buy, deploy, and operate than at any point in its history.</p>



<h3 class="wp-block-heading">Read more stories from Cisco Live 2026</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4180842/cisco-sees-quantum-networking-as-the-future-of-networking.html">Cisco sees quantum networking as the future of networking</a></li>



<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a> </li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>



<li><a href="https://www.networkworld.com/article/4181727/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages.html">How Cisco IT cut observability costs by 86% and eliminated major network outages</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities and Enterprise Systems]]></title>
<description><![CDATA[  A breach tied to the hacking collective ShinyHunters emerged during a wave of intrusions leveraging an undisclosed weakness in Oracle PeopleSoft platforms. Unauthorized entry occurred because security gaps went unpatched – access followed swiftly after initial compromise. Data theft…
Read more ...]]></description>
<link>https://tsecurity.de/de/3593857/it-security-nachrichten/shinyhunters-exploits-oracle-peoplesoft-zero-day-to-breach-universities-and-enterprise-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593857/it-security-nachrichten/shinyhunters-exploits-oracle-peoplesoft-zero-day-to-breach-universities-and-enterprise-systems/</guid>
<pubDate>Fri, 12 Jun 2026 17:09:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  A breach tied to the hacking collective ShinyHunters emerged during a wave of intrusions leveraging an undisclosed weakness in Oracle PeopleSoft platforms. Unauthorized entry occurred because security gaps went unpatched – access followed swiftly after initial compromise. Data theft…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/shinyhunters-exploits-oracle-peoplesoft-zero-day-to-breach-universities-and-enterprise-systems/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/shinyhunters-exploits-oracle-peoplesoft-zero-day-to-breach-universities-and-enterprise-systems/">ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities and Enterprise Systems</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)]]></title>
<description><![CDATA[OverviewOn June 10, 2026, Oracle published a security alert for CVE-2026-35273, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation...]]></description>
<link>https://tsecurity.de/de/3593644/it-security-nachrichten/active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593644/it-security-nachrichten/active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/</guid>
<pubDate>Fri, 12 Jun 2026 15:55:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On June 10, 2026, Oracle published a </span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span>security alert</span></a><span> for </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-35273"><span>CVE-2026-35273</span></a><span>, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation. The vulnerability has a CVSSv3.1 score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span>9.8</span></a><span> and is remotely exploitable without authentication. Per the vendor advisory, successful exploitation may result in remote code execution (RCE). TrendAI has </span><a href="https://success.trendmicro.com/en-US/solution/KA-0023679"><span>classified</span></a><span> the underlying flaw as a server-side request forgery (</span><a href="https://cwe.mitre.org/data/definitions/918.html"><span>CWE-918</span></a><span>). PeopleTools versions </span><span><span data-type="inlineCode">8.61</span></span><span> and </span><span><span data-type="inlineCode">8.62</span></span><span> are affected.</span></p><p></p><p><span>CVE-2026-35273 was reported to Oracle through TrendAI's Zero Day Initiative. According to a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span>report published by Mandiant</span></a><span> on June 11, 2026,</span><span><strong> this vulnerability has been exploited in the wild as a zero-day prior to the vendor security alert</strong></span><span>, with active exploitation observed between May 27 and June 9, 2026, predating Oracle's advisory by two weeks.</span></p><p></p><p><span>Mandiant has attributed the campaign to UNC6240 (ShinyHunters), a financially motivated cybercriminal collective known for data theft and extortion. ShinyHunters has been linked to breaches across cloud services, SaaS platforms, and telecommunications providers, frequently exploiting weak authentication controls, stolen credentials, and cloud misconfigurations rather than deploying sophisticated malware.</span></p><p></p><p><span>Based on information published by Mandiant, the campaign heavily targeted the higher education sector; 68 percent of the more than 100 notified organizations were universities and colleges. The observed exploitation targeted PeopleSoft's Environment Management Hub (PSEMHUB) endpoints, and data stolen during the campaign was published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026.</span></p><p></p><p><span>The </span><span><span data-type="inlineCode">/PSIGW/HttpListeningConnector</span></span><span> URI path appears in both the indicators of compromise for this campaign and in a PeopleSoft exploit chain for </span><a href="https://www.cve.org/CVERecord?id=CVE-2013-3821"><span>CVE-2013-3821</span></a><span>, </span><a href="https://blog.lexfo.fr/oracle-peoplesoft-xxe-to-rce.html"><span>detailed by Lexfo in 2017</span></a><span>. A related XML External Entity (XXE) vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2017-3548"><span>CVE-2017-3548</span></a><span>, targeted a different Integration Gateway connector (</span><span><span data-type="inlineCode">PeopleSoftServiceListeningConnector</span></span><span>) under the same </span><span><span data-type="inlineCode">/PSIGW/</span></span><span> path.</span></p><h2>Technical overview</h2><p><span>TrendAI's detection signatures for CVE-2026-35273 classify the underlying vulnerability as an SSRF. These include IPS Rule 1012580 ("Oracle Peoplesoft PeopleTools SSRF Vulnerability") and DDI Rule 5855 ("Peoplesoft PeopleTools Environment Management Hub (PSEMHUB) SSRF Exploit"). Mandiant describes CVE-2026-35273 as a critical remote code execution vulnerability, indicating that the SSRF serves as the mechanism through which code execution is achieved. Based on Mandiant's analysis, two endpoints are involved in exploitation: </span><span><span data-type="inlineCode">/PSEMHUB/hub</span></span><span> and </span><span><span data-type="inlineCode">/PSIGW/HttpListeningConnector</span></span><span>. The exploit chain may also cause the target system to make outbound SMB connections (TCP port 445) to external destinations, potentially allowing attackers to capture Windows machine-account NetNTLM hashes.</span></p><p></p><p><span>Post-exploitation activity observed by Mandiant included the deployment of </span><a href="https://meshcentral.com/"><span>MeshCentral</span></a><span> (an open-source, and self-hosted web-based remote monitoring and management platform) remote management agents configured to masquerade as Microsoft Azure services (e.g., </span><span><span data-type="inlineCode">meshagent64-azure-ops.exe</span></span><span>), with C2 communications directed to </span><span><span data-type="inlineCode">wss://azurenetfiles[.]net:443/agent.ashx</span></span><span>. The attackers performed internal reconnaissance of PeopleSoft configurations, deployed lateral movement scripts, and exfiltrated data using </span><span><span data-type="inlineCode">zstd</span></span><span> compression.</span></p><h2>Mitigation guidance</h2><p><span>Organizations running PeopleTools versions </span><span><span data-type="inlineCode">8.61</span></span><span> or </span><span><span data-type="inlineCode">8.62</span></span><span> should apply the vendor-supplied </span><a href="https://support.oracle.com/support/?documentId=CPU187"><span>patch</span></a><span> on an emergency basis, without waiting for a regular patch cycle to occur. Oracle has characterized this as a high-priority risk reduction measure.</span></p><p></p><p><span>In addition to patching, organizations should implement the following compensating controls:</span></p><p></p><ul><li><p><span><strong>Disable the Environment Management Hub (EMHub) Service</strong></span><span> in multi-server configurations, or completely remove the </span><span><span data-type="inlineCode">PSEMHUB</span></span><span> application in single-server configurations.</span></p></li><li><p><span><strong>Block external access</strong></span><span> to </span><span><span data-type="inlineCode">/PSEMHUB/*</span></span><span> and </span><span><span data-type="inlineCode">/PSIGW/HttpListeningConnector</span></span><span> at the network perimeter or firewall level. Per Mandiant, restricting these endpoints is considered non-breaking for standard end-user PeopleSoft Internet Architecture (PIA) browser sessions.</span></p></li><li><p><span><strong>Monitor outbound SMB traffic</strong></span><span> (TCP port 445) from PeopleSoft servers to untrusted external destinations.</span></p></li></ul><p></p><p><span>Given that exploitation occurred as early as May 27, 2026, Rapid7 strongly recommends investigating for signs of compromise even after patching, using the indicators of compromise outlined below.</span></p><p></p><p><span>For the latest mitigation guidance, please refer to the </span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span>Oracle security alert</span></a><span> and </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span>Mandiant's report</span></a><span>.</span></p><h2>Rapid7 customers</h2><h3><span>Exposure Command, InsightVM, and Nexpose</span></h3><p><span>Exposure Command, InsightVM, and Nexpose customers can assess exposure to</span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span> CVE-2026-35273</span></a><span> with authenticated</span><span><strong> </strong></span><span>vulnerability checks available in the 12th June 2026 content release.</span></p><h3><span>Intelligence Hub</span></h3><p><span>Customers leveraging Rapid7's Intelligence Hub can track the latest developments surrounding CVE-2026-35273, including indicators of compromise (IOCs) from the Mandiant report published on June 11, 2026.</span></p><h2>Indicators of compromise</h2><p><span>The following indicators of compromise are sourced from </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span>Mandiant's report</span></a><span>. Mandiant has also published a </span><a href="https://www.virustotal.com/gui/collection/50ac0ffbc9ecf4559949faa026a412c9bb57e81d3ae0714a4dcd25b4fec35105"><span>GTI collection</span></a><span> with additional IOCs for registered users.</span></p><h3><span>Network indicators</span></h3><p><span><strong>Staging and C2 infrastructure:</strong></span></p><p></p><ul><li><p><span>142.11.200[.]186</span></p></li><li><p><span>142.11.200[.]187</span></p></li><li><p><span>142.11.200[.]188</span></p></li><li><p><span>142.11.200[.]189</span></p></li><li><p><span>142.11.200[.]190</span></p></li><li><p><span>azurenetfiles[.]net (C2 domain masquerading as Microsoft Azure)</span></p></li><li><p><span>176.120.22[.]24 (ShinyHunters DLS mirror)</span></p></li></ul><h3><span>File indicators</span></h3><table><colgroup data-width="750"><col><col><col></colgroup><thead><tr><th><p><span><strong>Filename</strong></span></p></th><th><p><span><strong>Description</strong></span></p></th><th><p><span><strong>SHA-256</strong></span></p></th></tr></thead><tbody><tr><td><p><span>meshagent64-azure-ops.exe</span></p></td><td><p><span>Pre-configured Windows MeshCentral agent</span></p></td><td><p><span>f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc</span></p></td></tr><tr><td><p><span>meshagent64-v2.exe</span></p></td><td><p><span>Pre-configured Windows MeshCentral agent</span></p></td><td><p><span>d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f</span></p></td></tr><tr><td><p><span>meshagent32-azure-ops.exe</span></p></td><td><p><span>Pre-configured Windows MeshCentral agent (32-bit)</span></p></td><td><p><span>c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f</span></p></td></tr><tr><td><p><span>meshagent</span></p></td><td><p><span>Unconfigured Linux MeshCentral agent</span></p></td><td><p><span>68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309</span></p></td></tr><tr><td><p><span>.bash_history</span></p></td><td><p><span>Attacker command history</span></p></td><td><p><span>2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35</span></p></td></tr></tbody></table><h3><span>Host-based indicators</span></h3><ul><li><p><span>Unexpected </span><span><span data-type="inlineCode">.jsp</span></span><span> files under </span><span><span data-type="inlineCode">&lt;PS_CFG_HOME&gt;/webserv/&lt;domain&gt;/applications/peoplesoft/PSEMHUB.war/</span></span></p></li><li><p><span>Unauthorized files or directories under </span><span><span data-type="inlineCode">.../PSEMHUB.war/envmetadata/transactions/</span></span></p></li><li><p><span>Unexpected directories named </span><span><span data-type="inlineCode">logs</span></span><span>, </span><span><span data-type="inlineCode">persistantstorage</span></span><span>, or </span><span><span data-type="inlineCode">scratchpad</span></span><span> under PSEMHUB paths</span></p></li><li><p><span>Recently created or modified </span><span><span data-type="inlineCode">.xml</span></span><span> files under </span><span><span data-type="inlineCode">&lt;docroot&gt;/envmetadata/data/environment/</span></span><span> (potential XMLDecoder persistence)</span></p></li><li><p><span>Defacement and extortion marker file: </span><span><span data-type="inlineCode">README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT</span></span></p></li></ul><h3><span>Log-based indicators</span></h3><p><span>HTTP </span><span><span data-type="inlineCode">POST</span></span><span> requests to the following endpoints from external source IPs:</span></p><ul><li><p><span><span data-type="inlineCode">/PSEMHUB/hub</span></span></p></li><li><p><span><span data-type="inlineCode">/PSIGW/HttpListeningConnector</span></span></p></li></ul><p><span>Requests to </span><span><span data-type="inlineCode">/PSIGW/HttpListeningConnector</span></span><span> containing loopback addresses (</span><span><span data-type="inlineCode">127.0.0.1</span></span><span>, </span><span><span data-type="inlineCode">localhost</span></span><span>, </span><span><span data-type="inlineCode">::1</span></span><span>) or internal IP ranges within request headers or parameters may indicate SSRF exploitation.</span></p><h2>Updates</h2><ul><li><p><span><strong>June 12, 2026</strong></span><span>: Initial publication.</span></p></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Header Manipulation: Bypasses, Probing, and the Security Audit Nobody Does]]></title>
<description><![CDATA[Request headers are not metadata. They are inputs, and inputs can be manipulated.Series: curl — The Request Engine You Never Learned Properly Article: 7 of 16Request headers are not just metadata. They are inputs. And like any input that reaches server-side logic, they can be manipulated — to byp...]]></description>
<link>https://tsecurity.de/de/3592760/hacking/header-manipulation-bypasses-probing-and-the-security-audit-nobody-does/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592760/hacking/header-manipulation-bypasses-probing-and-the-security-audit-nobody-does/</guid>
<pubDate>Fri, 12 Jun 2026 09:33:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>Request headers are not metadata. They are inputs, and inputs can be manipulated.</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cnjXMO_MJlD_PMoDDoF3wg.png"></figure><blockquote><strong><em>Series:</em></strong><em> curl — The Request Engine You Never Learned Properly </em><strong><em>Article:</em></strong><em> 7 of 16</em></blockquote><p>Request headers are not just metadata. They are inputs. And like any input that reaches server-side logic, they can be manipulated — to bypass access controls, probe for misconfigurations, spoof identity, and test security posture.</p><p>This article covers the header manipulation techniques that show up constantly on THM/HTB machines and in real web application testing: Host header attacks, IP spoofing headers, 403 bypass patterns, CORS misconfiguration testing, and the security header audit that most beginners skip entirely.</p><p>Most techniques here are one flag or one -H addition away from a curl command you already know how to write.</p><h3>The -H Flag as an Attack Surface</h3><p>You have used -H for Content-Type and Authorization. The same flag is the entry point for every manipulation technique in this article.</p><pre>curl -H "Header-Name: value" http://target.com</pre><p>A header is just a key-value pair sent as part of the HTTP request. The server reads it and acts on it — or ignores it. Your job is to find the headers that affect server behavior in ways the developer did not intend.</p><p>Multiple -H flags stack. This single command sends three attack-relevant headers simultaneously:</p><pre>curl -H "X-Forwarded-For: 127.0.0.1" \<br>     -H "X-Real-IP: 127.0.0.1" \<br>     -H "Host: internal.target.com" \<br>     http://127.0.0.1:8080/admin</pre><pre>==================================================<br>  curl Lab Echo Server<br>==================================================<br>METHOD       : GET<br>PATH         : /admin<br>FULL URL     : /admin<br>--- REQUEST HEADERS ---<br>  Host: internal.target.com<br>  User-Agent: curl/7.68.0<br>  Accept: */*<br>  X-Forwarded-For: 127.0.0.1<br>  X-Real-IP: 127.0.0.1<br>--- QUERY STRING PARAMS ---<br>  (none)<br>--- RAW BODY ---<br>  (empty)<br>--- PARSED BODY PARAMS ---<br>  (none)<br>==================================================</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/843/1*vK6Zsr_Lwdu2QGy1P8d5tg.png"><figcaption>Three attack headers, one command. The echo server shows Host overridden to an internal hostname and both IP headers spoofed — exactly as sent, no browser normalisation stripping the payload.</figcaption></figure><p>curl sends exactly what you specify. The echo server confirms all three headers arrived intact at the application layer — Host overridden, both IP headers spoofed. That said, in real deployments, proxies, load balancers, and application frameworks may rewrite or strip certain headers before they reach the application. What curl sends and what the application ultimately reads are not always identical.</p><h3>Host Header Attacks</h3><p>The Host header tells the server which virtual host to serve. On servers running multiple sites, this is how the server knows which application to route the request to.</p><p>Manipulating the Host header — and its override cousin X-Forwarded-Host — lets you probe for virtual hosts that are not publicly advertised:</p><pre>curl -H "Host: internal.target.com" http://target.com<br>curl -H "Host: admin.target.com" http://target.com<br>curl -H "Host: dev.target.com" http://target.com<br>curl -H "Host: staging.target.com" http://target.com<br>curl -H "X-Forwarded-Host: admin.target.com" http://target.com</pre><p>Run each and compare response sizes and content against the baseline. A response that differs — in size, content, or status code — indicates the server is routing to a different virtual host at that address. Internal applications, development environments, and admin interfaces are commonly found this way.</p><p>Beyond virtual host discovery, Host header manipulation is also the foundation of password reset poisoning (poisoning the reset link generated server-side) and cache poisoning (storing a malicious response under a legitimate cache key). Those are covered in depth elsewhere — the recon step here is the same.</p><p><strong>--resolve for clean DNS mapping:</strong></p><p>When you want to test a specific IP address with a custom hostname, without modifying /etc/hosts:</p><pre>curl --resolve target.com:80:192.168.1.100 http://target.com<br>curl --resolve admin.target.com:443:192.168.1.100 https://admin.target.com</pre><p>--resolve host:port:ip tells curl to resolve that hostname to that IP for this request only. No system-wide DNS change, no file modification, no cleanup needed.</p><h3>IP Restriction Bypass: X-Forwarded-For and X-Real-IP</h3><p>Some applications restrict access based on the client’s IP address. “Only allow requests from 127.0.0.1” or “only allow requests from internal network ranges” are common access control patterns.</p><p>When a reverse proxy sits in front of the application, the application may read the client’s IP from the X-Forwarded-For header rather than the TCP connection's source address. X-Forwarded-For is a de facto standard and typically carries a comma-separated list of addresses — the client IP, then each proxy in the chain. If the application trusts this header without validation and reads the first value in the list, you can prepend a spoofed IP.</p><pre>curl -s -H "X-Forwarded-For: 127.0.0.1" http://127.0.0.1:8080/admin</pre><pre>[ADMIN PANEL] Access granted.<br>Bypass vector: IP spoof — X-Forwarded-For / X-Real-IP set to 127.0.0.1<br>Method: GET | Path: /admin</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/834/1*GMe2_yh7EBrUGPvFCZSjpQ.png"><figcaption>X-Forwarded-For: 127.0.0.1 turns a 403 into a confirmed bypass. The server names the vector — IP spoof via a trusted but user-controlled header. On real targets, this only fires when the application reads this header for authorization decisions.</figcaption></figure><p>In this lab, the baseline returns 403, and the spoofed header returns 200. On real targets, this only works when the application improperly trusts the authorization header — which does happen and is a vulnerability when it does.</p><p>Headers worth trying for IP-based bypass. The order is a heuristic, not a universal ranking — different stacks trust different headers, and some validate against a list of values rather than a single one:</p><pre>curl -H "X-Forwarded-For: 127.0.0.1" http://target.com/restricted<br>curl -H "X-Real-IP: 127.0.0.1" http://target.com/restricted<br>curl -H "X-Client-IP: 127.0.0.1" http://target.com/restricted<br>curl -H "X-Remote-IP: 127.0.0.1" http://target.com/restricted<br>curl -H "X-Originating-IP: 127.0.0.1" http://target.com/restricted<br>curl -H "True-Client-IP: 127.0.0.1" http://target.com/restricted<br>curl -H "CF-Connecting-IP: 127.0.0.1" http://target.com/restricted</pre><p>Try each independently. X-Forwarded-For is the most common. True-Client-IP is used by Cloudflare and CF-Connecting-IP by Cloudflare Workers — applications behind those services sometimes trust those values directly.</p><h3>Referer Header Manipulation</h3><p>Some applications check the Referer header to verify that a request came from within the application itself — a naive CSRF protection or hotlink prevention.</p><pre># With spoofed Referer<br>curl -H "Referer: http://127.0.0.1:8080/dashboard" \<br>     http://127.0.0.1:8080/sensitive-action</pre><pre>==================================================<br>  curl Lab Echo Server<br>==================================================<br>METHOD       : GET<br>PATH         : /sensitive-action<br>FULL URL     : /sensitive-action<br>--- REQUEST HEADERS ---<br>  Host: 127.0.0.1:8080<br>  User-Agent: curl/7.68.0<br>  Accept: */*<br>  Referer: http://127.0.0.1:8080/dashboard<br>--- QUERY STRING PARAMS ---<br>  (none)<br>--- RAW BODY ---<br>  (empty)<br>--- PARSED BODY PARAMS ---<br>  (none)<br>==================================================</pre><p>The Referer arrives at the server exactly as set. If an endpoint returns 403 without a Referer and 200 with an expected value, the access control is bypassable by spoofing the header. This is not a strong control — any client can set any Referer value, and browsers and privacy tools may omit or trim it entirely, so it should never be relied on for authentication or authorization. It appears in real applications regardless, and sometimes combines with other checks to form a bypass chain.</p><h3>403 Bypass Patterns</h3><p>A 403 on an endpoint you want to reach is not the end. It is the beginning of a checklist.</p><p><strong>Path normalization tricks:</strong></p><p>Web servers and application frameworks sometimes process paths differently. A rule that blocks /admin may not block equivalent paths on every server — these variations sometimes bypass controls, but behavior is server-specific:</p><pre>curl -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin     # baseline<br>curl -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin/<br>curl -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/%2fadmin<br>curl -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/./admin<br>curl -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin%20<br>curl -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/ADMIN</pre><pre>403<br>200<br>200<br>403<br>200<br>200</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/874/1*rNAj4A3HmDNNXF_zLSbKDg.png"><figcaption>Path normalization against a blocked /admin. The baseline returns 403. Trailing slash, encoded slash, trailing space, and case variation each return 200. /./admin stays blocked — the server normalised it back. Not every trick works on every target.</figcaption></figure><p>Reading the results from this lab:</p><p>/admin → 403 — The rule fires on the exact path.</p><p>/admin/ → 200 — Trailing slash creates a different string that does not match the rule.</p><p>/%2fadmin → 200 — URL-encoded slash. The access control reads the encoded path; the application decodes it and serves the resource.</p><p>/./admin → 403 — the server normalizes ./admin back to /admin before routing, so the rule still matches. Not every path trick works on every server — this one did not.</p><p>/admin%20 → 200 — trailing encoded space. The rule matches /admin Exactly; the space breaks the match.</p><p>/ADMIN → 200 — case variation. The access rule is case-sensitive; the application routing is not.</p><p><strong>Method switching:</strong></p><p>An access control rule might only apply to certain HTTP methods. In this lab, the rule covers GET only:</p><pre>curl -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin          # GET<br>curl -X POST -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin  # POST<br>curl -X PUT -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin   # PUT<br>curl -X HEAD -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin  # HEAD</pre><pre>403<br>200<br>200<br>200</pre><p>On a real target, results depend entirely on how the access rule is written — POST and HEAD are not guaranteed to work just because GET is blocked. But when they do return 200, verify what content HEAD returns in its response headers and what POST responds with in its body. A method switch that reaches the resource is a finding.</p><p><strong>Header-based bypass:</strong></p><pre>curl -H "X-Forwarded-For: 127.0.0.1" -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/admin<br>curl -H "X-Original-URL: /admin" -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/<br>curl -H "X-Rewrite-URL: /admin" -o /dev/null -sw "%{http_code}\n" http://127.0.0.1:8080/</pre><pre>200<br>200<br>200</pre><p>X-Original-URL and X-Rewrite-URL are headers that some reverse proxies honor to override the request path — this is a proxy-specific behavior, not universal. Where it applies, the access control evaluates the request to / (permitted), while the application reads X-Original-URL and serves /admin. The protection and the application are not evaluating the same path.</p><p><strong>Header chaining — when two modifications together unlock access:</strong></p><p>Sometimes a single bypass attempt fails, but a combination works:</p><pre>curl -X POST \<br>  -H "X-Forwarded-For: 127.0.0.1" \<br>  -H "Referer: http://127.0.0.1:8080/admin" \<br>  -o /dev/null -sw "%{http_code}\n" \<br>  http://127.0.0.1:8080/admin</pre><pre>200</pre><p>When single-vector attempts fail, start combining. Method, IP header, and Referer each target a different check — stacking them clears multiple gates at once.</p><h3>CORS Origin Manipulation</h3><p>CORS (Cross-Origin Resource Sharing) determines which external domains are allowed to make requests to an API from a browser. A misconfigured CORS policy can allow an attacker’s website to make credentialed requests to the API on behalf of a victim.</p><p>Testing CORS with curl is active testing — you are not just checking whether a header exists, you are testing whether the server accepts your controlled origin.</p><p>The echo server reflects headers but does not implement CORS — it shows the Origin arriving but returns no Access-Control headers. For live CORS testing, httpbin.org demonstrates the vulnerability pattern:</p><pre>curl -sI -H "Origin: https://evil.com" http://httpbin.org/get | grep -i "access-control"</pre><pre>Access-Control-Allow-Origin: https://evil.com<br>Access-Control-Allow-Credentials: true</pre><p>httpbin reflects any origin it receives and pairs it with Allow-Credentials: true. This is a misconfiguration: the server accepts any origin and signals that credentialed cross-origin requests are permitted. The real danger is the reflected origin combined with credentials — a browser making a cross-origin request to this API from an attacker-controlled page could include the victim's session cookies in the request.</p><p><strong>Testing whether the server reflects arbitrary origins:</strong></p><pre>for origin in "https://evil.com" "null" "https://httpbin.org.evil.com"; do<br>  echo -n "Origin: $origin -&gt; "<br>  curl -sI -H "Origin: $origin" http://httpbin.org/get | grep -i "access-control-allow-origin"<br>done</pre><pre>Origin: https://evil.com -&gt; Access-Control-Allow-Origin: https://evil.com<br>Origin: null -&gt; Access-Control-Allow-Origin: null<br>Origin: https://httpbin.org.evil.com -&gt; Access-Control-Allow-Origin: https://httpbin.org.evil.com</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/875/1*Uad8o_ZpASysboBiHhAkLg.png"><figcaption>Three different origins sent, three reflected. The server reflects whatever origin it receives — the subdomain spoof (httpbin.org.evil.com) reflects too, confirming no origin validation. Combined with Allow-Credentials: true reflected origins, the real exploitable CORS case.</figcaption></figure><p>All three reflected. The subdomain spoof (https://httpbin.org.evil.com) reflects too — the server is not validating that the origin is actually under its own domain.</p><p>The null origin is worth testing but deserves nuance. It is sent by sandboxed iframes and certain redirect chains. Whether a server is accepting null is exploitable depends on whether the browser will expose a credentialed response in that context — it is a signal worth investigating, not an automatic finding.</p><p>Read the response headers for these values:</p><p><strong>Access-Control-Allow-Origin: *</strong> — wildcard policy. On its own, this allows any origin to read the response. Combined with Allow-Credentials: true, Browsers will actually block it per spec — the combination is invalid. The exploitable case is a reflected specific origin plus credentials, not a wildcard.</p><p><strong>Access-Control-Allow-Origin: &lt;your value&gt;</strong> — origin reflected. If any origin you send is reflected, the policy is effectively open to any origin the attacker controls.</p><p><strong>Access-Control-Allow-Credentials: true</strong> — The server signals that cross-origin requests may include cookies and authorization headers. Paired with a reflected origin, this is the combination that makes CORS misconfigurations exploitable.</p><p><strong>No Access-Control headers</strong> — the API is not advertising a cross-origin policy in the response. Not a CORS finding in itself, though it does not mean the endpoint is safe.</p><h3>The Security Header Audit</h3><p>This is the audit most testers skip because it does not produce an immediate exploit. But missing security headers are findings in real reports, and running the audit takes thirty seconds.</p><p>Run it against a hardened site first — this is what a well-configured target looks like:</p><pre>curl -sI https://github.com | grep -iE "strict-transport|content-security|x-frame|x-content-type|referrer-policy|permissions-policy|x-xss"</pre><pre>strict-transport-security: max-age=31536000; includeSubdomains; preload<br>x-frame-options: deny<br>x-content-type-options: nosniff<br>x-xss-protection: 0<br>referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin<br>content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com ...</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bIDjn2HJk8Hu7IszYIQcxQ.png"><figcaption>Security header audit on GitHub — six headers present, all highlighted in red by the terminal. strict-transport-security, x-frame-options, x-content-type-options, referrer-policy, and a full content-security-policy. This is what you want to see. Run the same command on your target and compare.</figcaption></figure><p>Six headers present. Now run the same command against a target that has implemented none of them:</p><pre>curl -sI http://httpbin.org | grep -iE "strict-transport|content-security|x-frame|x-content-type|referrer-policy|permissions-policy|x-xss"</pre><pre>(no output)</pre><p>No output means none of the security headers are present. That is the finding. Some headers matter more than others depending on the application — HSTS and CSP carry more weight than Permissions-Policy — but their collective absence signals that security hardening was not a priority.</p><p><strong>What each header does and what its absence means:</strong></p><p>Strict-Transport-Security tells browsers to use HTTPS for all future visits to this domain. Missing HSTS leaves first-visit downgrade risk open — an attacker on the network path can intercept the initial HTTP request before the browser learns to upgrade.</p><p>Content-Security-Policy controls what resources the page can load and from where. Missing CSP means XSS payloads have full execution scope — no sandbox, no source allowlist blocking exfiltration.</p><p>X-Frame-Options: deny prevents the page from being embedded in an iframe on another domain. Missing means clickjacking is possible — wrap the page in an invisible iframe, overlay buttons, harvest clicks, or credential entries.</p><p>X-Content-Type-Options: nosniff prevents the browser from MIME-sniffing a response away from its declared Content-Type. Missing means a browser may execute a response as a script even when the server said otherwise.</p><p>Referrer-Policy controls how much of the URL appears in the Referer header when a user navigates away. Missing means internal paths and query parameters can leak to third-party resources loaded by the page.</p><p>X-XSS-Protection is largely deprecated — modern browsers ignore it or disable XSS auditors by default. Its presence, as in the GitHub response above, where it is set to 0 (disabled), is informational. Do not weigh it heavily in a report.</p><p>Permissions-Policy controls browser feature access (camera, microphone, geolocation). Missing is less critical but still noted in thorough assessments.</p><p>Document which are present and those that are missing. In aggregate, they paint a picture of the target’s security maturity — useful context for the rest of the assessment.</p><p>The discipline this article builds: headers are inputs, not fixed metadata. Every header that reaches server-side logic is a potential manipulation point. Build the habit of checking what the server does with them before moving on to application-level testing.</p><p><em>Next: Article 8 — curl + Burp: The Manual Testing Stack</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=62e85ad28cb0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/header-manipulation-bypasses-probing-and-the-security-audit-nobody-does-62e85ad28cb0">Header Manipulation: Bypasses, Probing, and the Security Audit Nobody Does</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's DiffusionGemma generates 256 tokens in parallel and self-corrects as it goes]]></title>
<description><![CDATA[GenAI image generators like Stable Diffusion do not draw a picture pixel by pixel from left to right. They start with noise and iteratively refine the entire image in parallel until it converges, in a process known as diffusion. For years, applying that same principle to text generation had remai...]]></description>
<link>https://tsecurity.de/de/3591156/it-nachrichten/googles-diffusiongemma-generates-256-tokens-in-parallel-and-self-corrects-as-it-goes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591156/it-nachrichten/googles-diffusiongemma-generates-256-tokens-in-parallel-and-self-corrects-as-it-goes/</guid>
<pubDate>Thu, 11 Jun 2026 18:02:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GenAI image generators like Stable Diffusion do not draw a picture pixel by pixel from left to right. They start with noise and iteratively refine the entire image in parallel until it converges, in a process known as diffusion. For years, applying that same principle to text generation had remained out of reach at scale.</p><p>Standard language models work like a typewriter: one token at a time, left to right, with no ability to revise a committed output. That pattern works in the cloud, where batch sizes keep GPUs saturated. For local inference or low-concurrency deployments, the GPU is idle most of the time.</p><p>Google's DiffusionGemma, released this week, is an open source experimental model that applies diffusion to text generation at production scale. Built on the<a href="https://venturebeat.com/technology/googles-new-open-source-gemma-4-12b-analyzes-audio-video-and-runs-entirely-locally-on-a-typical-16gb-enterprise-laptop"> Gemma 4</a> backbone and released under the Apache 2.0 license, it is the first diffusion language model natively supported in the open source vLLM inference platform. It generates a 256-token block in parallel rather than sequentially, with every token position attending to every other. Google says DiffusionGemma generates text up to 4x faster than standard models on GPUs. At batch size 1 on a single Nvidia H100, the FP8 version reaches 1,008 tokens per second. On H200, it hits 1,288 — roughly six times a standard autoregressive baseline, according to vLLM benchmark results published today.</p><p>Despite the speed gains, Google did not oversell the release. The company's<a href="https://blog.google/innovation-and-ai/technology/developers-tools/diffusion-gemma-faster-text-generation/"> launch post</a> acknowledged directly that DiffusionGemma's overall output quality is lower than standard Gemma 4, adding "For applications that demand maximum quality, we recommend deploying standard Gemma 4."</p><h2>What DiffusionGemma does</h2><p>DiffusionGemma does not generate tokens in order. It starts with a block of 256 random placeholder tokens, effectively a blank canvas, and runs multiple refinement passes over the entire block at once. On each pass, it evaluates every position and locks in the ones it is most confident about. Uncertain positions get randomized and reconsidered on the next pass, with the model using what it resolved in the previous round to inform the next attempt. The block converges progressively until enough positions stabilize to anchor the rest.</p><p>Two things follow from that architecture.</p><ul><li><p><b>Self-correction.</b> An autoregressive model that commits to a wrong token is stuck with it, because subsequent tokens are already conditioned on the mistake. DiffusionGemma can identify low-confidence positions and re-evaluate them on the next pass.</p></li><li><p><b>Bidirectional context.</b> Every position attends to every other position in the block simultaneously, including tokens that appear later in the sequence. That makes the model structurally better suited to constrained generation tasks where left-to-right generation fails.</p></li></ul><p>Google demonstrated both properties with a fine-tuned Sudoku solver. The base model solved zero puzzles. After fine-tuning on a Sudoku dataset, it reached an 80% success rate and converged in 12 denoising steps rather than 48. The efficiency gain came directly from the model's ability to self-correct and stop early.</p><h2><b>How it was built</b></h2><p>DiffusionGemma runs as a 26B Mixture of Experts model that activates only 3.8B parameters during inference. Quantized, it fits within 18GB VRAM on consumer hardware including the Nvidia RTX 4090 and 5090. Google and NVIDIA also optimized for enterprise Hopper and Blackwell servers using NVFP4 kernels.</p><p>The vLLM integration required new work because DiffusionGemma does not fit the standard serving model. A typical vLLM batch applies the same attention type to every request. DiffusionGemma requests alternate between causal and bidirectional attention as they cycle through prompt reading, canvas refinement and block commit. The team built per-request attention switching into both the Triton and FlashAttention 4 backends and reused the existing speculative decoding path for the refinement loop.</p><p>The new ModelState interface the team built for this integration is designed to support additional diffusion models in vLLM as they emerge.</p><h2>Where the speed wins and where it does not</h2><p>DiffusionGemma's speed advantage is real but conditional. Where it applies depends entirely on deployment context.</p><p><b>The numbers.</b> At batch size 1 on a single H100, vLLM's published benchmarks put the FP8 model at roughly five times a standard autoregressive baseline. On H200, roughly six times. Those peak figures reflect optimal conditions: single user, dedicated hardware, FP8 quantization.</p><p><b>Where it wins.</b> Local inference, single-user applications and low-concurrency serving. In those conditions the GPU has spare compute and memory bandwidth is the bottleneck. DiffusionGemma's parallel block generation fills that gap.</p><p><b>Where it does not.</b> High-throughput cloud serving. When a server is batching hundreds of concurrent requests, autoregressive models already saturate available compute and DiffusionGemma's parallel decoding provides diminishing returns.</p><p><b>The quality ceiling.</b> Guilherme O'Tina, an AI researcher, <a href="https://x.com/guilhermeotina/status/2064745517922279473">put a finer point on it on X</a>. "Local artifacts vs hallucinations are different problems and that decides where this actually wins," O'Tina wrote.</p><h2>How it compares</h2><p>Diffusion language models are not new. Researchers have built them at smaller scales for several years, and<a href="https://www.inceptionlabs.ai/blog/introducing-mercury"> Inception Labs' Mercury Coder</a> applied the approach commercially to coding tasks in 2025. What DiffusionGemma adds is scale — a 26B MoE backbone, native vLLM serving and a general-purpose instruction-tuned model rather than a domain-specific one.</p><p>The more useful comparison for engineers evaluating this against existing inference tooling is speculative decoding, and the distinction matters. Speculative decoding keeps a standard autoregressive target model and uses a smaller draft model to guess several tokens ahead. The target model verifies them in one pass. If sampling is correct, the output distribution stays identical to the target. The architecture is unchanged.</p><p><a href="https://x.com/AndrewK404/status/2064775703334105170">Andrew Kuncevich</a>, an ML and AI researcher focused on production AI systems, put it directly on X. "DiffusionGemma is different. It does not just guess future tokens. It creates a noisy 256-token canvas and repeatedly denoises the whole block in parallel. So it's not just a decoding trick — it's a different generation paradigm," Kuncevich wrote.</p><p>Compared to standard Gemma 4, the trade is speed for quality. Google's benchmark data shows DiffusionGemma below standard Gemma 4 on general output quality metrics, with the gap varying by task.</p><p>On structured constrained tasks, including code infilling, template generation and problems requiring bidirectional constraint propagation, the architecture has a structural advantage that fine-tuning can surface, as the Sudoku result demonstrates. On open-ended generation, standard Gemma 4 remains the stronger option.</p><h2>What this means for enterprises</h2><p>DiffusionGemma serves via a standard vLLM OpenAI-compatible endpoint with no diffusion-specific pipeline changes required. </p><p>This is not a general-purpose model upgrade.</p><p><b>For teams running local or low-concurrency inference, the architecture choice just expanded.</b> Until now, cutting generation latency on dedicated GPU hardware meant using a smaller model and accepting the quality trade-off. DiffusionGemma offers a third path at the same parameter footprint, on consumer hardware, with same-day vLLM support.</p><p><b>For constrained generation workloads, bidirectional attention is worth evaluating.</b> Code infilling, structured data generation and tasks where correct output depends on context not yet generated are where this architecture has a structural edge.</p><p>The ModelState interface built for this integration is designed to generalize as additional diffusion models emerge.</p><p>The quality trade-off is real and Google acknowledges it. For teams running local inference on dedicated GPU hardware, this is worth testing.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub CLI 2.94.0]]></title>
<description><![CDATA[Issue types, sub-issues, and relationships in gh issue

This release brings GitHub's advanced issue features to gh issue create, edit, view, and list. You can set and view an issue's type, organize work with sub-issues, and track blocked-by and blocking relationships without leaving the command l...]]></description>
<link>https://tsecurity.de/de/3589036/downloads/github-cli-2940/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589036/downloads/github-cli-2940/</guid>
<pubDate>Thu, 11 Jun 2026 00:01:47 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Issue types, sub-issues, and relationships in <code>gh issue</code></h2>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/47394200/606083507-fd2c6a89-0ac2-472d-a1df-b4e6124f270b.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODExMjkxOTMsIm5iZiI6MTc4MTEyODg5MywicGF0aCI6Ii80NzM5NDIwMC82MDYwODM1MDctZmQyYzZhODktMGFjMi00NzJkLWExZGYtYjRlNjEyNGYyNzBiLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA2MTAlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNjEwVDIyMDEzM1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWI2ODY4OTFkOTI2OGNjZjU2ZDMwMjczOGM5YmU3NDE0MmEyYTY1NWU5YTc5NWVhMjJlNjZlYWI5OGI5YzIxMzAmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.wwUd2iz_yfdnWDvFXOSn9SmqpobAinNCLCvgtjWewxY"><img width="2000" height="1073" alt="issue-view-monas-cafe-with-frame" src="https://private-user-images.githubusercontent.com/47394200/606083507-fd2c6a89-0ac2-472d-a1df-b4e6124f270b.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODExMjkxOTMsIm5iZiI6MTc4MTEyODg5MywicGF0aCI6Ii80NzM5NDIwMC82MDYwODM1MDctZmQyYzZhODktMGFjMi00NzJkLWExZGYtYjRlNjEyNGYyNzBiLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA2MTAlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNjEwVDIyMDEzM1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWI2ODY4OTFkOTI2OGNjZjU2ZDMwMjczOGM5YmU3NDE0MmEyYTY1NWU5YTc5NWVhMjJlNjZlYWI5OGI5YzIxMzAmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.wwUd2iz_yfdnWDvFXOSn9SmqpobAinNCLCvgtjWewxY" content-type-secured-asset="image/png"></a>
<p>This release brings GitHub's advanced issue features to <code>gh issue create</code>, <code>edit</code>, <code>view</code>, and <code>list</code>. You can set and view an issue's type, organize work with sub-issues, and track blocked-by and blocking relationships without leaving the command line:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="# Set an issue's type
gh issue create --type Bug
gh issue edit 123 --type Bug

# Organize work with sub-issues
gh issue create --parent 100
gh issue edit 100 --add-sub-issue 123

# Track blocked-by and blocking relationships
gh issue create --blocked-by 200
gh issue edit 123 --add-blocking 300"><pre><span class="pl-c"><span class="pl-c">#</span> Set an issue's type</span>
gh issue create --type Bug
gh issue edit 123 --type Bug

<span class="pl-c"><span class="pl-c">#</span> Organize work with sub-issues</span>
gh issue create --parent 100
gh issue edit 100 --add-sub-issue 123

<span class="pl-c"><span class="pl-c">#</span> Track blocked-by and blocking relationships</span>
gh issue create --blocked-by 200
gh issue edit 123 --add-blocking 300</pre></div>
<p>Issue types and sub-issues are available on GitHub.com and GHES 3.17+; relationships require GHES 3.19+.</p>
<h2>Manage discussions with <code>gh discussion</code></h2>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/47394200/606083981-c625fe16-b625-4b24-b8b1-80e0c5336b8c.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODExMjkxOTMsIm5iZiI6MTc4MTEyODg5MywicGF0aCI6Ii80NzM5NDIwMC82MDYwODM5ODEtYzYyNWZlMTYtYjYyNS00YjI0LWI4YjEtODBlMGM1MzM2YjhjLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA2MTAlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNjEwVDIyMDEzM1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTk5MzAwZjEyMDk3MTMwN2Q2Y2RiMzkzOGRiOWJkYzQ0Y2U3MWJkODYzYmY0ZmRlYWM3NjhhMjc2NjcyMTljNDQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.9TND_5NT2834sU1tOldVlNHv8Sp6csqjq7NSkCste6c"><img width="2000" height="847" alt="discussion-view-monas-cafe-with-frame" src="https://private-user-images.githubusercontent.com/47394200/606083981-c625fe16-b625-4b24-b8b1-80e0c5336b8c.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3ODExMjkxOTMsIm5iZiI6MTc4MTEyODg5MywicGF0aCI6Ii80NzM5NDIwMC82MDYwODM5ODEtYzYyNWZlMTYtYjYyNS00YjI0LWI4YjEtODBlMGM1MzM2YjhjLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNjA2MTAlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjYwNjEwVDIyMDEzM1omWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTk5MzAwZjEyMDk3MTMwN2Q2Y2RiMzkzOGRiOWJkYzQ0Y2U3MWJkODYzYmY0ZmRlYWM3NjhhMjc2NjcyMTljNDQmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JnJlc3BvbnNlLWNvbnRlbnQtdHlwZT1pbWFnZSUyRnBuZyJ9.9TND_5NT2834sU1tOldVlNHv8Sp6csqjq7NSkCste6c" content-type-secured-asset="image/png"></a>
<p>This release introduces the <code>discussion</code> command set for working with GitHub Discussions in <code>gh</code>:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="# List discussions
gh discussion list

# View a discussion, its comments, or replies to a comment
gh discussion view 123 --comments

# Create a discussion
gh discussion create

# Edit a discussion
gh discussion edit 123

# Comment on a discussion
gh discussion comment 123

# Reply to a comment using its URL
gh discussion comment &lt;url&gt;"><pre><span class="pl-c"><span class="pl-c">#</span> List discussions</span>
gh discussion list

<span class="pl-c"><span class="pl-c">#</span> View a discussion, its comments, or replies to a comment</span>
gh discussion view 123 --comments

<span class="pl-c"><span class="pl-c">#</span> Create a discussion</span>
gh discussion create

<span class="pl-c"><span class="pl-c">#</span> Edit a discussion</span>
gh discussion edit 123

<span class="pl-c"><span class="pl-c">#</span> Comment on a discussion</span>
gh discussion comment 123

<span class="pl-c"><span class="pl-c">#</span> Reply to a comment using its URL</span>
gh discussion comment <span class="pl-k">&lt;</span>url<span class="pl-k">&gt;</span></pre></div>
<p>Run <code>gh discussion --help</code> for more information.</p>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p>The <code>discussion</code> command set is in preview and is subject to change without notice.</p>
</div>
<h2>Equip your agents with new <code>gh</code> features</h2>
<p>Teach your agents how to leverage new GitHub CLI features on release day by installing the <code>gh</code> skill:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="# Install
gh skill install cli/cli gh --scope user

# Or update
gh skill update gh"><pre><span class="pl-c"><span class="pl-c">#</span> Install</span>
gh skill install cli/cli gh --scope user

<span class="pl-c"><span class="pl-c">#</span> Or update</span>
gh skill update gh</pre></div>
<h2>What's Changed</h2>
<h3>✨ Features</h3>
<ul>
<li>Add <code>gh discussion</code> command set (<code>list</code>, <code>view</code>, <code>create</code>, <code>edit</code>) as a preview by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/babakks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/babakks">@babakks</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxbeizer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxbeizer">@maxbeizer</a> in <a href="https://github.com/cli/cli/pull/13541" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13541/hovercard">#13541</a></li>
<li>Add <code>gh discussion comment</code> to comment on and reply to discussions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/babakks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/babakks">@babakks</a> in <a href="https://github.com/cli/cli/pull/13620" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13620/hovercard">#13620</a></li>
<li>Add Issues 2.0 support: issue types, sub-issues, and relationships by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BagToad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BagToad">@BagToad</a> in <a href="https://github.com/cli/cli/pull/13057" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13057/hovercard">#13057</a></li>
<li>Add <code>gh skill list</code> to inventory installed agent skills by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tommaso-moro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tommaso-moro">@tommaso-moro</a> in <a href="https://github.com/cli/cli/pull/13418" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13418/hovercard">#13418</a></li>
<li>Add <code>--all</code> flag to <code>gh skill install</code> to install every skill in a repository by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tommaso-moro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tommaso-moro">@tommaso-moro</a> in <a href="https://github.com/cli/cli/pull/13471" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13471/hovercard">#13471</a></li>
<li>Skip skills without metadata when running <code>gh skill update --all</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tommaso-moro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tommaso-moro">@tommaso-moro</a> in <a href="https://github.com/cli/cli/pull/13469" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13469/hovercard">#13469</a></li>
<li>Alias <code>gh extension uninstall</code> to <code>gh extension remove</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BagToad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BagToad">@BagToad</a> in <a href="https://github.com/cli/cli/pull/13599" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13599/hovercard">#13599</a></li>
<li>Auto-install official extensions in CI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BagToad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BagToad">@BagToad</a> in <a href="https://github.com/cli/cli/pull/13581" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13581/hovercard">#13581</a></li>
</ul>
<h3>🐛 Fixes</h3>
<ul>
<li>fix(skill): support skill discovery in nested directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tommaso-moro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tommaso-moro">@tommaso-moro</a> in <a href="https://github.com/cli/cli/pull/13459" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13459/hovercard">#13459</a></li>
</ul>
<h3>📚 Docs &amp; Chores</h3>
<ul>
<li>Bump Go to 1.26.4 by @github-actions[bot] in <a href="https://github.com/cli/cli/pull/13578" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13578/hovercard">#13578</a></li>
<li>Clean up deferred issue update helper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BagToad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BagToad">@BagToad</a> in <a href="https://github.com/cli/cli/pull/13584" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13584/hovercard">#13584</a></li>
<li>Add terminal-mockup canvas extension for marketing screenshots by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BagToad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BagToad">@BagToad</a> in <a href="https://github.com/cli/cli/pull/13612" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13612/hovercard">#13612</a></li>
<li>Add <code>gh discussion</code> and Issues 2.0 reference to the <code>gh</code> skill, plus a README note by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BagToad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BagToad">@BagToad</a> in <a href="https://github.com/cli/cli/pull/13631" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13631/hovercard">#13631</a></li>
</ul>
<h3><img class="emoji" title=":dependabot:" alt=":dependabot:" src="https://github.githubassets.com/images/icons/emoji/dependabot.png" height="20" width="20" align="absmiddle"> Dependencies</h3>
<ul>
<li>chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a href="https://github.com/cli/cli/pull/13521" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13521/hovercard">#13521</a></li>
<li>chore(deps): bump github.com/gdamore/tcell/v2 from 2.13.9 to 2.13.10 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a href="https://github.com/cli/cli/pull/13520" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13520/hovercard">#13520</a></li>
<li>chore(deps): bump github.com/mattn/go-colorable from 0.1.14 to 0.1.15 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a href="https://github.com/cli/cli/pull/13572" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13572/hovercard">#13572</a></li>
<li>chore(deps): bump charm.land/bubbletea/v2 from 2.0.6 to 2.0.7 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a href="https://github.com/cli/cli/pull/13595" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13595/hovercard">#13595</a></li>
<li>chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>  in <a href="https://github.com/cli/cli/pull/13596" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13596/hovercard">#13596</a></li>
<li>chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a href="https://github.com/cli/cli/pull/13597" data-hovercard-type="pull_request" data-hovercard-url="/cli/cli/pull/13597/hovercard">#13597</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cli/cli/compare/v2.93.0...v2.94.0"><tt>v2.93.0...v2.94.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11081 | Google Chrome up to 148.0.7778.216 Canvas cross-domain policy (ID 500076)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Google Chrome. This issue affects some unknown processing of the component Canvas. Performing a manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is identified as CVE-2026-1108...]]></description>
<link>https://tsecurity.de/de/3588003/sicherheitsluecken/cve-2026-11081-google-chrome-up-to-14807778216-canvas-cross-domain-policy-id-500076/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588003/sicherheitsluecken/cve-2026-11081-google-chrome-up-to-14807778216-canvas-cross-domain-policy-id-500076/</guid>
<pubDate>Wed, 10 Jun 2026 16:41:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/google:chrome">Google Chrome</a>. This issue affects some unknown processing of the component <em>Canvas</em>. Performing a manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-11081">CVE-2026-11081</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitslücke im Microsoft SharePoint: Microsoft Patch im Juli schließt riskante Lücke]]></title>
<description><![CDATA[Windows DHCP Server (9,1); Windows Hyper-V (8,4); Microsoft Live Share Canvas SDK (8,0); Active Directory Domain Services (8,8) ...]]></description>
<link>https://tsecurity.de/de/3587811/windows-server/sicherheitsluecke-im-microsoft-sharepoint-microsoft-patch-im-juli-schliesst-riskante-luecke/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587811/windows-server/sicherheitsluecke-im-microsoft-sharepoint-microsoft-patch-im-juli-schliesst-riskante-luecke/</guid>
<pubDate>Wed, 10 Jun 2026 15:46:46 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows</b> DHCP <b>Server</b> (9,1); <b>Windows</b> Hyper-V (8,4); Microsoft Live Share Canvas SDK (8,0); Active Directory Domain Services (8,8) ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Building Integrated Cyber Defence at NATO Integrated Cyber Cent]]></title>
<description><![CDATA[Author: natoccdcoe - Bewertung: 0x - Views:0 This session highlights how NATO is building a resilient, mission-ready cyber posture by operationalising cyberspace as a military domain, protecting Alliance networks, and improving shared situational awareness through close cooperation with Allies, i...]]></description>
<link>https://tsecurity.de/de/3587771/it-security-video/building-integrated-cyber-defence-at-nato-integrated-cyber-cent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587771/it-security-video/building-integrated-cyber-defence-at-nato-integrated-cyber-cent/</guid>
<pubDate>Wed, 10 Jun 2026 15:19:18 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: natoccdcoe - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/aTNlgu-BXlE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This session highlights how NATO is building a resilient, mission-ready cyber posture by operationalising cyberspace as a military domain, protecting Alliance networks, and improving shared situational awareness through close cooperation with Allies, industry, and academia. The session outlines the NATO Integrated Cyber Centre’s approach to strengthening NATO’s collective defence in an increasingly contested digital environment through three lines of effort: modernising digital infrastructure, developing a skilled cyber workforce, and accelerating the adoption of innovative technologies.<br />
<br />
Speakers: <br />
Mr. Luc Dandurand, Chief of the NATO Cyber Security Centre, NATO Integrated Cyber Defence Centre <br />
Brigadier General Ümit Ersoy, Director Cyberspace Operations Centre at Supreme Headquarters Allied Powers Europe (SHAPE) and NICC <br />
Col Davide Dettori, Head of Cyber Operations at NATO HQ Cyber and Digital Transformation Division<br />
<br />
#cycon2026 #ccdcoe<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Commanders' Panel]]></title>
<description><![CDATA[Author: natoccdcoe - Bewertung: 0x - Views:2 CyCon 2026  | Senior cyber commanders from the UK, France, Poland and Ukraine discussed how national cyber commands are evolving to meet the demands of modern conflict, from building capable forces to contributing to collective defence.

Speakers:
Gene...]]></description>
<link>https://tsecurity.de/de/3587770/it-security-video/cyber-commanders-panel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587770/it-security-video/cyber-commanders-panel/</guid>
<pubDate>Wed, 10 Jun 2026 15:19:17 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: natoccdcoe - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/lpO-xpa8Z2w?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>CyCon 2026  | Senior cyber commanders from the UK, France, Poland and Ukraine discussed how national cyber commands are evolving to meet the demands of modern conflict, from building capable forces to contributing to collective defence.<br />
<br />
Speakers:<br />
General Sir Robert Magowan, Commander, Cyber & Specialist Operations Command, UK<br />
Major General Emmanuel Naëgelen, Commander, French Cyber Command<br />
Brigadier General Mariusz Chmielewski, Deputy and Incoming Commander, Polish Cyber Command<br />
Brigadier General Oleksandr Potii, Chairman, State Service of Special Communications and Information Protection of Ukraine<br />
Dr. Michael Sulmeyer, Professor, Georgetown University (moderator)<br />
<br />
#CCDCOE #CyCon2026<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber and Modern War: Operational Lessons from Ukraine]]></title>
<description><![CDATA[Author: natoccdcoe - Bewertung: 0x - Views:4 CyCon 2026 | What does it take to defend a nation's digital infrastructure during active war? Brigadier General Oleksandr Potii, Chairman of Ukraine's State Service of Special Communications and Information Protection, drew on frontline experience to d...]]></description>
<link>https://tsecurity.de/de/3587768/it-security-video/cyber-and-modern-war-operational-lessons-from-ukraine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587768/it-security-video/cyber-and-modern-war-operational-lessons-from-ukraine/</guid>
<pubDate>Wed, 10 Jun 2026 15:19:15 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: natoccdcoe - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ucHoTjE9XAA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>CyCon 2026 | What does it take to defend a nation's digital infrastructure during active war? Brigadier General Oleksandr Potii, Chairman of Ukraine's State Service of Special Communications and Information Protection, drew on frontline experience to discuss wartime cyber defence, cross-sector coordination and the role of international cooperation in building collective resilience.<br />
<br />
#CCDCOE #CyCon2026<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DocLang aims to make documents readable by AI, not humans]]></title>
<description><![CDATA[AIs struggle to understand documents designed for humans; the DocLang working group seeks to flip that imbalance with its specification for machine-readable business documents “built from the ground up for LLM tokenizers.”



The working group, founded by IBM, Nvidia, and Red Hat and hosted by th...]]></description>
<link>https://tsecurity.de/de/3586922/it-security-nachrichten/doclang-aims-to-make-documents-readable-by-ai-not-humans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586922/it-security-nachrichten/doclang-aims-to-make-documents-readable-by-ai-not-humans/</guid>
<pubDate>Wed, 10 Jun 2026 10:15:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AIs struggle to understand documents designed for humans; the DocLang working group seeks to flip that imbalance with its specification for machine-readable business documents “built from the ground up for LLM tokenizers.”</p>



<p>The working group, founded by IBM, Nvidia, and Red Hat and hosted by the Linux Foundation’s LF AI &amp; Data project, aims to create an open, universal, AI-native document format designed to improve how enterprises prepare, exchange, and govern document data for AI systems. ABBYY and Human Signal will also be involved in its development, and other contributors are welcome.</p>



<p>“Enterprises today work across a fragmented landscape of document formats, including PDFs, JPEGs, and other file types built primarily for human consumption rather than AI interpretation,” the group said in its launch <a href="https://www.linuxfoundation.org/press/lf-ai-data-foundation-launches-doclang-specification-working-group-to-advance-an-open-standard-for-ai-native-documents" target="_blank" rel="nofollow">announcement</a>.</p>



<p>“This disconnect can introduce complexity, raise costs, and reduce reliability when extracting meaning from business documents,” as organizations increasingly rely on generative AI and agentic systems, it said.</p>



<p><a href="https://www.linkedin.com/in/markcollier/" target="_blank" rel="nofollow">Mark Collier</a>, executive director of LF AI &amp; Data, said the goal of the <a href="https://doclang.ai/" rel="nofollow">DocLang Specification</a> Working Group is to “develop a vendor-neutral, interoperable standard that helps organizations prepare document data for AI more reliably, transparently, and at scale.”</p>



<p>DocLang defines a structured, machine-readable format for documents of any type, like JSON for data, that any tool can implement and any pipeline can consume. It builds on <a href="https://www.infoworld.com/article/3997240/docling-an-open-source-tool-kit-for-advanced-document-processing.html">DocLing</a>, a document processing toolkit hosted by LF AI &amp; Data that can transform human-readable PDFs, word processor documents or spreadsheets into structured data.</p>



<p><strong>Standards must evolve for AI</strong></p>



<p>Something like DocLang is needed, said independent technology analyst <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="nofollow">Carmi Levy</a>. “Existing document standards have done an admirable job allowing global stakeholders to confidently collaborate for decades, but it’s becoming increasingly clear that they are in desperate need of an update as AI reshapes the rules around how work gets done,” he explained.</p>



<p>Largely static document types, he said, “can be somewhat limiting when AI is redefining the very word, ‘document.’ In many ways. AI-age documents are far more iterative and dynamic than what they once were, and the definitions need to evolve with the times. The documents we currently live with simply weren’t designed for the AI age.”</p>



<p>Within that context, Levy said, “DocLang represents an early, best hope of achieving some kind of foundational baseline for document standards, one that will hopefully allow more intelligent, more efficient, lower-risk workflows than is currently the case.”</p>



<p>Taking an open-source, vendor-agnostic approach to the process ensures the collective will take precedence over the needs of specific vendors, he said, adding, “earlier standards-setting efforts around networking, documentation, the web, and the cloud powered the free-flowing digital landscape that defines modern life.”</p>



<p>An AI-centric documentation standard will carry that reality into the next generation of technology, said Levy.</p>



<p><strong>A question of governance</strong></p>



<p>The entire concept of LLMs, <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy said, “involves using natural human languages. The computer is supposed to understand us without us changing our syntax or language. Forcing a syntax on users is exactly what we have today with SEO and more advanced programming languages.”</p>



<p>With something like DocLang, where the standard can be applied to content ingestion, he said, “I would be OK with that being automated, which seems to be the intent. The use case I envision is that when I upload a document to an agent, a skill can be run to preprocess the document into the DocLang standard format, saving tokens.”</p>



<p>That makes sense, he said, adding that he thinks it’s good “if it can help generate outputs, like a visualization, that can be shared outside an AI tool. On that front, that is also why I am liking Web MCP, since you are just adding some code to the page, like CSS or JavaScript, and the consumer, in this case, an AI browser or skill, is better equipped to handle the site.”</p>



<p>The point, he said, is, “these standards need to preserve the fact that humans can still do what they want, and do not need to know any coding to be proficient. In terms of governance, I am not sure if it matters.”</p>



<p>But one analyst did foresee governance problems arising from DocLang’s use.</p>



<p><a href="https://www.infotech.com/profiles/yaz-palanichamy" target="_blank" rel="nofollow">Yaz Palanichamy</a>, senior research analyst at Info-Tech Research Group, said DocLang adoption will require organizations to implement and review controls in order to scale its use accountably and securely.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Working group formed to develop standard for AI-native docs]]></title>
<description><![CDATA[LF AI & Data Foundation, a division of the Linux Foundation, launched a working group on Tuesday that will focus on the development of DocLang, a specification intended to support interoperable document processing across AI and agentic workflows.



The working group, founded by premier members I...]]></description>
<link>https://tsecurity.de/de/3586345/it-nachrichten/working-group-formed-to-develop-standard-for-ai-native-docs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586345/it-nachrichten/working-group-formed-to-develop-standard-for-ai-native-docs/</guid>
<pubDate>Wed, 10 Jun 2026 04:47:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>LF AI &amp; Data Foundation, a division of the Linux Foundation, launched a working group on Tuesday that will focus on the development of DocLang, a specification intended to support interoperable document processing across AI and agentic workflows.</p>



<p>The working group, founded by premier members IBM, Nvidia and Red Hat, is tasked with the creation of an open, universal, AI-native document format designed to improve how enterprises prepare, exchange, and govern document data for AI systems. Contributors ABBYY and Human Signal will also be involved in its development.</p>



<p>The <a href="https://www.linuxfoundation.org/press/lf-ai-data-foundation-launches-doclang-specification-working-group-to-advance-an-open-standard-for-ai-native-documents" target="_blank" rel="noreferrer noopener">announcement</a> stated, “enterprises today work across a fragmented landscape of document formats, including PDFs, JPEGs, and other file types built primarily for human consumption rather than AI interpretation.”</p>



<p>As organizations increasingly rely on generative AI and agentic systems, it said, “this disconnect can introduce complexity, raise costs, and reduce reliability when extracting meaning from business documents.”</p>



<p><a href="https://www.linkedin.com/in/markcollier/" target="_blank" rel="noreferrer noopener">Mark Collier</a>, executive director of LF AI &amp; Data, said the goal of the DocLang Specification Working Group is to “develop a vendor-neutral, interoperable standard that helps organizations prepare document data for AI more reliably, transparently, and at scale.”</p>



<p>To that end, an <a href="https://doclang.ai/" target="_blank" rel="noreferrer noopener">information document</a> released by the group stated, “PDF was built for print, DOCX was built for editors. DocLang is built for what comes next, a machine-readable document standard your models can actually trust.”</p>



<p>DocLang, it said, “defines a structured, machine-readable format for documents of any type. Not a converter. Not an API. A standard, like JSON for data, like HTML for the web, that any tool can implement and any pipeline can consume.”</p>



<h2 class="wp-block-heading">Standards must evolve for AI</h2>



<p>Something like DocLang is needed, said independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a>. “Existing document standards have done an admirable job allowing global stakeholders to confidently collaborate for decades, but it’s becoming increasingly clear that they are in desperate need of an update as AI reshapes the rules around how work gets done,” he explained.</p>



<p>Largely static document types, he said, “can be somewhat limiting when AI is redefining the very word, ‘document.’ In many ways. AI-age documents are far more iterative and dynamic than what they once were, and the definitions need to evolve with the times. The documents we currently live with simply weren’t designed for the AI age.”</p>



<p>Within that context, Levy said, “DocLang represents an early, best hope of achieving some kind of foundational baseline for document standards, one that will hopefully allow more intelligent, more efficient, lower-risk workflows than is currently the case.”</p>



<p>Taking an open-source, vendor-agnostic approach to the process ensures the collective will take precedence over the needs of specific vendors, he said, adding, “earlier standards-setting efforts around networking, documentation, the web, and the cloud powered the free-flowing digital landscape that defines modern life.”</p>



<p>An AI-centric documentation standard will carry that reality into the next generation of technology, said Levy.</p>



<h2 class="wp-block-heading">A question of governance</h2>



<p>Asked what a DocLang standard will mean for human workers and in particular for governance and accountability, <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy said, “at a high level, I like and understand the idea of standards, but the question raises an important point.”</p>



<p>The entire concept of LLMs, said Andersen, “involves using natural human languages. The computer is supposed to understand us without us changing our syntax or language. Forcing a syntax on users is exactly what we have today with SEO and more advanced programming languages.”</p>



<p>With something like DocLang, where the standard can be applied to content ingestion, he said, “I would be OK with that being automated, which seems to be the intent. The use case I envision is that when I upload a document to an agent, a skill can be run to preprocess the document into the DocLang standard format, saving tokens.”</p>



<p>That makes sense, he said, adding that he thinks it’s good “if it can help generate outputs, like a visualization, that can be shared outside an AI tool. On that front, that is also why I am liking Web MCP, since you are just adding some code to the page, like CSS or JavaScript, and the consumer, in this case, an AI browser or skill, is better equipped to handle the site.”</p>



<p>The point, he said, is, “these standards need to preserve the fact that humans can still do what they want, and do not need to know any coding to be proficient. In terms of governance, I am not sure if it matters.”</p>



<p>Again, Andersen pointed out, “if there is some sort of preprocessing that appends metadata or code to the document, as long as it’s maintained, there should be no issue; in fact, it could make governance easier, since there is some standardization of the context. But that’s not coming across yet in the specs, and I’d encourage the team to consider it.” </p>



<p><a href="https://www.infotech.com/profiles/yaz-palanichamy" target="_blank" rel="noreferrer noopener">Yaz Palanichamy</a>, senior research analyst at Info-Tech Research Group, said, “in theory, the concept of AI-native documents, at least from a user productivity standpoint, can certainly help organizations better prepare their organization’s documentation data for AI-embedded systems.”</p>



<p>However, he added, “organizational compliance controls and an overarching governance model would be absolutely necessary to employ if and when an organization does decide to proceed with such a use case.”</p>



<p>Moreover, in addition to model training permissions and fine-tuning extraction scope, Palanichamy said, “the hypothetical organization ‘X’ that wants to employ AI-embedded document management workflows needs to also understand whether their company, from a technology readiness standpoint, is able to appropriately standardize their internal document management practices across both AI and agentic workflows.”</p>



<p>That being said, he added, “without doing any internal feasibility studies or prepping their organization in advance, change management from a document lifecycle management standpoint will not be enforced appropriately, and, therefore this would deter the organization from maturing and/or scaling their AI-embedded document processing capabilities further.”</p>



<p>Palanichamy pointed out, “in essence, while in theory DocLang as a universal AI-native documentation format is not an ineffective idea as such, there will still be several organizational controls that will need to be reviewed appropriately from a governance standpoint to ensure that the organization scales this new collaborative standard and toolkit in an accountable and secure manner.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4183187/working-group-formed-to-develop-standard-for-ai-native-docs.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Working group formed to develop standard for AI-native docs]]></title>
<description><![CDATA[LF AI & Data Foundation, a division of the Linux Foundation, launched a working group on Tuesday that will focus on the development of DocLang, a specification intended to support interoperable document processing across AI and agentic workflows.



The working group, founded by premier members I...]]></description>
<link>https://tsecurity.de/de/3586329/it-nachrichten/working-group-formed-to-develop-standard-for-ai-native-docs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586329/it-nachrichten/working-group-formed-to-develop-standard-for-ai-native-docs/</guid>
<pubDate>Wed, 10 Jun 2026 04:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>LF AI &amp; Data Foundation, a division of the Linux Foundation, launched a working group on Tuesday that will focus on the development of DocLang, a specification intended to support interoperable document processing across AI and agentic workflows.</p>



<p>The working group, founded by premier members IBM, Nvidia and Red Hat, is tasked with the creation of an open, universal, AI-native document format designed to improve how enterprises prepare, exchange, and govern document data for AI systems. Contributors ABBYY and Human Signal will also be involved in its development.</p>



<p>The <a href="https://www.linuxfoundation.org/press/lf-ai-data-foundation-launches-doclang-specification-working-group-to-advance-an-open-standard-for-ai-native-documents" target="_blank" rel="nofollow">announcement</a> stated, “enterprises today work across a fragmented landscape of document formats, including PDFs, JPEGs, and other file types built primarily for human consumption rather than AI interpretation.”</p>



<p>As organizations increasingly rely on generative AI and agentic systems, it said, “this disconnect can introduce complexity, raise costs, and reduce reliability when extracting meaning from business documents.”</p>



<p><a href="https://www.linkedin.com/in/markcollier/" target="_blank" rel="nofollow">Mark Collier</a>, executive director of LF AI &amp; Data, said the goal of the DocLang Specification Working Group is to “develop a vendor-neutral, interoperable standard that helps organizations prepare document data for AI more reliably, transparently, and at scale.”</p>



<p>To that end, an <a href="https://doclang.ai/" target="_blank" rel="nofollow">information document</a> released by the group stated, “PDF was built for print, DOCX was built for editors. DocLang is built for what comes next, a machine-readable document standard your models can actually trust.”</p>



<p>DocLang, it said, “defines a structured, machine-readable format for documents of any type. Not a converter. Not an API. A standard, like JSON for data, like HTML for the web, that any tool can implement and any pipeline can consume.”</p>



<h2 class="wp-block-heading">Standards must evolve for AI</h2>



<p>Something like DocLang is needed, said independent technology analyst <a href="https://www.linkedin.com/in/carmi/" rel="nofollow">Carmi Levy</a>. “Existing document standards have done an admirable job allowing global stakeholders to confidently collaborate for decades, but it’s becoming increasingly clear that they are in desperate need of an update as AI reshapes the rules around how work gets done,” he explained.</p>



<p>Largely static document types, he said, “can be somewhat limiting when AI is redefining the very word, ‘document.’ In many ways. AI-age documents are far more iterative and dynamic than what they once were, and the definitions need to evolve with the times. The documents we currently live with simply weren’t designed for the AI age.”</p>



<p>Within that context, Levy said, “DocLang represents an early, best hope of achieving some kind of foundational baseline for document standards, one that will hopefully allow more intelligent, more efficient, lower-risk workflows than is currently the case.”</p>



<p>Taking an open-source, vendor-agnostic approach to the process ensures the collective will take precedence over the needs of specific vendors, he said, adding, “earlier standards-setting efforts around networking, documentation, the web, and the cloud powered the free-flowing digital landscape that defines modern life.”</p>



<p>An AI-centric documentation standard will carry that reality into the next generation of technology, said Levy.</p>



<h2 class="wp-block-heading">A question of governance</h2>



<p>Asked what a DocLang standard will mean for human workers and in particular for governance and accountability, <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy said, “at a high level, I like and understand the idea of standards, but the question raises an important point.”</p>



<p>The entire concept of LLMs, said Andersen, “involves using natural human languages. The computer is supposed to understand us without us changing our syntax or language. Forcing a syntax on users is exactly what we have today with SEO and more advanced programming languages.”</p>



<p>With something like DocLang, where the standard can be applied to content ingestion, he said, “I would be OK with that being automated, which seems to be the intent. The use case I envision is that when I upload a document to an agent, a skill can be run to preprocess the document into the DocLang standard format, saving tokens.”</p>



<p>That makes sense, he said, adding that he thinks it’s good “if it can help generate outputs, like a visualization, that can be shared outside an AI tool. On that front, that is also why I am liking Web MCP, since you are just adding some code to the page, like CSS or JavaScript, and the consumer, in this case, an AI browser or skill, is better equipped to handle the site.”</p>



<p>The point, he said, is, “these standards need to preserve the fact that humans can still do what they want, and do not need to know any coding to be proficient. In terms of governance, I am not sure if it matters.”</p>



<p>Again, Andersen pointed out, “if there is some sort of preprocessing that appends metadata or code to the document, as long as it’s maintained, there should be no issue; in fact, it could make governance easier, since there is some standardization of the context. But that’s not coming across yet in the specs, and I’d encourage the team to consider it.” </p>



<p><a href="https://www.infotech.com/profiles/yaz-palanichamy" target="_blank" rel="nofollow">Yaz Palanichamy</a>, senior research analyst at Info-Tech Research Group, said, “in theory, the concept of AI-native documents, at least from a user productivity standpoint, can certainly help organizations better prepare their organization’s documentation data for AI-embedded systems.”</p>



<p>However, he added, “organizational compliance controls and an overarching governance model would be absolutely necessary to employ if and when an organization does decide to proceed with such a use case.”</p>



<p>Moreover, in addition to model training permissions and fine-tuning extraction scope, Palanichamy said, “the hypothetical organization ‘X’ that wants to employ AI-embedded document management workflows needs to also understand whether their company, from a technology readiness standpoint, is able to appropriately standardize their internal document management practices across both AI and agentic workflows.”</p>



<p>That being said, he added, “without doing any internal feasibility studies or prepping their organization in advance, change management from a document lifecycle management standpoint will not be enforced appropriately, and, therefore this would deter the organization from maturing and/or scaling their AI-embedded document processing capabilities further.”</p>



<p>Palanichamy pointed out, “in essence, while in theory DocLang as a universal AI-native documentation format is not an ineffective idea as such, there will still be several organizational controls that will need to be reviewed appropriately from a governance standpoint to ensure that the organization scales this new collaborative standard and toolkit in an accountable and secure manner.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday - June 2026]]></title>
<description><![CDATA[Microsoft is publishing 200 vulnerabilities on June 2026 Patch Tuesday. Microsoft is not aware of exploitation in the wild for any of these vulnerabilities, and is aware of public disclosure for three. This is similar to last month’s Patch Tuesday, however several of last month’s vulnerabilities ...]]></description>
<link>https://tsecurity.de/de/3586067/it-security-nachrichten/patch-tuesday-june-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586067/it-security-nachrichten/patch-tuesday-june-2026/</guid>
<pubDate>Tue, 09 Jun 2026 23:52:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Microsoft is publishing 200 vulnerabilities on </span><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun"><span>June 2026 Patch Tuesday</span></a><span>. Microsoft is not aware of exploitation in the wild for any of these vulnerabilities, and is aware of public disclosure for three. This is similar to last month’s Patch Tuesday, however several of last month’s vulnerabilities ended up on CISA KEV in the days following their publication. So far this month, Microsoft has provided patches to address 360 browser vulnerabilities, which is an order of magnitude more than has been typical in any given month over the past few years. As usual, browser vulns are not included in the Patch Tuesday count above. Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update Guide. Other vulnerability categories, especially Linux kernel vulnerabilities, are seeing a similar increase in AI-assisted vulnerability reports.</span></p><h3><span>What's the opposite of coordinated disclosure?</span></h3><p><span>In recent weeks, an independent vulnerability researcher going by the pseudonym Nightmare Eclipse has attracted significant attention by publishing details of six Microsoft vulnerabilities, including elevation of privilege vulnerabilities in Defender, and a Secure Boot disk encryption bypass. The researcher provided full proof-of-concept code for some, and provided  significant-but-incomplete detail around the path to exploitation for others. Microsoft has confirmed that these disclosures were not coordinated, and it is clear that the relationship between this researcher and Microsoft is less than cordial. Two of the disclosures emerged in the hours after last month’s Patch Tuesday, which provides maximum visibility, while limiting Microsoft’s ability to respond without out-of-cycle patches.</span></p><p><span>At time of writing, Microsoft has provided mitigation advice and patches for </span><a href="http://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825"><span>CVE-2026-33825</span></a><span>, </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><span>CVE-2026-45585</span></a><span>, </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498"><span>CVE-2026-45498</span></a><span>, and </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a><span>, leaving only two elevation of privilege vulnerabilities unpatched, known as MiniPlasma and GreenPlasma. However, a recent blog post by Nightmare Eclipse with the title “7” has been widely interpreted to mean that there is at least one more vulnerability to come. The post contained no content other than an image of Albert Vesker, a character from the Resident Evil video game series who formerly worked as a researcher for a technology corporation before going rogue. Any inference around the possible meaning of the image is left as an exercise for the reader.</span></p><p><span>Given the timing of last month’s disclosures in the hours following Patch Tuesday, a further high-friction disclosure today would perhaps be unsurprising. Indeed, a new blog post and a new GitHub account from the same researcher have emerged in the hours following Microsoft’s publication of the June 2026 Patch Tuesday updates. The apparent seventh disclosure is nicknamed RoguePlanet, and appears to describe another elevation of privilege to SYSTEM in Defender.</span></p><p><span>It is not at all difficult to understand why Microsoft and many blue team practitioners are deeply alarmed by the partial or even full disclosure of proof-of-concept code for an ongoing series of vulnerabilities affecting fully-patched Windows systems. However, multiple leading voices in the broader vulnerability disclosure community have expressed concern that Microsoft’s invocation of the Digital Crimes Unit in a </span><a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure"><span>May 27, 2026 blog post</span></a><span> may yet prove counterproductive, especially if it causes other researchers to back away from mutually beneficial engagements with MSRC. A few days later, </span><a href="https://x.com/msftsecresponse/status/2061293718942908925"><span>MSRC issued a further statement</span></a><span> clarifying that they have no intention of pursuing action against security researchers, but only those who break the law or engage in malicious activity causing real harm. For now, one safe conclusion is that this unusually sensational Microsoft vulnerability management story arc is far from over.</span></p><h3><span>HTTP/2: denial of service</span></h3><p><span>Every so often, a new round of denial of service vulnerabilities emerge which affect web servers implementing HTTP/2 and HTTP/3 standards. This class of vulnerabilities is likely to expand further as researchers, including the discoverers of </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a><span>, use advances in LLM capability to probe not just specific software, but also the standards on which software rests. Microsoft warns that exploitation leads to uncontrolled resource consumption over a network, and expects that exploitation is more likely. The advisory credits both a third-party research firm and OpenAI’s Codex.</span></p><p><span>Microsoft has not yet directly addressed another HTTP/2 vulnerability which </span><a href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb"><span>allows trivial denial-of-service</span></a><span> against the default HTTP/2 configuration of multiple web server platforms, including Microsoft IIS. CVE-2026-49975, also known as HTTP/2 Bomb, became public knowledge a week ago. This denial of service works by exhausting memory on the target server, and unlike a distributed denial of service attack, there is no requirement that an attacker control a large amount of bandwidth. Patches are available for NGINX and Apache, with IIS presumably to follow at some point. If practically possible, disabling HTTP/2 is a valid mitigation.</span></p><h3><span>PowerToys: SYSTEM EoP</span></h3><p><span>The Microsoft PowerToys utility provides a wide variety of useful control and configuration options for Windows power users which aren’t otherwise easily accessible. It turns out that PowerToys also offers an undocumented extra: local elevation of privilege to SYSTEM via successful exploitation of </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a><span>. It is worth noting that the fix was included in PowerToys v0.99.1 on April 29, 2026, without any apparent mention in the </span><a href="https://github.com/microsoft/PowerToys/releases/tag/v0.99.1"><span>release notes</span></a><span>. Attackers with patch-diffing toolkits may well take note of this discrepancy.</span></p><h3><span>Microsoft lifecycle update</span></h3><p><span>There are no significant Microsoft product lifecycle changes this month. </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2016?branch=live"><span>SQL Server 2016</span></a><span> moves beyond regular extended support and into the pay-to-play Extended Security Updates (ESU) phase after July 14, 2026. On that same date, SharePoint </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2016?branch=live"><span>2016</span></a><span> and </span><a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2019?branch=live"><span>2019</span></a><span> will also move past extended support, but since there’s no ESU available, the only remaining option for fully-supported self-hosted SharePoint after the middle of next month will be SharePoint Subscription Edition.</span></p><h2>Summary charts</h2><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt31130c38c8b60ba5/6a28853699795c2e8b593776/2026-06-vuln_count_impact.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-06-vuln_count_impact.png" asset-alt="2026-06-vuln_count_impact.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt31130c38c8b60ba5/6a28853699795c2e8b593776/2026-06-vuln_count_impact.png" data-sys-asset-uid="blt31130c38c8b60ba5" data-sys-asset-filename="2026-06-vuln_count_impact.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-06-vuln_count_impact.png" sys-style-type="display"></figure><p></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc597c95907fb5964/6a288536f022834cea65c650/2026-06-vuln_count_component.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-06-vuln_count_component.png" asset-alt="2026-06-vuln_count_component.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc597c95907fb5964/6a288536f022834cea65c650/2026-06-vuln_count_component.png" data-sys-asset-uid="bltc597c95907fb5964" data-sys-asset-filename="2026-06-vuln_count_component.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-06-vuln_count_component.png" sys-style-type="display"></figure><p></p><figure><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3d7af9ae98ec4154/6a2885368c60340ef6c46d6f/2026-06-vuln_count_impact-component-heatmap.png" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="2026-06-vuln_count_impact-component-heatmap.png" asset-alt="2026-06-vuln_count_impact-component-heatmap.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3d7af9ae98ec4154/6a2885368c60340ef6c46d6f/2026-06-vuln_count_impact-component-heatmap.png" data-sys-asset-uid="blt3d7af9ae98ec4154" data-sys-asset-filename="2026-06-vuln_count_impact-component-heatmap.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="2026-06-vuln_count_impact-component-heatmap.png" sys-style-type="display"></figure><p></p><p></p><h2>Vulnerabilities by Product Family</h2><h3>Apps vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45650">CVE-2026-45650</a></td><td><p>Microsoft Bing Search Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-49161">CVE-2026-49161</a></td><td><p>Microsoft PC Manager Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42902">CVE-2026-42902</a></td><td><p>Microsoft PowerToys Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45649">CVE-2026-45649</a></td><td><p>Office for Android Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44803">CVE-2026-44803</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44812">CVE-2026-44812</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><h3>Azure vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-32193">CVE-2026-32193</a></td><td><p>Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47643">CVE-2026-47643</a></td><td><p>Azure Stack Edge Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41098">CVE-2026-41098</a></td><td><p>Azure Stack Edge Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr></tbody></table><h3>Developer Tools vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45490">CVE-2026-45490</a></td><td><p>.NET SDK Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45491">CVE-2026-45491</a></td><td><p>.NET Tampering Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45591">CVE-2026-45591</a></td><td><p>ASP.NET Core Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45644">CVE-2026-45644</a></td><td><p>Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45482">CVE-2026-45482</a></td><td><p>Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40376">CVE-2026-40376</a></td><td><p>Visual Studio Code Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47281">CVE-2026-47281</a></td><td><p>Visual Studio Code Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47284">CVE-2026-47284</a></td><td><p>Visual Studio Code Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47292">CVE-2026-47292</a></td><td><p>Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48569">CVE-2026-48569</a></td><td><p>Visual Studio Code Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47287">CVE-2026-47287</a></td><td><p>Visual Studio Code Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr></tbody></table><h3>ESU vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-10263">CVE-2025-10263</a></td><td><p>ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel]</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44815">CVE-2026-44815</a></td><td><p>DHCP Client Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-49160">CVE-2026-49160</a></td><td><p>HTTP.sys Denial of Service Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47291">CVE-2026-47291</a></td><td><p>HTTP.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45642">CVE-2026-45642</a></td><td><p>Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>3.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45637">CVE-2026-45637</a></td><td><p>Microsoft DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45504">CVE-2026-45504</a></td><td><p>Microsoft Exchange Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45502">CVE-2026-45502</a></td><td><p>Microsoft Exchange Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45503">CVE-2026-45503</a></td><td><p>Microsoft Exchange Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45583">CVE-2026-45583</a></td><td><p>Microsoft Exchange Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45500">CVE-2026-45500</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45501">CVE-2026-45501</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47631">CVE-2026-47631</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42986">CVE-2026-42986</a></td><td><p>Microsoft Graphics Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41092">CVE-2026-41092</a></td><td><p>Microsoft Kinect Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45606">CVE-2026-45606</a></td><td><p>Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42980">CVE-2026-42980</a></td><td><p>NT OS Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42916">CVE-2026-42916</a></td><td><p>NT OS Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47289">CVE-2026-47289</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47653">CVE-2026-47653</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48563">CVE-2026-48563</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42909">CVE-2026-42909</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42992">CVE-2026-42992</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44799">CVE-2026-44799</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44801">CVE-2026-44801</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42985">CVE-2026-42985</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42993">CVE-2026-42993</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45588">CVE-2026-45588</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48568">CVE-2026-48568</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48570">CVE-2026-48570</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48573">CVE-2026-48573</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48575">CVE-2026-48575</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48576">CVE-2026-48576</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48578">CVE-2026-48578</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45656">CVE-2026-45656</a></td><td><p>UEFI Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8863">CVE-2026-8863</a></td><td><p>UEFI Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34335">CVE-2026-34335</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45601">CVE-2026-45601</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45598">CVE-2026-45598</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45596">CVE-2026-45596</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45638">CVE-2026-45638</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45603">CVE-2026-45603</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42911">CVE-2026-42911</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45594">CVE-2026-45594</a></td><td><p>Windows Application Identity (AppID) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45655">CVE-2026-45655</a></td><td><p>Windows BitLocker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45658">CVE-2026-45658</a></td><td><p>Windows BitLocker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50507">CVE-2026-50507</a></td><td><p>Windows BitLocker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45640">CVE-2026-45640</a></td><td><p>Windows Bluetooth Port Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45605">CVE-2026-45605</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47656">CVE-2026-47656</a></td><td><p>Windows Boot Manager Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45586">CVE-2026-45586</a></td><td><p>Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42987">CVE-2026-42987</a></td><td><p>Windows Deployment Services (WDS) Remote Code Execution</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33828">CVE-2026-33828</a></td><td><p>Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45634">CVE-2026-45634</a></td><td><p>Windows DHCP Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45608">CVE-2026-45608</a></td><td><p>Windows DHCP Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41108">CVE-2026-41108</a></td><td><p>Windows DNS Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42905">CVE-2026-42905</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42983">CVE-2026-42983</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44802">CVE-2026-44802</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45602">CVE-2026-45602</a></td><td><p>Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42836">CVE-2026-42836</a></td><td><p>Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44803">CVE-2026-44803</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44812">CVE-2026-44812</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42972">CVE-2026-42972</a></td><td><p>Windows Hyper-V Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45607">CVE-2026-45607</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45641">CVE-2026-45641</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45592">CVE-2026-45592</a></td><td><p>Windows Internet (wininet.dll) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42903">CVE-2026-42903</a></td><td><p>Windows Kerberos Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42914">CVE-2026-42914</a></td><td><p>Windows Kerberos Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47288">CVE-2026-47288</a></td><td><p>Windows Kerberos Key Distribution Center (KDC) Remote Code Execution</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48583">CVE-2026-48583</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45653">CVE-2026-45653</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42984">CVE-2026-42984</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45595">CVE-2026-45595</a></td><td><p>Windows Mark of the Web Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48574">CVE-2026-48574</a></td><td><p>Windows Media Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45636">CVE-2026-45636</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50508">CVE-2026-50508</a></td><td><p>Windows NTLM Spoofing Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45487">CVE-2026-45487</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42828">CVE-2026-42828</a></td><td><p>Windows Projected File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42837">CVE-2026-42837</a></td><td><p>Windows Projected File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42969">CVE-2026-42969</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42971">CVE-2026-42971</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42970">CVE-2026-42970</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42973">CVE-2026-42973</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42978">CVE-2026-42978</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42977">CVE-2026-42977</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42979">CVE-2026-42979</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42991">CVE-2026-42991</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45639">CVE-2026-45639</a></td><td><p>Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42908">CVE-2026-42908</a></td><td><p>Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45593">CVE-2026-45593</a></td><td><p>Windows SDK Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42906">CVE-2026-42906</a></td><td><p>Windows Shell Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42907">CVE-2026-42907</a></td><td><p>Windows Shell Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47648">CVE-2026-47648</a></td><td><p>Windows Storage Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42915">CVE-2026-42915</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42904">CVE-2026-42904</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42968">CVE-2026-42968</a></td><td><p>Windows Telephony Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42912">CVE-2026-42912</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40409">CVE-2026-40409</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40404">CVE-2026-40404</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45599">CVE-2026-45599</a></td><td><p>Windows UPnP Device Host Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45635">CVE-2026-45635</a></td><td><p>Windows UPnP Device Host Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42989">CVE-2026-42989</a></td><td><p>Winlogon Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><p></p><p></p><h3>Mariner vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40930">CVE-2026-40930</a></td><td><p>LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.4</p></td></tr></tbody></table><h3>Microsoft Dynamics vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40371">CVE-2026-40371</a></td><td><p>Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr></tbody></table><h3>Microsoft Office vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44822">CVE-2026-44822</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45455">CVE-2026-45455</a></td><td><p>Microsoft Excel Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>3.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45469">CVE-2026-45469</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44817">CVE-2026-44817</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44818">CVE-2026-44818</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44820">CVE-2026-44820</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44823">CVE-2026-44823</a></td><td><p>Microsoft Excel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45459">CVE-2026-45459</a></td><td><p>Microsoft Excel Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>3.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47293">CVE-2026-47293</a></td><td><p>Microsoft Office Click-To-Run Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45485">CVE-2026-45485</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>3.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44821">CVE-2026-44821</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45460">CVE-2026-45460</a></td><td><p>Microsoft Office Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45483">CVE-2026-45483</a></td><td><p>Microsoft Office Project Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45475">CVE-2026-45475</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45472">CVE-2026-45472</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45474">CVE-2026-45474</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44819">CVE-2026-44819</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44824">CVE-2026-44824</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45461">CVE-2026-45461</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45645">CVE-2026-45645</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45463">CVE-2026-45463</a></td><td><p>Microsoft Office Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45456">CVE-2026-45456</a></td><td><p>Microsoft Outlook and Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45458">CVE-2026-45458</a></td><td><p>Microsoft Outlook and Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47635">CVE-2026-47635</a></td><td><p>Microsoft Outlook and Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45484">CVE-2026-45484</a></td><td><p>Microsoft SharePoint Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45454">CVE-2026-45454</a></td><td><p>Microsoft SharePoint Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47298">CVE-2026-47298</a></td><td><p>Microsoft SharePoint Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45467">CVE-2026-45467</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45468">CVE-2026-45468</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45479">CVE-2026-45479</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45453">CVE-2026-45453</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47636">CVE-2026-47636</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47637">CVE-2026-47637</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47638">CVE-2026-47638</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47639">CVE-2026-47639</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47641">CVE-2026-47641</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33113">CVE-2026-33113</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45462">CVE-2026-45462</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45464">CVE-2026-45464</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45465">CVE-2026-45465</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47634">CVE-2026-47634</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47640">CVE-2026-47640</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45481">CVE-2026-45481</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48560">CVE-2026-48560</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48562">CVE-2026-48562</a></td><td><p>Microsoft SharePoint Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>4.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42835">CVE-2026-42835</a></td><td><p>Microsoft Teams for Android Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45466">CVE-2026-45466</a></td><td><p>Microsoft Word Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>3.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45471">CVE-2026-45471</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45486">CVE-2026-45486</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45643">CVE-2026-45643</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45457">CVE-2026-45457</a></td><td><p>Microsoft Word Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45649">CVE-2026-45649</a></td><td><p>Office for Android Spoofing Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44803">CVE-2026-44803</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44812">CVE-2026-44812</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><h3>Open Source Software vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-11463">CVE-2026-11463</a></td><td><p>USCiLab Cereal Shared Pointer type confusion</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-49975">CVE-2026-49975</a></td><td><p>Apache HTTP Server: mod_http2 denial of service</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50265">CVE-2026-50265</a></td><td><p>Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40930">CVE-2026-40930</a></td><td><p>LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-10879">CVE-2026-10879</a></td><td><p>DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>8.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50261">CVE-2026-50261</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50256">CVE-2026-50256</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50262">CVE-2026-50262</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50260">CVE-2026-50260</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50259">CVE-2026-50259</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50257">CVE-2026-50257</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>6.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50258">CVE-2026-50258</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50263">CVE-2026-50263</a></td><td><p>Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()</p></td><td><p>n/a</p></td><td><p>No</p></td><td><p>5.5</p></td></tr></tbody></table><p></p><p></p><h3>Other vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45476">CVE-2026-45476</a></td><td><p>Microsoft Azure Network Adapter Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-26142">CVE-2026-26142</a></td><td><p>Nuance PowerScribe Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr></tbody></table><h3>Server Software vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45504">CVE-2026-45504</a></td><td><p>Microsoft Exchange Server Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45502">CVE-2026-45502</a></td><td><p>Microsoft Exchange Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45503">CVE-2026-45503</a></td><td><p>Microsoft Exchange Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45583">CVE-2026-45583</a></td><td><p>Microsoft Exchange Server Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45500">CVE-2026-45500</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45501">CVE-2026-45501</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47631">CVE-2026-47631</a></td><td><p>Microsoft Exchange Server Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr></tbody></table><h3>System Center vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45647">CVE-2026-45647</a></td><td><p>Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr></tbody></table><h3>Windows vulnerabilities</h3><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-10263">CVE-2025-10263</a></td><td><p>ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel]</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44815">CVE-2026-44815</a></td><td><p>DHCP Client Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-49160">CVE-2026-49160</a></td><td><p>HTTP.sys Denial of Service Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47291">CVE-2026-47291</a></td><td><p>HTTP.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45642">CVE-2026-45642</a></td><td><p>Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>3.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44810">CVE-2026-44810</a></td><td><p>Microsoft Cryptographic Services Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45637">CVE-2026-45637</a></td><td><p>Microsoft DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42986">CVE-2026-42986</a></td><td><p>Microsoft Graphics Component Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41092">CVE-2026-41092</a></td><td><p>Microsoft Kinect Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45606">CVE-2026-45606</a></td><td><p>Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42980">CVE-2026-42980</a></td><td><p>NT OS Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42916">CVE-2026-42916</a></td><td><p>NT OS Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47289">CVE-2026-47289</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47653">CVE-2026-47653</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47654">CVE-2026-47654</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48563">CVE-2026-48563</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42909">CVE-2026-42909</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42913">CVE-2026-42913</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42992">CVE-2026-42992</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44799">CVE-2026-44799</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44801">CVE-2026-44801</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42985">CVE-2026-42985</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42993">CVE-2026-42993</a></td><td><p>Remote Desktop Client Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45588">CVE-2026-45588</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48568">CVE-2026-48568</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48570">CVE-2026-48570</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48573">CVE-2026-48573</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48575">CVE-2026-48575</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48576">CVE-2026-48576</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48578">CVE-2026-48578</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45654">CVE-2026-45654</a></td><td><p>Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45656">CVE-2026-45656</a></td><td><p>UEFI Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-8863">CVE-2026-8863</a></td><td><p>UEFI Secure Boot Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45648">CVE-2026-45648</a></td><td><p>Windows Active Directory Domain Services Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>8.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42829">CVE-2026-42829</a></td><td><p>Windows Administrator Protection Secure Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-34335">CVE-2026-34335</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45601">CVE-2026-45601</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45598">CVE-2026-45598</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45596">CVE-2026-45596</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45638">CVE-2026-45638</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45603">CVE-2026-45603</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42911">CVE-2026-42911</a></td><td><p>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45594">CVE-2026-45594</a></td><td><p>Windows Application Identity (AppID) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45655">CVE-2026-45655</a></td><td><p>Windows BitLocker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45658">CVE-2026-45658</a></td><td><p>Windows BitLocker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50507">CVE-2026-50507</a></td><td><p>Windows BitLocker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45640">CVE-2026-45640</a></td><td><p>Windows Bluetooth Port Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45605">CVE-2026-45605</a></td><td><p>Windows Bluetooth Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47656">CVE-2026-47656</a></td><td><p>Windows Boot Manager Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.9</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45586">CVE-2026-45586</a></td><td><p>Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44809">CVE-2026-44809</a></td><td><p>Windows Common Log File System Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42987">CVE-2026-42987</a></td><td><p>Windows Deployment Services (WDS) Remote Code Execution</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-33828">CVE-2026-33828</a></td><td><p>Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45634">CVE-2026-45634</a></td><td><p>Windows DHCP Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45608">CVE-2026-45608</a></td><td><p>Windows DHCP Client Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-41108">CVE-2026-41108</a></td><td><p>Windows DNS Client Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42905">CVE-2026-42905</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44811">CVE-2026-44811</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44808">CVE-2026-44808</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44807">CVE-2026-44807</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42983">CVE-2026-42983</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44802">CVE-2026-44802</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44813">CVE-2026-44813</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44804">CVE-2026-44804</a></td><td><p>Windows DWM Core Library Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48566">CVE-2026-48566</a></td><td><p>Windows DWM Core Library Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44814">CVE-2026-44814</a></td><td><p>Windows DWM Core Library Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45602">CVE-2026-45602</a></td><td><p>Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42836">CVE-2026-42836</a></td><td><p>Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44803">CVE-2026-44803</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44812">CVE-2026-44812</a></td><td><p>Windows Graphics Component Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42910">CVE-2026-42910</a></td><td><p>Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42972">CVE-2026-42972</a></td><td><p>Windows Hyper-V Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45607">CVE-2026-45607</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45641">CVE-2026-45641</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47652">CVE-2026-47652</a></td><td><p>Windows Hyper-V Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.2</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45592">CVE-2026-45592</a></td><td><p>Windows Internet (wininet.dll) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42903">CVE-2026-42903</a></td><td><p>Windows Kerberos Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42914">CVE-2026-42914</a></td><td><p>Windows Kerberos Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47288">CVE-2026-47288</a></td><td><p>Windows Kerberos Key Distribution Center (KDC) Remote Code Execution</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48583">CVE-2026-48583</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45653">CVE-2026-45653</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42984">CVE-2026-42984</a></td><td><p>Windows Kernel Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45657">CVE-2026-45657</a></td><td><p>Windows Kernel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45600">CVE-2026-45600</a></td><td><p>Windows Kernel-Mode Driver Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45604">CVE-2026-45604</a></td><td><p>Windows Managed Installer Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45595">CVE-2026-45595</a></td><td><p>Windows Mark of the Web Security Feature Bypass Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.4</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48574">CVE-2026-48574</a></td><td><p>Windows Media Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48565">CVE-2026-48565</a></td><td><p>Windows Narrator Braille Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44805">CVE-2026-44805</a></td><td><p>Windows Network Controller (NC) Host Agent Denial of Service Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45636">CVE-2026-45636</a></td><td><p>Windows NTFS Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50508">CVE-2026-50508</a></td><td><p>Windows NTLM Spoofing Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42981">CVE-2026-42981</a></td><td><p>Windows Performance Monitor Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42974">CVE-2026-42974</a></td><td><p>Windows Performance Monitor Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45487">CVE-2026-45487</a></td><td><p>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42828">CVE-2026-42828</a></td><td><p>Windows Projected File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42837">CVE-2026-42837</a></td><td><p>Windows Projected File System Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42969">CVE-2026-42969</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42971">CVE-2026-42971</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42970">CVE-2026-42970</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42973">CVE-2026-42973</a></td><td><p>Windows Push Notification Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42978">CVE-2026-42978</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42977">CVE-2026-42977</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42979">CVE-2026-42979</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42991">CVE-2026-42991</a></td><td><p>Windows Push Notifications Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45639">CVE-2026-45639</a></td><td><p>Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42908">CVE-2026-42908</a></td><td><p>Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45593">CVE-2026-45593</a></td><td><p>Windows SDK Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42906">CVE-2026-42906</a></td><td><p>Windows Shell Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42907">CVE-2026-42907</a></td><td><p>Windows Shell Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>6.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47648">CVE-2026-47648</a></td><td><p>Windows Storage Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42915">CVE-2026-42915</a></td><td><p>Windows TCP/IP Denial of Service Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.7</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42904">CVE-2026-42904</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42968">CVE-2026-42968</a></td><td><p>Windows Telephony Server Information Disclosure Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>5.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42912">CVE-2026-42912</a></td><td><p>Windows Telephony Service Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45597">CVE-2026-45597</a></td><td><p>Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>7.0</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40409">CVE-2026-40409</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-40404">CVE-2026-40404</a></td><td><p>Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45599">CVE-2026-45599</a></td><td><p>Windows UPnP Device Host Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45635">CVE-2026-45635</a></td><td><p>Windows UPnP Device Host Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>8.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42989">CVE-2026-42989</a></td><td><p>Winlogon Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>7.8</p></td></tr></tbody></table><br><p></p><p></p><h2>Zero-Day Vulnerabilities: Publicly Disclosed (No known exploitation)</h2><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-49160">CVE-2026-49160</a></td><td><p>HTTP.sys Denial of Service Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>7.5</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50507">CVE-2026-50507</a></td><td><p>Windows BitLocker Security Feature Bypass Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>6.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45586">CVE-2026-45586</a></td><td><p>Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>Yes</p></td><td><p>7.8</p></td></tr></tbody></table><h2>Critical RCEs</h2><table><thead><tr><th><p>CVE</p></th><th><p>Title</p></th><th><p>Exploitation status</p></th><th><p>Publicly disclosed?</p></th><th><p>CVSS v3 base score</p></th></tr></thead><tbody><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-10263">CVE-2025-10263</a></td><td><p>ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel]</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.3</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47643">CVE-2026-47643</a></td><td><p>Azure Stack Edge Remote Code Execution Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-44815">CVE-2026-44815</a></td><td><p>DHCP Client Service Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47291">CVE-2026-47291</a></td><td><p>HTTP.sys Remote Code Execution Vulnerability</p></td><td><p>Exploitation More Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-26142">CVE-2026-26142</a></td><td><p>Nuance PowerScribe Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-47281">CVE-2026-47281</a></td><td><p>Visual Studio Code Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45602">CVE-2026-45602</a></td><td><p>Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.1</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45657">CVE-2026-45657</a></td><td><p>Windows Kernel Remote Code Execution Vulnerability</p></td><td><p>Exploitation Less Likely</p></td><td><p>No</p></td><td><p>9.8</p></td></tr><tr><td><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42904">CVE-2026-42904</a></td><td><p>Windows TCP/IP Elevation of Privilege Vulnerability</p></td><td><p>Exploitation Unlikely</p></td><td><p>No</p></td><td><p>9.6</p></td></tr></tbody></table><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Arista unveils 1.6T rack-scale switch family for AI infrastructure]]></title>
<description><![CDATA[Arista Networks has taken the wraps off its 7060XE7 Series, a new portfolio of 1.6T networking platforms designed to provide the foundation for rack-scale AI infrastructure. 



The 7060XE7 family features fixed switch platforms and configurable rack-scale systems, targeting racks for vertical an...]]></description>
<link>https://tsecurity.de/de/3585875/it-security-nachrichten/arista-unveils-16t-rack-scale-switch-family-for-ai-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585875/it-security-nachrichten/arista-unveils-16t-rack-scale-switch-family-for-ai-infrastructure/</guid>
<pubDate>Tue, 09 Jun 2026 21:53:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Arista Networks has taken the wraps off its <a href="https://www.arista.com/en/products/7060xe7-series" target="_blank" rel="noreferrer noopener">7060XE7 Series</a>, a new portfolio of 1.6T networking platforms designed to provide the foundation for rack-scale AI infrastructure. </p>



<p>The 7060XE7 family features fixed switch platforms and configurable rack-scale systems, targeting racks for vertical and horizontal AI workflows. All will run <a href="https://www.networkworld.com/article/4134083/arista-hints-at-in-the-works-telemetry-tools-to-manage-ai-fabrics.html">Arista’s Extensible Operating System</a> (EOS), which includes low-latency and intelligent packet buffering to manage the intense microbursts typical of AI communication and collective patterns, Arista stated. </p>



<p>The 7060XE7 family is built on <a href="https://www.networkworld.com/article/4001239/broadcoms-102-4-tbps-tomahawk-6-targets-million-xpu-ai-clusters.html">Broadcom Tomahawk</a> 6 silicon. Arista is also working with AMD on next-generation compute silicon and NICs to enable scale-out AI fabrics. the company said.</p>



<p>Strategically, the 7060XE7 Series signifies <a href="https://www.networkworld.com/article/4111354/arista-rides-ai-wave-but-battle-for-campus-networks-looms.html">Arista’s transition</a> from offering standalone, high-performance switches to providing rack-scale systems that can handle the extreme density, power, and thermal efficiency AI requires, Arista stated. The platforms allow customers to build scale-up and scale-out AI fabrics using air, liquid and hybrid-cooled technology.</p>



<p>Specific configurations include:</p>



<ul class="wp-block-list">
<li><strong>7060XE7-64PS and 7060XE7-64PRS 4U Rack Switches:</strong> Available in Q4, these air-cooled systems offer support for pluggable Integrated heat sink (IHS) and Riding heat sink (RHS) optics. IHS is aimed at current air-cooled data centers, and RHS would be aimed at future <a href="https://www.networkworld.com/article/4144556/arista-targets-ai-data-centers-with-new-liquid-cooled-pluggable-optic-module.html">liquid‑cooled AI fabrics</a> and extreme port density, Arista stated.</li>



<li><strong>7060XE7-64PRS-RV3-L</strong>: This is a specialized 2OU liquid-cooled platform for high-density clusters, featuring 224G SerDes. This system uses DC power from the ORv3 rack and contains no internal fans, integrating with liquid-cooled XPU servers to maximize power efficiency. It will be available in Q1 2027.</li>



<li><strong>7060XE7-128PE:</strong> Also coming in Q1 2027, these devices provide 128 800G ports in an air-cooled 4RU design, utilizing 100G SerDes, for environments requiring deployment flexibility and backward compatibility.</li>
</ul>



<p>On the software side, EOS is the featured network operating system, but the family also supports open-source software such as Software for Open Networking in the Cloud (SONIC) and OpenSwitch. </p>



<p>One of the portfolio’s key features is the inclusion of full support for Open Compute Project’s Multipath Reliable Connection (MRC). MRC is an RDMA‑based transport protocol that allows a single reliable connection to simultaneously use many network paths over Ethernet.</p>



<p>“MRC is an open protocol where endstation NICs stripe their traffic across multiple links and paths to the receiver, with out of order packets automatically handled,” wrote Arista’s Kenneth Duda, president and CTO, and Alan Judge, distinguished engineer, in a <a href="https://blogs.arista.com/blog/three-genius-ideas-for-ai-fabrics?utm_medium=email&amp;_hsenc=p2ANqtz--WV6LFrLQIOXZHtuGYeEKiuwNfFuJQ9m-MGbQfYkZKH83a2Ipt6bx62xTsOxZmx0DeDEgfQwoZB6ctv378pILXW8A8pFeDYbZ-yk3y2xnwaZAJDUs&amp;_hsmi=422934827&amp;utm_content=422934827&amp;utm_source=hs_email">blog</a> about the technology. “MRC responds to network congestion signals (ECN and packet trimming), shifting load to the best-performing paths, and avoiding links and paths that can’t actually reach the destination altogether.”</p>



<p>MRC monitors each path, steering around congestion, avoiding paths with link errors, and avoiding failed links, the authors stated. “We’ve proven in production that this approach achieves very high fabric utilization with good load balancing, while interoperating seamlessly with scale-across and WAN networks utilizing standard dynamic routing protocols,” Duda and Judge wrote.</p>



<p>The software also supports load balancing, congestion management, telemetry and diagnostics, and other technologies that will be core to AI networking, Arista stated.</p>



<p>The new Arista family joins a growing ecosystem of vendors looking to tap into the <a href="https://www.naddod.com/ai-insights/why-1-6t-networking-is-becoming-the-core-of-next-generation-ai-clusters?srsltid=AfmBOoqj9QMeYLmDLWs2APuF2t3EpzTOlhSV7l0PPdbSbyDCm0ECuEo5">1.6T Ethernet</a> world, which includes <a href="https://www.networkworld.com/article/4130263/cisco-amps-up-silicon-one-line-delivers-new-systems-and-optics-for-ai-networking.html">Cisco</a>, <a href="https://www.networkworld.com/article/4080459/nvidia-looks-to-power-ai-factory-networks.html">Nvidia</a>, Celestica and others.</p>



<p>“Arista Network’s new 7060XE7 Series is a strong signal of where large-scale AI fabrics are heading: higher bandwidth, better power efficiency, and tighter integration between compute, optics, silicon, cooling, and network operating software,” wrote <a href="https://www.linkedin.com/in/samehboujelbene/">Sameh Boujelbene</a>, vice president, data center switch and AI networks market research for Dell Oro, in a <a href="https://www.linkedin.com/posts/samehboujelbene_arista-networks-is-excited-to-announce-the-activity-7470170955978534912-t5xu?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAIU6MwBFxiRF-TyMhFw863yphjSyKaHiqc">LinkedIn post</a>. Among the features that stand out to her are “strong customer and ecosystem validation from Microsoft Azure, Oracle Cloud Infrastructure, Meta, AMD, and Broadcom.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45644 | Microsoft Live Share Canvas SDK prior 1.4.2 cross site scripting]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Microsoft Live Share Canvas SDK. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is listed as CVE-2026-45644. The attack may be performed from remote. There is no a...]]></description>
<link>https://tsecurity.de/de/3585655/sicherheitsluecken/cve-2026-45644-microsoft-live-share-canvas-sdk-prior-142-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585655/sicherheitsluecken/cve-2026-45644-microsoft-live-share-canvas-sdk-prior-142-cross-site-scripting/</guid>
<pubDate>Tue, 09 Jun 2026 20:40:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/microsoft:live_share_canvas_sdk">Microsoft Live Share Canvas SDK</a>. The impacted element is an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-45644">CVE-2026-45644</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Collective Cyber Resilience in Supply Chains]]></title>
<description><![CDATA[Author: natoccdcoe - Bewertung: 1x - Views:1 CyCon 2026 | How can allies build cyber resilience across supply chains when critical dependencies span across borders, sectors, and organisations of various sizes? This panel builds on the perspectives offered by featured CyCon research papers, couple...]]></description>
<link>https://tsecurity.de/de/3585606/it-security-video/collective-cyber-resilience-in-supply-chains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585606/it-security-video/collective-cyber-resilience-in-supply-chains/</guid>
<pubDate>Tue, 09 Jun 2026 20:33:31 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: natoccdcoe - Bewertung: 1x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/p8LUBtfMSjA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>CyCon 2026 | How can allies build cyber resilience across supply chains when critical dependencies span across borders, sectors, and organisations of various sizes? This panel builds on the perspectives offered by featured CyCon research papers, coupled with panellists that will expand the discussion to consider how joint exercises, policy alignment, operational frameworks, and trusted partnerships can improve readiness, situational awareness, and resilience across allied and critical supply networks. Together, these contributions highlight both the policy and operational dimensions of collective resilience: from jurisdictional gaps, vendor dependency, and alliance coordination, to public-private partnerships, preparedness campaigns, and the role of smaller suppliers in national and allied security.<br />
<br />
Speakers:<br />
Mr. Ben Hiller, Head, Cyber Strategy and Policy Section, NATO <br />
Mr. Erlend Andreas Gjære, Co-founder, Secure Practice <br />
Maxim Kovalsky, Managing Director, Consortium Networks <br />
Mrs Manisha Parmar, Head, NCSC Transformation Branch, NATO Cyber Security Centre <br />
Mr. Jason Blais, VP Program Management, Mattermost <br />
<br />
#CCDCOE #CyCon2026<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Security Update Review]]></title>
<description><![CDATA[I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a ...]]></description>
<link>https://tsecurity.de/de/3585580/it-security-nachrichten/the-june-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585580/it-security-nachrichten/the-june-2026-security-update-review/</guid>
<pubDate>Tue, 09 Jun 2026 20:20:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our <a href="https://www.youtube.com/playlist?list=PLeFSM_a8Jri75_5-NpydcFneOaTvr3vJE">YouTube</a> channel. It should be posted within a couple of hours after the release.</p><p class=""><strong>Adobe Patches for June 2026</strong></p><p class="">For May, June released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank">APSB26-66</a></td>
    <td>Adobe Campaign Classic</td>
    <td>2</td>
    <td>Critical</td>
    <td>10.0</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank">APSB26-64</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank">APSB26-63</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>20</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank">APSB26-57</a></td>
    <td>Adobe Experience Manager Forms</td>
    <td>3</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html" target="_blank">APSB26-62</a></td>
    <td>Adobe Dreamweaver</td>
    <td>5</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html" target="_blank">APSB26-65</a></td>
    <td>Adobe Format Plugins</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-59.html" target="_blank">APSB26-59</a></td>
    <td>Adobe InCopy</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank">APSB26-58</a></td>
    <td>Adobe InDesign</td>
    <td>12</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html" target="_blank">APSB26-60</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html" target="_blank">APSB26-61</a></td>
    <td>Content Credentials SDK</td>
    <td>8</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html" target="_blank">APSB26-56</a></td>
    <td>Adobe Experience Manager</td>
    <td>57</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>11 bulletins</td>
    <td>123</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  




  <p class="">Obviously, the update for Campaign Classic should be on the top of your deployment list if you’re a user. A CVSS 10 is rare; two in the same bulletin is pretty much a unicorn. Adobe says there are no active attacks, but I would expect heavy research into creating one. The update for Coldfusion is also a Priority 1, but again, no known attacks is the wild. I suspect the Reader patch will also receive a lot of attention as malicious PDFs are common in ransomware attacks. The update for Experience Manager may be large, but it’s mostly just cross-site scripting (XSS) bugs.</p><p class=""><strong>Microsoft Patches for June 2026</strong></p><p class="">This month, Microsoft released a new record 208 CVEs Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Secure Boot, and BitLocker. At least, that’s my count. Microsoft’s tools seem to be having some issues, as they initially included a CVE from 2020 in this release. Regardless, the count is over 200, and I counted several times.</p><p class="">One of these bugs came through the ZDI program, but bugs submitted during Pwn2Own Berlin remain unpatched. If you include the Chromium and other third-party bugs, the total CVE count for June comes to a staggering 571 CVEs. 38 of these cases are rated Critical while the rest are rated Important in severity.</p><p class="">I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time. The previous record was 177 set last year. It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns. How many of these cases were found using AI tools? How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal? The last two months were also large releases. Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future. BTW – just a note – the current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.</p><p class="">One of the bugs patched by Microsoft this month is listed as under active exploitation and three others are listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the bug being exploited in the wild.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><strong>CVE-2026-41091</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged, which indicates multiple parties say this is in the wild, meaning exploitation is likely significant. The good news is that most people won’t need to take action as Defender updates itself. However, if you don’t have this configured or are in an isolated environment, you’ll need to update to the latest version.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><strong>CVE-2026-45657</strong></a><strong> - Windows Kernel Remote Code Execution Vulnerability<br></strong>This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><strong>CVE-2026-47291</strong></a><strong> - HTTP.sys Remote Code Execution Vulnerability<br></strong>Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><strong>CVE-2026-44815</strong></a><strong> - DHCP Client Service Remote Code Execution Vulnerability<br></strong>Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><strong>CVE-2026-45585</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><strong>CVE-2026-50507</strong></a><strong> - Windows BitLocker Security Feature Bypass Vulnerability<br></strong>If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “<a href="https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085">bone shattering</a>” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.</p><p class=""> Here’s the full list of CVEs released by Microsoft for June 2026:</p>





















  
  




  
    





<link rel="File-List" href="new2026-Jun-cvrf.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="1024">
 <col width="144">
 <col width="256">
 <col width="104" span="6">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">XI</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a></td>
  <td width="256" class="xl68">Microsoft Defender
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl71">Yes</td>
  <td class="xl70">0</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a></td>
  <td width="256" class="xl68">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><span>CVE-2026-50507</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586"><span>CVE-2026-45586</span></a></td>
  <td width="256" class="xl68">Windows Collaborative
  Translation Framework (CTFMON) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="91">
  <td class="xl67" height="91"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10263"><span>CVE-2025-10263 *</span></a></td>
  <td width="256" class="xl68">ARM: CVE-2025-10263
  Completion of affected memory accesses might not be guaranteed by completion
  of a TLBI [kernel]</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567"><span>CVE-2026-48567</span></a></td>
  <td width="256" class="xl68">Azure HorizonDB<span>  </span>Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">10</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32193"><span>CVE-2026-32193</span></a></td>
  <td width="256" class="xl68">Azure Kubernetes
  Service (AKS) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644"><span>CVE-2026-47644</span></a></td>
  <td width="256" class="xl68">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><span>CVE-2026-44815</span></a></td>
  <td width="256" class="xl68">DHCP Client Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><span>CVE-2026-47291</span></a></td>
  <td width="256" class="xl68">HTTP.sys Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824"><span>CVE-2026-42824</span></a></td>
  <td width="256" class="xl68">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476"><span>CVE-2026-45476</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Network Adapter Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810"><span>CVE-2026-44810</span></a></td>
  <td width="256" class="xl68">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579"><span>CVE-2026-48579</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Online Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47655"><span>CVE-2026-47655</span></a></td>
  <td width="256" class="xl68">Microsoft Graph
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497"><span>CVE-2026-45497</span></a></td>
  <td width="256" class="xl68">Microsoft M365 Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45460"><span>CVE-2026-45460</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">4.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472"><span>CVE-2026-45472</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474"><span>CVE-2026-45474</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461"><span>CVE-2026-45461</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463"><span>CVE-2026-45463</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456"><span>CVE-2026-45456</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458"><span>CVE-2026-45458</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635"><span>CVE-2026-47635</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26142"><span>CVE-2026-26142</span></a></td>
  <td width="256" class="xl68">Nuance PowerScribe
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289"><span>CVE-2026-47289</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47654"><span>CVE-2026-47654</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48563"><span>CVE-2026-48563</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42992"><span>CVE-2026-42992</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44799"><span>CVE-2026-44799</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44801"><span>CVE-2026-44801</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985"><span>CVE-2026-42985</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648"><span>CVE-2026-45648</span></a></td>
  <td width="256" class="xl68">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987"><span>CVE-2026-42987</span></a></td>
  <td width="256" class="xl68">Windows Deployment
  Services (WDS) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828"><span>CVE-2026-33828</span></a></td>
  <td width="256" class="xl68">Windows Device Health
  Attestation (DHA) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803"><span>CVE-2026-44803</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812"><span>CVE-2026-44812</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607"><span>CVE-2026-45607</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641"><span>CVE-2026-45641</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652"><span>CVE-2026-47652</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288"><span>CVE-2026-47288</span></a></td>
  <td width="256" class="xl68">Windows Kerberos Key
  Distribution Center (KDC) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><span>CVE-2026-45657</span></a></td>
  <td width="256" class="xl68">Windows Kernel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48574"><span>CVE-2026-48574</span></a></td>
  <td width="256" class="xl68">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"><span>CVE-2026-45490</span></a></td>
  <td width="256" class="xl68">.NET SDK Elevation of
  Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491"><span>CVE-2026-45491</span></a></td>
  <td width="256" class="xl68">.NET Tampering
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591"><span>CVE-2026-45591</span></a></td>
  <td width="256" class="xl68">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47643"><span>CVE-2026-47643</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41098"><span>CVE-2026-41098</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642"><span>CVE-2026-45642</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Attestation service and Device Health Attestation Service Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45650"><span>CVE-2026-45650</span></a></td>
  <td width="256" class="xl68">Microsoft Bing Search
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45637"><span>CVE-2026-45637</span></a></td>
  <td width="256" class="xl68">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45647"><span>CVE-2026-45647</span></a></td>
  <td width="256" class="xl68">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371"><span>CVE-2026-40371</span></a></td>
  <td width="256" class="xl68">Microsoft Dynamics 365
  (on-premises) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44822"><span>CVE-2026-44822</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45455"><span>CVE-2026-45455</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45469"><span>CVE-2026-45469</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44817"><span>CVE-2026-44817</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44818"><span>CVE-2026-44818</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44820"><span>CVE-2026-44820</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44823"><span>CVE-2026-44823</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45459"><span>CVE-2026-45459</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504"><span>CVE-2026-45504</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45502"><span>CVE-2026-45502</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503"><span>CVE-2026-45503</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583"><span>CVE-2026-45583</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45500"><span>CVE-2026-45500</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45501"><span>CVE-2026-45501</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631"><span>CVE-2026-47631</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42986"><span>CVE-2026-42986</span></a></td>
  <td width="256" class="xl68">Microsoft Graphics
  Component Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41092"><span>CVE-2026-41092</span></a></td>
  <td width="256" class="xl68">Microsoft Kinect
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45644"><span>CVE-2026-45644</span></a></td>
  <td width="256" class="xl68">Microsoft Live Share
  Canvas SDK Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47293"><span>CVE-2026-47293</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45485"><span>CVE-2026-45485</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44821"><span>CVE-2026-44821</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45483"><span>CVE-2026-45483</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Project Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45475"><span>CVE-2026-45475</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44819"><span>CVE-2026-44819</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44824"><span>CVE-2026-44824</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45645"><span>CVE-2026-45645</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49161"><span>CVE-2026-49161</span></a></td>
  <td width="256" class="xl68">Microsoft PC Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a></td>
  <td width="256" class="xl68">Microsoft PowerToys
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45484"><span>CVE-2026-45484</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45454"><span>CVE-2026-45454</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298"><span>CVE-2026-47298</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45467"><span>CVE-2026-45467</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45468"><span>CVE-2026-45468</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45479"><span>CVE-2026-45479</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45453"><span>CVE-2026-45453</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636"><span>CVE-2026-47636</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47637"><span>CVE-2026-47637</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47638"><span>CVE-2026-47638</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47639"><span>CVE-2026-47639</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47641"><span>CVE-2026-47641</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33113"><span>CVE-2026-33113</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45462"><span>CVE-2026-45462</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45464"><span>CVE-2026-45464</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45465"><span>CVE-2026-45465</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47634"><span>CVE-2026-47634</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47640"><span>CVE-2026-47640</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45481"><span>CVE-2026-45481</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48560"><span>CVE-2026-48560</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48562"><span>CVE-2026-48562</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835"><span>CVE-2026-42835</span></a></td>
  <td width="256" class="xl68">Microsoft Teams for
  Android Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45606"><span>CVE-2026-45606</span></a></td>
  <td width="256" class="xl68">Microsoft UxTheme
  Library (uxtheme.dll) Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482"><span>CVE-2026-45482</span></a></td>
  <td width="256" class="xl68">Microsoft Visual
  Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466"><span>CVE-2026-45466</span></a></td>
  <td width="256" class="xl68">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45471"><span>CVE-2026-45471</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45486"><span>CVE-2026-45486</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45643"><span>CVE-2026-45643</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45457"><span>CVE-2026-45457</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980"><span>CVE-2026-42980</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42916"><span>CVE-2026-42916</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45649"><span>CVE-2026-45649</span></a></td>
  <td width="256" class="xl68">Office for Android
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47653"><span>CVE-2026-47653</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42909"><span>CVE-2026-42909</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42913"><span>CVE-2026-42913</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42993"><span>CVE-2026-42993</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45588"><span>CVE-2026-45588</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48568"><span>CVE-2026-48568</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48570"><span>CVE-2026-48570</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48573"><span>CVE-2026-48573</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48575"><span>CVE-2026-48575</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48576"><span>CVE-2026-48576</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48578"><span>CVE-2026-48578</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45654"><span>CVE-2026-45654</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45656"><span>CVE-2026-45656</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863"><span>CVE-2026-8863</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376"><span>CVE-2026-40376</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281"><span>CVE-2026-47281</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284"><span>CVE-2026-47284</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292"><span>CVE-2026-47292</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  MSSQL Extension Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569"><span>CVE-2026-48569</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287"><span>CVE-2026-47287</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42829"><span>CVE-2026-42829</span></a></td>
  <td width="256" class="xl68">Windows Administrator
  Protection Secure Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70"></td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34335"><span>CVE-2026-34335</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45601"><span>CVE-2026-45601</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45598"><span>CVE-2026-45598</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45596"><span>CVE-2026-45596</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45638"><span>CVE-2026-45638</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45603"><span>CVE-2026-45603</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42911"><span>CVE-2026-42911</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45594"><span>CVE-2026-45594</span></a></td>
  <td width="256" class="xl68">Windows Application
  Identity (AppID) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45655"><span>CVE-2026-45655</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45658"><span>CVE-2026-45658</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45640"><span>CVE-2026-45640</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth Port
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45605"><span>CVE-2026-45605</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47656"><span>CVE-2026-47656</span></a></td>
  <td width="256" class="xl68">Windows Boot Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44809"><span>CVE-2026-44809</span></a></td>
  <td width="256" class="xl68">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45634"><span>CVE-2026-45634</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45608"><span>CVE-2026-45608</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41108"><span>CVE-2026-41108</span></a></td>
  <td width="256" class="xl68">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42905"><span>CVE-2026-42905</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44811"><span>CVE-2026-44811</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44808"><span>CVE-2026-44808</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44807"><span>CVE-2026-44807</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42983"><span>CVE-2026-42983</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44802"><span>CVE-2026-44802</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44813"><span>CVE-2026-44813</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44804"><span>CVE-2026-44804</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566"><span>CVE-2026-48566</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44814"><span>CVE-2026-44814</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602"><span>CVE-2026-45602</span></a></td>
  <td width="256" class="xl68">Windows Dynamic Host
  Configuration Protocol (DHCP) Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42836"><span>CVE-2026-42836</span></a></td>
  <td width="256" class="xl68">Windows Function
  Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42910"><span>CVE-2026-42910</span></a></td>
  <td width="256" class="xl68">Windows Hotpatch
  Monitoring Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42972"><span>CVE-2026-42972</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45592"><span>CVE-2026-45592</span></a></td>
  <td width="256" class="xl68">Windows Internet
  (wininet.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42903"><span>CVE-2026-42903</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42914"><span>CVE-2026-42914</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48583"><span>CVE-2026-48583</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45653"><span>CVE-2026-45653</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42984"><span>CVE-2026-42984</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45600"><span>CVE-2026-45600</span></a></td>
  <td width="256" class="xl68">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45604"><span>CVE-2026-45604</span></a></td>
  <td width="256" class="xl68">Windows Managed
  Installer Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45595"><span>CVE-2026-45595</span></a></td>
  <td width="256" class="xl68">Windows Mark of the
  Web Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45636"><span>CVE-2026-45636</span></a></td>
  <td width="256" class="xl68">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508"><span>CVE-2026-50508</span></a></td>
  <td width="256" class="xl68">Windows NTLM Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48565"><span>CVE-2026-48565</span></a></td>
  <td width="256" class="xl68">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44805"><span>CVE-2026-44805</span></a></td>
  <td width="256" class="xl68">Windows Network
  Controller (NC) Host Agent Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42981"><span>CVE-2026-42981</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42974"><span>CVE-2026-42974</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45487"><span>CVE-2026-45487</span></a></td>
  <td width="256" class="xl68">Windows Program
  Compatibility Assistant Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828"><span>CVE-2026-42828</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42837"><span>CVE-2026-42837</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42969"><span>CVE-2026-42969</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42971"><span>CVE-2026-42971</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42970"><span>CVE-2026-42970</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42973"><span>CVE-2026-42973</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978"><span>CVE-2026-42978</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977"><span>CVE-2026-42977</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42979"><span>CVE-2026-42979</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42991"><span>CVE-2026-42991</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45639"><span>CVE-2026-45639</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42908"><span>CVE-2026-42908</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45593"><span>CVE-2026-45593</span></a></td>
  <td width="256" class="xl68">Windows SDK Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42906"><span>CVE-2026-42906</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42907"><span>CVE-2026-42907</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47648"><span>CVE-2026-47648</span></a></td>
  <td width="256" class="xl68">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915"><span>CVE-2026-42915</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904"><span>CVE-2026-42904</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42968"><span>CVE-2026-42968</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912"><span>CVE-2026-42912</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45597"><span>CVE-2026-45597</span></a></td>
  <td width="256" class="xl68">Windows UI Automation
  Manager (uiamanager.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45599"><span>CVE-2026-45599</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45635"><span>CVE-2026-45635</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40409"><span>CVE-2026-40409</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40404"><span>CVE-2026-40404</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42989"><span>CVE-2026-42989</span></a></td>
  <td width="256" class="xl68">Winlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  




  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this release, the scariest-looking one is actually nothing to concern yourself with at all. The CVSS 10 bug in Azure HorizonDB has already been addressed by Microsoft and is just being documented now. That’s also the case for five others. Of course, there wouldn’t be a release without Office bugs that have the Preview Pane as an attack vector. There are multiple in June. There’s a handful of bugs in the Remote Desktop Client, but these rely on connecting to a malicious RDP server. There are three patches for Hyper-V that allow for guest-to-host code execution. The bug in Active Directory requires authentication, but any authenticated user can hit it. For the Windows Directory Service vulnerability, it needs to be listening for TFTP. You have blocked that everywhere, right? The bug in Azure Network Adapter is somewhat unique as you need to update your Linux kernel to be protected. The bug in Azure Kubernetes allows an attacker to break out of a container and gain control of the AKS worker node. Finally, the bug in the Kerberos Key Distribution Center (KDC) seems unlikely, but if exploited, it could allow authenticated attackers to get code execution on affected systems.</p><p class="">Moving on to the other code execution bugs, there are the ubiquitous open-an-own bugs in Office components like Excel and Word. The code injection bug in Exchange Server looks troubling, but it requires a machine-in-the-middle (MiTM), so exploitation is unlikely. The bugs in SharePoint require authentication, but you should note that the patch applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. The two bugs in UPnP are interesting. Both can lead to code execution by causing an error during the handling of specially crafted data, which could lead to a Use After Free (UAF) bug. The bugs in RDP Client all require connecting to a malicious RDP server, but it’s not clear why some are rated Critical and some are rated Important. The NTFS vulnerability requires a user to mount a virtual hard drive on an affected system. The last RCE bug this month is in Azure Stack Edge and requires the attacker to send a specially crafted file upload request that includes a manipulated file name or path, leading to code execution.</p><p class="">There are more than 60 Elevation of Privilege (EoP) bugs in this month’s release, and as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. A notable exception is in Exchange Server, where a user on Outlook Web Access (OWA) could gain access to other mailboxes. The bug in Visual Studio Code could allow attackers to gain permissions associated with the MCP Server’s managed identity. The bugs in Windows SDK and Windows UI Automation Manager could let attacker go from low integrity up to medium integrity code execution. The bug in Bluetooth just allows “elevated” privileges without really describing what elevated might be. </p><p class="">Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls. </p><p class="">Turning our attention to the mass of spoofing bugs in the release, we instantly see 18 impacting SharePoint Server. Fortunately, these are simply cross-site scripting (XSS) bugs. It’s the Exchange bugs we should really watch for. One is an XSS that an attacker can exploit by convincing an Exchange administrator to open a malicious link or message, which then runs code in the admin's web session. That's a meaningful privilege escalation path. Another is listed as an SSRF-based attack, but no other details are available. The last is a lower-impact XSS with limited confidentiality/integrity loss. The bug in Bing Search (remember Bing?) is a classic search result spoofing. The bug in Azure Stack Edge is interesting as it could allow access to resources outside the vulnerable component's security boundary. The bug in Office for Android requires user interaction. The Office Project Server bug is an authenticated XSS with low impact. The final spoofing bug is in Azure Attestation but has already been addressed. You should still verify you are protected by following the instructions in the write-up from Microsoft.</p><p class="">There are 30 different information disclosure bugs in this release, and fortunately, the vast majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The two bugs in Visual Studio require user interaction and could “disclose information over a network.” How obtuse. The bug in GitHub Copilot and Visual Studio Code could disclose discloses a sign-in access token for a user's work account. That's a meaningful credential exposure, not just random memory. That leaves the two bugs in Exchange Server. One could allow an authenticated user to gain information about which network services that the Exchange server can reach. The other sounds much like the spoofing bug in OWA as it allows attackers to see information in mailboxes they should not have access to.</p><p class="">I’ve never been a fan of the “tampering” category, as it could mean so many different things. For example, the bug in .NET simply says it could allow an unauthorized attacker to perform tampering locally. Similarly, the bug in Visual Studio says the same, expect here the tampering occurs over a network. Microsoft doesn’t even bother with a CWE for the tampering bug in the DHCP Server, so your guess is as good as mine.</p><p class="">There are seven DoS bugs in the June release, and as usual, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting is the bug in HTTP.sys, which is listed as publicly known. This is an uncontrolled resource consumption, rated "Exploitation More Likely," and publicly disclosed. Since, HTTP.sys sits at the core of IIS and Windows web services, a network-accessible DoS here can take down any Windows server running HTTP-based services. Based on the Acknowledgement, it looks like this bug may have been found using AI. There are no real details for the other bugs, but based simply on the impact, I would focus on the Kerberos and TCP/IP bugs if you had to prioritize.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on July 14 and will be the last one before Black Hat/DEFCON. It’s usually a big release, so strap in and hang on. I’ll be back then to give you my full thoughts. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p><p class=""> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stability Under Strain: Legal Response in a Contested Cyberspace]]></title>
<description><![CDATA[Author: natoccdcoe - Bewertung: 0x - Views:0 CyCon 2026 | When a cyber operation disrupts hospitals, elections, financial systems or undersea cables, the consequences rarely stop at one border. In an interconnected digital environment, harm to one State can ripple outward, raising questions about...]]></description>
<link>https://tsecurity.de/de/3585355/it-security-video/stability-under-strain-legal-response-in-a-contested-cyberspace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585355/it-security-video/stability-under-strain-legal-response-in-a-contested-cyberspace/</guid>
<pubDate>Tue, 09 Jun 2026 19:33:13 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: natoccdcoe - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/JTLR3xjfs6E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>CyCon 2026 | When a cyber operation disrupts hospitals, elections, financial systems or undersea cables, the consequences rarely stop at one border. In an interconnected digital environment, harm to one State can ripple outward, raising questions about shared stability and collective protection.  This panel explores how international law responds when cyber operations implicate interests that transcend purely bilateral disputes. It examines the architecture of State responsibility in cyberspace, including attribution, due diligence, and the legal consequences of internationally wrongful acts. Particular focus is placed on lawful responses below the threshold of force: countermeasures, coordinated and collective countermeasures, sanctions, cyber defensive actions, and other forms of diplomatic and economic pressure. What are the legal limits of solidarity in responding to malicious cyber activity? Can multiple States act together to uphold shared digital stability without escalating conflict?  Bringing doctrine into conversation with evolving State practice, the panel probes whether existing legal tools are robust enough for today’s contested cyberspace.<br />
<br />
Speakers: <br />
Karen De Vos, PhD candidate, Institute for International Law, KU Leuven & Leuven Centre for Global Governance studies <br />
Dr. René Värk, Head of International Law Division, Estonian Ministry of Foreign Affairs <br />
Ms. Jimena Sofia Viveros, Founder and CEO, IQuilibriumAI <br />
Dr. Joanna Kulesza, Assistant Professor of International Law, University of Lodz <br />
Mr Robert Young, Deputy Director of Criminal, Security and Diplomatic Law Division, Global Affairs Canada<br />
<br />
#CCDCOE #cycon2026<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protecting Environmental Rights Defenders Is Key to Giving Communities a Voice]]></title>
<description><![CDATA[Environmental human rights defenders must be empowered to design and implement their own forms of collective protection to shift the power imbalance.
The post Protecting Environmental Rights Defenders Is Key to Giving Communities a Voice appeared first on Just Security.]]></description>
<link>https://tsecurity.de/de/3584710/it-security-nachrichten/protecting-environmental-rights-defenders-is-key-to-giving-communities-a-voice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584710/it-security-nachrichten/protecting-environmental-rights-defenders-is-key-to-giving-communities-a-voice/</guid>
<pubDate>Tue, 09 Jun 2026 15:39:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Environmental human rights defenders must be empowered to design and implement their own forms of collective protection to shift the power imbalance.</p>
<p>The post <a href="https://www.justsecurity.org/141453/protecting-environmental-rights-defenders/">Protecting Environmental Rights Defenders Is Key to Giving Communities a Voice</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why hackers hit canvas during finals week]]></title>
<description><![CDATA[The Canvas attack reveals a threat actor's strategy, and why it works.]]></description>
<link>https://tsecurity.de/de/3584187/it-nachrichten/why-hackers-hit-canvas-during-finals-week/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584187/it-nachrichten/why-hackers-hit-canvas-during-finals-week/</guid>
<pubDate>Tue, 09 Jun 2026 12:46:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Canvas attack reveals a threat actor's strategy, and why it works.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kuwait and Oman Sign Cybersecurity Pact to Counter Rising Digital Threats]]></title>
<description><![CDATA[As digital transformation accelerates across the Gulf region, Kuwait and Oman have taken a significant step toward strengthening their collective cybersecurity capabilities. The two countries recently signed a Memorandum of Understanding (MoU) designed to enhance bilateral cooperation in cybersec...]]></description>
<link>https://tsecurity.de/de/3583712/it-security-nachrichten/kuwait-and-oman-sign-cybersecurity-pact-to-counter-rising-digital-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583712/it-security-nachrichten/kuwait-and-oman-sign-cybersecurity-pact-to-counter-rising-digital-threats/</guid>
<pubDate>Tue, 09 Jun 2026 09:21:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1101" height="614" src="https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Kuwait and Oman" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman.webp 1101w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-750x418.webp 750w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman.webp 1101w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/Kuwait-and-Oman-750x418.webp 750w" sizes="(max-width: 1101px) 100vw, 1101px" title="Kuwait and Oman Sign Cybersecurity Pact to Counter Rising Digital Threats 1"></p><span data-contrast="auto">As digital transformation accelerates across the Gulf region, Kuwait and Oman have taken a significant step toward strengthening their collective cybersecurity capabilities. The two countries recently signed a Memorandum of Understanding (MoU) designed to enhance bilateral cooperation in cybersecurity and improve their ability to address sophisticated digital threats.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The agreement reflects a growing recognition that <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28637">cybersecurity</a> has become a critical component of national security. With government services, public institutions, and essential infrastructure becoming more dependent on digital technologies, Kuwait and Oman are seeking to strengthen their defenses against emerging cyber risks while ensuring the security of sensitive government <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28636">data</a> and digital systems.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Key Areas Covered Under the Kuwait and Oman Cybersecurity MoU</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The <a href="https://www.voiceofemirates.com/en/news/2026/06/09/kuwait-and-oman-sign-strategic-agreement-to-strengthen-cybersecurity-cooperation/#google_vignette" target="_blank" rel="nofollow noopener">cybersecurity MoU</a> between Kuwait and Oman outlines several areas of cooperation aimed at boosting digital resilience and preparedness in both countries.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">One of the primary focuses of the agreement is the exchange of technical expertise. Through dedicated communication channels, both nations will share information related to newly identified <a href="https://thecyberexpress.com/cbse-osm-vulnerability/" target="_blank" rel="noopener">vulnerabilities</a>, cyber threats, and emerging attack methods. This information-sharing framework is expected to improve situational awareness and enable faster responses to evolving <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28639">cybersecurity</a> challenges.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The MoU also emphasizes joint training initiatives. Kuwait and Oman plan to launch advanced training programs designed to develop highly skilled national professionals specializing in cybersecurity <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28638">incident response</a>. By strengthening local expertise, both countries aim to improve their readiness to manage and mitigate <a href="https://thecyberexpress.com/cybersecurity-incidents-prosper-700credit/" target="_blank" rel="noopener">cyber incidents</a> effectively.</span>

<span data-contrast="auto">In addition, the agreement promotes greater field coordination between relevant authorities. Enhanced coordination will help improve the ability of both nations to respond to advanced cyberattacks, particularly those targeting critical sectors and essential infrastructure. </span>
<h3 aria-level="2"><b><span data-contrast="none">A Shared Vision for a Secure Digital Future</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Officials from Kuwait and Oman have described the MoU as a reflection of their shared commitment to building what they referred to as a “digital fortress” capable of protecting national assets and strategic resources.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The agreement comes at a time when government institutions are expanding the use of electronic services and cloud computing technologies. In this environment, cybersecurity is no longer viewed as an optional technical consideration. Instead, it has become a foundational requirement for ensuring business continuity, safeguarding <a href="https://thecyberexpress.com/situsamc-data-breach/" target="_blank" rel="noopener">sensitive information</a>, and protecting citizen privacy.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The cybersecurity partnership demonstrates how Kuwait and Oman are aligning their efforts to address common digital security concerns while preparing for future technological developments. By working together, both countries aim to establish stronger protective measures against <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28640">cyber</a> threats that transcend national borders.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Expanding Cooperation Beyond Cyber Defense</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Beyond immediate security objectives, the MoU is expected to create opportunities for broader technological collaboration between Kuwait and Oman. Officials noted that the agreement represents an advancement in bilateral relations and could serve as a foundation for future initiatives in emerging areas of cybersecurity innovation.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">Potential areas of cooperation include the development of advanced encryption technologies, the integration of artificial intelligence into cyber defense systems, and the creation of unified security standards. Such initiatives could contribute to stronger regional cybersecurity frameworks and support the shared interests of Gulf Cooperation Council (GCC) member states.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The agreement therefore extends beyond traditional cyber protection measures, positioning Kuwait and Oman to explore innovative solutions that address the evolving nature of <a href="https://thecyberexpress.com/ai-powered-bots-create-governance-challenges/" target="_blank" rel="noopener">digital threats</a> while supporting long-term technological growth.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI’s Lockdown Mode is trying to solve the problem that it created]]></title>
<description><![CDATA[OpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of enterprises using mul...]]></description>
<link>https://tsecurity.de/de/3583455/it-security-nachrichten/openais-lockdown-mode-is-trying-to-solve-the-problem-that-it-created/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583455/it-security-nachrichten/openais-lockdown-mode-is-trying-to-solve-the-problem-that-it-created/</guid>
<pubDate>Tue, 09 Jun 2026 06:07:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of enterprises using multiple AI vendors for their agentic models further complicates an already dicey governance strategy.</p>



<p>When activated within OpenAI products’ settings, Lockdown Mode limits web browsing to cached content, limits image support, disables Deep Research and Agent Mode, denies users the ability to approve Canvas-generated code to access the network, and prevents ChatGPT from downloading files for data analysis, though it can still operate on manually uploaded files, <a href="https://help.openai.com/en/articles/20001061-lockdown-mode" target="_blank" rel="noreferrer noopener">OpenAI said in a blog post</a>. The company did not respond to a request for comment.</p>



<p>That post included a frequently-asked-questions section in which <a href="https://www.csoonline.com/article/4181294/openai-responds-to-white-house-executive-order-on-ai-governance.html" target="_blank">OpenAI</a> wrote its own questions. and then answered them. One notably asked “Is prompt injection a major risk?” with the response, “Prompt injection is not currently a major risk, but its impact could grow as attackers develop more sophisticated methods.”</p>



<p>Consultants found that sentence baffling.</p>



<p>“OpenAI’s own posture is telling. It calls prompt injection a frontier research problem, hard enough to warrant a containment mode, while saying in the same breath that it is not currently a major risk,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “A vendor does not build a panic room for a house it believes is safe. Lockdown Mode is the admission itself.”</p>



<p>And the risk of AI-enabled data exfiltration was illustrated recently when <a href="https://www.documentcloud.org/documents/28202858-meta-ai-ag-maine/" target="_blank" rel="noreferrer noopener">some Instagram users’ personal data was stolen</a> after Meta had turned over control of password changes for accounts to an AI agent. </p>



<h2 class="wp-block-heading">Still allows some exfiltration</h2>



<p>Gogia added that the Lockdown Mode is porous, as it will still allow some data exfiltration; he called the OpenAI effort “a model carrying a trusted user’s authority while acting on instructions hidden in untrusted content. Data can leave by a side door rather than be announced in the chat.”</p>



<p><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, also questioned whether OpenAI could block all of what it claims it can block. “It is yet to be seen whether [Lockdown Mode] can be breached or not. Is it Nirvana? Probably not, but this is likely the best they could have done, given the infrastructure they have today.”</p>



<p>An executive with a major agentic cybersecurity firm, who asked to be not named, agreed with Findling: Lockdown Mode “is not going to be validated until someone tries breaking it. Almost every sandboxing solution out there, AI has been able to break out of,” he said.</p>



<h2 class="wp-block-heading">Debate over who has control</h2>



<p>Analysts and consultants disagreed over whether enterprises should use the OpenAI capabilities for isolation or use the enterprise’s own restrictions.</p>



<p>“The question I immediately asked myself was whether organizations need OpenAI to do this for them. The answer, in my opinion, is no,” said <a href="https://www.infotech.com/profiles/erik-avakian" target="_blank" rel="noreferrer noopener">Erik Avakian</a>, technical counselor at Info-Tech Research Group. “Security professionals have been implementing similar concepts for years through control areas like network segmentation, least privilege, applying Zero Trust concepts and principles, application controls, and ‘air-gapping’ some environments.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, also has doubts. “So long as the LLM and associated components are provided as a service by OpenAI, customers can only partially control where those systems can reach out, so this lockdown mode seems to be the answer to that,” he said. </p>



<p>“Yes, customers could use a secure gateway,” he added, “but if the LLM and/or agent sitting at OpenAI premises accesses other third party services, there would not be a way for the IT and/or cybersecurity team from the customer to restrict this. The most secure approach is always the deployment of the AI infrastructure on premises, but that’s just not viable for the majority of organizations.”</p>



<p><a href="https://www.gartner.com/en/experts/dennis-xu" target="_blank" rel="noreferrer noopener">Dennis Xu</a>, a research VP with Gartner, flatly stated that enterprises need to rely on AI vendor provided cutoffs. </p>



<p>“This is not something end user clients can do on their own. As this controls how traffic flows from OpenAI infrastructure, the ChatGPT application, going outbound, only OpenAI has the ability to control that flow. ChatGPT is a web/SaaS based application that cannot be air gapped,” Xu said. “In the shared responsibility model, this falls under provider responsibility. End user clients will need to rely on what is available from providers such as OpenAI. Without that, they have no control over this data flow. So if they like this OpenAI feature, they need to raise this as a feature request with other providers for them to implement into their solution.”</p>



<p>That can get exponentially more complex if all AI vendors deploy such shutoff valves in different ways. </p>



<p>Gogia noted that vendor-specific controls are useful tactically and weak strategically, because each vendor can only constrain its own product. “OpenAI can limit OpenAI but it cannot govern a local model in a business unit or an assistant embedded elsewhere,” he said. “Its own model shows the limit: in managed workspaces, apps and connectors remain governed by role-based access and Lockdown Mode does not automatically disable every app. The hard work does not vanish. It moves into governance.”</p>



<p>Villanustre added that the result will be that customers may need to deal with “a patchwork of controls” until independent third party governance tools come to the rescue and support this cross-vendor management model.</p>



<p>As well, Avakian said, “rather than relying on a single AI platform, organizations will likely use multiple models from multiple vendors, in which each will serve different business functions. We might soon find ourselves talking about AI trust zones, AI segmentation, AI least privilege, and AI governance frameworks the same way we talk today about network segmentation and Zero Trust architectures.”</p>



<p>However, <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, said that the OpenAI move is an improvement, albeit an incremental one.</p>



<p>“It is not a replacement for pre-existing best practices within any organization. Rather, it enables greater in-model protections before organizational limitations can be imposed. With different vendors incorporating different lockdown modes into their models, IT is challenged to update its own protocols to integrate with an increasingly diverse vendor landscape,” he said. “There’s no getting around the fact that this will add ongoing overhead to IT and cybersecurity operations, as different vendors continue to evolve their own protection-focused regimes.”</p>



<h2 class="wp-block-heading">Humans are the problem</h2>



<p>One of the reasons that Lockdown Mode can’t halt all exfiltration, even if it works perfectly, is the human factor, coupled with the tendency of autonomous agents to bypass rules. </p>



<p>For example, let’s say that an end user works for a large publicly-held American company, and the user asks the agent to gather financial details about an upcoming quarter’s revenue and net income. Security and Exchange Commission (SEC) rules in the US make it illegal to selectively share that unannounced data with the public.</p>



<p>If the agent finds a way to access internal emails and documents from Finance and shares the answer with the end user, and that end user then copies and pastes that information into an email sent to some investors, or possibly even a financial journalist, the user is in contravention of the rule; the model that supplied the data may not have even known that this disclosure was prohibited. </p>



<h2 class="wp-block-heading">Expands the attack surface</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, noted that the most interesting thing about Lockdown Mode is that it acknowledges a reality many organizations are wrestling with: AI’s value often comes from its ability to connect to systems, access data, browse the web, and take action.</p>



<p>“Those same capabilities also expand the attack surface. As AI becomes more integrated into critical business processes, the conversation shifts from maximizing capability to balancing capability with control,” he said. “The broader implication is that we’re likely moving toward a world where AI systems have configurable operating modes based on business context, data sensitivity, user privileges, and risk tolerance. That’s a much more nuanced model than the all-or-nothing approaches we’ve seen so far.”</p>



<p>Greis would like the OpenAI option to offer IT granular functionality choices. “IT needs to have the availability to configure it and not just accept the default settings from OpenAI,” he said. For example, IT might want to customize based on connectors, or GPTs, or models, or zones, or regions.</p>



<p>Another Gartner VP analyst, <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>, said that OpenAI created Lockdown Mode “with a narrow set of clients in mind, specifically for non-classified government use, potentially for specific governments, the reason being that if an enterprise client has this level of concern regarding data sensitivity, they are not likely going to trust any provider, including OpenAI,” he pointed out. “Those clients are likely to seek on premises large language models, or large language models hosted in secure, trusted environments.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is OpenAI’s New Lockdown Mode an Admission That Default ChatGPT Was Never Safe Enough?]]></title>
<description><![CDATA[OpenAI introduced two new protections designed to help users and organizations mitigate prompt injection attacks when it launched Lockdown Mode in February. Last week, the LLM giant announced rollout of Lockdown Mode to all personal ChatGPT accounts, including Free, Go, Plus, and Pro, and also se...]]></description>
<link>https://tsecurity.de/de/3581071/it-security-nachrichten/is-openais-new-lockdown-mode-an-admission-that-default-chatgpt-was-never-safe-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581071/it-security-nachrichten/is-openais-new-lockdown-mode-an-admission-that-default-chatgpt-was-never-safe-enough/</guid>
<pubDate>Mon, 08 Jun 2026 12:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1000" height="666" src="https://thecyberexpress.com/wp-content/uploads/SearchGPT.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="SearchGPT, OpenAI, Sam Altman, Lockdown Mode" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/SearchGPT.jpg 1000w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-300x200.jpg 300w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-768x511.jpg 768w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-600x400.jpg 600w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-150x100.jpg 150w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-750x500.jpg 750w, https://thecyberexpress.com/wp-content/uploads/SearchGPT.avif 1000w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-300x200.avif 300w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-768x511.avif 768w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-600x400.avif 600w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-150x100.avif 150w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-750x500.avif 750w" sizes="(max-width: 1000px) 100vw, 1000px" title="Is OpenAI's New Lockdown Mode an Admission That Default ChatGPT Was Never Safe Enough? 1"></p><p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">OpenAI introduced two new protections designed to help users and organizations mitigate prompt injection attacks when it <a href="https://thecyberexpress.com/openai-new-lockdown-mode/" target="_blank" rel="nofollow noopener">launched</a> Lockdown Mode in February. Last week, the LLM giant <a href="https://help.openai.com/en/articles/20001061-lockdown-mode" target="_blank" rel="nofollow noopener">announced</a> rollout of Lockdown Mode to all personal ChatGPT accounts, including Free, Go, Plus, and Pro, and also self-serve ChatGPT Business accounts. Users can enable it from ChatGPT Settings under Security.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The rollout is notable not just for what Lockdown Mode does, but for what its existence concedes.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Does the existence of Lockdown Mode imply that ChatGPT, in its default settings, does not provide robust protection against sufficiently determined <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28631">data</a> exfiltration attacks. OpenAI does not seem to dispute this. Lockdown Mode is designed to help prevent the final stage of data exfiltration from a prompt injection attack by limiting outbound network requests that could transfer sensitive data to an attacker. Lockdown Mode does not prevent prompt injections from appearing in the content ChatGPT processes.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">That distinction matters enormously. Lockdown Mode is not an anti-injection control. It is a last-line-of-defense control. OpenAI is not stopping malicious instructions from reaching the model — it is blocking the network paths those instructions might use to smuggle data out. The attack still happens; the payload just has nowhere to go.</p>

<h5>Also read: <a href="https://thecyberexpress.com/openai-new-lockdown-mode/">OpenAI’s New Enterprise Security Mode Locks Down ChatGPT Against Prompt Injection</a></h5>
<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>What Prompt Injection Actually Is</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Prompt injection is the attack class Lockdown Mode is designed to constrain. In these attacks, a third party attempts to mislead a conversational AI system into following malicious instructions or revealing sensitive information.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">In a connected AI system — one that browses the web, processes documents, or interacts with external tools — the attack surface is every piece of external content the model touches. A malicious instruction embedded in a webpage, a PDF, a calendar invite, or a shared <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-password-protect-a-word-document/" title="document" data-wpil-keyword-link="linked" data-wpil-monitor-id="28628">document</a> can hijack the model's behavior without the user ever knowing it happened. The model reads the injected instruction, treats it as a legitimate command, and acts accordingly — potentially exfiltrating whatever is in the conversation window to an attacker-controlled endpoint via a web request.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">As AI systems become more capable and connected, this threat class has moved from academic demonstration to production risk. Agent Mode, Deep Research, live web browsing, and file connectors all dramatically expand the surface area available for injection attacks — and all of them represent outbound network paths a compromised model could abuse.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>What Lockdown Mode Disables and Why</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">When enabled, the Lockdown Mode limits or turns off certain features that connect ChatGPT to the web or external services, including live web access, image support in responses, Deep Research including shopping research, Agent Mode, Canvas networking, live connectors and file downloads.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Each disabled feature maps directly to an exploitation pathway. Live web access allows the model to retrieve attacker-controlled content. Agent Mode allows autonomous multi-step actions, meaning an injected instruction has more time and capability to execute before a human notices. File downloads create an outbound data transfer channel. Image support in responses can encode and transmit data through image URLs. Disabling all of them simultaneously removes the most exploitable exfiltration paths without modifying the model itself.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The tradeoff is real. Lockdown Mode disables several important features, including Deep Research and live web access. If you rely on up-to-date information, advanced workflows, or multi-step research tools, enabling it may limit your productivity in certain parameters. OpenAI is explicit that this is a deliberate trade — capability for <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28629">security</a> surface reduction — and that it is designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>Lockdown Mode is for Whom?</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Lockdown Mode is aimed at people facing elevated digital risk, including journalists, activists, and users working in sensitive environments. To that population, add legal, financial, and healthcare professionals who paste client or patient documents into ChatGPT; executives whose conversations contain strategic or deal-sensitive information; security analysts who process <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/different-types-of-threat-intelligence/" target="_blank" rel="noopener" title="threat intelligence" data-wpil-keyword-link="linked" data-wpil-monitor-id="28630">threat intelligence</a> in AI workflows; and any organization operating under data residency or confidentiality obligations that prohibit third-party data transmission.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">For folks who have an elevated risk profile due to who they are, what they work on, or the types of data they work with, it's an excellent tool for further securing themselves. This has some tradeoffs on functionality and utility, but for these users, the tradeoff is worthwhile.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">For everyone else, as AI systems take on more complex tasks — especially those that involve the web and connected apps — the security stakes change. Lockdown Mode going to all personal accounts is the right moment for every user who regularly pastes sensitive material into ChatGPT to make an explicit, informed decision about whether the productivity features they are trading away are worth more than the exfiltration risk they are trading for.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Lockdown Mode is available now across all ChatGPT account types. It can be enabled from <em>Settings → Safety and security → Advanced security → Lockdown Mode toggle</em>, with a per-session override in the header for moments when a connected feature is needed for a lower-risk task.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why most enterprise security teams would fail a military readiness test]]></title>
<description><![CDATA[Have you ever watched a military cyber ops team go to work responding to a cyberattack simulation? It’s like that scene from Die Hard 4.0 when all the screens start flashing red and systems start shutting down; however, unlike the movies, where bumbling government IT workers are caught out and pa...]]></description>
<link>https://tsecurity.de/de/3580904/it-security-nachrichten/why-most-enterprise-security-teams-would-fail-a-military-readiness-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580904/it-security-nachrichten/why-most-enterprise-security-teams-would-fail-a-military-readiness-test/</guid>
<pubDate>Mon, 08 Jun 2026 11:09:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Have you ever watched a military cyber ops team go to work responding to a cyberattack simulation? It’s like that scene from Die Hard 4.0 when all the screens start flashing red and systems start shutting down; however, unlike the movies, where bumbling government IT workers are caught out and panicking, our military actually moves with practiced precision to understand, contain, and mitigate the threat. Everybody understands their roles and any gaps are quickly highlighted and handled. This is because the military treats cyber as a kinetic threat requiring constant mission rehearsal, while the corporate sector is still treating cyber defense as a compliance checkbox, rather than an operational capability. This is untenable in a world where attackers constantly innovate their tactics and techniques to probe and access systems.</p>



<p>Over the past 12 months, we’ve seen just how unprepared different industry sectors have been in the face of major cyber incidents. Early in 2025, retailers and insurance brokers were brought down by the Scattered Spider group, and major manufacturers, including Jaguar Land Rover and Asahi Beer, saw months of downtime following ransomware attacks resulting from <a href="https://www.csoonline.com/article/4154550/supply-chain-security-is-now-a-board-level-issue-heres-what-csos-need-to-know.html">supply chain compromises</a>.</p>



<p>More recently, researchers at Cisco revealed that frontier models from OpenAI, Anthropic, Google, xAI, and Amazon <a href="https://www.csoonline.com/article/4177903/ai-models-more-vulnerable-than-claimed-when-faced-with-iterative-attacks.html">have significantly worse risk profiles</a> when pressured in multi-turn attacks, a discovery that revealed attack success rates are considerably higher than those benchmarked in simulated single-prompt attacks. This, combined with recent news that the Google Threat Intelligence Group identified what researchers believe to be <a href="https://www.csoonline.com/article/4169046/google-discovers-weaponized-zero-day-exploits-created-with-ai.html">the first zero-day exploit created using AI</a>, represents an entirely new stage in the technological arms race.</p>



<p>Those old-fashioned tabletop exercises where, once a year, you’d get everyone from IT to PR in a room for a couple of days and play out various scenarios and then tick that audit box for another 12 months aren’t going to cut it when attackers are probing on a daily basis. The military is using dynamic cyber ranges to test their real tools, people, and processes, in an exact simulation of their unique environment, against real-world threats like the tactics of Scattered Spider. Without real-world testing of your team’s capabilities, you’re not going to be able to go into an incident scenario confident that everyone’s prepared.</p>



<p>So, what can we learn from how the military prepares for cyberattacks in terms of mindset, readiness, and execution?</p>



<p>Military cyber doctrine starts with the assumption that you will be attacked and so prepare as though an attack is inevitable and not hypothetical. Businesses need to shift their mindset from “preventing breaches” to “detail, contain, and recover” and treat incidents as operational events rather than reputational crises. This reduces panic and leads to better decisions under pressure. It’s also critical for business leaders to understand their true vulnerabilities. Reputational and financial harm is typical collateral damage following a cyberattack, but was this the intended outcome? If sensitive data is compromised, are there persistent threats beyond the initial attack? Just as the military examines the secondary and tertiary impacts of risk scenarios in threat modeling, business leaders have to consider what else beyond their reputation and stock price may be compromised when they are attacked.</p>



<p>The military runs constant exercises; simulations, red team and blue team drills, and scenario planning that reflects real adversary behavior. Businesses can exercise that muscle by running regular live cyber simulations and updating based on real-world attacks. Conventional training still has its place, and companies should continue to invest in professional development programs that provide a strong foundational understanding of the most urgent threats facing their business. But, as the military says, “train like you fight.” There is simply no substitute for practical, hands-on training, especially when it comes to high-pressure, time-sensitive scenarios such as large-scale cyberattacks.</p>



<p>This readiness and preparedness training can, and should<em>,</em> extend to AI Agents too. Think about it like an “AI Proving Grounds”. Effectively, a realistic, intelligent environment where organizations can safely train human operators alongside AI agents, test autonomous workflows, and validate how both perform under real adversarial pressure before deployment. Continue to involve all the stakeholders, including executives and comms teams, who are going to be on the front line of customer, investor, and media inquiries should an attack occur. Without realism, readiness is an assumption, not a fact.</p>



<p>In a military cyber incident, everyone knows who decides, who communicates, and who executes, reducing any mid-crisis debate and empowering teams to act without permission to faster contain the incident. This principle is just as relevant in a corporate environment. Individual training is crucial, and operators should be confident acting in isolation, but it’s just as important that everyone in a rapid response team can work effectively with others, under often-intense pressure. This simulated teamwork is another advantage offered by AI Proving Grounds. In the same way that everyone in a military chain of command understands their role and that of their unit, businesses can pre-assign decision makers and define escalation paths before an incident to ensure clarity and calm rather than blind panic.</p>



<p>Finally, attackers are sharing knowledge all the time. <a href="https://www.csoonline.com/article/4177308/what-the-industrialization-of-exploitation-means-for-defenders.html">Defenders must adopt the same approach</a>. We know that militaries collaborate extensively across allies, agencies, and domains, recognizing that no unit has the full threat picture. Businesses can benefit from this information sharing by participating in ISACs, CERTs, and industry groups, treating threat intel as a collective defense rather than a competitive weakness.</p>



<p>AI Proving Grounds themselves are only part of the solution. Security is cultural, not just procedural. Even the most realistic simulated attack scenario is only useful if structures are in place for stakeholders to learn from it. What didn’t work well? What didn’t go as expected? What are the weakest links in the response chain? These are all questions executives and technical leadership should be comfortable asking themselves, and businesses must adopt cultures of responsibility to identify potential weaknesses beyond technical limitations. Such retrospectives can and should inform rapid-response playbooks to ensure that training is relevant and that weaknesses cannot be exploited in a production environment.</p>



<p>Many of the clients we work with are corporations and enterprises, but AI Proving Grounds have other applications. Recent years have seen coordinated attacks on critical infrastructure such as the nation’s power grid, including the prolonged intrusion by the Volt Typhoon persistent threat actor, which maintained unauthorized access to the operational technology networks of Littleton Electric Light and Water Departments in Massachusetts from February 2024 to November 2024. Such threats can also be simulated in AI Proving Grounds and provide crucial hands-on training opportunities for critical infrastructure providers that, until now, have been challenging to realistically model. With geopolitical tensions rising across the globe, operational readiness has never been more critical.</p>



<p>“Cyber resilience” has become something of a buzzword in itself and I can almost hear the eye rolls just using the phrase, but it is something the military does actively practice. Cyber resilience isn’t about prevention; it means being able to recover from as well as protect against attacks. With <a href="https://www.csoonline.com/article/4159305/helmut-reisinger-palo-alto-networks-anthropics-groundbreaking-mythos-model-represents-a-radical-shift-in-cybersecurity.html">AI-powered adversaries scaling their approach</a> to infiltration, extortion, and espionage, attacks are only going to increase and businesses need to be prepared to deal with them as well as prevent them. Continuous training within highly realistic and dynamic environments against real threat examples is the best way to ensure your teams are prepared at a military grade to secure your organization.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[깃허브마저 사용량 기반 청구 시대로… 코파일럿 신기능도 대거 추가]]></title>
<description><![CDATA[깃허브가 AI 코딩 도구 코파일럿의 활용 범위를 IDE 밖으로 확대한다. 새 데스크톱 애플리케이션과 협업 작업 공간인 ‘캔버스(Canvas)’를 선보이며, 코파일럿을 에이전트 네이티브(agent-native) 소프트웨어 개발의 컨트롤 타워로 자리매김시키겠다는 전략이다.



깃허브는 이번 주 열린 마이크로소프트(MS) 연례 개발자 행사 ‘빌드(Build)’에서 데스크톱 애플리케이션을 공개했다. 회사는 블로그를 통해 이 애플리케이션이 개발자가 소프트웨어 개발 전 과정에서 AI 에이전트와 협업할 수 있는 전용 환경을 제공하도록 설...]]></description>
<link>https://tsecurity.de/de/3580385/it-security-nachrichten//</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580385/it-security-nachrichten//</guid>
<pubDate>Mon, 08 Jun 2026 05:52:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>깃허브가 AI 코딩 도구 코파일럿의 활용 범위를 IDE 밖으로 확대한다. 새 데스크톱 애플리케이션과 협업 작업 공간인 ‘캔버스(Canvas)’를 선보이며, 코파일럿을 에이전트 네이티브(agent-native) 소프트웨어 개발의 컨트롤 타워로 자리매김시키겠다는 전략이다.</p>



<p>깃허브는 이번 주 열린 마이크로소프트(MS) 연례 개발자 행사 ‘빌드(Build)’에서 데스크톱 애플리케이션을 공개했다. 회사는 <a href="https://github.blog/news-insights/product-news/github-copilot-app-the-agent-native-desktop-experience/" target="_blank" rel="nofollow">블로그를 통해</a> 이 애플리케이션이 개발자가 소프트웨어 개발 전 과정에서 AI 에이전트와 협업할 수 있는 전용 환경을 제공하도록 설계됐다고 설명했다. 기존처럼 편집기 내부에서 코드 생성 작업에만 AI를 활용하는 수준을 넘어선다는 의미다.</p>



<p>애플리케이션에는 ‘캔버스’라는 협업 작업 공간도 포함됐다. 개발자는 이 공간에서 AI와 함께 아이디어를 구상하고, 요구사항을 구체화하며, 프로젝트 계획을 수립하고, 반복적인 개선 작업을 수행할 수 있다.</p>



<p>또한 새로운 ‘에이전트 머지(Agent Merge)’와 코드 리뷰 기능도 탑재됐다. 이를 통해 개발자는 여러 AI 에이전트의 작업을 결합해 특정 목표를 달성하도록 코파일럿을 자동화하거나, 사전에 설정한 기준에 따라 자율적으로 코드 검토를 수행하도록 할 수 있다.</p>



<p>시장조사업체 HFS리서치(HFS Research)의 CEO <a href="https://www.hfsresearch.com/team/philfersht/" target="_blank" rel="nofollow">필 퍼슈트</a>는 “이러한 신규 기능은 개발자의 작업 전환(context switching)을 줄이고 엔지니어링 효율성을 높이는 동시에 소프트웨어 제공 주기를 단축하는 데 기여할 수 있다”고 평가했다.</p>



<h2 class="wp-block-heading">사용량 기반 과금 전환, 정당한 변화인가</h2>



<p>하지만 최근 몇 주 동안 개발자 커뮤니티의 관심은 신규 기능보다 다른 이슈에 쏠려 있었다. 바로 깃허브가 지난 4월 발표하고 이번 주부터 적용한 코파일럿의 사용량 기반 과금 체계 전환이다.</p>



<p>이 같은 변화는 <a href="https://github.com/orgs/community/discussions/192948?sort=top#discussioncomment-17134630" target="_blank" rel="nofollow">깃허브 커뮤니티 포럼</a>에서 거센 비판에 직면했다. 일부 사용자는 이를 “미끼 상품 판매 후 조건 변경(bait and switch)”이라고 비난했고, 일부는 환불을 요구하거나 구독 해지 계획을 밝히기도 했다.</p>



<p>그러나 업계 분석가들은 적어도 깃허브의 관점에서 보면 이번 가격 정책 변화가 필요하고 정당한 조치였다고 평가했다.</p>



<p>브로드컴(Broadcom)의 수석 신뢰성 엔지니어<a href="https://www.linkedin.com/in/advaitpatel93" target="_blank" rel="nofollow"> 아드바이트 파텔</a>은 “이번 가격 정책 변화는 현재의 제품이 아니라 깃허브가 지향하는 미래 방향에 근거한 것”이라며 “샌드박스 환경에서 여러 에이전트를 병렬로 운영하고, 캔버스 검토와 에이전트 머지를 지속적 통합(CI) 프로세스와 연계하는 작업은 IDE 플러그인보다 클라우드 컴퓨팅에 훨씬 가깝다. 컴퓨팅 자원을 정액 좌석 라이선스로 가격 책정할 수는 없기 때문에 사용량 기반 과금은 구조적으로 올바른 선택”이라고 설명했다.</p>



<p>HFS리서치의 퍼슈트는 개발자와 CIO가 코파일럿을 단순한 코딩 보조 도구가 아닌 소프트웨어 개발 에이전트와 워크플로우를 조율하는 플랫폼으로 바라봐야 한다고 강조했다.</p>



<p>퍼슈트는 “이 변화는 투자 대비 효과(ROI)를 평가하는 방식을 크게 바꾼다”라며 “CIO는 더 이상 코파일럿을 좌석 라이선스 기반 생산성 도구로 볼 것이 아니라 AI 기반 소프트웨어 개발 플랫폼으로 평가해야 한다”고 말했다.</p>



<p>이어 “평가 지표 역시 ‘생성된 코드 라인 수’에서 벗어나 배포 속도, 코드 품질, 결함 감소, 엔지니어링 효율성 등 보다 폭넓은 운영 성과 중심으로 전환돼야 한다”고 설명했다.</p>



<p>AI 에이전트가 기업 전반으로 확산되고 더 복잡하면서도 연산 집약적인 소프트웨어 개발 업무를 수행하기 시작하면서 가격 정책을 재검토하는 기업은 깃허브가 처음은 아니다.</p>



<p>지난 1년 동안 클로드 코드(Claude Code), 리플릿(Replit), 커서(Cursor), 키로(Kiro) 등 플랫폼도 사용자 반발에도 불구하고 가격 체계를 지속적으로 조정해 왔다. 증가하는 인프라 비용과 제한된 GPU 공급, 그리고 갈수록 고도화되는 AI 모델 및 에이전트 운영 비용이 주요 배경으로 꼽힌다.</p>



<h2 class="wp-block-heading">CIO의 과제는 ROI 입증</h2>



<p>IT 컨설팅 기업 카네리카(Kanerika)의 최고분석책임자(CAO) <a href="https://www.linkedin.com/in/amitchandak78/" target="_blank" rel="nofollow">아밋 찬닥</a>은 이러한 공통된 압박 요인 때문에 개발자와 CIO가 깃허브의 과금 방식 자체보다 실제 비즈니스 가치 창출 여부에 더 집중해야 한다고 조언했다.</p>



<p>찬닥은 “깃허브가 발표한 신규 기능은 생산성을 크게 높이는 촉매제가 될 수 있지만, 반대로 이에 상응하는 비즈니스 가치를 제공하지 못한 채 사용량만 늘릴 가능성도 있다”라며 “도입 이전에 생산성 기준선을 설정하지 않으면 기업은 비용만 증가하고 그 비용이 실제 성과로 이어졌는지 확인하지 못하는 상황에 처할 수 있다”고 지적했다.</p>



<p>퍼슈트는 가격 체계가 변화하는 만큼 개발자와 CIO가 거버넌스, 모니터링, 재무 통제에 더욱 집중해야 한다고 강조했다.</p>



<p>그는 “거버넌스 문제는 매우 현실적인 과제”라며 “자율형 에이전트는 지속적으로 추론하고 테스트하며 수정 작업을 수행하는 동시에 여러 시스템과 상호작용한다. 이는 기존 SaaS 도구보다 훨씬 예측하기 어려운 사용 패턴을 만들어낼 수 있다”고 설명했다.</p>



<p>반면 파텔은 신규 기능이 아직 기술 프리뷰 단계라는 점을 고려할 때 사용자와 의사결정권자가 보다 신중한 태도를 취해야 한다고 조언했다.</p>



<p>파텔은 “고객은 아직 실제 운영 환경에서 검증되지 않은 가치에 대해 변동 요금을 지불하도록 요구받고 있다”라며 “새로운 기능이 더 높은 비용 지출을 정당화한다고 섣불리 가정해서는 안 된다”고 말했다.</p>



<p>이어 “90일간 파일럿 프로젝트를 진행한 뒤 투자 금액 대비 병합된 풀리퀘스트(PR) 수가 얼마나 늘어났는지 측정하고 데이터에 따라 판단해야 한다”라며 “그 비율이 개선됐다면 현재 가격은 합리적이다. 하지만 그렇지 않다면 기업은 실제 성과가 아니라 미래에 대한 기대에 비용을 지불하고 있는 것”이라고 덧붙였다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixel Bureaucracy At The Scale Of Chaos - or: Torturing 286 People By Pretending To Be The Governmen]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 1x - Views:1 https://media.ccc.de/v/gpn24-450-pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-government

This talk could be described as "pixelebbe Wrapped", except that it is at a different time of the year, has better jo...]]></description>
<link>https://tsecurity.de/de/3579423/it-security-video/pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-governmen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579423/it-security-video/pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-governmen/</guid>
<pubDate>Sun, 07 Jun 2026 15:18:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 1x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/7j9DE1vdndA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/gpn24-450-pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-government<br />
<br />
This talk could be described as "pixelebbe Wrapped", except that it is at a different time of the year, has better jokes, provides more technical and moral insights and is not personalized. So erm it probably isn't a "pixelebbe Wrapped" at all, but hey, learn how we built and hosted pixelebbe, achieved better uptime than GitHub and spent only a reasonable amount of effort on this shitpost-turned-project (that's what we tell ourselves at night).<br />
<br />
In the history of human kind, there is a set of unfortunate innovations that have caused a lot of suffering and destroyed many lives. One might think of the nuclear bomb, or the internet. One could also think of pixelebbe. At least if one were to be untroubled by accusations of exaggeration and over-dramatising.<br />
<br />
Well what is pixelebbe? It's a pixel-setting experience designed to frustrate the player using everyones' favorite thing: ✨ excessive bureaucracy ✨. The idea is very simple: we provide a 40x30 canvas, everyone can then tell us to set a specific pixel to a specific colour from our limited colourset, which we then do and so a picture will be created. Just add on top of that large amounts of red tape, such as limited office hours, a dedicated queueing system, having to use an official government form, very strict formality control and stamps.<br />
<br />
In this talk, we want to lift the curtains and give a backoffice tour through pixelebbe. We'll talk about the technology abused to build and host pixelebbe, how we made professional software designed to look like it was put together in 2 hours. We'll even leak official secrets and risk going to pixeljail. There'll be time for a Q&A and a rare live-pixel-setting-session. Rumour has it, that even our agency lead might appear on stage, which had been notoriously always-absent during 39c3.<br />
<br />
luap42, 9hax (lydia!)<br />
<br />
https://cfp.gulas.ch/gpn24/talk/VJDF8H/<br />
<br />
#gpn24 #ArtCultureandGames<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixel Bureaucracy At The Scale Of Chaos - or: Torturing 286 People By Pretending To Be The Government (gpn24)]]></title>
<description><![CDATA[This talk could be described as "pixelebbe Wrapped", except that it is at a different time of the year, has better jokes, provides more technical and moral insights and is not personalized. So erm it probably isn't a "pixelebbe Wrapped" at all, but hey, learn how we built and hosted pixelebbe, ac...]]></description>
<link>https://tsecurity.de/de/3579393/it-security-video/pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-government-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579393/it-security-video/pixel-bureaucracy-at-the-scale-of-chaos-or-torturing-286-people-by-pretending-to-be-the-government-gpn24/</guid>
<pubDate>Sun, 07 Jun 2026 15:03:18 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This talk could be described as "pixelebbe Wrapped", except that it is at a different time of the year, has better jokes, provides more technical and moral insights and is not personalized. So erm it probably isn't a "pixelebbe Wrapped" at all, but hey, learn how we built and hosted pixelebbe, achieved better uptime than GitHub and spent only a reasonable amount of effort on this shitpost-turned-project (that's what we tell ourselves at night).

In the history of human kind, there is a set of unfortunate innovations that have caused a lot of suffering and destroyed many lives. One might think of the nuclear bomb, or the internet. One could also think of pixelebbe. At least if one were to be untroubled by accusations of exaggeration and over-dramatising.

Well what is pixelebbe? It's a pixel-setting experience designed to frustrate the player using everyones' favorite thing: ✨ excessive bureaucracy ✨. The idea is very simple: we provide a 40x30 canvas, everyone can then tell us to set a specific pixel to a specific colour from our limited colourset, which we then do and so a picture will be created. Just add on top of that large amounts of red tape, such as limited office hours, a dedicated queueing system, having to use an official government form, very strict formality control and stamps.

In this talk, we want to lift the curtains and give a backoffice tour through pixelebbe. We'll talk about the technology abused to build and host pixelebbe, how we made professional software designed to look like it was put together in 2 hours. We'll even leak official secrets and risk going to pixeljail. There'll be time for a Q&amp;A and a rare live-pixel-setting-session. Rumour has it, that even our agency lead might appear on stage, which had been notoriously always-absent during 39c3.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/VJDF8H/]]></content:encoded>
</item>
<item>
<title><![CDATA[Víctor Fancelli Capdevila: KeepKarlsruheBoring: collective agendas, boredom and maintenance]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:13 https://media.ccc.de/v/gpn24-600-keepkarlsruheboring-collective-agendas-boredom-and-maintenance

[KeepKarlsruheBoring](https://keepkarlsruheboring.org/) is an agenda for Karlsruhe using [gancio](https://gancio.org/) to allow users, with or without r...]]></description>
<link>https://tsecurity.de/de/3577873/it-security-video/vctor-fancelli-capdevila-keepkarlsruheboring-collective-agendas-boredom-and-maintenance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577873/it-security-video/vctor-fancelli-capdevila-keepkarlsruheboring-collective-agendas-boredom-and-maintenance/</guid>
<pubDate>Sat, 06 Jun 2026 16:32:41 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:13 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/KMJ7Nm5_tys?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/gpn24-600-keepkarlsruheboring-collective-agendas-boredom-and-maintenance<br />
<br />
[KeepKarlsruheBoring](https://keepkarlsruheboring.org/) is an agenda for Karlsruhe using [gancio](https://gancio.org/) to allow users, with or without registration, to add events that will be displayed in a web and in the Fediverse. In this talk, we will have an overview on the maintenance of the system beyond the software.<br />
<br />
Some people complain about how boring Karlsruhe can be (literally, the name of the city can be translated as the calm or dream of Carl). Yet, having a more in-depth look, there are many people and collectives doing astonishing things: maybe the issue was never the lack of activity, but not having a shared agenda to get an overview on that is going on, especially if you refuse to use Instagram or other (a)social media. Under this premise, KeepKarlsruheBoring was launched in 2025 and since them have been collecting events.<br />
<br />
Contrary to what most of the people think, technical set up and maintenance is almost effortless and what really requires work is the social maintenance: reaching out to people and helping them to put their events, moderation and correction of events. After having a brief look and the technical set-up, we will have an overview on what we have been doing in this first year to let people know and use this agenda.<br />
<br />
Víctor Fancelli Capdevila<br />
<br />
https://cfp.gulas.ch/gpn24/talk/DLSLS7/<br />
<br />
#gpn24 #ArtCultureandGames<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KeepKarlsruheBoring: collective agendas, boredom and maintenance (gpn24)]]></title>
<description><![CDATA[[KeepKarlsruheBoring](https://keepkarlsruheboring.org/) is an agenda for Karlsruhe using [gancio](https://gancio.org/) to allow users, with or without registration, to add events that will be displayed in a web and in the Fediverse. In this talk, we will have an overview on the maintenance of the...]]></description>
<link>https://tsecurity.de/de/3577848/it-security-video/keepkarlsruheboring-collective-agendas-boredom-and-maintenance-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577848/it-security-video/keepkarlsruheboring-collective-agendas-boredom-and-maintenance-gpn24/</guid>
<pubDate>Sat, 06 Jun 2026 16:17:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[[KeepKarlsruheBoring](https://keepkarlsruheboring.org/) is an agenda for Karlsruhe using [gancio](https://gancio.org/) to allow users, with or without registration, to add events that will be displayed in a web and in the Fediverse. In this talk, we will have an overview on the maintenance of the system beyond the software.

Some people complain about how boring Karlsruhe can be (literally, the name of the city can be translated as the calm or dream of Carl). Yet, having a more in-depth look, there are many people and collectives doing astonishing things: maybe the issue was never the lack of activity, but not having a shared agenda to get an overview on that is going on, especially if you refuse to use Instagram or other (a)social media. Under this premise, KeepKarlsruheBoring was launched in 2025 and since them have been collecting events.

Contrary to what most of the people think, technical set up and maintenance is almost effortless and what really requires work is the social maintenance: reaching out to people and helping them to put their events, moderation and correction of events. After having a brief look and the technical set-up, we will have an overview on what we have been doing in this first year to let people know and use this agenda.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/DLSLS7/]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten Digital Whiteboards]]></title>
<description><![CDATA[Physische Whiteboards haben in Zeiten hybrider Arbeitsmodelle zwar noch nicht ganz ausgedient, Visual Collaboration Apps laufen ihnen jedoch den Rang ab. 
					Foto: Shift Drive – shutterstock.com




Remote Work beschäftigt weiterhin Unternehmen weltweit. Sie müssen sicherstellen, dass ihre Mita...]]></description>
<link>https://tsecurity.de/de/3576995/it-security-nachrichten/die-besten-digital-whiteboards/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576995/it-security-nachrichten/die-besten-digital-whiteboards/</guid>
<pubDate>Sat, 06 Jun 2026 05:22:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Physische Whiteboards haben in Zeiten hybrider Arbeitsmodelle zwar noch nicht ganz ausgedient, Visual Collaboration Apps laufen ihnen jedoch den Rang ab. " title="Physische Whiteboards haben in Zeiten hybrider Arbeitsmodelle zwar noch nicht ganz ausgedient, Visual Collaboration Apps laufen ihnen jedoch den Rang ab. " src="https://images.computerwoche.de/bdb/3328302/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Physische Whiteboards haben in Zeiten hybrider Arbeitsmodelle zwar noch nicht ganz ausgedient, Visual Collaboration Apps laufen ihnen jedoch den Rang ab. </p></figcaption></figure><p class="imageCredit">
					Foto: Shift Drive – shutterstock.com</p></div>




<p>Remote Work beschäftigt weiterhin Unternehmen weltweit. Sie müssen sicherstellen, dass ihre Mitarbeiter produktiv und kreativ bleiben. Deswegen rücken auch Visual Collaboration Tools in den Fokus, die vorher vor allem von <a title="Softwareentwicklern" href="https://www.computerwoche.de/article/2802329/wie-sie-der-developer-hoelle-entkommen.html" target="_blank">Softwareentwicklern</a> genutzt wurden und die deutlich über die eher simplen Whiteboard-Funktionen von Plattformen wie <a title="Zoom, Teams oder Webex" href="https://www.computerwoche.de/article/2794620/die-wichtigsten-videokonferenz-systeme.html" target="_blank">Zoom, Teams oder Webex</a> hinausgehen.</p>



<p>Kollaborationsprozesse müssen in ein durchgängiges, digitales Format überführt werden, wie <a href="https://www.crunchbase.com/person/mike-fasciani" target="_blank" rel="noreferrer noopener">Mike Fasciani</a>, Senior Research Director bei Gartner, weiß: “Es geht darum, alle Remote-Beteiligten mit den gleichen Kollaborationsfähigkeiten auszustatten und ihnen die gleichen Informationen zur Verfügung zu stellen, wie den physisch Anwesenden. Das physische Whiteboard spielt in diesem Szenario keine Rolle mehr.”</p>



<h2 class="wp-block-heading">Visual Collaboration Tools – Top 7</h2>



<p>Wenn es um die Auswahl einer Digital Whiteboard Software geht, sollten Unternehmen im ersten Schritt darauf achten, was reine Whiteboard-Emulationen von echten Visual Collaboration Tools unterscheidet. Letztere zeichnet zum Beispiel aus: </p>



<ul class="wp-block-list">
<li><p>ein “Collaboration Canvas”, der durchgängige Workspaces erschafft, auf denen alle Beteiligten Dokumente, Bilder, Videos, Designentwürfe, Diagramme oder andere Content-Typen nach Belieben hinzufügen können; </p></li>



<li><p>Templates, Planungs-Tools und Task-Assignment-Optionen;</p></li>



<li><p>Security auf Enterprise-Niveau;</p></li>



<li><p>administrative Tools und Integrationsmöglichkeiten mit populären <a title="Enterprise Apps" href="https://www.computerwoche.de/article/2802531/die-besten-enterprise-tech-newcomer.html" target="_blank">Enterprise Apps</a>; </p></li>
</ul>



<p>Der Einsatzzweck der digitalen Whiteboard Apps geht dabei laut Gartner-Analyst Fasciani über die Softwareentwicklung hinaus. Seiner Einschätzung nach können verschiedene Teams im Unternehmen Visual Collaboration Tools nutzen – etwa für: </p>



<ul class="wp-block-list">
<li><p>Brainstorming-Prozesse,</p></li>



<li><p>Designprozesse,</p></li>



<li><p>Strategie- und Geschäftsprozessplanung,</p></li>



<li><p>Produktentwicklung,</p></li>



<li><p>Marketing-Pläne,</p></li>



<li><p>oder Projektmanagement.</p></li>
</ul>



<p>Um Ihnen den Weg zum richtigen Visual Collaboration Tool für Ihre Zwecke zu erleichtern, haben wir einige etablierte und aufstrebende Plattformen für Sie zusammengetragen.</p>



<h3 class="wp-block-heading"><a href="https://www.bluescape.com/" target="_blank" rel="noreferrer noopener">Bluescape</a></h3>



<p>Bluescape ist eine digitale Plattform für die visuelle Zusammenarbeit in einer hybriden Arbeitsumgebung. Die unbegrenzte Anzahl an Workspaces schaffen einen gesicherten Treffpunkt für das Team und bieten ein Content-Repository, zum Beispiel für Brainstorming, Planung und <a title="Entscheidungsfindung" href="https://www.computerwoche.de/article/2804130/wie-cios-sich-selbst-sabotieren.html" target="_blank">Entscheidungsfindung</a>. Zusätzlich zu den Whiteboard-, Präsentations- und Anmerkungsfunktionen bietet die Plattform eine fortschrittliche Alternative zur Bildschirmfreigabe, da Benutzer mit mehreren Inhalten gleichzeitig interagieren können, anstatt lineares Screen Sharing zu betreiben. Funktionen wie Wasserzeichen für Inhalte und Video-Uploads mit synchronisiertem Playback sind ebenfalls an Bord.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Nutzer von Bluescape können mit verschiedenen Content-Typen zeitgleich interagieren." title="Nutzer von Bluescape können mit verschiedenen Content-Typen zeitgleich interagieren." src="https://images.computerwoche.de/bdb/3328295/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Nutzer von Bluescape können mit verschiedenen Content-Typen zeitgleich interagieren.</p></figcaption></figure><p class="imageCredit">
					Foto: Bluescape </p></div>




<p><strong>Weitere Funktionen sind:</strong></p>



<ul class="wp-block-list">
<li><p>Vorlagen für eine einheitliche Formatierung in Meetings, Präsentationen oder Projekten</p></li>



<li><p>Integrationen mit wichtigen Unternehmens-Tools wie Microsoft 365, Google Docs, OneDrive, Dropbox, Box, Google Drive, Outlook, Cisco Webex und Zoom</p></li>
</ul>



<p><strong>Bemerkenswert:</strong> Bluescape bietet eigene Clients für mobile Geräte, Browser und touch-fähige In-Room-Displays, inklusive Multi-Screen-Installationen.</p>



<p><strong>Sicherheit:</strong></p>



<ul class="wp-block-list">
<li><p>Datenverschlüsselung mit TLS 1.2 und 256-Bit-AES</p></li>



<li><p>Datenspeicherung in Public oder Private Cloud</p></li>



<li><p>Unterstützung für Bring Your Own Key (BYOK)</p></li>



<li><p>Single Sign-On (SAML 2.0)</p></li>



<li><p>NIST-800-171- und NIST-Cybersecurity-Framework-konform</p></li>



<li><p>ISO-27001-Zertifizierung</p></li>
</ul>



<p><strong>Enterprise-Funktionen</strong><strong>:</strong></p>



<ul class="wp-block-list">
<li><p>Bereitstellung in einer von Bluescape verwalteten Public-Cloud-Instanz oder</p></li>



<li><p>als Managed Virtual Private Cloud sowie </p></li>



<li><p>in einer von Partnern oder Kunden verwalteten privaten Cloud und</p></li>



<li><p>On-Premises.</p></li>
</ul>



<p>Administratoren können darüber hinaus auf selbst erstellte Berichte und Diagramme zugreifen, um Nutzungs- und Verbrauchsdaten von Nutzern, Workspaces oder Clients einzusehen. </p>



<p><strong>Preisgefüge:</strong> Bluescape konzentriert sich nach eigenen Angaben auf den Enterprise-Einsatz und erarbeitet mit seinen Kunden ein für die jeweiligen Bedürfnisse passendes Preismodell.</p>



<h3 class="wp-block-heading"><a href="https://conceptboard.com/de/" target="_blank" rel="noreferrer noopener">Conceptboard</a></h3>



<p>Conceptboard ist ein deutscher Anbieter digitaler Whiteboards für visuelle Kollaboration. Durch seine Größe und die Nutzung von bis zu 100 Elementen allein in der kostenlosen Version eignet es sich besonders für komplexe Boards. Conceptboard bietet eine Reihe von Templates für moderne Brainstorming-Methoden, Planungen und Meetings, die Anwender auch selbst erstellen können. Mit einer (Video-)Chat-Funktion, einem Moderationsmodus, Tagging- und Kommentarfunktionen sowie der Möglichkeit, Dateien direkt auf dem Board zu teilen, lässt sich die Lösung als ganzheitliche Plattform für kollaboratives Arbeiten und Projektmanagement bezeichnen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Punktet beim Thema Datenschutz und Sicherheit: die deutsche Whiteboard-Lösung Conceptboard." title="Punktet beim Thema Datenschutz und Sicherheit: die deutsche Whiteboard-Lösung Conceptboard." src="https://images.computerwoche.de/bdb/3368750/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Punktet beim Thema Datenschutz und Sicherheit: die deutsche Whiteboard-Lösung Conceptboard.</p></figcaption></figure><p class="imageCredit">
					Foto: Conceptboard</p></div>




<p><strong>Weitere Funktionen sind:</strong></p>



<ul class="wp-block-list">
<li><p>Teilen der Boards auch mit Personen außerhalb des Unternehmens über einen Direkt-Link</p></li>



<li><p>Anbindung an bestehende Teamwork-Apps wie Google Drive, Dropbox und MS Teams</p></li>



<li><p>Kompatibilität mit Promethean-Smartboards für hybrides Arbeiten</p></li>



<li><p>Individuelle Zugriffsverwaltung der einzelnen Boards</p></li>



<li><p>Ein History Mode, mit dem Fortschritte im Projekt für alle transparent nachvollziehbar sind</p></li>



<li><p>Live-Cursor, mit denen sich alle Aktionen in Echtzeit verfolgen lassen</p></li>
</ul>



<p><strong>Bemerkenswert:</strong> Conceptboard wird gerne in der öffentlichen Verwaltung genutzt, da es die nötigen Compliance-Anforderungen erfüllt. </p>



<p><strong>Sicherheit:</strong></p>



<ul class="wp-block-list">
<li><p>DSGVO-konform und ISO-27001-zertifiziert</p></li>



<li><p>SAML 2.0 / OAUTH 2.0 Single Sign-On</p></li>



<li><p>256-bit AES Data-at-Rest Excryption</p></li>



<li><p>Secure A+ SSL Encryption</p></li>
</ul>



<p><strong>Enterprise-Funktionen:</strong></p>



<ul class="wp-block-list">
<li><p>Public Cloud: Bereitstellung in einer Public Cloud;</p></li>



<li><p>Dedicated Server: Mit Unterstützung der eigenen Domain ermöglicht Conceptboard schnelle Ladezeiten und Stabilität;</p></li>



<li><p>On-Premises: Conceptboard lässt sich auf dem eigenen Server oder im eigenen RZ betreiben.</p></li>
</ul>



<p><strong>Preisgefüge:</strong> Kostenlos nutzbar ist Conceptboard im Rahmen eines Testzeitraums. Der <strong>Starter-Plan</strong> kostet <strong>5 Euro</strong> pro Nutzer, der <strong>Advanced-Plan 10 Euro</strong>. Lösungen für größere Unternehmen und Institutionen sind ebenfalls erhältlich ab <strong>14 Euro</strong> pro Monat. Individuelle Preispläne für spezielle Anforderungen gibt es auf Anfrage.</p>



<h3 class="wp-block-heading"><a href="https://klaxoon.com/board" target="_blank" rel="noreferrer noopener">Klaxoon Board</a></h3>



<p>Board ist die Flaggschiff-Anwendung des Softwareunternehmens Klaxoon, die keine Installation erfordert. Der visuelle Workspace ermöglicht es seinen Anwendern, Inhalte in verschiedenen Formaten über vorgefertigte Templates zu teilen. Der Collaboration Canvas ist dabei unbegrenzt und soll genutzt werden, um Ideen visuell zu teilen, zu priorisieren und zu organisieren. Board wurde für verschiedene Szenarien entwickelt, darunter für wöchentliche Meetings mit Visual-Collaboration-Ansatz.</p>



<p>Dafür benötigt man allerdings die kostenpflichtige “Live App”, die <a href="https://www.computerwoche.de/article/2794620/die-wichtigsten-videokonferenz-systeme.html" title=") und/oder Shop-Software erfolgen kann. Nur so lässt sich die letztlich benötigte Performance abschätzen." target="_blank">) und/oder Shop-Software erfolgen kann. Nur so lässt sich die letztlich benötigte Performance abschätzen.</a> für bis zu 15 Teilnehmer ermöglicht. Board lässt sich auch mit Microsoft Teams, Google Meet, Skype, Cisco Webex und Zoom integrieren. Konzipiert für crossfunktionale Teams, verfügt die App über eine ansehnliche Bibliothek von Meeting-Vorlagen.</p>



<p>Klaxoon bietet auch eine App- und Tool-Suite für Board, die Funktionen wie Umfragen, Word Clouds oder ein Quiz einbindet, um die Interaktionsrate in Meetings zu steigern. Die Klaxoon Suite integriert mit Dropbox und Microsoft Teams – Jira soll in Kürze folgen. Dank eines hybriden Software/Hardware-Ansatzes (über Klaxoon Box und MeetingBoard) ist auch ein Offline-Zugriff möglich.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Ein Klaxoon Board kann bis zu 15 Teilnehmer per Video einbinden. " title="Ein Klaxoon Board kann bis zu 15 Teilnehmer per Video einbinden. " src="https://images.computerwoche.de/bdb/3328297/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Ein Klaxoon Board kann bis zu 15 Teilnehmer per Video einbinden. </p></figcaption></figure><p class="imageCredit">
					Foto: Klaxoon </p></div>




<p><strong>Bemerkenswert:</strong> Die verschiedenen Ansichtsmodi wie Whiteboard, <a href="https://www.computerwoche.de/article/2793573/was-scrum-von-kanban-unterscheidet.html" title="Kanban" target="_blank">Kanban</a> und Liste ermöglichen es, Informationen schneller zu sortieren. Mit Funktionen wie Quiz oder Umfrage lässt sich Teamwissen auf die Probe stellen, beziehungsweise ein gegenseitiger Lernprozess anregen.</p>



<p><strong>Sicherheit:</strong></p>



<ul class="wp-block-list">
<li><p>Benutzerdatenverschlüsselung (bei der Übertragung über TLS 1.3 und im Ruhezustand über AES-256)</p></li>



<li><p>Backups ebenfalls verschlüsselt</p></li>



<li><p>Hosting in europäischen Rechenzentren</p></li>



<li><p>Single Sign-On (optional)</p></li>
</ul>



<p><strong>Enterprise-Funktionen</strong>: Zusätzlich zu SSO und SCIM bietet Klaxoon eine Administrationskonsole, die beispielsweise zur Aktivitätsüberwachung genutzt werden oder Auskunft über die Anzahl der generierten Interaktionen pro Benutzer geben kann. Die interne Consulting-Abteilung und das globale Partnernetzwerk unterstützen Kunden mit Meeting-Audits, Visual-Collaboration-Schulungen und anderen Support-Leistungen.</p>



<p><strong>Preisgefüge: </strong>Kostenloses Ausprobieren der Board-Vorlagen (bis zu 15 Teilnehmer, einmalige Nutzung der Vorlagen); <strong>Starter-Tarif</strong> (bis zu 100 Teilnehmer, unbegrenzte Anzahl von Boards, inklusive Live-Videokonferenz-App, Vorlagenbibliothek, 10 GB Speicherplatz) für <strong>24,90 Dollar</strong> pro Monat und Benutzer; einen Enterprise-Plan (bis zu 300 Benutzer, zusätzliche Management-, Sicherheits- und Analysefunktionen) gibt es auf Anfrage.</p>



<h3 class="wp-block-heading"><a href="https://lucidspark.com/de" target="_blank" rel="noreferrer noopener">Lucidspark</a></h3>



<p>Einfache Whiteboards, wie sie in Web-Conferencing-Apps zu finden sind, können dabei helfen, Ideen zusammenzutragen. Lucidspark wurde hingegen für Teams entwickelt, die diese Ideen umsetzen sollen. Zu den Anwendungsfällen gehören zum Beispiel:</p>



<ul class="wp-block-list">
<li><p>Engineering,</p></li>



<li><p>Projektmanagement,</p></li>



<li><p>Marketing,</p></li>



<li><p>User Experience Management,</p></li>



<li><p>Produktmanagement,</p></li>



<li><p>Führungsteams und</p></li>



<li><p>funktionsübergreifende Teams.</p></li>
</ul>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Lucidspark arbeitet mit Farbzuweisungen, um die Übersicht jederzeit zu wahren." title="Lucidspark arbeitet mit Farbzuweisungen, um die Übersicht jederzeit zu wahren." src="https://images.computerwoche.de/bdb/3328298/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Lucidspark arbeitet mit Farbzuweisungen, um die Übersicht jederzeit zu wahren.</p></figcaption></figure><p class="imageCredit">
					Foto: Lucidspark</p></div>




<p><strong>Die Funktionen umfassen unter anderem:</strong></p>



<ul class="wp-block-list">
<li><p>intelligente Datensynthese, mit der Inhalte automatisch nach Themen gruppiert werden können, ohne die Beiträge manuell sortieren zu müssen. Die Software organisiert die Ideen, hebt wichtige Erkenntnisse hervor und weist die nächsten Schritte zu;</p></li>



<li><p>die Möglichkeit, große Gruppen auf einem Lucidspark-Board zusammenzubringen, um sie dann in kleinere Breakout Boards für Brainstorming und Ideenfindung leiten;</p></li>



<li><p>Sprachunterstützung für Englisch, Spanisch, Französisch, Portugiesisch, Deutsch und Niederländisch;</p></li>



<li><p>diverse Voting-Optionen (namentlich und anonym);</p></li>



<li><p>integrierbar mit Slack, Jira, Microsoft Teams und Google Drive sowie Lucidchart;</p></li>
</ul>



<p><strong>Bemerkenswert:</strong> Das Tool bietet die Möglichkeit, jedem Mitwirkenden eine bestimmte Farbe zuzuweisen, um die Übersichtlichkeit zu wahren.</p>



<p><strong>Sicherheit:</strong></p>



<ul class="wp-block-list">
<li><p>Datenübertragung mit TLS v1.2 verschlüsselt;</p></li>



<li><p>im Ruhezustand AES-256-Verschlüsselung;</p></li>



<li><p>sichere Domain-Bereitstellung;</p></li>



<li><p>Benutzerauthentifizierung;</p></li>



<li><p>Domain-Sperrung und Schlüsselverwaltungsdienste;</p></li>



<li><p>kryptografische Schlüssel werden durch Amazons Key Management Services geschützt;</p></li>



<li><p>Lucids Cloud-Anbieter ist Amazon Web Services (AWS);</p></li>



<li><p>das Unternehmen ist PCI-, SOC-2- und EU-US Privacy Shield-zertifiziert und erfüllt die Anforderungen von CCPA und DSGVO;</p></li>
</ul>



<p><strong>Enterprise-Funktionen:</strong></p>



<ul class="wp-block-list">
<li><p>zentralisierte Account-Verwaltung für Benutzer und Administratoren in der gesamten Lucid Visual Collaboration Suite;</p></li>



<li><p>zentralisierte Account- und Abrechnungsverwaltung;</p></li>



<li><p>Lizenzverwaltung zur einfachen Bereitstellung,</p></li>



<li><p>Deprovisionierung und Neuzuweisung von Lizenzen;</p></li>



<li><p>Dokumentenverwaltung, einschließlich Teamordnern, Dokumenten-Tags und Status;</p></li>



<li><p>Möglichkeit, anonyme Gastfunktionen zu deaktivieren.</p></li>
</ul>



<p><strong>Preisgefüge:</strong> für bis zu drei Boards (mit jeweils maximal 300 Objekten) <strong>kostenlos</strong>; der <strong>Individual-Plan</strong> beginnt bei <strong>9 Euro</strong> pro Monat mit unbegrenzten Boards und Objekten; der <strong>Team-Plan</strong> (mindestens 3 Benutzer) beginnt bei <strong>10 Euro</strong> pro Benutzer und Monat und enthält erweiterte Funktionen für die Zusammenarbeit und einige Verwaltungsfunktionen. Der Enterprise-Plan bietet mehr Integrationen und erweiterte Admin-Kontrollen, die Preisgestaltung gibt es auf Anfrage.</p>



<h3 class="wp-block-heading"><a href="https://miro.com/" target="_blank" rel="noreferrer noopener">Miro</a></h3>



<p>Das digitale Whiteboard Miro soll sich für sämtliche Unternehmensfunktionen eignen, von der Produktentwicklung bis hin zu Marketing und Sales. Die Miro-App bietet einen unbegrenzten Collaboration Canvas, auf dem bis zu 1000 Teilnehmer gleichzeitig zusammenzuarbeiten können.</p>



<p>Hunderte von Vorlagen sind in Miro verfügbar, wobei die Kategorien von Frameworks (<a href="https://www.computerwoche.de/article/2797093/wie-funktioniert-entwickeln-aus-kundenperspektive.html" title="Design Thinking" target="_blank">Design Thinking</a>, <a href="https://www.computerwoche.de/article/2801830/wege-zur-agilen-selbstsabotage.html" title="Agile" target="_blank">Agile</a>, Lean oder <a href="https://www.computerwoche.de/article/2790744/machen-sie-ihren-projekten-schon-beine.html" title="SAFe" target="_blank">SAFe</a>) bis hin zu teambasierten Vorlagen reichen, die Vertrieb und Marketing, Entwicklung, Produktmanagement, UX-Design, IT, HR oder Teammitglieder auf Führungsebene unterstützen sollen. Miro lässt sich asynchron oder in Echtzeit nutzen und ermöglicht die Einbettung von Videokonferenzen, Chat und Bildschirmfreigaben. Auch was Integrationsmöglichkeiten mit Drittanbieter-Apps und -Diensten angeht, ist Miro breit aufgestellt – von Google Drive über Evernote bis hin zu Slack und <a href="https://www.computerwoche.de/article/2732704/microsoft-azure-mit-der-deutschen-cloud-zu-neuen-geldquellen.html" target="_blank" class="idgGlossaryLink">Azure</a> Active Directory. Die Live Embed <a href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" title="API" target="_blank">API</a> bietet darüber hinaus weitere Integrationsoptionen, zum Beispiel mit:</p>



<ul class="wp-block-list">
<li><p> Microsoft Teams,</p></li>



<li><p> Asana,</p></li>



<li><p> Trello,</p></li>



<li><p> Jira,</p></li>
</ul>



<p>Miro-Boards werden dabei in die bestehenden Oberflächen der Tools eingebunden. Miro-Benutzer können auch ihre eigenen Apps mit API, SDAK und iframe embed erstellen und diese dann mit anderen über einen Marketplace teilen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Miro integriert mit Cisco Webex und zahlreichen anderen Applikationen und Services. " title="Miro integriert mit Cisco Webex und zahlreichen anderen Applikationen und Services. " src="https://images.computerwoche.de/bdb/3328299/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Miro integriert mit Cisco Webex und zahlreichen anderen Applikationen und Services. </p></figcaption></figure><p class="imageCredit">
					Foto: Miro</p></div>




<p><strong>Bemerkenswert:</strong> Mit “Stickies Capture” lassen sich Fotos von einem physischen Whiteboard oder handschriftlichen Notizen digitalisieren, in Miro bearbeiten und organisieren oder als CSV- oder Jira-Dateien exportieren. Im November 2023 hat Miro die Whiteboard-Lösung <a href="https://miro.com/newsroom/miro-acquires-freehand-app-from-invision/">Freehand von Invision erworben</a> und in sein Angebot integriert.</p>



<p><strong>Sicherheit:</strong></p>



<ul class="wp-block-list">
<li><p>Datenübertragung verschlüsselt (TLS 1.2 oder höher);</p></li>



<li><p>Daten im Ruhezustand mit AES-256 verschlüsselt;</p></li>



<li><p>Hosting auf AWS;</p></li>



<li><p>Datenspeicherung innerhalb der EU (Irland) und den USA (Virginia);</p></li>



<li><p>Cloud-Security-Alliance-, SOC2-, SOC3-, CCPA-, DSGVO- und NIST-konform;</p></li>
</ul>



<p><strong>Enterprise-Funktionen:</strong></p>



<ul class="wp-block-list">
<li><p>flexibles Lizenzierungsprogramm,</p></li>



<li><p>Analyse-Tools, </p></li>



<li><p>KI-Funktionen, </p></li>



<li><p>Unternehmens-Dashboards,</p></li>



<li><p>Meeting- und Workshop-Zusammenfassungen sowie</p></li>



<li><p>zusätzliche Sicherheitsfunktionen wie Domain-Whitelisting,</p></li>



<li><p>Link-Zugriffskontrollen und</p></li>



<li><p>Domain-Kontrolloptionen.</p></li>
</ul>



<p><strong>Preisgefüge:</strong> Kostenlos nutzbar ist Miro mit drei Boards, inklusive Templates; der <strong>Starter-Plan</strong> kostet <strong>8 Euro</strong> pro Mitglied und Monat (jährliche Abrechnung) für unbegrenzte Boards, private Board-Freigabe, benutzerdefinierte Vorlagen und mehr; der <strong>Business-Plan</strong> (für 20+ Mitglieder) kostet <strong>20 Euro</strong> pro Mitglied und Monat (jährliche Abrechnung) und bietet zusätzlich <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2778438/wunderwaffe-sso.html" target="_blank">Single Sign-On</a>, Tagespässe und externe Editoren. Der Enterprise-Plan (auf Anfrage) bietet erweiterte Sicherheits- und Verwaltungsfunktionen mit flexiblen Lizenzierungsoptionen.</p>



<h3 class="wp-block-heading"><a href="https://www.mural.co/" target="_blank" rel="noreferrer noopener">Mural</a></h3>



<p>Laut Mural wird die eigene Plattform von mehr als der Hälfte der Fortune-100-Unternehmen eingesetzt. Zwar soll jeder Mitarbeiter im Unternehmen Mural nutzen können, in erster Linie richtet sich das Visual Collaboration Tool aber an Produkt-, Beratungs-, Führungs-, Vertriebs- und Customer-Success-Teams sowie an <a title="Innovationsabteilungen" href="https://www.computerwoche.de/article/2794348/so-wird-ihr-unternehmen-innovativ.html" target="_blank">Innovationsabteilungen</a>. Die Mural-Plattform umfasst mehr als 180 anpassbare, vorgefertigte Templates und Frameworks für verschiedene Zwecke, zum Beispiel:</p>



<ul class="wp-block-list">
<li><p>Brainstorming,</p></li>



<li><p>Mind Maps,</p></li>



<li><p>Design Sprints,</p></li>



<li><p>Sales Discovery, </p></li>



<li><p>Retrospektiven,</p></li>



<li><p>anpassbare Formen und Konnektoren,</p></li>



<li><p>einfaches Diagramming und</p></li>



<li><p>“Quick Talk” (Sprachanruf innerhalb eines Mural Boards)</p></li>
</ul>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Das visuelle Interface von Mural kann für diverse Aufgaben genutzt werden, etwa die Task-Priorisierung." title="Das visuelle Interface von Mural kann für diverse Aufgaben genutzt werden, etwa die Task-Priorisierung." src="https://images.computerwoche.de/bdb/3328300/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Das visuelle Interface von Mural kann für diverse Aufgaben genutzt werden, etwa die Task-Priorisierung.</p></figcaption></figure><p class="imageCredit">
					Foto: Mural</p></div>




<p>Integrationsmöglichkeiten:</p>



<ul class="wp-block-list">
<li><p>OneDrive,</p></li>



<li><p>Google Drive,</p></li>



<li><p>Slack,</p></li>



<li><p>Microsoft Teams,</p></li>



<li><p>Atlassian Jira,</p></li>



<li><p>Adobe Creative Cloud</p></li>



<li><p>Zapier (ermöglicht weitere Integrationen mit mehr als 2.000 Drittanbieter-Apps darunter Airtable, Trello, Evernote, Salesforce und Asana)</p></li>



<li><p>demnächst soll auch eine App erscheinen, die die Einbindung von Zoom-Videokonferenzen ermöglicht.</p></li>
</ul>



<p><strong>Bemerkenswert:</strong> “Facilitation Superpowers” ermöglicht es, Timer für Aktivitäten zu setzen, andere einzuladen oder auch anonym über Ideen abzustimmen. Ebenso können bestimmte Inhalte gesperrt, Schlüsselelemente zu einer Inhaltsbibliothek hinzugefügt oder das gesamte Mural Board als PDF- oder PNG-Datei exportiert werden.</p>



<p><strong>Sicherheit:</strong></p>



<ul class="wp-block-list">
<li><p>Daten im Ruhezustand befinden sich nur in der Produktionsumgebung und sind mit AES-256 verschlüsselt;</p></li>



<li><p>Datenübertragung mit TLS v1.2 und AES_128_CGM verschlüsselt;</p></li>



<li><p>ECDHE_RSA dient als Schlüsselaustauschmechanismus;</p></li>



<li><p>Hosting auf Microsoft Azure;</p></li>



<li><p>Single Sign-On (SAML 2.0);</p></li>



<li><p>CCPA- und DSGVO-konform, SOC-2-Typ-2-Zertifizierung;</p></li>
</ul>



<p><strong>Enterprise-Funktionen:</strong></p>



<ul class="wp-block-list">
<li><p>Unternehmens-Dashboard mit Überblick über die Workspace-Aktivitäten zur Verwaltung und Überwachung der Nutzung; </p></li>



<li><p>KI-Funktionen, </p></li>



<li><p>Abrechnungsgruppen;</p></li>



<li><p>Unternehmens-APIs für Deprovisionierung und Audit-Protokolle;</p></li>



<li><p>API-Schlüsselverwaltung;</p></li>



<li><p>Self-Service-Single-Sign-On sowie</p></li>



<li><p>Zugang zu Schulungen und praktischem Support.</p></li>
</ul>



<p><strong>Preisgefüge:</strong> kostenloser <strong>Free-Tarif</strong> (3 Murals, unbegrenzte Mitglieder); <strong>Team+-Plan</strong> ab <strong>9,99 Dollar</strong> pro Monat und Nutzer; der <strong>Business-Tarif</strong> inklusive SSO kostet <strong>17,99 Dollar</strong> pro Nutzer und Monat; Enterprise-Pläne sind – auf Anfrage – ebenfalls verfügbar;</p>



<h3 class="wp-block-heading"><a href="https://stormboard.com/" target="_blank" rel="noreferrer noopener">Stormboard</a></h3>



<p>Stormboard wurde entwickelt, um die Meeting-Probleme zu lösen, die ein durchschnittliches Digital Whiteboard nicht bewältigen kann. Die digitalen Arbeitsbereiche – Storms genannt – stellen Tools zur Verfügung, die Teams dabei unterstützen sollen, Ideen zu priorisieren und zu organisieren, Aufgaben zuzuweisen und nach einem Meeting aufzubereiten.</p>



<p>Zu den Funktionen gehören:</p>



<ul class="wp-block-list">
<li><p>agile Integrationen in Echtzeit,</p></li>



<li><p>Aufgabenverwaltung,</p></li>



<li><p>Reporting</p></li>



<li><p>die Möglichkeit, alle Inhalte als Notizen, Whiteboards, Dateien, Bilder und Videos zu teilen</p></li>



<li><p>automatisierte Erstellung von Besprechungsprotokollen</p></li>



<li><p>anpassbare Templates mit interaktiven Anleitungen</p></li>
</ul>



<p>Stormboard bietet Integrationen mit mehreren Business-Plattformen von Drittanbietern, darunter:</p>



<ul class="wp-block-list">
<li><p>Slack,</p></li>



<li><p>Microsoft Teams,</p></li>



<li><p>Jira,</p></li>



<li><p>Zapier und</p></li>



<li><p>Azure DevOps.</p></li>
</ul>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Stormboard stellt digitale Workspaces zur Verfügung, die Teams dabei unterstützen sollen, Projekte zu planen und im Blick zu behalten." title="Stormboard stellt digitale Workspaces zur Verfügung, die Teams dabei unterstützen sollen, Projekte zu planen und im Blick zu behalten." src="https://images.computerwoche.de/bdb/3328301/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Stormboard stellt digitale Workspaces zur Verfügung, die Teams dabei unterstützen sollen, Projekte zu planen und im Blick zu behalten.</p></figcaption></figure><p class="imageCredit">
					Foto: Stormboard</p></div>




<p><strong>Bemerkenswert:</strong> Karteikarten ermöglicht die zeilenweise Eingabe von Inhalten, so dass Benutzer Listen erstellen, Inhalte organisieren und gruppieren und auf einen Substorm (einen spezifischen Unterarbeitsbereich innerhalb eines Sturms) zugreifen können, in dem Teams an Projekten arbeiten, Brainstorming betreiben und Zeitpläne erstellen können.</p>



<p><strong>Sicherheit:</strong></p>



<ul class="wp-block-list">
<li><p>Datenübertragung mit TLS-Verschlüsselung</p></li>



<li><p>Verschlüsselung für Daten im Ruhezustand variiert je nach Abonnement</p></li>



<li><p>Hosting auf AWS</p></li>



<li><p>SOC-2-Zertifizierung</p></li>



<li><p>Zwei-Faktor-Authentifizierung (über Authenticator-App)</p></li>
</ul>



<p><strong>Enterprise-Funktionen:</strong></p>



<ul class="wp-block-list">
<li><p>Rechnungsstellung,</p></li>



<li><p>Single Sign-On,</p></li>



<li><p>erweiterte Benutzerverwaltung,</p></li>



<li><p>Service Level Agreements,</p></li>



<li><p>Single Tenant,</p></li>



<li><p>Aufbewahrung von Unternehmensdaten,</p></li>



<li><p>Corporate Branding,</p></li>



<li><p>zusätzliche Unternehmensvorlagen,</p></li>



<li><p>Concierge-Support, </p></li>



<li><p>KI-Funktionen, </p></li>



<li><p>Schulungsprogramme;</p></li>
</ul>



<p><strong>Preisgefüge:</strong> Der <strong>Personal-Plan</strong> ist für Einzelpersonen und Teams mit bis zu fünf Personen <strong>kostenlos</strong>; <strong>Business</strong> kostet <strong>10 Dollar</strong> pro Benutzer pro Monat; Enterprise-Pläne mit individueller Preisgestaltung gibt es auf Anfrage; kostenlose Testversionen sind verfügbar für Business- und Enterprise-Pläne.</p>



<h3 class="wp-block-heading">Mehr Digital Whiteboard Tools</h3>



<p>Nicht fündig geworden? Vielleicht reicht Ihnen auch eines der folgenden Tools, darunter Whiteboard-“Emulatoren” und Online Tools, die alle kostenlos getestet werden können:</p>



<ul class="wp-block-list">
<li><p><a title="Allo" href="https://allo.io/landing" target="_blank" rel="noopener">Allo</a> bietet einen Remote Workspace, der einfaches Projektmanagement mit Whiteboard-Funktionen kombiniert;</p></li>



<li><p><a title="Ayoa" href="https://www.ayoa.com/" target="_blank" rel="noopener">Ayoa</a> ist ein All-in-One Online Whiteboard beziehungsweise eine Mind Mapping App, beispielsweise für Brainstorming-Zwecke;</p></li>



<li><p><a title="Explain Everything" href="https://explaineverything.com/" target="_blank" rel="noopener">Explain Everything</a> ist ein Whiteboard für digitalen Unterricht;</p></li>



<li><p><a title="FlatFrog" href="https://www.flatfrog.com/" target="_blank" rel="noopener">FlatFrog</a> ist ein Projektvisualisierungs- und Task Tracking Tool für Agile, Lean, Pulse und andere Projekte;</p></li>



<li><p><a title="iObeya" href="https://www.iobeya.com/" target="_blank" rel="noopener">iObeya</a> ist eine Enterprise Collaboration App mit Digital Visual Management, das auf Lean- und Agile-Prinzipien beruht;</p></li>



<li><p>das Tool <a title="Milanote" href="https://milanote.com/" target="_blank" rel="noopener">Milanote</a> organisiert Ideen und Projekte in Form von visuellen Boards;</p></li>
</ul>



<p>(fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/3547198/enterprise-buyers-guide-digital-whiteboard-software.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong><br></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Hidden ChatGPT Features: Scheduled Tasks, Image Creation, and More]]></title>
<description><![CDATA[Learn 10 underused ChatGPT features, from Projects and Canvas to Deep Research and Scheduled Tasks, that can make AI more useful at work.]]></description>
<link>https://tsecurity.de/de/3576274/it-nachrichten/10-hidden-chatgpt-features-scheduled-tasks-image-creation-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576274/it-nachrichten/10-hidden-chatgpt-features-scheduled-tasks-image-creation-and-more/</guid>
<pubDate>Fri, 05 Jun 2026 20:02:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn 10 underused ChatGPT features, from Projects and Canvas to Deep Research and Scheduled Tasks, that can make AI more useful at work.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub adds new Copilot features as usage-based billing takes effect]]></title>
<description><![CDATA[GitHub is expanding Copilot beyond the IDE with a new desktop application and a new collaborative work surface called canvas as part of its broader efforts to pitch the AI-assisted coding tool as the control center for agent-native software development.



The desktop application announced at Mic...]]></description>
<link>https://tsecurity.de/de/3576235/ai-nachrichten/github-adds-new-copilot-features-as-usage-based-billing-takes-effect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576235/ai-nachrichten/github-adds-new-copilot-features-as-usage-based-billing-takes-effect/</guid>
<pubDate>Fri, 05 Jun 2026 19:49:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>GitHub is expanding <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">Copilot</a> beyond the IDE with a new desktop application and a new collaborative work surface called canvas as part of its broader efforts to pitch the AI-assisted coding tool as the control center for agent-native software development.</p>



<p>The desktop application announced at Microsoft’s annual Build conference this week is designed to give developers a dedicated environment for working with AI agents throughout the software development lifecycle, rather than limiting those interactions to code-generation tasks inside an editor, the company wrote in a <a href="https://github.blog/news-insights/product-news/github-copilot-app-the-agent-native-desktop-experience/?utm_source=live-blog-copilot-app-desktop-blog-cta&amp;utm_medium=blog&amp;utm_campaign=msbuild-2026" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>The application includes a collaborative workspace called canvas where developers can brainstorm ideas, refine requirements, generate plans, and iterate on projects alongside AI, it said.</p>



<p>It also has new Agent Merge and code review features that enable developers to automate Copilot to combine tasks of different agents to complete a specific goal or conduct autonomous code reviews according to set standards, it said.</p>



<p>These new features could reduce context switching, increase engineering efficiency, and accelerate delivery cycles, said <a href="https://www.hfsresearch.com/team/philfersht/" target="_blank" rel="noreferrer noopener">Phil Fersht</a>, CEO of HFS Research.</p>



<h2 class="wp-block-heading">Shift in pricing justified?</h2>



<p>However, despite the new features, much of the conversation among developers in recent weeks has centered on a different topic: this week’s <a href="https://www.infoworld.com/article/4164236/github-shifts-copilot-to-usage-based-billing-signaling-new-cost-model-for-enterprise-ai-tools.html">shift to a usage-based billing model for GitHub Copilot</a> that it announced in April.</p>



<p>The changes were met with a wave of criticism on the GitHub <a href="https://github.com/orgs/community/discussions/192948?sort=top#discussioncomment-17134630" target="_blank" rel="noreferrer noopener">community forum</a>, where some users accused the company of a “bait and switch,” while others requested refunds or announced plans to cancel their subscriptions.</p>



<p>For analysts, though, the pricing change was, at least from GitHub’s point of view, necessary and justified.</p>



<p>“The pricing change is justified by where GitHub is going, not by where the product is today. Running multiple agents in parallel with sandboxes, canvas reviews, and Agent Merge looping through CI is closer to cloud compute than an IDE plugin, and you cannot price compute on a flat seat fee. So metered billing is the right call structurally,” said <a href="https://www.linkedin.com/in/advaitpatel93" target="_blank" rel="noreferrer noopener">Advait Patel</a>, a senior reliability engineer at Broadcom.</p>



<p>Fersht said developers and CIOs need to focus on Copilot’s metamorphosis from being a coding assistant into a platform for orchestrating software-development agents and workflows.</p>



<p>“That changes the ROI conversation significantly. CIOs should stop thinking about Copilot as a seat-license productivity tool and instead evaluate it as an AI-powered software delivery platform,” he said. “The metrics shift from ‘lines of code generated’ to broader operational outcomes such as release velocity, code quality, defect reduction and engineering efficiency.”</p>



<p>GitHub is not the first company offering vibe-coding tools to rethink its pricing strategy as AI agents proliferate across enterprises and evolve to take on more complex software-development tasks that are computationally more intensive.</p>



<p>Over the past year, <a href="https://www.infoworld.com/article/4048198/the-era-of-cheap-ai-coding-assistants-may-be-over.html">platforms such as Claude Code, Replit, Cursor, and Kiro have repeatedly adjusted their pricing structures</a> to account for mounting infrastructure costs, limited GPU availability, and the expense of serving increasingly sophisticated AI models and agents, despite furor among their users.</p>



<h2 class="wp-block-heading">For CIOs, the challenge is proving ROI</h2>



<p>That common pressure across AI coding vendors is why <a href="https://www.linkedin.com/in/amitchandak78/" target="_blank" rel="noreferrer noopener">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika, thinks developers and CIOs should focus less on GitHub’s pricing mechanics and more on whether these increasingly capable tools are delivering measurable business value.</p>



<p>“The new features that GitHub announced can act as productivity multipliers as well as features that increase consumption without delivering proportional business value. Without productivity baselines established before adoption, enterprises risk absorbing higher costs with no clear line back to delivered value,” Chandak said.</p>



<p>For Fersht, developers and CIOs will need to focus on governance, monitoring and financial controls as the pricing model is changing.</p>



<p>“The governance challenge is very real. Autonomous agents can continuously reason, test, revise and interact with multiple systems in ways that create far less predictable consumption patterns than traditional SaaS tools,” he said.</p>



<p>Patel, however, advised users and decision-makers to be more skeptical, especially since the new features are currently in technical preview.</p>



<p>“Customers are being asked to pay variable rates now for value that has not been validated in production. Do not assume new capabilities justify higher spend,” he said. “Instead, run a 90 day pilot, measure PRs merged per dollar before and after, and let the data decide. If the ratio improves, the pricing is fair. If it does not, you are paying for promise, not delivery,” Patel added.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[viable/strict/1780671771]]></title>
<description><![CDATA[[Overlap Scheduling] Fix SymInt crash in collective/compute node benc…]]></description>
<link>https://tsecurity.de/de/3575787/downloads/viablestrict1780671771/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575787/downloads/viablestrict1780671771/</guid>
<pubDate>Fri, 05 Jun 2026 17:17:04 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>[Overlap Scheduling] Fix SymInt crash in collective/compute node benc…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Canvas Ransomware Attack: How ShinyHunters Exposed a Global Education Security Crisis]]></title>
<description><![CDATA[ShinyHunters’ Canvas ransomware attack exposed millions of student records, highlighting growing risks of data exfiltration in education.]]></description>
<link>https://tsecurity.de/de/3575756/it-security-nachrichten/the-canvas-ransomware-attack-how-shinyhunters-exposed-a-global-education-security-crisis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575756/it-security-nachrichten/the-canvas-ransomware-attack-how-shinyhunters-exposed-a-global-education-security-crisis/</guid>
<pubDate>Fri, 05 Jun 2026 16:56:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ShinyHunters’ Canvas ransomware attack exposed millions of student records, highlighting growing risks of data exfiltration in education.]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/484bc276f1928d6643993ce92485d7283f855b6c]]></title>
<description><![CDATA[[Overlap Scheduling] Fix SymInt crash in collective/compute node benc…]]></description>
<link>https://tsecurity.de/de/3575075/downloads/trunk484bc276f1928d6643993ce92485d7283f855b6c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575075/downloads/trunk484bc276f1928d6643993ce92485d7283f855b6c/</guid>
<pubDate>Fri, 05 Jun 2026 12:46:34 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>[Overlap Scheduling] Fix SymInt crash in collective/compute node benc…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nonfree DRM'd Games on GNU/Linux: Good or Bad? (by Richard Stallman)]]></title>
<description><![CDATA[Nonfree DRM'd Games on GNU/Linux: Good or Bad? by Richard Stallman A well known company, Valve, that distributes nonfree computer games with Digital Restrictions Management, recently announced it would distribute these games for GNU/Linux. What good and bad effects can this have? I suppose that a...]]></description>
<link>https://tsecurity.de/de/3573226/linux-tipps/nonfree-drmd-games-on-gnulinux-good-or-bad-by-richard-stallman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573226/linux-tipps/nonfree-drmd-games-on-gnulinux-good-or-bad-by-richard-stallman/</guid>
<pubDate>Thu, 04 Jun 2026 18:09:43 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><blockquote> <h2>Nonfree DRM'd Games on GNU/Linux: Good or Bad?</h2> <p><em>by <a href="https://www.stallman.org/">Richard Stallman</a></em></p> <p>A well known company, Valve, that distributes nonfree computer games with Digital Restrictions Management, recently announced it would distribute these games for GNU/Linux. What good and bad effects can this have?</p> <p>I suppose that availability of popular nonfree programs on the GNU/Linux system can boost adoption of the system. However, the aim of GNU goes beyond “success”; its purpose is to <a href="https://www.gnu.org/philosophy/free-software-even-more-important.en.html">bring freedom to the users</a>. Thus, the larger question is how this development affects users' freedom.</p> <p>The problem with these games is <em>not</em> that they are <a href="https://www.gnu.org/philosophy/words-to-avoid.en.html#Commercial">commercial</a>. (We see nothing wrong with that.) It is <em>not</em> that <a href="https://www.gnu.org/philosophy/selling.html">the developers sell copies</a>; that's not wrong either. The problem is that the games contain software that is <a href="https://www.gnu.org/philosophy/free-sw.en.html">not free</a> (free in the sense of freedom, of course).</p> <p>Nonfree game programs (like other nonfree programs) are unethical because they deny freedom to their users. (Game art is a different issue, because it <a href="https://www.gnu.org/philosophy/copyright-versus-community.en.html">isn't software</a>.) If you want freedom, one requisite for it is not having or running nonfree programs on your computer. That much is clear.</p> <p>However, if you're going to use these games, you're better off using them on GNU/Linux rather than on Microsoft Windows. At least you avoid <a href="https://www.fsf.org/windows">the harm to your freedom that Windows would do</a>.</p> <p>Thus, in direct practical terms, this development can do both harm and good. It might encourage GNU/Linux users to install these games, and it might encourage users of the games to replace Windows with GNU/Linux. My guess is that the direct good effect will be bigger than the direct harm. But there is also an indirect effect: what does the use of these games teach people in our community?</p> <p>Any GNU/Linux distro that comes with software to offer these games will teach users that the point is not freedom. <a href="https://www.gnu.org/distros/common-distros.en.html">Nonfree software in GNU/Linux distros</a> already works against the goal of freedom. Adding these games to a distro would augment that effect.</p> <p>Free software is a matter of freedom, not price. A free game need not be gratis. It is feasible to develop free games commercially, while respecting your freedom to change the software you use. Since the art in the game is not software, it is not ethically imperative to make the art free—though free art is an additional contribution. There is in fact free game software developed by companies, as well as free games developed noncommercially by volunteers. Crowdfunding development will only get easier.</p> <p>But if we suppose that it is <em>not feasible</em> in the current situation to develop a certain kind of free game—what would follow then? There's no good in writing it as a nonfree game. To have freedom in your computing requires rejecting nonfree software, pure and simple. You as a freedom-lover won't use the nonfree game if it exists, so you won't lose anything if it does not exist.</p> <p>If you want to promote the cause of freedom in computing, please take care not to talk about the availability of these games on GNU/Linux as support for our cause. Instead you could tell people about the <a href="https://libregamewiki.org/Main_Page">libre games wiki</a> that attempts to catalog free games, the <a href="https://web.archive.org/web/20260115013420/https://forum.freegamedev.net/index.php">Free Game Dev Forum</a>, and the LibrePlanet Gaming Collective's <a href="https://libreplanet.org/wiki/Group:LibrePlanet_Gaming_Collective">free gaming night</a>.</p> <h3>Note</h3> <p><a href="https://web.archive.org/web/20191125215630/http://onpon4.github.io/articles/gaming-trap.html">Watch out for “nonfree game data” that actually contains software.</a></p> </blockquote> <p><a href="https://www.gnu.org/philosophy/nonfree-games.en.html">https://www.gnu.org/philosophy/nonfree-games.en.html</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/WonderOlymp2"> /u/WonderOlymp2 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1twhd3q/nonfree_drmd_games_on_gnulinux_good_or_bad_by/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1twhd3q/nonfree_drmd_games_on_gnulinux_good_or_bad_by/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/136810cc9ce08999dc335f503bfe046d06100b74: Rename distributed collective ops to _single naming scheme (#186123)]]></title>
<description><![CDATA[Align the public torch.distributed collective APIs with the naming scheme
used by torchcomms' TorchCommBackend, where the single-tensor variants are
suffixed with _single. all_gather_into_tensor is renamed to
all_gather_single and reduce_scatter_tensor to reduce_scatter_single.
The previous names...]]></description>
<link>https://tsecurity.de/de/3571700/downloads/trunk136810cc9ce08999dc335f503bfe046d06100b74-rename-distributed-collective-ops-to-single-naming-scheme-186123/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571700/downloads/trunk136810cc9ce08999dc335f503bfe046d06100b74-rename-distributed-collective-ops-to-single-naming-scheme-186123/</guid>
<pubDate>Thu, 04 Jun 2026 09:01:45 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Align the public torch.distributed collective APIs with the naming scheme<br>
used by torchcomms' TorchCommBackend, where the single-tensor variants are<br>
suffixed with <code>_single</code>. <code>all_gather_into_tensor</code> is renamed to<br>
<code>all_gather_single</code> and <code>reduce_scatter_tensor</code> to <code>reduce_scatter_single</code>.</p>
<p>The previous names are kept as thin wrappers that delegate to the new<br>
functions and are marked deprecated via FutureWarning, so existing code keeps<br>
working. The new names are wired into the Dynamo / non-strict-export<br>
collective remaps so they are traceable under torch.compile just like the old<br>
names. Direct test usages are updated to the new names.</p>
<p>To review, start with distributed_c10d.py (the rename and the deprecated<br>
aliases), then the remap plumbing in _functional_collectives.py,<br>
_dynamo/variables/functions.py and _export/non_strict_utils.py, then the docs<br>
and test updates.</p>
<p>Authored by Claude.<br>
Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583448510" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/186123" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/186123/hovercard" href="https://github.com/pytorch/pytorch/pull/186123">#186123</a><br>
Approved by: <a href="https://github.com/tushar00jain">https://github.com/tushar00jain</a>, <a href="https://github.com/kapilsh">https://github.com/kapilsh</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Confirms Permanent Closure Dates for Three US Stores]]></title>
<description><![CDATA[Apple has confirmed the final closing dates for three retail stores in the United States, ending operations at locations in Connecticut, Maryland, and California later this month. The company says the decision comes after changing conditions at the shopping centers where the stores are located.

...]]></description>
<link>https://tsecurity.de/de/3571417/ios-mac-os/apple-confirms-permanent-closure-dates-for-three-us-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571417/ios-mac-os/apple-confirms-permanent-closure-dates-for-three-us-stores/</guid>
<pubDate>Thu, 04 Jun 2026 06:23:35 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has confirmed the final closing dates for three retail stores in the United States, ending operations at locations in Connecticut, Maryland, and California later this month. The company says the decision comes after changing conditions at the shopping centers where the stores are located.



The following Apple Stores will permanently close on June 20, 2026:




Apple Trumbull in Trumbull, Connecticut at 9 p.m.



Apple North County in Escondido, California at 9 p.m.



Apple Towson Town Center in Towson, Maryland at 8 p.m.




Apple said it evaluated the long-term conditions at these malls before making the decision. According to the company, several retailers have left these locations in recent years, while overall mall conditions have continued to decline.



What Happens to Employees?



Apple says employees at the Trumbull and North County stores will continue working at nearby Apple retail locations. Workers at the Towson Town Center store will be able to apply for other open positions within the company under the terms of their collective bargaining agreement.



The Towson location made history in 2022 when it became the first unionized Apple Store in the United States. Following the closure announcement, the International Association of Machinists and Aerospace Workers criticized the decision and raised concerns about its impact on employees and the local community.



Despite these closures, Apple continues investing in its retail business. Over the past year, the company has opened 11 new stores worldwide while also upgrading or relocating 14 existing locations. In the United States, Apple has opened two new stores and completed upgrades at eight others.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI saves workers a day a week, but they don’t know what to do with it]]></title>
<description><![CDATA[A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.



The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontlin...]]></description>
<link>https://tsecurity.de/de/3571382/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571382/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</guid>
<pubDate>Thu, 04 Jun 2026 06:01:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.</p>



<p>The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontline employees who use AI on a regular basis save upwards of a full day each week; however, 66% are not given guidance on what to do with time they save, and “more than half don’t redirect it to strategic work.”</p>



<p>The <a href="https://www.bcg.com/publications/2026/ai-at-work-why-strategy-matters-more-than-tools" target="_blank" rel="nofollow">report</a>, <em>AI at Work: Strategy Matters More Than Tools</em>, is based on a global survey of 11,749 employees in 14 markets, from industries ranging from financial services to the healthcare sector.</p>



<p><a href="https://www.bcg.com/about/people/experts/david-martin" target="_blank" rel="nofollow">David Martin</a>, global leader of people and organization work at BCG, and the report’s lead author, said via email that the number of employees lacking the required guidance is surprising, “but it also tracks with what we see in many AI transformations. Companies have moved quickly to give people tools, but many have not yet redesigned the work around those tools.”</p>



<p>Saved time, he added, does not automatically become value. If a frontline employee saves a few hours a week, but has no direction on whether to use that time for customer service, quality improvement, innovation, or faster execution, “that value can simply leak out of the organization”</p>



<p>The fix is for leaders to change the scoreboard, Martin said: “Don’t just measure AI adoption or hours saved. Decide where that time should go, measure whether it is being reinvested, and give managers clear guidance on how to help teams use it. This is where AI transformation becomes a management challenge, not just a technology rollout.”</p>



<p>In fact, said <a href="https://www.bcg.com/about/people/experts/vinciane-beauchene" target="_blank" rel="nofollow">Vinciane Beauchene,</a> a managing director and partner at BCG and one of the report’s five co-authors, “the first wave of AI focused on individual productivity. The coming wave will need to transform collective work.”</p>



<p>“Everyone is talking about AI replacing work,” she said, “but it is in fact really about rethinking the human value-add inside.”</p>



<h2 class="wp-block-heading">A managerial revolution underway</h2>



<p>According to Beauchene, “this is the role of leaders. Our survey reveals a true managerial revolution in the age of AI; 65% of managers and leaders now believe agents will take over at least half of their job in the next three years, and frontline workers see their jobs evolving towards more managing and directing AI.”</p>



<p>A BCG <a href="https://www.bcg.com/press/3june2026-ai-reshaping-jobs-faster-than-companies-reshaping-work" target="_blank" rel="nofollow">release</a> stated that the survey also highlights the continued emergence and maturity of AI agents, with 30% of respondents saying that agents are already integrated into workflows, more than double the number from last year’s report (13%).</p>



<p>Other key findings revealed that AI adoption among frontline workers has surged, with 74% saying they now use it daily or a few times a week, which is up 23 percentage points from a year ago. In addition, six out of 10 people believe that, within the next three years, AI agents could do at least half of their jobs.</p>



<p>And a survey <a href="https://web-assets.bcg.com/eb/92/4b39b729403fb6fcae4ff974b234/ai-at-work-slideshow-jun-2026-1.pdf" target="_blank" rel="nofollow">slideshow</a> released by the company pointed out, “the AI ‘honeymoon’ won’t last unless leaders bring strategic clarity driving sustained impact AI’s novelty and cognitive stretch fuel enjoyment early on. But sustained joy comes from strategic clarity. Employees thrive when the direction is real and the message reaches them with strong CEO involvement.”</p>



<h2 class="wp-block-heading">Strategic clarity is a key differentiator</h2>



<p>The report suggests that CEOs take a holistic approach to AI transformations by focusing on business outcomes as opposed to AI usage, investing in “redesigning work end-to-end, not in more tools,” placing people at the heart of that redesign, and governing AI not as a one-off program, but as a moving target.</p>



<p>Overall, BCG says that strategic clarity, “more broadly emerges from the survey as the most crucial differentiator in sustaining AI’s impact over time as organizations are moving past simply implementing AI tools in use case deployment initiatives.”</p>



<p>Increasingly, it adds, “the focus is shifting to redesigning end-to-end workﬂows and processes to reimagine functions, as well as to building and innovating new business models and products to drive growth, which have nearly doubled year-over-year.”</p>



<p>Global leader of BCG’s tech build and design unit BCG X <a href="https://www.bcg.com/about/people/experts/sylvain-duranton" target="_blank" rel="nofollow">Sylvain Duranton</a>, also a report co-author, added, “employees don’t push back on AI intensity; they thrive when the strategy is clear, the direction is real, and the message reaches them.”</p>



<p>He added, “Business value and employee enjoyment aren’t trade-offs. The organizations capturing the greatest business value are the same ones where employees enjoy work the most.”</p>



<p>Despite the opportunity, the report notes that only one-third of frontline employees say that leadership’s communications about AI are clear, and only 28% “see a strong connection between what leaders say and what the organization actually does.”</p>



<p>However, Martin said, management can’t deal with this situation on its own. “CIOs have a critical role, but this is not a problem they can solve alone, and I would not frame it as something IT created by itself,” he noted.</p>



<p>Many organizations, he said, “started with the natural first step of getting tools into people’s hands safely and at scale. That was necessary, but it is not sufficient.”</p>



<p>The next phase “has to be much more cross-functional,” he said. “CIOs should help set the technology foundation, governance, data model, and measurement systems, but they also have an important role in creating strategic clarity. Employees need to understand why the organization is using AI, where it is meant to create value, and how it should change the work.”</p>



<p>Martin pointed out that CIOs should also pay close attention to cognitive load, especially on technology teams, as those teams are often the heaviest AI users.</p>



<p>“This means they may be among the most exposed to the mental strain that can come with reviewing outputs, managing AI tools, and keeping up with constant change,” he observed. The biggest gains come when technology strategy, workforce strategy, and employee experience move together. If AI remains only an IT program, companies will “undercapture” the value.</p>



<h2 class="wp-block-heading">New expectations</h2>



<p>The abundance of AI activity is also having another effect, in that 60% of respondents say the bar for work that counts as ‘good enough’ is now higher.</p>



<p>That, said Martin, is because AI is changing expectations. “If a tool can produce a first draft, summarize research, generate options, or automate a routine task, then ‘good enough’ moves up the value chain,” he said. “People are being asked to spend less time producing basic output and more time exercising judgment like checking quality, improving the answer, making decisions, and applying context.” </p>



<p>While that can be a good thing, he said, because it can make work more interesting and more valuable, “it also explains why employees are feeling more mental strain. The work that remains is often more complex. Leaders need to recognize that AI does not just make people faster, it changes what excellence looks like. That means companies need to update training, performance expectations, and management support accordingly.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI saves workers a day a week, but they don’t know what to do with it]]></title>
<description><![CDATA[A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.



The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontlin...]]></description>
<link>https://tsecurity.de/de/3571380/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571380/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</guid>
<pubDate>Thu, 04 Jun 2026 06:01:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.</p>



<p>The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontline employees who use AI on a regular basis save upwards of a full day each week; however, 66% are not given guidance on what to do with time they save, and “more than half don’t redirect it to strategic work.”</p>



<p>The <a href="https://www.bcg.com/publications/2026/ai-at-work-why-strategy-matters-more-than-tools" target="_blank" rel="noreferrer noopener">report</a>, <em>AI at Work: Strategy Matters More Than Tools</em>, is based on a global survey of 11,749 employees in 14 markets, from industries ranging from financial services to the healthcare sector.</p>



<p><a href="https://www.bcg.com/about/people/experts/david-martin" target="_blank" rel="noreferrer noopener">David Martin</a>, global leader of people and organization work at BCG, and the report’s lead author, said via email that the number of employees lacking the required guidance is surprising, “but it also tracks with what we see in many AI transformations. Companies have moved quickly to give people tools, but many have not yet redesigned the work around those tools.”</p>



<p>Saved time, he added, does not automatically become value. If a frontline employee saves a few hours a week, but has no direction on whether to use that time for customer service, quality improvement, innovation, or faster execution, “that value can simply leak out of the organization”</p>



<p>The fix is for leaders to change the scoreboard, Martin said: “Don’t just measure AI adoption or hours saved. Decide where that time should go, measure whether it is being reinvested, and give managers clear guidance on how to help teams use it. This is where AI transformation becomes a management challenge, not just a technology rollout.”</p>



<p>In fact, said <a href="https://www.bcg.com/about/people/experts/vinciane-beauchene" target="_blank" rel="noreferrer noopener">Vinciane Beauchene,</a> a managing director and partner at BCG and one of the report’s five co-authors, “the first wave of AI focused on individual productivity. The coming wave will need to transform collective work.”</p>



<p>“Everyone is talking about AI replacing work,” she said, “but it is in fact really about rethinking the human value-add inside.”</p>



<h2 class="wp-block-heading">A managerial revolution underway</h2>



<p>According to Beauchene, “this is the role of leaders. Our survey reveals a true managerial revolution in the age of AI; 65% of managers and leaders now believe agents will take over at least half of their job in the next three years, and frontline workers see their jobs evolving towards more managing and directing AI.”</p>



<p>A BCG <a href="https://www.bcg.com/press/3june2026-ai-reshaping-jobs-faster-than-companies-reshaping-work" target="_blank" rel="noreferrer noopener">release</a> stated that the survey also highlights the continued emergence and maturity of AI agents, with 30% of respondents saying that agents are already integrated into workflows, more than double the number from last year’s report (13%).</p>



<p>Other key findings revealed that AI adoption among frontline workers has surged, with 74% saying they now use it daily or a few times a week, which is up 23 percentage points from a year ago. In addition, six out of 10 people believe that, within the next three years, AI agents could do at least half of their jobs.</p>



<p>And a survey <a href="https://web-assets.bcg.com/eb/92/4b39b729403fb6fcae4ff974b234/ai-at-work-slideshow-jun-2026-1.pdf" target="_blank" rel="noreferrer noopener">slideshow</a> released by the company pointed out, “the AI ‘honeymoon’ won’t last unless leaders bring strategic clarity driving sustained impact AI’s novelty and cognitive stretch fuel enjoyment early on. But sustained joy comes from strategic clarity. Employees thrive when the direction is real and the message reaches them with strong CEO involvement.”</p>



<h2 class="wp-block-heading">Strategic clarity is a key differentiator</h2>



<p>The report suggests that CEOs take a holistic approach to AI transformations by focusing on business outcomes as opposed to AI usage, investing in “redesigning work end-to-end, not in more tools,” placing people at the heart of that redesign, and governing AI not as a one-off program, but as a moving target.</p>



<p>Overall, BCG says that strategic clarity, “more broadly emerges from the survey as the most crucial differentiator in sustaining AI’s impact over time as organizations are moving past simply implementing AI tools in use case deployment initiatives.”</p>



<p>Increasingly, it adds, “the focus is shifting to redesigning end-to-end workﬂows and processes to reimagine functions, as well as to building and innovating new business models and products to drive growth, which have nearly doubled year-over-year.”</p>



<p>Global leader of BCG’s tech build and design unit BCG X <a href="https://www.bcg.com/about/people/experts/sylvain-duranton" target="_blank" rel="noreferrer noopener">Sylvain Duranton</a>, also a report co-author, added, “employees don’t push back on AI intensity; they thrive when the strategy is clear, the direction is real, and the message reaches them.”</p>



<p>He added, “Business value and employee enjoyment aren’t trade-offs. The organizations capturing the greatest business value are the same ones where employees enjoy work the most.”</p>



<p>Despite the opportunity, the report notes that only one-third of frontline employees say that leadership’s communications about AI are clear, and only 28% “see a strong connection between what leaders say and what the organization actually does.”</p>



<p>However, Martin said, management can’t deal with this situation on its own. “CIOs have a critical role, but this is not a problem they can solve alone, and I would not frame it as something IT created by itself,” he noted.</p>



<p>Many organizations, he said, “started with the natural first step of getting tools into people’s hands safely and at scale. That was necessary, but it is not sufficient.”</p>



<p>The next phase “has to be much more cross-functional,” he said. “CIOs should help set the technology foundation, governance, data model, and measurement systems, but they also have an important role in creating strategic clarity. Employees need to understand why the organization is using AI, where it is meant to create value, and how it should change the work.”</p>



<p>Martin pointed out that CIOs should also pay close attention to cognitive load, especially on technology teams, as those teams are often the heaviest AI users.</p>



<p>“This means they may be among the most exposed to the mental strain that can come with reviewing outputs, managing AI tools, and keeping up with constant change,” he observed. The biggest gains come when technology strategy, workforce strategy, and employee experience move together. If AI remains only an IT program, companies will “undercapture” the value.</p>



<h2 class="wp-block-heading">New expectations</h2>



<p>The abundance of AI activity is also having another effect, in that 60% of respondents say the bar for work that counts as ‘good enough’ is now higher.</p>



<p>That, said Martin, is because AI is changing expectations. “If a tool can produce a first draft, summarize research, generate options, or automate a routine task, then ‘good enough’ moves up the value chain,” he said. “People are being asked to spend less time producing basic output and more time exercising judgment like checking quality, improving the answer, making decisions, and applying context.” </p>



<p>While that can be a good thing, he said, because it can make work more interesting and more valuable, “it also explains why employees are feeling more mental strain. The work that remains is often more complex. Leaders need to recognize that AI does not just make people faster, it changes what excellence looks like. That means companies need to update training, performance expectations, and management support accordingly.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4181057/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | The Post-NVD Era: A Call for Global CVE Decentralization]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 0x - Views:14 For decades, the National Vulnerability Database (NVD), maintained by NIST, has served as a cornerstone of vulnerability intelligence, providing crucial enrichment for Common Vulnerabilities and Exposures (CVEs). However, the NVD is grappling with an u...]]></description>
<link>https://tsecurity.de/de/3571070/it-security-video/black-hat-europe-2025-the-post-nvd-era-a-call-for-global-cve-decentralization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571070/it-security-video/black-hat-europe-2025-the-post-nvd-era-a-call-for-global-cve-decentralization/</guid>
<pubDate>Thu, 04 Jun 2026 01:32:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 0x - Views:14 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/akiGi2WnHBU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>For decades, the National Vulnerability Database (NVD), maintained by NIST, has served as a cornerstone of vulnerability intelligence, providing crucial enrichment for Common Vulnerabilities and Exposures (CVEs). However, the NVD is grappling with an unprecedented backlog, stemming from budget cuts, an exponential surge in vulnerability disclosures, and inherent technical rigidities. This crisis has exposed its fragility and the systemic limitations of a centralized vulnerability management model. A model that leaves organizations blind to critical threats and exacerbates operational burdens. This talk argues that the current NVD crisis is a call for a fundamental paradigm shift, we must move towards global CVE decentralization now!<br />
<br />
We meticulously dissect the NVD's failures and their far-reaching implications, then envision and advocate for a resilient, scalable, and collaborative decentralized ecosystem. By exploring pioneering models such as the Global CVE Allocation System (GCVE), the principles of Federated Search, and the potential of blockchain technology, this talk proposes a multi-faceted architectural evolution. We outline a comprehensive roadmap, detailing evolving responsibilities for software vendors, security teams, government agencies, and researchers. The post-NVD Era is not just about fixing a broken system. It's about embracing a distributed future where collective intelligence, shared responsibility, and technological innovation converge to build a more robust and trustworthy global vulnerability management framework.<br />
<br />
By: Jerry Gamblin  |  Principal Engineer, Cisco<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/index.html#the-post-nvd-era-a-call-for-global-cve-decentralization-49430<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building the foundation for the agentic enterprise]]></title>
<description><![CDATA[Enterprise IT teams, the invisible force driving our modern work world, are struggling to manage environments that have become staggeringly complex, spanning thousands of devices, multiple security domains, and a patchwork of disconnected management tools.



This fragmentation runs across networ...]]></description>
<link>https://tsecurity.de/de/3570344/it-security-nachrichten/building-the-foundation-for-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570344/it-security-nachrichten/building-the-foundation-for-the-agentic-enterprise/</guid>
<pubDate>Wed, 03 Jun 2026 18:50:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise IT teams, the invisible force driving our modern work world, are struggling to manage environments that have become staggeringly complex, spanning thousands of devices, multiple security domains, and a patchwork of disconnected management tools.</p>



<p>This fragmentation runs across networking, security, infrastructure, observability, and collaboration systems and creates significant operational risk. When teams must act and defend infrastructure at machine speed and scale, yet manually stitch together context across siloed workflows, visibility suffers, response times slow, and the burden on already-stretched staff compounds, making it increasingly difficult to scale both human expertise and agentic automation.<br><br>These challenges are becoming more urgent as enterprises increasingly adopt AI and seek to gain the value of agentic operations. For human operators and AI agents to work together effectively, they need more than access to the same environment; they need a shared operational foundation that gives access to the same context, the same signals, and the same system of action across domains.</p>



<p>That foundation ensures that AI is no longer constrained by the fragmentation that limits scale and innovation, said Munish Mehta, senior director of networking at AMD, in this interview during Cisco Live:</p>



<figure class="wp-block-embed is-type-rich is-provider-embed-handler wp-block-embed-embed-handler"><div class="wp-block-embed__wrapper youtube-video">
https://youtube.com/watch?v=qc1YPrERGuU%3Fsi%3DLV4LsUrxuZ1Q8G0a
</div></figure>



<p>Cisco Cloud Control is that foundation. It’s a unified platform built to give both human operators and AI agents shared operational context across every IT domain. It consolidates identity, governance, and administration so that networking, security, and observability share a common management experience rather than separate consoles.</p>



<p>Cisco Cloud Control is built for an open ecosystem, extending to more than 50 platforms and tools such as AWS, Google Cloud, Linear, Microsoft and ServiceNow. New capabilities like App Builder, leveraging built-in agentic coding assistant OpenAI Codex, further expands what teams can create and manage over time. Designed to evolve with an organization’s operational maturity, Cisco Cloud Control becomes more valuable as teams adopt more of its capabilities, said DJ Sampath, senior vice president and general manager of Cisco AI Platform and Software, in this interview during Cisco Live:</p>



<figure class="wp-block-embed is-type-rich is-provider-embed-handler wp-block-embed-embed-handler"><div class="wp-block-embed__wrapper youtube-video">
https://youtube.com/watch?v=n9ZAOGONfyk%3Fsi%3Du2T35La8Em3mkshl
</div></figure>



<p>Central to Cisco Cloud Control is an operating model called AgenticOps, which is built on the premise that AI agents and human operators are most effective when they work together in a shared workspace rather than in parallel silos. That collaboration environment is called AI Canvas, and it surfaces cross-domain telemetry, connects teams and brings agents into a shared view so that investigations, remediations, and approvals happen in one place rather than across a chain of handoffs.</p>



<p>For example, new agentic loop automation can identify root causes and propose actions, while human operators retain oversight and approval authority before anything is executed. Anurag Dhingra, senior vice president and general manager of enterprise connectivity and collaboration at Cisco, offered further context during this interview at Cisco Live:</p>



<figure class="wp-block-embed is-type-rich is-provider-embed-handler wp-block-embed-embed-handler"><div class="wp-block-embed__wrapper youtube-video">
https://youtube.com/watch?v=ohcrPV7yl0c%3Fsi%3DEkbvU5iQ_oVm9N-k
</div></figure>



<p>As AI moves from experimentation to operational reality, the organizations that will capture the most value are those that invest in the foundational layer that makes coordinated, trustworthy automation possible. Cisco Cloud Control’s unified platform approach, AgenticOps framework, and open integration architecture give enterprise IT teams and AI agents the shared context they need to operate as genuine partners rather than disconnected actors working in adjacent silos.</p>



<p>And for CIOs navigating the growing complexity of their IT environments with finite resources, this unified foundation lays the groundwork for enabling current and future AI innovation. Unified operations reduces the overhead associated with managing fragmented systems, and ensures that security and networking teams are working from the same operational picture.</p>



<p>Taken together, Cisco Cloud Control allows organizations to move from isolated automation and AI efforts to repeatable, scalable AI-powered operations.</p>



<p>Cisco is continually innovating and collaborating with its partners to help customers seamlessly transform to agentic operations. <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m06/cisco-unveils-agentic-platform-for-operating-and-defending-critical-it-infrastructure.html" rel="sponsored">Delve into all the action that was announced at Cisco Live 2026</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is Cisco Cloud Control and why should customers care?]]></title>
<description><![CDATA[As is typical of Cisco, the company made several product announcements at its flagship event, Cisco Live. The most significant product announcement is Cisco Cloud Control, which recognizes that customers do not run separate Cisco products; they run one sprawling, interconnected environment that m...]]></description>
<link>https://tsecurity.de/de/3570274/it-security-nachrichten/what-is-cisco-cloud-control-and-why-should-customers-care/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570274/it-security-nachrichten/what-is-cisco-cloud-control-and-why-should-customers-care/</guid>
<pubDate>Wed, 03 Jun 2026 18:23:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As is typical of <a href="https://www.cisco.com/">Cisco</a>, the company made several product announcements at its flagship event, <a href="https://www.ciscolive.com/">Cisco Live</a>. The most significant product announcement is Cisco Cloud Control, which recognizes that customers do not run separate Cisco products; they run one sprawling, interconnected environment that must be monitored, secured, and increasingly operated with AI at machine speed.</p>



<p>That is what Cisco Cloud Control is supposed to be: a single management plane with one login, one view, and one operational model spanning networking, security, compute, observability, and collaboration. Cisco is positioning it as the foundation for its broader AgenticOps vision, in which human operators and AI agents work from the same data and in the same workspace, with humans still in control. For Cisco customers, this matters because the company is finally trying to turn its massive product portfolio into an actual platform.</p>



<h2 class="wp-block-heading">More than another console</h2>



<p>On paper, Cloud Control sounds simple enough. It provides a unified environment, a shared data layer, and a common system of action, while also giving customers access to capabilities such as unified inventory, topology, policy, identity, and event correlation across the Cisco estate. During the keynote demos, Cisco showed single sign-on, all assets in one place, a single topology view, and direct access to products such as Meraki, Splunk, Security Cloud Control, Intersight, Control Hub, and Cisco IQ.</p>



<p>That alone would be useful. Cisco’s biggest enterprise customers have spent years dealing with product silos that made perfect sense inside the org chart but far less sense in an actual IT environment. Networking had its console, security had its console, observability had its tools, collaboration had its dashboard, and the poor operator in the middle had to stitch it all together manually. Cloud Control is Cisco’s admission that this model no longer scales.</p>



<h2 class="wp-block-heading">Why the single dashboard matters now</h2>



<p>The timing here is not accidental. In the AI era, operations are no longer just about watching dashboards and opening tickets. Infrastructure teams are being asked to diagnose and fix problems faster, while the threat landscape is compressing the time between vulnerability disclosure and exploitation from weeks to minutes. Cisco’s argument is that if customers are going to operate and defend infrastructure at machine speed, they cannot keep jumping from console to console and trying to correlate everything by hand.</p>



<p>That is why the single dashboard is more strategic than it sounds. Cisco is not just aggregating links to existing products. It is trying to create a common operational context so people and agents can work from the same inventory, topology, telemetry, and policies. If the old model was “visibility first, action later,” the new model is supposed to be visibility, reasoning, and action, all within the same environment.</p>



<h2 class="wp-block-heading">The break from Cisco’s past</h2>



<p>At Cisco Live 2024, Chief Product Officer Jeetu Patel declared that within two years, Cisco would be unrecognizable in a positive way. Cisco Live 2026 marks that two-year milestone, and Patel (pictured at top) has indeed made Cisco unrecognizable, with Cloud Control the most recent example. Historically, Cisco has rolled out one “single pane of glass” after another. In the past, I’ve said that if there were a Magic Quadrant for single panes of glass, Cisco would be the runaway leader because it had so many.</p>



<p>This is what makes Cloud Control so interesting. Cisco explicitly says this is not a “single pane of glass,” and the company is right to make that distinction. In its own words, glass is passive; Cloud Control is designed to enable active execution, with policy and identity built directly into the control path. That is a sharp departure from the old enterprise management philosophy, in which the dashboard’s job was mostly to display information and leave the operator to figure out the rest.</p>



<p>Cisco is also changing the abstraction layer.</p>



<p>For years, the company sold management in product-sized chunks. Now it is talking about a secure harness for agentic infrastructure, complete with trusted access, normalized APIs, Model Context Protocol connectivity, telemetry, enforcement points, and governance to ensure actions are bounded, auditable, and reversible. That is a much more ambitious framing, and frankly, it has to be. In a world of AI agents, the real value is not in prettier user interfaces. It is in creating a trusted operating environment where agents can do useful work without breaking things. At Cisco Live, all product demonstrations have been delivered from within Cisco Cloud Control, showcasing the product’s breadth and depth. </p>



<h2 class="wp-block-heading">AI Canvas is where the story gets real</h2>



<p>One of the strongest parts of the announcement is AI Canvas, which Cisco is moving into controlled availability as part of Cloud Control, rather than keeping it locked inside individual products. Cisco describes AI Canvas as a multiplayer workspace where human operators and AI agents investigate and resolve issues together, using the same live evidence, with context persisting across handoffs, shift changes, and escalations.</p>



<p>That is important because enterprise IT does not need more AI window dressing. It needs help with the messy middle of operations, where a single performance issue can become a network, policy, application, and security question all at once. Cisco says AI Canvas can take a natural-language prompt, build a multi-agent investigation plan, gather evidence across domains, and return a sourced answer, with the operator still approving the path forward. If that works as advertised, Cisco is not just simplifying operations. It’s changing how infrastructure work gets done.</p>



<h2 class="wp-block-heading">The marketplace makes this bigger than Cisco</h2>



<p>The other notable component of the announcement is the Marketplace, which is central to whether Cloud Control becomes a platform or just a better Cisco front end.</p>



<p>The Marketplace is a catalog of apps, agents, and integrations built by Cisco, customers, and partners, and it already includes integrations from more than 50 ecosystem partners. The partner list includes AWS, Google Cloud, Linear, Microsoft, Okta, PagerDuty, ServiceNow, Slack, Snowflake, Tenable, and Wiz, among others.</p>



<p>That matters because no enterprise is all-Cisco. The company acknowledges that customers operate multivendor environments and need to customize workflows beyond what Cisco ships out of the box. With Agent Builder, App Builder, and Marketplace, Cisco is also enabling customers to connect third-party tools, build their own agents, and create custom apps on top of Cisco’s control plane rather than waiting for a roadmap. That is a big deal because it moves Cisco from a product vendor to a platform operator.</p>



<p>After the keynote, I caught up with Evan Mintzer, director of production infrastructure at <a href="https://customersbank.com/">Customers Bank</a>. While he appreciates having a single dashboard for their Cisco products, it’s the ecosystem partnerships that truly caught his attention. “When Cisco displayed the slide of supported vendors, I recognized several we already use and a few others we’re considering,” Mintzer shared. “That ecosystem will make integrating them into our environment much easier.”</p>



<h2 class="wp-block-heading">Why every Cisco customer should care</h2>



<p>During his keynote, Patel made a comment that I think succinctly captures the value of Cisco Cloud Control: “Cloud Control is at its core simplicity without losing the sophistication of Cisco, and so what we’ve tried to do is say all the products that you know from Cisco and love will be managed from it.”</p>



<p>Historically, customers had to choose between the ease of use of a dashboard and the CLI for more complex tasks. Now they can do both through a natural language interface.</p>



<p>It’s also about capturing more value from the Cisco investment many companies have already made. The more Cisco infrastructure a customer runs, the more value the platform should deliver by connecting inventory, topology, policy, security, and AI-driven workflows in one place. Cisco has always had broad reach across the stack, but breadth alone is not enough. Without a unifying control layer, breadth becomes portfolio sprawl. Cloud Control is Cisco’s best attempt yet to turn that sprawl into an advantage.</p>



<p>There is also a defensive reason to care. Cisco is positioning Cloud Control as the command center for a post-Mythos world, tying it to Live Protect, unified security policy, asset visibility, vulnerability posture, and broader agentic security controls. In other words, this is not just an operations console. Cisco wants it to become the place where customers defend infrastructure in real time.</p>



<h2 class="wp-block-heading">My advice to Cisco customers</h2>



<p>Customers should approach Cloud Control with both enthusiasm and discipline. If you are a Cisco-heavy shop, this could become the operational layer that finally ties your environment together. But do not accept the vision based on branding alone.</p>



<p>First, test how Cloud Control reduces cross-domain complexity. A single pane of links is not the same as a single operating model.</p>



<p>Second, rigorously evaluate the AI governance model. Cisco wisely emphasizes human approval, auditability and bounded actions, but customers should validate this in real workflows before letting agents take any consequential actions.</p>



<p>Third, take the Marketplace seriously from day one. The ability to manage the Cisco domain from a single dashboard has obvious appeal, but extending it across a large percentage of the overall environment can significantly simplify operations and troubleshooting.</p>



<p>Cisco has had the pieces for years: leadership positions in networking, security, observability, collaboration, and infrastructure, plus one of the deepest installed bases in enterprise IT. What it has lacked is the control plane to bind them all together. Cloud Control shows that the company understands the future will not be won by having the most dashboards. It will be won by having the operating layer where humans and AI agents can work.</p>



<p>And that is why this launch matters. Cisco Cloud Control is not just another product announcement. It is Cisco’s effort to become the system through which its customers run the agentic enterprise. It’s positioned itself as “Mission Critical Infrastructure for the AI era” — but with Cloud Control, it’s that plus the operational environment.</p>



<h4 class="wp-block-heading">Read more stories from Cisco Live 2026</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lessons from the Canvas cyberattack]]></title>
<description><![CDATA[Canvas cyberattack: Who, what, when, how?



What and when?



Over May 6 and 7, 2026, Canvas learning management system (LMS) users were served up a defaced web page in place of the expected login page. The altered web page displayed a warning by the ShinyHunters criminal hacker and extortion gr...]]></description>
<link>https://tsecurity.de/de/3568944/it-security-nachrichten/lessons-from-the-canvas-cyberattack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568944/it-security-nachrichten/lessons-from-the-canvas-cyberattack/</guid>
<pubDate>Wed, 03 Jun 2026 11:09:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Canvas cyberattack: Who, what, when, how?</h2>



<h3 class="wp-block-heading">What and when?</h3>



<p>Over May 6 and 7, 2026, Canvas learning management system (LMS) users were served up a defaced web page in place of the expected login page. The altered web page displayed a warning by the <em>ShinyHunters</em> criminal hacker and extortion group advising of the <em>Instructure</em> compromise. <a href="https://en.wikipedia.org/wiki/Instructure">Instructure</a>, a leading educational technology company based in Salt Lake City, Utah, was founded in 2008 and its Canvas LMS was launched in 2011. The ShinyHunters warning gave Instructure a deadline of May 12, 2026, by which to contact them and negotiate a ransom deal in order to prevent the disclosure of Canvas data.</p>



<p>As early as May 1, 2026, ShinyHunters claimed responsibility for the Instructure/Canvas attack that reportedly affected nearly <a href="https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/">9,000 educational institutions globally and exposed sensitive information tied to 275 million students, faculty members and staff</a>. Names, email addresses, student identifiers and private communications comprising a staggering <a href="https://en.wikipedia.org/wiki/ShinyHunters#:~:text=ShinyHunters%20is%20a%20black-hat%20criminal,significant%20number%20of%20data%20breaches">3.65 terabytes were stolen</a>. The timing of the attack was especially damaging since it caused widespread operational disruption during final examinations and temporarily blocked access to coursework, assignments and collaboration systems at colleges and universities worldwide.</p>



<h3 class="wp-block-heading">Who?</h3>



<p>The ShinyHunters criminal hacker group’s name is believed to be derived from the rare Shiny Pokémon video game character. The character is an aspect of the Pokémon video game franchise where Pokémon appear in an alternate color scheme and produce a special sparkle animation when entering battle. Players who try to collect the scarce Shiny Pokémon through in-game strategies are often referred to as “shiny hunters.”  </p>



<p>Ransomware.live, a free and independent website, continuously updates its threat intelligence platform and tracks ransomware groups and their victims. Their statistics on ShinyHunter’s nefarious activities identify staggering statistics. Starting in 2020, ShinyHunters successfully compromised 104 victims across 14 countries and stole trillions of records. Of the 104 victims on the list, 73 are located in the United States and include some big names: Microsoft, Ticketmaster, Google, Cisco Systems, 7-Eleven, CarMax, Amtrak, McDonald’s, Disney/Hulu, Princeton, Harvard and the University of Pennsylvania. AT&amp;T Wireless was compromised more than once as was Instructure.</p>



<p>The Instructure/Canvas attack represents far more than an isolated technology outage – it is a high-profile demonstration of how centralized digital ecosystems, third-party dependencies and modern extortion operations are reshaping enterprise cyber risk. While the attack primarily disrupted the education sector, the lessons emerging from the incident are directly applicable to CISOs, boards of directors, risk management leaders and executive teams across every industry.</p>



<h3 class="wp-block-heading">How?</h3>



<p>Specific technical details about how Canvas was compromised are thin. But on <a href="https://www.instructure.com/incident_update">Instructure’s Security Incident &amp; Update</a> page, the company identified a vulnerability with support tickets in their Free for Teacher environment was exploited. In the wake of the attack, Canvas temporarily disabled the Free for Teacher service while they complete a full security review. Free for Teacher is a standalone, no-cost version of the Canvas LMS, allowing teachers to build interactive classes and manage students independently, even if their school does not use Canvas.</p>



<p>Attackers target lower-security environments, legacy systems, support portals, testing infrastructure, API integrations and less-monitored external services because they often possess weaker controls than primary production environments. Organizations often invest heavily in protecting their primary customer-facing infrastructure while underestimating risks associated with support ecosystems, development platforms and auxiliary services.</p>



<h2 class="wp-block-heading">Lessons learned</h2>



<h3 class="wp-block-heading">Reliance on third-party cloud platforms that aggregate enormous quantities of sensitive data</h3>



<p>Educational institutions increasingly rely upon digital ecosystems not only for learning management but also for communication, grading, identity management, scheduling and operational continuity. Similar dependencies exist throughout the private sector. Modern enterprises increasingly centralize operational workflows within cloud-based Software as a Service (SaaS) providers, creating concentrated risk exposure. When these platforms fail, the consequences cascade rapidly.</p>



<p>I recently asked one professor whose university was affected by the incident as to how she was impacted. She replied that the impact was somewhat insignificant since she stores all her class and student information locally in spreadsheets and similar offline formats.</p>



<p>CISOs must reconsider how vendor risk is evaluated. Historically, many third-party risk programs focused heavily on compliance artifacts such as SOC reports, ISO certifications, penetration testing summaries and questionnaire-based responses. While these remain useful, the Canvas incident demonstrates that such controls alone do not guarantee operational security and resilience. Organizations must begin evaluating vendors not only on preventive security controls, but also on their incident response maturity, crisis communications capabilities, architectural resilience, data segmentation strategies, recovery timelines and executive transparency.</p>



<p>As I researched Instructure for this article, I found an impressive website, the <a href="https://trust.instructure.com/">Instructure Trust Center</a>. The site displays eleven compliance “badges” – SOC 2 Type 2, SOC 3, PCI, ISO 27001, GDPR, etc. The site also provides access to 74 compliance-supporting documents and 57 FAQ items. To illustrate an earlier point about organizations focusing on primary product offerings rather than risks associated with secondary products and services, I accessed and reviewed Instructure’s ISO 27001 certificate, which is current and expires October 15, 2027.</p>



<p>The certificate states that “The scope of this ISO/IEC 27001:2022 certificate includes Instructure’s products, teams and ISMS managed at its HQ location in Salt Lake City, UT, USA. The <em>in-scope</em> people, processes, technology and locations are defined within the Instructure Scope of the Information Security Management System (ISMS), dated August 1, 2025, and the Statement of Applicability, dated April 16, 2025. The scope of the ISMS implemented by Instructure includes the following elements:</p>



<ul class="wp-block-list">
<li>Products: Canvas, Studio, Mastery Connect, Impact, Parchment Award, Parchment Pathways, Parchment.</li>



<li>Services:  Parchment Digitary Services (MyEquals and MyCreds), Intelligent Insights, Elevate Standards</li>
</ul>



<p>Note that the Instructure in-scope product list reviewed as part of the ISO 27001 assessment does not include Free for Teachers.</p>



<h3 class="wp-block-heading">Communications management</h3>



<p>Subsequent to the compromise, Instructure took the defaced web page offline and served up a status page referring to the outage as a “scheduled maintenance event.” Then, the following day, Instructure officials declared that the incident had been contained, even though it was at least the third time in the past eight months that Instructure had been breached by ShinyHunters.</p>



<p>Public reporting suggested confusion surrounding the timeline, scope and nature of the compromise. Some institutions reportedly struggled to determine whether their local environments had been breached directly or whether the exposure was isolated to the vendor platform.</p>



<p>For executive leadership teams, this reinforces a critical lesson: cyber incidents are communications crises as much as technical events. Organizations that navigate major cyber incidents most successfully are often those capable of delivering clear, transparent and credible communications early in the response lifecycle.</p>



<p>Delayed or incomplete communication during a crisis often magnifies reputational damage because stakeholders begin filling information vacuums with speculation and distrust.</p>



<h3 class="wp-block-heading">Economics of attacks</h3>



<p>Boards of directors should also take note of the strategic implications surrounding ransomware and extortion economics. Although public details remain incomplete, multiple reports suggested that ransom negotiations or agreements may have occurred between the vendor and the attackers. This reflects a broader trend facing enterprises globally. Ransomware has evolved from operational disruption into multidimensional extortion campaigns involving data theft, reputational pressure, public exposure threats and business interruption leverage.</p>



<h3 class="wp-block-heading">Business continuity and recovery</h3>



<p>Executives must recognize that resilience planning cannot focus solely on technical recovery metrics. Business continuity strategies must incorporate operational timing risk, reputational escalation scenarios, communications management, regulatory exposure and executive decision-making frameworks surrounding extortion events. Organizations frequently underestimate how rapidly cyber incidents evolve into enterprise-wide crisis management situations requiring legal, public relations, compliance, insurance and board-level coordination.</p>



<h3 class="wp-block-heading">Data minimization</h3>



<p>Many organizations continue accumulating vast quantities of historical data without sufficiently evaluating whether long-term retention remains operationally necessary. The larger the centralized data repository, the more attractive the environment becomes for extortion-oriented threat actors. Healthcare and educational institutions are particularly vulnerable since supporting data management systems often contain years of communications, coursework, behavioral data, grading information and identity records. Data retention governance must therefore become a board-level strategic discussion rather than a purely operational records management issue.</p>



<h3 class="wp-block-heading">Long-term impacts and secondary breach concerns</h3>



<p>An often-overlooked concern with ransom/data exfiltration incidents is the potential long-term impact associated with exposed communications data. Even when passwords or financial information are reportedly unaffected, large-scale exposure of communications metadata, institutional relationships and personal identifiers creates significant downstream risk. Threat actors can leverage such information for future phishing campaigns, social engineering operations, credential harvesting and identity fraud. Cybersecurity leaders must think beyond immediate containment and evaluate how stolen information may fuel future attacks months or even years later.</p>



<h3 class="wp-block-heading">What’s next?</h3>



<p>In a letter dated May 11, 2026, from United States Congressman Andrew R. Garbarino, Chairman of the Committee on Homeland Security, requested Steve Daly, Chief Executive Officer Instructure Holdings, Inc., to participate in a briefing with the Committee, to be scheduled at a mutually convenient time no later than Thursday, May 21, 2026.</p>



<p>Stay tuned!</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's Codex update lets agents build interactive enterprise workspaces via Sites and role-specific plugins]]></title>
<description><![CDATA[Agentic AI is moving rapidly from the developer terminal to the corporate world.On Tuesday, OpenAI announced a major update of its agentic AI platform Codex, introducing domain-specific workflows, a rapid, semi-private web hosting feature within it for enterprises called "Sites," and an in-place ...]]></description>
<link>https://tsecurity.de/de/3567021/it-nachrichten/openais-codex-update-lets-agents-build-interactive-enterprise-workspaces-via-sites-and-role-specific-plugins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567021/it-nachrichten/openais-codex-update-lets-agents-build-interactive-enterprise-workspaces-via-sites-and-role-specific-plugins/</guid>
<pubDate>Tue, 02 Jun 2026 19:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Agentic AI is moving rapidly from the developer terminal to the corporate world.</p><p>On Tuesday, OpenAI announced a major update of its agentic AI platform Codex, introducing domain-specific workflows, a rapid, semi-private web hosting feature <i>within it</i> for enterprises called "Sites," and an in-place editing tool named "Annotations". </p><p>The release marks a deliberate strategy to transform Codex from a specialized programming assistant into an everyday operating environment for business professionals. </p><p>Non-developers—including financial analysts, marketers, operators, and researchers—now constitute approximately 20% of the platform’s 5 million weekly users and are adopting the technology three times faster than traditional engineers, according to research shared by OpenAI with VentureBeat and <a href="https://www.axios.com/2026/06/02/openai-codex-knowledge-workers">other outlets</a>.</p><p>OpenAI is capitalizing on this shift to position Codex as the premier application for white-collar task automation. The timing of the announcement is highly strategic, arriving precisely as its own primary investor turned business rival<a href="https://www.reuters.com/world/china/microsoft-expected-showcase-new-pc-cloud-ai-tools-developer-conference-2026-06-02/"> Microsoft this week kicks off its annual BUILD developer conference in San Francisco</a>—where a slate of competing enterprise productivity tools is expected—and hot on the heels of <a href="https://www.wsj.com/articles/anthropic-pushes-claude-deeper-into-knowledge-work-23bd5abe">Anthropic’s rapid adoption among knowledge-workers</a> via its Claude Cowork and Claude Code platorms.</p><h2><b>Annotations enable more precise agentic AI spreadsheet edits and updates</b></h2><p>For business users, the most critical technical upgrade is the elimination of full-document regeneration. Previously, instructing an AI to update a specific chart or spreadsheet calculation often meant the model had to rewrite the entire file, which frequently broke custom formatting or introduced hallucinations.</p><p>OpenAI addresses this through <b>Annotations</b>, a localized context-scoping mechanism. As demonstrated in the company's release materials, the platform maps a document's underlying data schema. </p><p>When a user highlights a specific segment—such as a block of cells in a financial model—Codex isolates those exact data arrays. </p><p>If an analyst prompts the system to "Add a chart of revenue, EBITDA, and net income over the selected years," the model executes the code strictly within that boundary, generating the visualization while leaving the surrounding cell dependencies, styles, and unselected formulas completely untouched. </p><h2><b>New role-specific Plugins for enterprise functions that bundle skills and external SaaS app connections</b></h2><p>To further anchor Codex in daily enterprise operations, OpenAI has introduced modular software bundles and a rapid-prototyping hosting environment. </p><p>The company is rolling out six role-specific plugins that aggregate 62 popular business applications (including Snowflake, Figma, and Salesforce) and 110 automated skills straight out of the box. </p><ul><li><p><b>Data Analytics:</b> Unifies cloud environments like Snowflake, Databricks Genie, Hex, and Tableau to translate natural language inquiries into data reports and change-analysis dashboards.</p></li><li><p><b>Creative Production:</b> Connects Figma, Canva, Shutterstock, Picsart, and Fal to generate and iterate on ad variations, campaign boards, and e-commerce assets directly from text briefs.</p></li><li><p><b>Sales:</b> Integrates pipeline infrastructure across Salesforce, HubSpot, Slack, Outreach, Clay, Rox, and Actively to automate follow-up communications, close plans, and account risk reviews.</p></li><li><p><b>Product Design:</b> Bridges Figma and Canva environments to audit live user journeys and transform static wireframes into clickable prototypes.</p></li><li><p><b>Public Equity &amp; Investment Banking:</b> Syncs institutional market feeds—including Moody’s, Daloopa, Datasite, FactSet, LSEG, S&amp;P, PitchBook, and Hebbia—to streamline financial modeling, competitive landscaping, and pitch book preparation.</p></li></ul><p>These integrations allow distinct departments—from data analytics and creative production to sales and investment banking—to automate complex, multi-step workflows without requiring IT to build custom API connections. </p><h2><b>Sites allow users to spin-up dynamic, hosted webpages they can share with their colleagues</b></h2><p>Concurrently, the new <b>Sites</b> feature introduces an interactive canvas that converts static data inputs or text documents into functional, web-hosted internal applications. </p><p>Rolling out in preview for Business and Enterprise tiers, Sites allow cross-functional teams to bypass front-end development. </p><p>Financial leaders, for example, can transform a static spreadsheet into an interactive scenario planner shared via a secure workspace URL, allowing executives to tweak assumptions in a live web app rather than clicking through document tabs. </p><p>Instead of static decks, Sites promise to keep enterprises updated on their latest metrics and important information in an easily digestible way. </p><h2><b>Availability &amp; deployment</b></h2><p>A critical operational distinction in this rollout centers on exactly where these new features can be executed. Codex's existing infrastructure runs natively across multiple surfaces, including IDE extensions and the terminal command line. </p><p>However, the release documentation notes that Sites are rolling out "through the Codex app" and that plugins are managed via a "Codex plugin directory". </p><p>An OpenAI spokesperson confirmed that Plugins and Sites are available int he CLI and desktop app, while Sites are hosted by OpenAI. </p><h2><b>Licensing and pricing</b></h2><p>These updates operate entirely within OpenAI's closed, proprietary enterprise licensing model. Unlike open-source frameworks, enterprise clients do not maintain code-level ownership over Codex’s integration nodes. </p><p>Instead, system administrators manage deployment through centralized workspace settings, giving them explicit authority to enable or disable hosted "Sites" and restrict underlying application permissions. </p><p>These new capabilities deploy seamlessly on top of Codex's existing commercial framework. Users will continue to access the agent via established baseline subscription tiers—such as the individual "Plus" plan ($20/month) or the high-volume "Pro" plan ($100/month)—or through a separate, seat-free pay-as-you-go model that draws down pre-purchased utility credits.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco brings agentic ops platform and security overhaul to Cisco Live]]></title>
<description><![CDATA[Cisco built the networking infrastructure that underpins the internet and the cloud. At Cisco Live this week, the company is making its case to hold that same position as enterprises shift from AI chatbots to autonomous agents. Where chatbots answer questions, agents take actions: They execute ta...]]></description>
<link>https://tsecurity.de/de/3566263/it-security-nachrichten/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566263/it-security-nachrichten/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live/</guid>
<pubDate>Tue, 02 Jun 2026 15:20:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.networkworld.com/article/3523958/cisco-latest-news-and-insights.html">Cisco</a> built the networking infrastructure that underpins the internet and the cloud. At <a href="https://www.ciscolive.com/">Cisco Live</a> this week, the company is making its case to hold that same position as enterprises shift from AI chatbots to autonomous agents. Where chatbots answer questions, agents take actions: They execute tasks, call tools, make changes, and operate continuously at machine speed. That changes the requirements for networking, security, and observability, and it is the frame for a series of announcements.</p>



<p>Among the key announcements from the Las Vegas event are:</p>



<ul class="wp-block-list">
<li><strong>Cisco Cloud Control:</strong> A unified management platform spanning Meraki, Nexus, Intersight, Splunk, and Collaboration.</li>



<li><strong>Agentic Actions for networking:</strong> Closed-loop autonomous remediation for campus and branch networks. </li>



<li><strong>Cisco Multicloud Fabric:</strong> A cloud-delivered service connecting branches, data centers, and cloud workloads across AWS, Azure, Google Cloud, and neoclouds.</li>



<li><strong>Live Protect expansion:</strong> Runtime vulnerability shielding without reboots or maintenance windows, expanding to campus and branch Smart Switches.</li>



<li><strong>Agentic IAM:</strong> Ephemeral, task-scoped access controls for AI agents delivered through Cisco Secure Access.</li>



<li><strong>Cisco Data Fabric powered by Splunk:</strong> Federated Search, a Turnkey Machine Data Lake, an AI Toolkit, and an Agentic SOC with six purpose-built security agents.</li>



<li><strong>New hardware:</strong> C9550 Core switch, 8100/8200/8300/8600 Secure Routers, outdoor Wi-Fi 7, the IR1000 industrial router, and the Cisco Board Pro G3.</li>
</ul>



<p>“It’s no longer about humans clicking through dashboards, in a multitude of dashboards, trying to keep up with what the agents are doing,” <a href="https://www.linkedin.com/in/djsampath/">DJ Sampath</a>, senior vice president and general manager for AI software and platform, said during a press briefing. “A true collaborative operating model starts when agents are doing the heavy lifting and humans are constantly staying in control of what matters.”</p>



<h2 class="wp-block-heading">Cisco Cloud Control</h2>



<p>Managing enterprise infrastructure today means logging into separate dashboards for networking, security, compute, observability, and collaboration. Cloud Control replaces that with a single environment where humans and agents work from the same data and the same interface.</p>



<p>“With Cloud Control, what you’re getting is a secureness that allows you to be able to manage your infrastructure really, you know, effectively,” Sampath said. “It provides you with observability controls, it provides you with, you know, a safe AI gateway, guardrails for these agents. All of these come bundled along with Cloud Control.”</p>



<p>Core capabilities in Cloud Control include:</p>



<ul class="wp-block-list">
<li><strong>Cross-domain telemetry</strong>: Cloud Control aggregates data across networking, security, observability, AI infrastructure and collaboration into a shared data fabric that both operators and agents draw from simultaneously.</li>



<li><strong>Purpose-built models</strong>: Incoming tasks are routed to the most appropriate model rather than sent through a single large language model. Cisco’s own models include the Deep Network Model, trained on four decades of operational networking data, a Foundation Security Model, and a time-series model for telemetry analysis. Frontier models are available for broad reasoning tasks.</li>



<li><strong>Trusted agents</strong>: Agents are grounded in live telemetry, governed with enterprise guardrails and action-ready to execute at machine speed. The Cisco AI Canvas is the multiplayer workspace where operators and agents investigate and resolve incidents from shared live data. An Actions queue surfaces recommendations, root cause analyses and confidence scores for human review before any change is deployed.</li>



<li><strong>Cloud Control Studio</strong>: Targeted for late 2026, Studio adds an Agent Builder for creating custom agents with connectivity to more than 50 third-party platforms via native connectors or the Model Context Protocol, and an App Builder that embeds OpenAI’s Codex into the platform. Anything built inside Cloud Control inherits its observability and security controls automatically.</li>



<li><strong>Cloud Control Marketplace:</strong> Launches with integrations across IT service management (ServiceNow, Atlassian, BMC), identity (Okta, Ping Identity, Microsoft Entra ID, Jamf), network monitoring (LiveAction, Panduit), infrastructure knowledge (NetBox Labs, Device42, Vertiv) and AI-native platforms (Anthropic, OpenAI, NVIDIA, Collibra), among others.</li>
</ul>



<h2 class="wp-block-heading">Agentic networking and Multicloud Fabric</h2>



<p>Network operations teams still rely on manual processes to detect problems and push fixes, while enterprise AI applications are increasingly split across multiple clouds. Cisco is addressing both with announcements this week.</p>



<p>First up is Agentic Actions for networking. Entering beta in June 2026 via Meraki, the feature follows a five-stage loop: sense, diagnose, remediate, validate, deploy. Experience Metrics converts raw device telemetry into user-experience measurements in real time. Deep Reasoning applies Cisco’s purpose-built models to multi-step root cause analysis. Digital Twin runs an emulated replica of the production network using actual software images rather than a mathematical model, allowing agents to test changes before deployment. Digital Twin enters alpha in July 2026.</p>



<p>The second announcement in this area is Cisco Multicloud Fabric. It connects branches, data centers, and cloud workloads across AWS, Azure, Google Cloud, and neocloud providers through a managed overlay with no customer-side hardware required. The fabric includes zero trust routing, cloud firewall service chaining and built-in ThousandEyes and Splunk observability.</p>



<p>“This is a cloud-delivered service that Cisco builds and operates, so there’s nothing for the customer to install or deploy,” said <a href="https://www.linkedin.com/in/anurag-dhingra/">Anurag Dhingra</a>, senior vice president and general manager for enterprise connectivity and collaboration. “It’s instantly available, configured seamlessly with one button in Cisco Cloud Control, and it stitches all of this connectivity in minutes.”</p>



<h2 class="wp-block-heading">Security: Live Protect and Agentic IAM</h2>



<p>Frontier AI models have compressed the window between vulnerability discovery and exploitation from months to minutes. Cisco is responding with runtime defenses that operate at the infrastructure layer and a new access control model built specifically for AI agents.</p>



<p><strong>Live Protect:</strong> Applies runtime compensating controls to network devices without reboots or maintenance windows, precise enough to target a specific process-to-file interaction on a running device. </p>



<p><strong>Agentic IAM</strong>: Rather than standing role-based access, agents receive ephemeral permissions scoped to a specific task, delivered through Cisco Secure Access via multi-turn LLM, API and MCP policy enforcement. </p>



<p>“So instead of access control, we start to move to action control,” said <a href="https://www.linkedin.com/in/tomgillis1/">Tom Gillis</a>, senior vice president and general manager for infrastructure and security. “It’s just in time, it’s just enough access, and it’s just long enough, meaning it’s ephemeral. So you don’t get six months or a year’s worth of access, you get the access that you need to be able to do and perform a task and no more.”</p>



<p><strong>Non-human identity and agent protection</strong>: Cisco is building on technology it gained via the<a href="https://www.networkworld.com/article/4166695/cisco-grabs-astrix-to-secure-ai-agents.html"> acquisition of Astrix Security</a> to improve agentic AI security. The technology uses process-level inspection to distinguish agent activity from human activity.<a href="https://www.networkworld.com/article/4148823/cisco-goes-all-in-on-agentic-ai-security.html"> DefenseClaw,</a> Cisco’s open-source runtime security framework for AI agents, is being embedded into Cisco Secure Client. With Secure Client deployed on more than 200 million enterprise devices, that means endpoint-level agent protections can be applied across the enterprise without requiring developers to instrument each agent individually.</p>



<h2 class="wp-block-heading">Cisco Data Fabric and the Agentic SOC</h2>



<p><a href="https://www.networkworld.com/article/4053209/cisco-launches-ai-driven-data-fabric-powered-by-splunk.html">Cisco Data Fabric</a>, which debuted in September 2025, is getting a big update at Cisco Live. Powered by Splunk, it consolidates telemetry across network, application, security and third-party sources into a common layer that both human analysts and automated agents draw from, and serves as the data foundation for Cloud Control and the Agentic SOC.</p>



<p>Among the enhancements is an improved federated search capability. “Instead of having to move data into Splunk, we bring Splunk to the data and we can query this data across different environments without copying, without moving it,” <a href="https://www.linkedin.com/in/kamal-hathi/">Kamal Hathi</a>, sernior vice president and general manager for Splunk, said.</p>



<p>There is also an AI Toolkit Agent Builder that provides domain-specific models for machine data operations as well as what Cisco is calling a Turnkey Machine Data Lake which automates schema management for raw machine data using AI. </p>



<p>On top of the data fabric, Cisco is deploying an Agentic SOC with purpose-built agents covering the full detection and response lifecycle. </p>



<p>“We’re reducing the time and sophistication required for security operations,” Hathi said. “We’re driving down from what used to take maybe days and hours down to minutes and seconds.”</p>



<p>Going a step further Cisco is integrating an AI SRE capability that performs autonomous root cause analysis for application and infrastructure performance issues. Technology gained by the<a href="https://www.networkworld.com/article/4156855/cisco-to-acquire-galileo-for-ai-observability.html"> acquisition of Galileo</a> earlier this year, adds trace-level observability into agent execution covering tool calls, LLM interactions and prompt injection detection.</p>



<p>“Splunk then provides us full visibility into all aspects of the use of AI and agentic solutions and really makes all of this possible at scale in a trusted manner,” Hathi said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Needs a New Operating Model]]></title>
<description><![CDATA[Explore how Security in Cisco Cloud Control with AI Canvas unifies context, policy, and AI-guided action across fragmented security operations.]]></description>
<link>https://tsecurity.de/de/3566013/it-security-nachrichten/security-needs-a-new-operating-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566013/it-security-nachrichten/security-needs-a-new-operating-model/</guid>
<pubDate>Tue, 02 Jun 2026 14:08:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Explore how Security in Cisco Cloud Control with AI Canvas unifies context, policy, and AI-guided action across fragmented security operations.]]></content:encoded>
</item>
<item>
<title><![CDATA[Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control]]></title>
<description><![CDATA[Identity in Cloud Control provides visibility, ability to take action on human, non-human, and AI agent identities, and powers identity-driven AgenticOps with AI Canvas.]]></description>
<link>https://tsecurity.de/de/3566009/it-security-nachrichten/identity-elevated-a-new-unified-identity-experience-in-cisco-cloud-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566009/it-security-nachrichten/identity-elevated-a-new-unified-identity-experience-in-cisco-cloud-control/</guid>
<pubDate>Tue, 02 Jun 2026 14:08:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Identity in Cloud Control provides visibility, ability to take action on human, non-human, and AI agent identities, and powers identity-driven AgenticOps with AI Canvas.]]></content:encoded>
</item>
<item>
<title><![CDATA[new app - Whisp - Anti Note for gnome]]></title>
<description><![CDATA[I was watching a random Mac apps video by Snazzy Labs, and he showed an app called Anti Note. I wanted something similar for GNOME that felt native, fast, and fluid. So, I built Whisp. Whisp is not Google Docs, Obsidian, or Notion. It is supposed to be the Anti-Note but for GNOME. It’s designed s...]]></description>
<link>https://tsecurity.de/de/3564723/linux-tipps/new-app-whisp-anti-note-for-gnome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564723/linux-tipps/new-app-whisp-anti-note-for-gnome/</guid>
<pubDate>Tue, 02 Jun 2026 03:53:03 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I was watching a random Mac apps video by Snazzy Labs, and he showed an app called Anti Note. I wanted something similar for GNOME that felt native, fast, and fluid. So, I built <strong>Whisp</strong>.</p> <p>Whisp is not Google Docs, Obsidian, or Notion. It is supposed to be the Anti-Note but for GNOME. It’s designed strictly for the GNOME desktop using GTK4 and Libadwaita. It completely abandons traditional file hierarchies in favor of a spatial, swipeable canvas.</p> <p><strong>Features:</strong></p> <ul> <li><strong>Touchpad Swiping:</strong> Fluidly swipe left/right to move between your active notes. (You can also use keyboard shortcuts to navigate).</li> <li><strong>Live Markdown:</strong> Real-time formatting with a WYSIWYG toggle to instantly hide syntax.</li> <li><strong>Native Paper Themes:</strong> Switch between Dotted, Grid, or Blank backgrounds.</li> <li><strong>Instant:</strong> It only renders your active notes, making it incredibly lightweight and fast.</li> <li><strong>Smart Paste:</strong> Features like Plain Paste and a built-in URL Link shortener.</li> </ul> <p>This is my very first app release for GNOME, and I am still learning things! I am going to be adding many more features, and my long-term goal is to move this app to GNOME Circle, though I know that is a long road.</p> <p><strong>You can check it out here:</strong> <br> 🔗 <strong>Flathub:</strong> <a href="https://flathub.org/apps/io.github.tanaybhomia.Whisp">https://flathub.org/apps/io.github.tanaybhomia.Whisp</a> <br> 🔗 <strong>GitHub:</strong> <a href="https://github.com/tanaybhomia/Whisp">https://github.com/tanaybhomia/Whisp</a></p> <p>Please check it out, give it a try, and feel free to file issues! New things are coming soon.</p> <p><em>P.S. I have attached some photos, but they don't show the movement of the app/gestures because I don't know how to record proper videos on Linux yet. If anyone can record and send me a nice demo video, it would help me a lot for the website and GitHub repo!</em></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Baajjii"> /u/Baajjii </a> <br> <span><a href="https://i.redd.it/k5vyyyy9qp4h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tu0uk1/new_app_whisp_anti_note_for_gnome/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[NSDI '26 - HeteCCL: Synthesizing Near-Optimal Collective Communication Schedules for Heterogeneous]]></title>
<description><![CDATA[Author: USENIX - Bewertung: 0x - Views:1 HeteCCL: Synthesizing Near-Optimal Collective Communication Schedules for Heterogeneous GPU Clusters

Chenyang Hei, Fuliang Li, and Jiayi Li, Northeastern University; Jiamin Cao, Alibaba Cloud; Chengxi Gao, Shenzhen Institutes of Advanced Technology, Chine...]]></description>
<link>https://tsecurity.de/de/3564519/it-security-video/nsdi-26-heteccl-synthesizing-near-optimal-collective-communication-schedules-for-heterogeneous/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564519/it-security-video/nsdi-26-heteccl-synthesizing-near-optimal-collective-communication-schedules-for-heterogeneous/</guid>
<pubDate>Tue, 02 Jun 2026 01:02:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: USENIX - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/N-ljCebXugw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>HeteCCL: Synthesizing Near-Optimal Collective Communication Schedules for Heterogeneous GPU Clusters<br />
<br />
Chenyang Hei, Fuliang Li, and Jiayi Li, Northeastern University; Jiamin Cao, Alibaba Cloud; Chengxi Gao, Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences; Xiuzhu Sha, Tongrui Liu, and Dengke Zhang, Northeastern University; Ennan Zhai, Alibaba Cloud; Xingwei Wang, Northeastern University<br />
<br />
Training large language models demands massive computing and networking resources. However, existing clusters often face shortages of homogeneous resources and vendor lock-in, forcing the use of heterogeneous hardware, which makes synchronizing training across nodes highly challenging. Current solutions to cluster heterogeneity suffer from low collective communication efficiency, with suboptimal scheduling and slow algorithm synthesis. We present HeteCCL, a unified method for generating near-optimal collective communication schedules on heterogeneous clusters. HeteCCL models the cluster topology and link bandwidth in detail, quantizes data chunks at the schedule-step level, and formulates the scheduling problem as a maximum parallel transfer problem on a weighted directed graph. To accelerate synthesis, HeteCCL encodes bandwidth and routing constraints as SMT formulas and applies counterexample-guided inductive synthesis to refine constraints and prune the search space iteratively. Experiments on heterogeneous testbeds, each consisting of 32 H20 and V100 GPUs, show that HeteCCL outperforms NCCL, TACCL, and TE-CCL, achieving up to 2.8×, 4.4×, and 2.6× higher bandwidth. It also accelerates synthesis by up to 2 orders of magnitude compared to state-of-the-art efforts, and improves end-to-end training efficiency by 23%–37%.<br />
<br />
View the full NSDI '26 program at https://www.usenix.org/conference/nsdi26/technical-sessions<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tom Ritter: webgl renderer privacy]]></title>
<description><![CDATA[WebGL exposes the details of your graphics hardware (specifically, the string that describes the rendering engine) in 2 ways.  There are three levels of protection that browsers have taken to protect this data.



	gl.getParameter(gl.VENDOR) and gl.getParameter(gl.RENDERER) - these are the 'simpl...]]></description>
<link>https://tsecurity.de/de/3564223/tools/tom-ritter-webgl-renderer-privacy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564223/tools/tom-ritter-webgl-renderer-privacy/</guid>
<pubDate>Mon, 01 Jun 2026 22:07:39 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>WebGL exposes the details of your graphics hardware (specifically, the string that describes the rendering engine) in 2 ways.  There are three levels of protection that browsers have taken to protect this data.</p>


<ol>
	<li><code>gl.getParameter(gl.VENDOR)</code> and <code>gl.getParameter(gl.RENDERER)</code> - these are the 'simple' names.  At some point in the past, someone argued that it wasn't enough information, and therefore we have a second API</li>
	<li> <code>let ext = gl.getExtension('WEBGL_debug_renderer_info');</code> and then <code>gl.getParameter(ext.UNMASKED_VENDOR_WEBGL)</code> and <code>gl.getParameter(ext.UNMASKED_RENDERER_WEBGL)</code></li>
</ol>

<p>The unmasked values are intended to be the more detailed ones, so always make sure you're comparing apples to apples.  Another axis is that WebGL can render with Hardware or Software.  This isn't a guarentee which one you'll get, but you can hint towards one or the other and the browser may or may not respect it. Here are your values:</p>

<blockquote>
  <p class="hint"></p>
  <table>
    <tbody></tbody>
  </table>
  <p class="hint"></p>
</blockquote>
  <canvas height="1" width="1"></canvas>

  <span class="err"></span><code class="badge"></code><code class="badge"></code><code class="badge"></code><span class="err"></span>


<p>Alright, now let's talk about what browsers do about it.  There's no point in talking about Vendor, Renderer, and Unmasked Vendor - they don't really show as much detailed info, it's all about Unmasked Renderer.  There are three levels:</p>

<ol>
	<li>Give a constant value.  (Or don't return anything at all.)  </li>
	<li>'Round' the values into buckets</li>
	<li>Give the exact value back</li>
</ol>

<p><b>Safari</b> and <b>Tor Browser</b> give constant values.</p>

<p><b>Firefox</b> 'rounds'.</p>

<p><b>Chrome</b> (and <b>Brave</b>, and I assume all-ish other Chrome-based browsers) give the exact value.</p>

<p>Firefox actually is purusing constant values, <em>this week</em>.  I wrote <a href="https://docs.google.com/document/d/1CPeDrno-OmMj5BSKTqD8dJTgnZbUq-ZgNCyKB8_xPTE/edit?tab=t.0#heading=h.kub2qfspnqw7">this document</a> for our QA team to test it. (You can get a sense of the internal sausage making it takes to launch a privacy feature from it.)  I don't know if you can see the dates but I made it May 20th.  The problem is <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036879">this</a> - websites use this data legitimately to adjust behavior so that users get the best experience possible.  I found one example where they detect a buggy graphics stack; and a couple of examples where they adjust rendering so things are more performant for users with lower end machines - a problem Apple has less to worry about because they only support certain machine models!  </p>

<p>A common response to this seems to be ambivalence, and I would suggest that is a bit elitist. Yes, if you're caring about the details reveal by a particular Web API you probably have a computer where you don't need to worry, but making the web work well for everyone is important for equitable access to improving everyone's human condition.</p>

<p>We have been bucketing WebGL Renderer <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1715690">since 2021</a>.  While many of our (supported, on-by-default) fingerprinting protections are part of Enhanced Tracking Protection - rolling out first in PBM/ETP Strict before making it to ETP Standard/Normal Browsing Mode - the bucketing is <strong>on by default, for everyone, and is not disabled if ETP is disabled</strong>. </p>

<p>How much of a difference does it make?  A lot!  Here is the distribution of the raw values.  <strong>83,705 distinct values</strong>.</p>

<img alt="WebGL Renderer Value Distribution, before bucketing" src="https://ritter.vg/resources/webgl-renderer-before.png">

<p>Compare that to the bucketed data.  <strong>131 distinct values</strong>.</p>

<img alt="WebGL Renderer Value Distribution, after bucketing" src="https://ritter.vg/resources/webgl-renderer-after.png">

<p>Now this data is from Firefox, so I cant say conclusively what the distribution of data is in other browsers, but... yeah.  To claim Chrome (of all browsers!) is doing this better than us is pure FUD.  We're making a big impact in how fingerprintable you are <em>today</em> and we're trying to improve it even further.  </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Press Release: CSO30 ASEAN & Hong Kong Awards 2026 open for nominations]]></title>
<description><![CDATA[>The CSO30 ASEAN & Hong Kong Awards return in 2026, as an important moment to recognise the cybersecurity leaders and teams who are making resilience measurable across the region. In a landscape shaped by rapid threat evolution, board-level scrutiny and rising expectations of business continuity,...]]></description>
<link>https://tsecurity.de/de/3562178/it-security-nachrichten/press-release-cso30-asean-hong-kong-awards-2026-open-for-nominations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562178/it-security-nachrichten/press-release-cso30-asean-hong-kong-awards-2026-open-for-nominations/</guid>
<pubDate>Mon, 01 Jun 2026 09:08:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>&gt;The CSO30 ASEAN &amp; Hong Kong Awards return in 2026, as an important moment to recognise the cybersecurity leaders and teams who are making resilience measurable across the region. In a landscape shaped by rapid threat evolution, board-level scrutiny and rising expectations of business continuity, these awards spotlight the people and programmes that are turning security into an enterprise capability, not just a control function. On our sixth consecutive edition this year, this awards programme is a regional benchmark for cybersecurity maturity across ASEAN and Hong Kong, and a unique platform for organisations to showcase their most impactful achievements, gain regional and global visibility, and join a distinguished community of Chief Information Security Officers(CISOs) and Chief Security Officers(CSOs) who are redefining the role of cybersecurity.</p>&gt;&gt;



<p>Globally respected, the CSO30 ASEAN and Hong Kong Awards celebrate not just individual leaders but the collective efforts of teams that drive transformation, cyber resiliency and business continuity. This year, you and your team could stand alongside the past winners which include this region’s most influential organizations, to be a recognise force in the ASEAN and HK cybersecurity landscape.</p>



<p>Calling on CISOs and CSOs to nominate themselves, their peers and their teams now. If your organisation has strengthened its cyber posture, shifted strategic decision-making, or built stronger ecosystem partnerships in the past year, this is the moment to put that work forward.</p>



<p>This year’s awards spans three nomination pathways: </p>



<p>CSO Leadership – Individual <a href="https://form.jotform.com/261483329388468">Online Form</a></p>



<p>CSO Transformation – Individual <a href="https://form.jotform.com/261483300714450">Online Form</a></p>



<p>Ecosystem – Team <a href="https://form.jotform.com/261483142852457">Online Form</a></p>



<p>Together, these categories reflect the full scope of modern security leadership, from board-level influence and enterprise transformation to ecosystem collaboration and measurable resilience.</p>



<p>Individual Leadership nominations are expected to show how a cybersecurity leader has delivered real value, changed the way the organisation is protected, influenced executive decision-making, and prepared the business to respond to emerging cyber risks while ensuring long-term resilience and continuity. </p>



<p>The Transformation category goes further, asking for a cybersecurity-led project from the past one year that changed how the organisation is protected, overcame key challenges, delivered quantifiable impact, and contributed to the wider cybersecurity community. </p>



<p>Ecosystem Team nominations must show how a project shaped and strengthened the cybersecurity agenda across the organisation, its partners and even the broader country context, with clear challenges, outcomes and quantifiable value.</p>



<p>If you lead a cybersecurity team that has delivered measurable impact, or if you know a peer whose leadership deserves broader recognition, nominate them. If you are a CISO or CSO whose work has materially improved your organisation’s resilience, nominate yourself. The region needs to see the leaders and teams setting the standard for security maturity, operational continuity and business trust.</p>



<p><strong>The deadline for nominations: 31 July 2026.</strong></p>



<p><strong>Awards Gala website:</strong> <a href="https://event.foundryco.com/cio-100-asean-and-hk/">https://event.foundryco.com/cio-100-asean-and-hk/</a></p>



<p>Due to the sensitive nature of cybersecurity work, project details will not be published, which gives nominees the confidence to submit meaningful work without exposing sensitive information.</p>



<p>The CSO30 ASEAN &amp; Hong Kong Awards matter because we recognise a kind of leadership the region increasingly depends on – decisive, collaborative, strategic and resilient. We give visibility to the people and teams making cybersecurity a stronger part of business performance and long-term continuity.</p>



<p>Media Contact: <strong><em>Estelle Quek</em></strong> <em>Editorial Director, CIO ASEAN &amp; CSO ASEAN </em></p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_0ab37f.png?w=1024" alt="" class="wp-image-4179075" width="1024" height="439" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure></div>



<p></p>



<p></p>



<p></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Press Release: CIO100 ASEAN & Hong Kong Awards 2026 is open for nominations]]></title>
<description><![CDATA[The CIO100 ASEAN & Hong Kong Awards return in 2026 for the sixth edition, building on a record-high 245 entries in 2025 and an Awards Gala that brought together the region’s most eminent Chief Information Officers(CIOs) and technology leaders for an exchange of thought leadership and peer insight...]]></description>
<link>https://tsecurity.de/de/3562085/it-security-nachrichten/press-release-cio100-asean-hong-kong-awards-2026-is-open-for-nominations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562085/it-security-nachrichten/press-release-cio100-asean-hong-kong-awards-2026-is-open-for-nominations/</guid>
<pubDate>Mon, 01 Jun 2026 08:20:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The CIO100 ASEAN &amp; Hong Kong Awards return in 2026 for the sixth edition, building on a record-high 245 entries in 2025 and an Awards Gala that brought together the region’s most eminent Chief Information Officers(CIOs) and technology leaders for an exchange of thought leadership and peer insight. This Awards programme is more than recognition; it is a regional benchmark for technology maturity across ASEAN and Hong Kong, and a unique platform for organisations to showcase their most impactful achievements, gain regional and global visibility, and join a distinguished community of innovators who are redefining the role of technology.</p>



<p>Globally respected, this CIO100 ASEAN &amp; Hong Kong Awards  celebrates not just individual leaders but the collective efforts of teams that drive transformation, operational efficiency, and sustained growth. This year, you and your team could stand alongside the past winners which include this region’s most influential organizations, to be recognised for outstanding projects.</p>



<p>Calling on CIOs and senior level technology leaders to nominate themselves, their peers and their teams now. If your organisation has delivered outstanding projects that have made an impact over the past year, this is the moment to put that work forward.</p>



<p>This year’s award spans eight nomination pathways:</p>



<p><strong>CIO Individua</strong>l <a href="https://form.jotform.com/261481571362457" rel="nofollow">Online Form</a></p>



<p><strong>Next CIO Individual</strong> <a href="https://form.jotform.com/261482836490464" rel="nofollow">Online Form</a></p>



<p><strong>Ecosystem Team</strong> <a href="https://form.jotform.com/261481866823466" rel="nofollow">Online Form</a></p>



<p><strong>Future Ready Enterprise Team</strong> <a href="https://form.jotform.com/261483415909463" rel="nofollow">Online Form</a></p>



<p><strong>Sustainability Team</strong> <a href="https://form.jotform.com/261482756607465" rel="nofollow">Online Form</a></p>



<p><strong>Transformation – Modernisation Team</strong> <a href="https://form.jotform.com/261482941586467" rel="nofollow">Online Form</a></p>



<p><strong>Transformation – Innovation Team</strong> <a href="https://form.jotform.com/261482752014453" rel="nofollow">Online Form</a></p>



<p><strong>Transformation – AI Team</strong> <a href="https://form.jotform.com/261483217953462" rel="nofollow">Online Form</a></p>



<p>Together, these categories reflect the full spectrum of enterprise technology maturity, from leadership influence and people development to ecosystem value, sustainability, modernisation and the strategic use of AI and emerging technology.</p>



<p>To the impartial judges, what matters most is not the volume of activity, but the quality of outcomes. The nomination forms are deliberately built to surface real projects that have moved beyond intent and into implementation, with clear business metrics, measurable impact and a story that shows how the work changed the organisation. This same discipline shaped the 2025 Awards.</p>



<p>For individual categories, the focus is on leadership that delivers real value, changes how the organisation operates, and influences people across the enterprise. Meanwhile, team categories nominations should show how technology is creating value across customer and supplier value chains, developing future-ready skills, advancing sustainability, modernising core environments, or scaling innovation and AI in ways that matter to the business. </p>



<p>If you know of a team that has transformed the customer experience, strengthened resilience, improved efficiency, or advanced the organisation’s capability, nominate them. If you are a leader whose work has moved the business forward, nominate yourself. This is a great opportunity to showcase the people and projects that are setting the standard for what effective technology leadership looks like.</p>



<p><strong>The deadline for nominations: 31 July 2026</strong>. </p>



<p><strong>Awards Gala website:</strong> <a href="https://event.foundryco.com/cio-100-asean-and-hk/" rel="nofollow">https://event.foundryco.com/cio-100-asean-and-hk/</a></p>



<p>The CIO100 ASEAN &amp; Hong Kong Awards continue to matter because we do more than recognise achievement. We provide a credible regional benchmark for technology maturity, and they bring together the leaders whose decisions are shaping the next phase of enterprise transformation.</p>



<p>Media Contact : <strong><em>Estelle Quek</em></strong>, <em>Editorial Director, CIO ASEAN &amp; CSO ASEAN </em></p>



<p></p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_e44e53.png?w=1024" alt="" class="wp-image-4179081" width="1024" height="439" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure></div>



<p></p>



<p>&gt;<i>&gt;Learn more about our global CIO Awards</i>:</p>



<p><em>CIO 100 USA (August 2026)</em><em><u></u></em></p>



<p><em>CIO of the Year Germany (October 2026) </em><em><u></u></em></p>



<p><em>CIO 100 UK (September 2026) </em><em><u></u></em></p>



<p><em>CIO 50 Spain (October 2026) </em><em><u></u></em></p>



<p><em>CIO 100 India (September 2026) </em><em><u></u></em></p>



<p><em>CIO 100 Australia (September 2026)</em><em><u></u></em><em><u></u></em></p>



<p><em>CIO 50 Japan (December 2026)</em><em><u></u></em><em><u></u></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Servo Blog: April in Servo: new Android UI, focus, forms, security fixes, and more!]]></title>
<description><![CDATA[Servo 0.2.0 contains all of the changes we landed in April, which came out to yet another record 534 commits (March: 530).
For security fixes, see § Security.

Note: the GitHub release is available now, but the crates.io release is not yet complete.
We expect to publish it some time next week.


...]]></description>
<link>https://tsecurity.de/de/3560659/tools/the-servo-blog-april-in-servo-new-android-ui-focus-forms-security-fixes-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560659/tools/the-servo-blog-april-in-servo-new-android-ui-focus-forms-security-fixes-and-more/</guid>
<pubDate>Sun, 31 May 2026 13:08:28 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/servo/servo/releases/tag/v0.2.0"><strong>Servo 0.2.0</strong></a> contains all of the changes we landed in April, which came out to yet another record <strong>534 commits</strong> (March: 530).
For security fixes, see <a href="https://servo.org/blog/2026/05/31/april-in-servo/#security"><strong>§ Security</strong></a>.</p>
<aside class="_note">
<p><strong>Note:</strong> the GitHub release is available now, but <a href="https://crates.io/crates/servo">the crates.io release</a> is not yet complete.
We expect to publish it some time <strong>next week</strong>.</p>
</aside>
<figure>
    <a href="https://servo.org/img/blog/2026-05-diffie.png"><img alt="servoshell 0.2.0 showing several new features: better wrapping for CJK scripts, ‘tab-size’, better file pickers and `&lt;textarea&gt;`, `&lt;select multiple&gt;`, ‘::details-content::before’ and ‘::details-content::after’, and ‘color-mix()’ with any number of colors" src="https://servo.org/img/blog/2026-05-diffie.png"></a>
</figure>
<p>We’ve shipped several new web platform features:</p>
<ul>
<li><strong>&lt;select multiple&gt;</strong> (<a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43189">#43189</a>)</li>
<li><strong>&lt;template shadowrootslotassignment&gt;</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44246">#44246</a>)</li>
<li><strong>&lt;video&gt;</strong> playback on OpenHarmony (<a href="https://github.com/rayguo17">@rayguo17</a>, <a href="https://github.com/servo/servo/pull/43208">#43208</a>)</li>
<li><strong>‘minimum-scale’</strong> and <strong>‘maximum-scale’</strong> values in <strong>&lt;meta name=viewport&gt;</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/40098">#40098</a>, <a href="https://github.com/servo/servo/pull/43715">#43715</a>)</li>
<li><strong>‘color-mix()’</strong> with <strong>any number of &lt;color&gt; values</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43890">#43890</a>)</li>
<li><strong>‘&amp;::before’</strong> and <strong>‘&amp;::after’</strong> in <strong>‘::details-content’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>)</li>
<li><strong>‘revert-rule’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>)</li>
<li><strong>‘tab-size’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44480">#44480</a>)</li>
<li><strong>‘text-align: match-parent’</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/44073">#44073</a>)</li>
<li><strong>new Worker()</strong> with <strong>blob URLs</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44004">#44004</a>)</li>
<li><strong>get­Context(<code>"webgl"</code>)</strong> on <strong>Offscreen­Canvas</strong> (<a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/servo/servo/pull/44159">#44159</a>)</li>
<li>the <strong>detail</strong> property on <strong>Performance­Mark</strong> and <strong>Performance­Measure</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44289">#44289</a>, <a href="https://github.com/servo/servo/pull/44272">#44272</a>)</li>
</ul>
<p>Plus a bunch of new DOM APIs:</p>
<ul>
<li><strong>‘selectionchange’</strong> events on &lt;input&gt; and &lt;textarea&gt; (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44461">#44461</a>)</li>
<li><strong>Storage­Manager</strong>, in experimental mode (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/43976">#43976</a>)</li>
<li><strong>active­Element</strong> on <strong>Document</strong> and <strong>Shadow­Root</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43861">#43861</a>)</li>
<li><strong>crypto.subtle.supports()</strong> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/43703">#43703</a>) – Servo is the first major browser engine to support this!</li>
<li><strong>cell­Padding</strong>, <strong>cell­Spacing</strong>, and <strong>align</strong> properties on <strong>HTML­Table­Element</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43903">#43903</a>) – previously supported in HTML only</li>
<li><strong>related­Target</strong> on <strong>‘focus’</strong> and <strong>‘blur’</strong> events (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43926">#43926</a>)</li>
<li><strong>transfer­From­Image­Bitmap()</strong> on <strong>Image­Bitmap­Rendering­Context</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43984">#43984</a>)</li>
</ul>
<p>Servo’s support for text in <strong>Chinese</strong>, <strong>Japanese</strong>, and <strong>Korean</strong> languages has improved, with correct wrapping in the layout engine (<a href="https://github.com/SharanRP">@SharanRP</a>, <a href="https://github.com/servo/servo/pull/43744">#43744</a>), and CJK fonts now enabled in servoshell’s browser UI on Windows, Linux, and FreeBSD (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/CynthiaOketch">@CynthiaOketch</a>, <a href="https://github.com/nortti0">@nortti0</a>, <a href="https://github.com/servo/servo/pull/44055">#44055</a>, <a href="https://github.com/servo/servo/pull/44138">#44138</a>, <a href="https://github.com/servo/servo/pull/44514">#44514</a>).</p>
<p>Navigating to a <strong>JSON file</strong> as the top-level document now renders the JSON with an <strong>interactive pretty-printer</strong> (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43702">#43702</a>).</p>
<p>April was a big milestone for Servo, with some automated tests failing because they had hard-coded cookie expiry dates set to April 2016 plus ten years.
Surprise!
We’re still here.
Here’s to the next 100 years of Servo (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44341">#44341</a>).</p>
<p>This is another big update, so here’s an outline:</p>
<ul>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#security"><strong>Security</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#work-in-progress"><strong>Work in progress</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#servoshell"><strong>servoshell</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#for-developers"><strong>For developers</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#embedding-api"><strong>Embedding API</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#more-on-the-web-platform"><strong>More on the web platform</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#performance-and-stability"><strong>Performance and stability</strong></a></p>
</li>
</ul>
<h3>Security <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#security">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong>Crypto­Key</strong> now zeroes buffers containing key material after use (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44597">#44597</a>).</p>
<p>With only a few exceptions, you can only access DOM APIs in another document if that document is in the <strong>same origin</strong>.
But if that document is in the same <em>site</em> with a different port number, Servo currently allows these accesses even though it shouldn’t.
We’ve fixed some (but not all) of these incorrect accesses, specifically those that involve binding a Window or Location method in this document with a <code>this</code> from the other document (<a href="https://github.com/yvt">@yvt</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/28583">#28583</a>).</p>
<p>We’ve fixed a bug where <strong>local­Storage</strong> and <strong>session­Storage</strong> were usable in <strong>sandboxed &lt;iframe&gt;</strong> and shared with every other sandboxed &lt;iframe&gt;, rather than throwing Security­Error (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44002">#44002</a>).</p>
<p>We’ve fixed a bug where <strong>local­Storage</strong> and <strong>session­Storage</strong> were shared between all <strong>&lt;iframe srcdoc&gt; documents</strong>, rather than isolated using the origin of the containing document (<a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/servo/servo/pull/43988">#43988</a>, <a href="https://github.com/servo/servo/pull/44038">#44038</a>).</p>
<p>We’ve fixed a bug where <strong>IndexedDB</strong> was usable in <strong>sandboxed &lt;iframe&gt;</strong> and <strong>data: URL web workers</strong> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44088">#44088</a>).</p>
<p>We’ve fixed a bug where pages in some <strong>IP address origins</strong> can evict cookies from other IP address origins (<a href="https://github.com/officialasishkumar">@officialasishkumar</a>, <a href="https://github.com/servo/servo/pull/44152">#44152</a>).
Only evicting cookies was possible, not reading or writing them.</p>
<p>We’ve fixed an <strong>out-of-bounds memory read</strong> in <strong>tex­Image3D()</strong> on <strong>Web­GL2­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/servo/servo/pull/44270">#44270</a>), and fixed some undefined behaviour in servoshell’s signal handler (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/43891">#43891</a>).</p>
<h3>Work in progress <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#work-in-progress">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong>IndexedDB</strong> is now enabled in servoshell’s experimental mode (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/44245">#44245</a>).
As always, embedders can enable it with <a href="https://doc.servo.org/servo/struct.Preferences.html"><code>Preferences</code></a>::<a href="https://doc.servo.org/servo/struct.Preferences.html#structfield.dom_indexeddb_enabled"><code>dom­_indexeddb­_enabled</code></a> (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/44245">#44245</a>, <a href="https://github.com/servo/servo/pull/44283">#44283</a>).</p>
<p>IndexedDB now uses Servo’s new <strong>“client storage”</strong> system, which is based on the <a href="https://storage.spec.whatwg.org/">Storage Standard</a> and will allow us to have a unified on-disk format and quota management for all web platform features that persistently store data (<a href="https://github.com/gterzian">@gterzian</a>, <a href="https://github.com/servo/servo/pull/44374">#44374</a>, <a href="https://github.com/servo/servo/pull/43900">#43900</a>).
We’ve also made key range queries more efficient (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/39009">#39009</a>), landed improvements to IDB­Database, IDB­Object­Store, IDB­Cursor, IDB­Key­Range, IDB­Request, and to the handling of transactions, keys, values, and exceptions (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44128">#44128</a>, <a href="https://github.com/servo/servo/pull/43901">#43901</a>, <a href="https://github.com/servo/servo/pull/44009">#44009</a>, <a href="https://github.com/servo/servo/pull/43914">#43914</a>, <a href="https://github.com/servo/servo/pull/44161">#44161</a>, <a href="https://github.com/servo/servo/pull/44183">#44183</a>, <a href="https://github.com/servo/servo/pull/44059">#44059</a>, <a href="https://github.com/servo/servo/pull/44215">#44215</a>, <a href="https://github.com/servo/servo/pull/42998">#42998</a>, <a href="https://github.com/servo/servo/pull/43805">#43805</a>).</p>
<p>We’ve made more progress on the <strong>Intersection­Observer API</strong>, under <code>--pref dom­_intersection­_observer­_enabled</code> (<a href="https://github.com/stevennovaryo">@stevennovaryo</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/42204">#42204</a>).</p>
<p>We’re continuing to implement <strong>document.exec­Command()</strong> for <strong>rich text editing</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44529">#44529</a>), under <code>--pref dom­_exec­_command­_enabled</code>.
This release adds support for the <strong>‘bold’</strong>, <strong>‘font­Name’</strong>, <strong>‘font­Size’</strong>, <strong>‘italic’</strong>, <strong>‘strikethrough’</strong>, and <strong>‘underline’</strong> commands (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44511">#44511</a>, <a href="https://github.com/servo/servo/pull/43287">#43287</a>, <a href="https://github.com/servo/servo/pull/44432">#44432</a>, <a href="https://github.com/servo/servo/pull/44410">#44410</a>, <a href="https://github.com/servo/servo/pull/44194">#44194</a>, <a href="https://github.com/servo/servo/pull/44030">#44030</a>, <a href="https://github.com/servo/servo/pull/44039">#44039</a>, <a href="https://github.com/servo/servo/pull/44041">#44041</a>, <a href="https://github.com/servo/servo/pull/44075">#44075</a>, <a href="https://github.com/servo/servo/pull/44234">#44234</a>, <a href="https://github.com/servo/servo/pull/44250">#44250</a>, <a href="https://github.com/servo/servo/pull/44331">#44331</a>, <a href="https://github.com/servo/servo/pull/44390">#44390</a>, <a href="https://github.com/servo/servo/pull/44137">#44137</a>, <a href="https://github.com/servo/servo/pull/44293">#44293</a>, <a href="https://github.com/servo/servo/pull/44312">#44312</a>, <a href="https://github.com/servo/servo/pull/44347">#44347</a>).</p>
<p>All of the features above are enabled in servoshell’s experimental mode.</p>
<p>Servo can now build a very basic <strong>accessibility tree</strong> for web contents, under <code>--pref accessibility­_enabled</code> (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/servo/servo/pull/42338">#42338</a>, <a href="https://github.com/servo/servo/pull/43558">#43558</a>, <a href="https://github.com/servo/servo/pull/44437">#44437</a>, <a href="https://github.com/servo/servo/pull/44438">#44438</a>).
This includes text runs, plus nine other non-interactive accessibility roles (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/servo/servo/pull/44255">#44255</a>).
We’ve also fixed a crash when reloading pages with accessibility enabled (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/servo/servo/pull/44473">#44473</a>), and made accessibility tree updates more efficient (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/servo/servo/pull/44208">#44208</a>).</p>
<p>We’ve started implementing the <strong>Sanitizer API</strong>, under <code>--pref dom­_sanitizer­_enabled</code> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44198">#44198</a>, <a href="https://github.com/servo/servo/pull/44290">#44290</a>, <a href="https://github.com/servo/servo/pull/44335">#44335</a>, <a href="https://github.com/servo/servo/pull/44421">#44421</a>, <a href="https://github.com/servo/servo/pull/44452">#44452</a>, <a href="https://github.com/servo/servo/pull/44481">#44481</a>, <a href="https://github.com/servo/servo/pull/44585">#44585</a>, <a href="https://github.com/servo/servo/pull/44594">#44594</a>).</p>
<p>We’ve also started implementing <strong>Shared­Worker</strong>, under <code>--pref dom­_sharedworker­_enabled</code> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44375">#44375</a>, <a href="https://github.com/servo/servo/pull/44440">#44440</a>).</p>
<p>We’re working on the <strong>Wake­Lock API</strong> too, under <code>--pref dom­_wakelock­_enabled</code> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/43617">#43617</a>, <a href="https://github.com/servo/servo/pull/44343">#44343</a>).</p>
<h3>servoshell <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#servoshell">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>servoshell for Android now has a <strong>revamped browser UI</strong>, including a new <strong>history view</strong> (<a href="https://github.com/espy">@espy</a>, <a href="https://github.com/servo/servo/pull/43795">#43795</a>), the <strong>apk is 30% smaller</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44278">#44278</a>, <a href="https://github.com/servo/servo/pull/44182">#44182</a>), and we’ve fixed the black screen bug when closing settings or switching back from another app (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44327">#44327</a>).
You can now close tabs on OpenHarmony too (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/42713">#42713</a>).</p>
<figure>
    <a href="https://servo.org/img/blog/2026-05-android.png"><img alt="servoshell 0.2.0 showing the revamped browser UI on Android. from left to right: viewing a web page, the settings view, the history view" src="https://servo.org/img/blog/2026-05-android.png"></a>
</figure>
<p>As for servoshell on desktop platforms, we’ve fixed some focus- and IME-related bugs (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43872">#43872</a>, <a href="https://github.com/servo/servo/pull/43932">#43932</a>), and on Windows, we now install a normal shortcut without the strange behaviour of an “advertised” shortcut (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44223">#44223</a>).</p>
<h3>For developers <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#for-developers">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>When using the <strong>Inspector</strong> tab in the Firefox <strong>DevTools</strong>, the <strong>Rules</strong> panel now includes declarations in <strong>‘@layer’ rules</strong> (<a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/servo/servo/pull/43912">#43912</a>).</p>
<p>When <strong>logging expressions</strong> in the <strong>Console</strong> tab, and when <strong>hovering over symbols</strong> in the <strong>Debugger</strong> tab, you can now get more information about the contents of functions, arrays, objects, and other values (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/servo/servo/pull/44172">#44172</a>, <a href="https://github.com/servo/servo/pull/44173">#44173</a>, <a href="https://github.com/servo/servo/pull/44022">#44022</a>, <a href="https://github.com/servo/servo/pull/44233">#44233</a>, <a href="https://github.com/servo/servo/pull/44196">#44196</a>, <a href="https://github.com/servo/servo/pull/44181">#44181</a>, <a href="https://github.com/servo/servo/pull/44064">#44064</a>, <a href="https://github.com/servo/servo/pull/44023">#44023</a>, <a href="https://github.com/servo/servo/pull/44164">#44164</a>, <a href="https://github.com/servo/servo/pull/44369">#44369</a>, <a href="https://github.com/servo/servo/pull/44262">#44262</a>).</p>
<p>When using the <strong>Debugger</strong> tab, you can now use the <strong>Scopes</strong> panel to inspect local and global variables (<a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/43792">#43792</a>, <a href="https://github.com/servo/servo/pull/43791">#43791</a>), you can now debug <strong>web worker</strong> scripts (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/43981">#43981</a>), and we’ve started implementing <strong>blackboxing</strong>, aka the <strong>Ignore source</strong> button (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/44142">#44142</a>).</p>
<p>We’ve also landed some initial support for the <strong>Style Editor</strong> tab (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44517">#44517</a>, <a href="https://github.com/servo/servo/pull/44462">#44462</a>).</p>
<p>We’re working towards re-enabling our automated DevTools tests in CI, which should make the feature more reliable (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/44577">#44577</a>), and we’ve landed a small build reproducibility fix too (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44459">#44459</a>).</p>
<p>For developers of Servo itself, please note that the <strong>Cargo ‘release’ profile</strong> is no longer <code>#[cfg(debug­_assertions)]</code> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44177">#44177</a>).
If you’ve been using ‘release’ as a “faster ‘debug’ with assertions” build locally, consider switching to ‘checked-release’ or ‘medium’.</p>
<p>The pull request template has been updated (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44135">#44135</a>).
<strong>‘Testing’</strong> and <strong>‘Fixes’</strong> should go at the <em>bottom</em> of the PR description, and <strong>‘Testing’</strong> is about automated tests, not how you tested the PR locally.</p>
<p>We’ve made more progress on the new <a href="https://containers.dev/"><strong>dev container</strong></a>, which will provide an alternative to <a href="https://book.servo.org/building/building.html">our usual procedures</a> for setting up a Servo build environment (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/44126">#44126</a>, <a href="https://github.com/servo/servo/pull/44111">#44111</a>, <a href="https://github.com/servo/servo/pull/44162">#44162</a>, <a href="https://github.com/servo/servo/pull/44641">#44641</a>, <a href="https://github.com/servo/servo/pull/44109">#44109</a>).
Keep an eye out for that <a href="https://book.servo.org/building/building.html">in the book</a>!</p>
<p>In the meantime, did you know that you can use <a href="https://lix.systems/"><strong>Lix</strong></a> or <a href="https://nixos.org/manual/nix/stable"><strong>Nix</strong></a> to build Servo on Linux with a lot less hassle, <em>even if</em> you’re not using NixOS?
For now at least, head to the <a href="https://book.servo.org/building/nixos.html">NixOS page</a> in the book to learn more.
We’ve also fixed a regression that made <code>--debug-mozjs</code> and <code>MOZJS­_FROM­_SOURCE</code> builds take much longer to complete on Linux when not using Nix (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44346">#44346</a>).</p>
<p>We’ve fixed building Servo with the <strong>‘jitspew’ feature</strong> in mozjs, allowing you to set <strong>IONFLAGS</strong> to enable JIT logging (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44010">#44010</a>).
We’ve also fixed build issues on Windows and FreeBSD (<a href="https://github.com/zhangxichang">@zhangxichang</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44264">#44264</a>, <a href="https://github.com/servo/servo/pull/44591">#44591</a>).</p>
<h3>Embedding API <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#embedding-api">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>With this second monthly release of the Servo library, we have some quick notes about <strong>API stability</strong> and <strong>semver compatibility</strong>:</p>
<ul>
<li>
<p><strong>The <a href="https://crates.io/crates/servo">‘servo’</a> package</strong> follows <a href="https://doc.rust-lang.org/1.88.0/cargo/reference/specifying-dependencies.html#default-requirements">Cargo’s rules for semver compatibility</a>.
0.1.1 is compatible with version 0.1.0, but 0.2.0 is a breaking update.</p>
</li>
<li>
<p>Until we integrate semver analysis into our release process, each monthly release will have a breaking version number, while non-breaking version numbers may be used for LTS updates.</p>
</li>
<li>
<p>In general, <strong>dependencies of ‘servo’</strong>, like <a href="https://crates.io/crates/servo-base">‘servo-base’</a> and <a href="https://crates.io/crates/servo-script">‘servo-script’</a>, <strong>do not use semver</strong>.
Any release may include breaking changes.</p>
</li>
</ul>
<p>We’ve fixed a <strong>build failure</strong> affecting embedders with a <strong>new or updated Cargo.lock</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44093">#44093</a>), and landed several other changes to help us with the Servo library release process (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/43972">#43972</a>, <a href="https://github.com/servo/servo/pull/44642">#44642</a>, <a href="https://github.com/servo/servo/pull/43182">#43182</a>, <a href="https://github.com/servo/servo/pull/43866">#43866</a>, <a href="https://github.com/servo/servo/pull/44086">#44086</a>, <a href="https://github.com/servo/servo/pull/43797">#43797</a>).</p>
<p>Breaking changes:</p>
<ul>
<li>
<p><a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>::<a href="https://doc.servo.org/servo/struct.WebView.html#method.animating"><code>animating</code></a> now takes <code>&amp;self</code> instead of <code>self</code>, so you can call it without cloning the handle (<a href="https://github.com/JavaDerg">@JavaDerg</a>, <a href="https://github.com/servo/servo/pull/44253">#44253</a>)</p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/struct.Servo.html"><code>Servo</code></a>::<a href="https://doc.servo.org/servo/struct.Servo.html#method.site_data_manager"><code>site­_data­_manager</code></a> now returns <code>&amp;SiteDataManager</code> instead of <code>Ref&lt;'_, SiteDataManager&gt;</code> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44116">#44116</a>)</p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>::<code>play­_gamepad­_haptic­_effect</code> and <code>stop­_gamepad­_haptic­_effect</code> have been removed (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43895">#43895</a>), but they have not worked since February 2026 – use <a href="https://doc.servo.org/servo/trait.GamepadDelegate.html"><code>Gamepad­Delegate</code></a> instead</p>
</li>
</ul>
<p>You can now load a URL with <strong>custom request headers</strong> by calling <a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>::<a href="https://doc.servo.org/servo/struct.WebView.html#method.load_request"><code>load­_request</code></a> (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43338">#43338</a>).</p>
<p>You can now <strong>retrieve cookies asynchronously</strong> by calling <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.cookies_for_url_async"><code>cookies­_for­_url­_async</code></a> (<a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/servo/servo/pull/43794">#43794</a>).</p>
<p>The synchronous version of that method, <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.cookies_for_url"><code>cookies­_for­_url</code></a>, was previously not callable because <a href="https://doc.servo.org/servo/enum.CookieSource.html"><code>Cookie­Source</code></a> was not exposed to the public API, but we’ve fixed that now (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/44124">#44124</a>).</p>
<p>You can now <strong>clear session cookies</strong> without clearing <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Cookies#removal_defining_the_lifetime_of_a_cookie">permanent cookies</a> by calling <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.clear_session_cookies"><code>clear­_session­_cookies</code></a> (<a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/servo/servo/pull/44166">#44166</a>).</p>
<p>When <strong>intercepting requests</strong> with <a href="https://doc.servo.org/servo/trait.ServoDelegate.html"><code>Servo­Delegate</code></a>:: and <a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>::<a href="https://doc.servo.org/servo/trait.WebViewDelegate.html#method.load_web_resource"><code>load­_web­_resource</code></a>, we now include a <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html#structfield.destination"><code>destination</code></a> and <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html#structfield.referrer_url"><code>referrer­_url</code></a> in the <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html"><code>Web­Resource­Request</code></a>, which can be helpful if you’re implementing <strong>ad blocking</strong> (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44493">#44493</a>).</p>
<p>You can configure Servo to <strong>write all of its storage to a unique directory</strong> for that session by enabling <a href="https://doc.servo.org/servo/struct.Opts.html"><code>Opts</code></a>::<a href="https://doc.servo.org/servo/struct.Opts.html#structfield.temporary_storage"><code>temporary­_storage</code></a> (<a href="https://github.com/janvarga">@janvarga</a>, <a href="https://github.com/servo/servo/pull/44433">#44433</a>).
Note that these unique directories currently persist after Servo exits, so it’s an isolation feature, not a privacy feature.</p>
<p><a href="https://doc.servo.org/servo/struct.WindowRenderingContext.html"><code>Window­Rendering­Context</code></a>::<a href="https://doc.servo.org/servo/struct.WindowRenderingContext.html#method.new"><code>new</code></a> and <a href="https://doc.servo.org/servo/struct.SoftwareRenderingContext.html"><code>Software­Rendering­Context</code></a>::<a href="https://doc.servo.org/servo/struct.SoftwareRenderingContext.html#method.new"><code>new</code></a> now return an error if the given <code>size</code> is less than 1x1 (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44011">#44011</a>).</p>
<p>We’ve improved our API docs for <a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>, <a href="https://doc.servo.org/servo/struct.WebViewBuilder.html"><code>Web­View­Builder</code></a>, <a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>, <a href="https://doc.servo.org/servo/trait.ServoDelegate.html"><code>ServoDelegate</code></a>, <a href="https://doc.servo.org/servo/struct.PromptDialog.html"><code>Prompt­Dialog</code></a>, <a href="https://doc.servo.org/servo/struct.WebResourceLoad.html"><code>Web­Resource­Load</code></a>, <a href="https://doc.servo.org/servo/webxr/trait.WebXrRegistry.html"><code>Web­Xr­Registry</code></a>, <a href="https://doc.servo.org/servo/struct.Preferences.html"><code>Preferences</code></a>, and servoshell’s <a href="https://doc.servo.org/servoshell/prefs/static.EXPERIMENTAL_PREFS.html"><code>EXPERIMENTAL­_PREFS</code></a> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/43892">#43892</a>, <a href="https://github.com/servo/servo/pull/43787">#43787</a>, <a href="https://github.com/servo/servo/pull/44171">#44171</a>, <a href="https://github.com/servo/servo/pull/43947">#43947</a>).</p>
<p>We’ve also improved our API docs for <a href="https://doc.servo.org/servo/struct.Opts.html"><code>Opts</code></a>, <a href="https://doc.servo.org/servo/enum.OutputOptions.html"><code>Output­Options</code></a>, <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><code>Diagnostics­Logging</code></a>, <a href="https://doc.servo.org/servo/enum.PrefValue.html"><code>Pref­Value</code></a>, <a href="https://doc.servo.org/servo/index.html"><code>servo</code></a>::<a href="https://doc.servo.org/servo/opts/index.html"><code>opts</code></a>, and <a href="https://doc.servo.org/servo_config/index.html"><code>servo­_config</code></a> (<a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/43802">#43802</a>).</p>
<h3>More on the web platform <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#more-on-the-web-platform">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong><kbd>Tab</kbd> navigation</strong> now works across <strong>&lt;iframe&gt;</strong> boundaries (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44397">#44397</a>), and <strong><kbd>Ctrl</kbd>+<kbd>Backspace</kbd></strong> (or <strong><kbd>⌥</kbd><kbd>⌫</kbd></strong>) now <strong>deletes a whole word</strong> in input fields (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43940">#43940</a>).</p>
<p><strong>Tab characters</strong> are now rendered correctly in <strong>&lt;pre&gt;</strong> (and other elements with <strong>‘white-space: pre’</strong>), with proper tab stops (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44480">#44480</a>).
<strong>Spaces</strong> are now rendered correctly in <strong>2D &lt;canvas&gt;</strong>, instead of twice as wide as they should be (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43899">#43899</a>).</p>
<p><strong>&lt;a href&gt;</strong> now correctly resolves the URL with the page encoding (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/43822">#43822</a>).</p>
<p>We’ve improved the default appearance of <strong>&lt;input type=file&gt;</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44496">#44496</a>) and <strong>&lt;textarea placeholder&gt;</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43770">#43770</a>).</p>
<p>All <strong>keyboard events</strong>, <strong>mouse events</strong>, <strong>wheel events</strong>, and <strong>pointer events</strong>, other than <strong>‘pointerenter’</strong> and <strong>‘pointerleave’</strong>, now <strong>bubble out of shadow roots</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/43799">#43799</a>, <a href="https://github.com/servo/servo/pull/44094">#44094</a>).
<strong>‘error’ events</strong> on <strong>Window</strong> now report the correct <strong>filename</strong> (<strong>source</strong> in <strong>onerror</strong>) and <strong>lineno</strong> (<a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/servo/servo/pull/43632">#43632</a>).</p>
<p><strong>console.log()</strong> and friends now support <strong>printf-style formatting directives</strong>, although for now <code>%c</code> is ignored (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43897">#43897</a>).</p>
<p><strong>file: URLs</strong> are now considered <strong>secure contexts</strong>, so they can now use features like <strong>crypto.subtle</strong> and <strong>crypto.random­UUID</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/43989">#43989</a>).</p>
<p><strong>Exception messages</strong> have improved in Location, Static­Range, and the HTML­Element family of types (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/MuhammadMouostafa">@MuhammadMouostafa</a>, <a href="https://github.com/treetmitterglad">@treetmitterglad</a>, <a href="https://github.com/servo/servo/pull/44282">#44282</a>, <a href="https://github.com/servo/servo/pull/43260">#43260</a>, <a href="https://github.com/servo/servo/pull/43882">#43882</a>).</p>
<p>We’ve improved the conformance of <strong>fetch algorithms</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/43970">#43970</a>, <a href="https://github.com/servo/servo/pull/43798">#43798</a>), <strong>focus</strong> and <strong>tab navigation</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43842">#43842</a>, <a href="https://github.com/servo/servo/pull/44029">#44029</a>, <a href="https://github.com/servo/servo/pull/44360">#44360</a>, <a href="https://github.com/servo/servo/pull/43859">#43859</a>, <a href="https://github.com/servo/servo/pull/44535">#44535</a>), <strong>form submission</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43700">#43700</a>), <strong>JS modules</strong> (<a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/servo/servo/pull/43741">#43741</a>, <a href="https://github.com/servo/servo/pull/44179">#44179</a>, <a href="https://github.com/servo/servo/pull/44042">#44042</a>), <strong>page navigation</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43857">#43857</a>), <strong>&lt;svg view­Box&gt;</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44420">#44420</a>), <strong>‘attr()’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>), <strong>‘:focus’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43873">#43873</a>), <strong>‘font’</strong> (<a href="https://github.com/RichardTjokroutomo">@RichardTjokroutomo</a>, <a href="https://github.com/servo/servo/pull/44061">#44061</a>), <strong>‘@keyframes’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/43461">#43461</a>), <strong>‘@property’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>), <strong>‘load’</strong> events (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/servo/servo/pull/43807">#43807</a>, <a href="https://github.com/servo/servo/pull/44046">#44046</a>), <strong>fetch­Later()</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43627">#43627</a>), <strong>axes</strong> and <strong>buttons</strong> on <strong>Gamepad</strong> (<a href="https://github.com/log101">@log101</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44411">#44411</a>, <a href="https://github.com/servo/servo/pull/44357">#44357</a>), <strong>copy­Tex­Image­2D()</strong> on <strong>Web­GL­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43608">#43608</a>), <strong>tex­Image3D()</strong> on <strong>Web­GL2­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/servo/servo/pull/44367">#44367</a>), <strong>environment­Blend­Mode</strong> on <strong>XR­Session</strong> (<a href="https://github.com/msub2">@msub2</a>, <a href="https://github.com/servo/servo/pull/44155">#44155</a>), <strong>mark()</strong> and <strong>measure()</strong> on <strong>Performance</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44471">#44471</a>, <a href="https://github.com/servo/servo/pull/44199">#44199</a>, <a href="https://github.com/servo/servo/pull/43990">#43990</a>, <a href="https://github.com/servo/servo/pull/43753">#43753</a>), and <strong>Performance­Resource­Timing</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44228">#44228</a>).</p>
<p>We’ve fixed bugs related to <strong>console logging</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44243">#44243</a>), <strong>‘animation’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44299">#44299</a>), <strong>‘box-shadow’</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44474">#44474</a>, <a href="https://github.com/servo/servo/pull/44457">#44457</a>), <strong>‘display: contents’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44551">#44551</a>, <a href="https://github.com/servo/servo/pull/44299">#44299</a>), <strong>‘display: inline-flex’</strong> (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44281">#44281</a>), <strong>‘display: table-cell’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44550">#44550</a>), <strong>‘display: table-row-group’</strong> (<a href="https://github.com/Veercodeprog">@Veercodeprog</a>, <a href="https://github.com/servo/servo/pull/43674">#43674</a>), <strong>‘overflow-x: clip’</strong> and <strong>‘overflow-y: clip’</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43620">#43620</a>), <strong>‘position: absolute’</strong> on grid items (<a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/servo/servo/pull/44324">#44324</a>), <strong>‘word-spacing: &lt;percentage&gt;’</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44031">#44031</a>), <strong>remove­Child()</strong> on <strong>Document</strong> (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44133">#44133</a>), and <strong>URL.revoke­Object­URL()</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/43746">#43746</a>, <a href="https://github.com/servo/servo/pull/43977">#43977</a>, <a href="https://github.com/servo/servo/pull/44035">#44035</a>).</p>
<h3>Performance and stability <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#performance-and-stability">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>We’ve fixed some big inefficiencies in Servo.
<strong>append­Child()</strong> with nested shadow roots is no longer <math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mi>O</mi><mrow><mo>(</mo><msup><mn>2</mn><mi>n</mi></msup><mo>)</mo></mrow></mrow></math> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44016">#44016</a>), and we’ve halved the time it takes to load <a href="https://262.ecma-international.org/16.0/index.html">the ECMAScript spec</a> by fixing the <math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mi>O</mi><mrow><mo>(</mo><mtext>whole DOM tree</mtext><mo>)</mo></mrow></mrow></math> processing of <strong>‘id’</strong> and <strong>‘name’ attributes</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44120">#44120</a>, <a href="https://github.com/servo/servo/pull/44127">#44127</a>, <a href="https://github.com/servo/servo/pull/44117">#44117</a>).</p>
<p>Servo makes its <strong>first TLS connection</strong> in each session <strong>30–60 ms faster</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44242">#44242</a>), and we’ve instrumented the Servo and servoshell startup processes to find more opportunities for optimisation (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44443">#44443</a>, <a href="https://github.com/servo/servo/pull/44456">#44456</a>).</p>
<p>Like most browser engines, Servo is a multi-threaded (and sometimes multi-process) system requiring a great deal of IPC messages to keep everything connected.
<a href="https://book.servo.org/design-documentation/architecture.html">Two key components</a> of this system are the <strong>constellation</strong> thread, which manages the engine as a whole, and the <strong>script threads</strong> (or web processes), which render the web pages.
Sending these messages can be expensive though, so to <strong>reduce unnecessary IPC traffic</strong>, we’ve landed an optimisation that allows script threads to selectively receive only the relevant messages from the constellation (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/43124">#43124</a>).</p>
<p>We’ve reduced the <strong>memory usage</strong> of each <strong>Attr</strong>, <strong>Text</strong>, and <strong>Character­Data</strong> node in the DOM by 16 bytes (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44074">#44074</a>), and <strong>fixed a memory leak</strong> when deleting <strong>&lt;video controls&gt;</strong> or <strong>&lt;audio controls&gt;</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43983">#43983</a>).</p>
<p>Our <strong>about:memory</strong> page is more accurate now too, with new tracking of <strong>libc memory allocations</strong> on macOS, improved tracking of libc memory allocations on Linux (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44037">#44037</a>), and more accurate tracking of Path­Buf and types in <code>tokio</code>, <code>http</code>, <code>data­_url</code>, and <code>urlpattern</code> (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/43858">#43858</a>).</p>
<p>Less memory usage isn’t always better in browser engines though, because there are many kinds of caches and other optimisations we can do to make browsing the web faster, at the expense of increased memory usage.
For example, we can greatly speed up <strong>prototype checks</strong> for DOM objects by storing a number in each object that identifies the concrete type, at the expense of making each DOM object 64 bits larger (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44364">#44364</a>).</p>
<p>Layout can now <strong>reuse fragments</strong> in later reflows, in many cases that involve block layout or ‘position: absolute’ (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/42904">#42904</a>, <a href="https://github.com/servo/servo/pull/44231">#44231</a>).
We’re also working on <strong>reusing shaping results</strong> in later reflows, and making inline layout more efficient (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44370">#44370</a>, <a href="https://github.com/servo/servo/pull/43974">#43974</a>, <a href="https://github.com/servo/servo/pull/44436">#44436</a>).</p>
<p>We’ve landed several changes that should reduce the <strong>binary size</strong> of Servo (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/44227">#44227</a>, <a href="https://github.com/servo/servo/pull/44221">#44221</a>, <a href="https://github.com/servo/servo/pull/44303">#44303</a>, <a href="https://github.com/servo/servo/pull/44338">#44338</a>, <a href="https://github.com/servo/servo/pull/44428">#44428</a>, <a href="https://github.com/servo/servo/pull/44134">#44134</a>).</p>
<p>We’ve also reduced clones, allocations, borrow checks, GC rooting steps, and other operations in many parts of Servo (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44008">#44008</a>, <a href="https://github.com/servo/servo/pull/44544">#44544</a>, <a href="https://github.com/servo/servo/pull/44271">#44271</a>, <a href="https://github.com/servo/servo/pull/44279">#44279</a>, <a href="https://github.com/servo/servo/pull/43826">#43826</a>, <a href="https://github.com/servo/servo/pull/44052">#44052</a>, <a href="https://github.com/servo/servo/pull/44139">#44139</a>).</p>
<p>Several crashes have been fixed:</p>
<ul>
<li>in compressed­Tex­Sub­Image2D() on Web­GL­Rendering­Context (<a href="https://github.com/thebabalola">@thebabalola</a>, #44050)</li>
<li>in console.log() (<a href="https://github.com/thebabalola">@thebabalola</a>, <a href="https://github.com/servo/servo/pull/43844">#43844</a>)</li>
<li>in get­Data() on Data­Transfer (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44607">#44607</a>)</li>
<li>in remove() on Element (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44435">#44435</a>)</li>
<li>in replace­With() on Element (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44503">#44503</a>)</li>
<li>in <code>--debug-mozjs</code> builds (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44386">#44386</a>, <a href="https://github.com/servo/servo/pull/44573">#44573</a>, <a href="https://github.com/servo/servo/pull/44581">#44581</a>)</li>
<li>in flex and grid layout (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/servo/servo/pull/44424">#44424</a>, <a href="https://github.com/servo/servo/pull/44203">#44203</a>)</li>
<li>in layout queries like <code>offset­Height</code> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44560">#44560</a>)</li>
<li>in the devtools Debugger tab, when stepping and when inspecting nested values (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/servo/servo/pull/44024">#44024</a>, <a href="https://github.com/servo/servo/pull/43995">#43995</a>)</li>
<li>when removing &lt;colgroup&gt; from the DOM (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43846">#43846</a>)</li>
<li>when running garbage collection (<a href="https://github.com/drasticactions">@drasticactions</a>, <a href="https://github.com/servo/servo/pull/43933">#43933</a>)</li>
<li>when running servoshell with a <a href="https://doc.rust-lang.org/1.88.0/std/primitive.u64.html"><code>u64</code></a> <code>--pref</code> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44079">#44079</a>)</li>
<li>when shadow roots are deeply nested, or when calling attach­Shadow() removes elements from the flat tree (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43888">#43888</a>, <a href="https://github.com/servo/servo/pull/43930">#43930</a>, <a href="https://github.com/servo/servo/pull/44259">#44259</a>)</li>
<li>when <a href="https://storage.spec.whatwg.org/">web storage features</a> fail to write to disk or encounter SQLite errors (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/43918">#43918</a>, <a href="https://github.com/servo/servo/pull/43949">#43949</a>)</li>
</ul>
<p>We fixed a crash in servoshell when pressing keys like Ctrl+2 or ⌘2 with not enough tabs open (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44070">#44070</a>).</p>
<p><strong>DOM data structures</strong> (<code>#[dom­_struct]</code>) can refer to one another, with the help of <a href="https://research.mozilla.org/2014/08/26/javascript-servos-only-garbage-collector/">garbage collection</a>.
But when DOM objects are being destroyed, those references can become invalid for a brief moment, depending on the order the GC finalizers run in.
This can be unsound if those references are accessed, which is a very easy mistake to make if the type has an <code>impl Drop</code>.
To help prevent that class of bug, we’re reworking our DOM types so that none of them have <code>#[dom­_struct]</code> and <code>impl Drop</code> at the same time (<a href="https://github.com/willypuzzle">@willypuzzle</a>, <a href="https://github.com/servo/servo/pull/44119">#44119</a>, <a href="https://github.com/servo/servo/pull/44501">#44501</a>, <a href="https://github.com/servo/servo/pull/44513">#44513</a>).</p>
<p>We’ve improved our static analysis for GC rooting (<a href="https://github.com/officialasishkumar">@officialasishkumar</a>, <a href="https://github.com/servo/servo/pull/44489">#44489</a>), and we’ve continued our long-running effort to <strong>use the Rust type system</strong> to make certain kinds of dynamic borrow failures impossible (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/nodelpit">@nodelpit</a>, <a href="https://github.com/servo/servo/pull/43174">#43174</a>, <a href="https://github.com/servo/servo/pull/43524">#43524</a>, <a href="https://github.com/servo/servo/pull/43928">#43928</a>, <a href="https://github.com/servo/servo/pull/43943">#43943</a>, <a href="https://github.com/servo/servo/pull/43942">#43942</a>, <a href="https://github.com/servo/servo/pull/43944">#43944</a>, <a href="https://github.com/servo/servo/pull/43946">#43946</a>, <a href="https://github.com/servo/servo/pull/43952">#43952</a>, <a href="https://github.com/servo/servo/pull/43975">#43975</a>, <a href="https://github.com/servo/servo/pull/44018">#44018</a>, <a href="https://github.com/servo/servo/pull/44175">#44175</a>, <a href="https://github.com/servo/servo/pull/44241">#44241</a>, <a href="https://github.com/servo/servo/pull/44368">#44368</a>, <a href="https://github.com/servo/servo/pull/44406">#44406</a>, <a href="https://github.com/servo/servo/pull/44441">#44441</a>, <a href="https://github.com/servo/servo/pull/44422">#44422</a>, <a href="https://github.com/servo/servo/pull/44475">#44475</a>, <a href="https://github.com/servo/servo/pull/44478">#44478</a>, <a href="https://github.com/servo/servo/pull/44484">#44484</a>, <a href="https://github.com/servo/servo/pull/44476">#44476</a>, <a href="https://github.com/servo/servo/pull/44490">#44490</a>, <a href="https://github.com/servo/servo/pull/44477">#44477</a>, <a href="https://github.com/servo/servo/pull/44494">#44494</a>, <a href="https://github.com/servo/servo/pull/44497">#44497</a>, <a href="https://github.com/servo/servo/pull/44498">#44498</a>, <a href="https://github.com/servo/servo/pull/44495">#44495</a>, <a href="https://github.com/servo/servo/pull/44505">#44505</a>, <a href="https://github.com/servo/servo/pull/44506">#44506</a>, <a href="https://github.com/servo/servo/pull/44507">#44507</a>, <a href="https://github.com/servo/servo/pull/44508">#44508</a>, <a href="https://github.com/servo/servo/pull/44509">#44509</a>, <a href="https://github.com/servo/servo/pull/44510">#44510</a>, <a href="https://github.com/servo/servo/pull/44512">#44512</a>, <a href="https://github.com/servo/servo/pull/44482">#44482</a>, <a href="https://github.com/servo/servo/pull/44527">#44527</a>, <a href="https://github.com/servo/servo/pull/44528">#44528</a>, <a href="https://github.com/servo/servo/pull/44531">#44531</a>, <a href="https://github.com/servo/servo/pull/44534">#44534</a>, <a href="https://github.com/servo/servo/pull/44542">#44542</a>, <a href="https://github.com/servo/servo/pull/44533">#44533</a>, <a href="https://github.com/servo/servo/pull/44543">#44543</a>, <a href="https://github.com/servo/servo/pull/44553">#44553</a>, <a href="https://github.com/servo/servo/pull/44547">#44547</a>, <a href="https://github.com/servo/servo/pull/44563">#44563</a>, <a href="https://github.com/servo/servo/pull/44562">#44562</a>, <a href="https://github.com/servo/servo/pull/44565">#44565</a>, <a href="https://github.com/servo/servo/pull/44558">#44558</a>, <a href="https://github.com/servo/servo/pull/44583">#44583</a>, <a href="https://github.com/servo/servo/pull/44606">#44606</a>, <a href="https://github.com/servo/servo/pull/44605">#44605</a>, <a href="https://github.com/servo/servo/pull/44608">#44608</a>, <a href="https://github.com/servo/servo/pull/44602">#44602</a>, <a href="https://github.com/servo/servo/pull/44584">#44584</a>, <a href="https://github.com/servo/servo/pull/44620">#44620</a>, <a href="https://github.com/servo/servo/pull/44590">#44590</a>, <a href="https://github.com/servo/servo/pull/44254">#44254</a>, <a href="https://github.com/servo/servo/pull/44628">#44628</a>, <a href="https://github.com/servo/servo/pull/44629">#44629</a>, <a href="https://github.com/servo/servo/pull/44638">#44638</a>, <a href="https://github.com/servo/servo/pull/44626">#44626</a>, <a href="https://github.com/servo/servo/pull/44081">#44081</a>).</p>
<p>Thanks to a wide range of people, we’ve also landed a bunch of cleanups and refactors (<a href="https://github.com/delan">@delan</a>, <a href="https://github.com/alice">@alice</a>, <a href="https://github.com/Skgland">@Skgland</a>, <a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/thebabalola">@thebabalola</a>, <a href="https://github.com/CynthiaOketch">@CynthiaOketch</a>, <a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/treetmitterglad">@treetmitterglad</a>, <a href="https://github.com/foresterre">@foresterre</a>, <a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/StaySafe020">@StaySafe020</a>, <a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43772">#43772</a>, <a href="https://github.com/servo/servo/pull/44006">#44006</a>, <a href="https://github.com/servo/servo/pull/43860">#43860</a>, <a href="https://github.com/servo/servo/pull/44121">#44121</a>, <a href="https://github.com/servo/servo/pull/44160">#44160</a>, <a href="https://github.com/servo/servo/pull/43884">#43884</a>, <a href="https://github.com/servo/servo/pull/44154">#44154</a>, <a href="https://github.com/servo/servo/pull/44569">#44569</a>, <a href="https://github.com/servo/servo/pull/43939">#43939</a>, <a href="https://github.com/servo/servo/pull/44003">#44003</a>, <a href="https://github.com/servo/servo/pull/44110">#44110</a>, <a href="https://github.com/servo/servo/pull/44122">#44122</a>, <a href="https://github.com/servo/servo/pull/43824">#43824</a>, <a href="https://github.com/servo/servo/pull/44635">#44635</a>, <a href="https://github.com/servo/servo/pull/44103">#44103</a>, <a href="https://github.com/servo/servo/pull/43978">#43978</a>, <a href="https://github.com/servo/servo/pull/44092">#44092</a>, <a href="https://github.com/servo/servo/pull/44114">#44114</a>, <a href="https://github.com/servo/servo/pull/44277">#44277</a>, <a href="https://github.com/servo/servo/pull/44454">#44454</a>, <a href="https://github.com/servo/servo/pull/44274">#44274</a>, <a href="https://github.com/servo/servo/pull/44237">#44237</a>, <a href="https://github.com/servo/servo/pull/44232">#44232</a>, <a href="https://github.com/servo/servo/pull/44167">#44167</a>, <a href="https://github.com/servo/servo/pull/44214">#44214</a>, <a href="https://github.com/servo/servo/pull/43820">#43820</a>, <a href="https://github.com/servo/servo/pull/43825">#43825</a>, <a href="https://github.com/servo/servo/pull/43810">#43810</a>, <a href="https://github.com/servo/servo/pull/43838">#43838</a>, <a href="https://github.com/servo/servo/pull/43841">#43841</a>, <a href="https://github.com/servo/servo/pull/43847">#43847</a>, <a href="https://github.com/servo/servo/pull/43875">#43875</a>, <a href="https://github.com/servo/servo/pull/43876">#43876</a>, <a href="https://github.com/servo/servo/pull/43889">#43889</a>, <a href="https://github.com/servo/servo/pull/43893">#43893</a>, <a href="https://github.com/servo/servo/pull/43896">#43896</a>, <a href="https://github.com/servo/servo/pull/43881">#43881</a>, <a href="https://github.com/servo/servo/pull/43906">#43906</a>, <a href="https://github.com/servo/servo/pull/43913">#43913</a>, <a href="https://github.com/servo/servo/pull/43908">#43908</a>, <a href="https://github.com/servo/servo/pull/43917">#43917</a>, <a href="https://github.com/servo/servo/pull/43910">#43910</a>, <a href="https://github.com/servo/servo/pull/43921">#43921</a>, <a href="https://github.com/servo/servo/pull/43924">#43924</a>, <a href="https://github.com/servo/servo/pull/43925">#43925</a>, <a href="https://github.com/servo/servo/pull/43907">#43907</a>, <a href="https://github.com/servo/servo/pull/43923">#43923</a>, <a href="https://github.com/servo/servo/pull/43916">#43916</a>, <a href="https://github.com/servo/servo/pull/43909">#43909</a>, <a href="https://github.com/servo/servo/pull/43911">#43911</a>, <a href="https://github.com/servo/servo/pull/43957">#43957</a>, <a href="https://github.com/servo/servo/pull/43969">#43969</a>, <a href="https://github.com/servo/servo/pull/43967">#43967</a>, <a href="https://github.com/servo/servo/pull/43915">#43915</a>, <a href="https://github.com/servo/servo/pull/43954">#43954</a>, <a href="https://github.com/servo/servo/pull/43963">#43963</a>, <a href="https://github.com/servo/servo/pull/43959">#43959</a>, <a href="https://github.com/servo/servo/pull/43955">#43955</a>, <a href="https://github.com/servo/servo/pull/44067">#44067</a>, <a href="https://github.com/servo/servo/pull/44068">#44068</a>, <a href="https://github.com/servo/servo/pull/44071">#44071</a>, <a href="https://github.com/servo/servo/pull/44084">#44084</a>, <a href="https://github.com/servo/servo/pull/44265">#44265</a>, <a href="https://github.com/servo/servo/pull/44115">#44115</a>, <a href="https://github.com/servo/servo/pull/44358">#44358</a>, <a href="https://github.com/servo/servo/pull/43848">#43848</a>).</p>
<h3>Donations <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#donations">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>Thanks again for your generous support!
We are now receiving <strong>7349 USD/month</strong> (+2.5% from March) in recurring donations.
This helps us cover the cost of our <strong><a href="https://ci0.servo.org/">speedy</a> <a href="https://ci1.servo.org/">CI</a> <a href="https://ci2.servo.org/">and</a> <a href="https://ci3.servo.org/">benchmarking</a> <a href="https://ci4.servo.org/">servers</a></strong>, one of our latest <strong><a href="https://www.outreachy.org/alums/2025-06/#:~:text=Servo">Outreachy interns</a></strong>, and funding <strong><a href="https://servo.org/blog/2025/09/17/your-donations-at-work-funding-jdm/">maintainer work</a></strong> that helps more people contribute to Servo.</p>
<p>Servo is also on <a href="https://thanks.dev/">thanks.dev</a>, and already <strong>33 GitHub users</strong> (−4 from March) that depend on Servo are sponsoring us there.
If you use Servo libraries like <a href="https://crates.io/crates/url/reverse_dependencies">url</a>, <a href="https://crates.io/crates/html5ever/reverse_dependencies">html5ever</a>, <a href="https://crates.io/crates/selectors/reverse_dependencies">selectors</a>, or <a href="https://crates.io/crates/cssparser/reverse_dependencies">cssparser</a>, signing up for <a href="https://thanks.dev/">thanks.dev</a> could be a good way for you (or your employer) to give back to the community.</p>
<p>We now have <a href="https://servo.org/blog/2025/11/21/sponsorship-tiers/"><strong>sponsorship tiers</strong></a> that allow you or your organisation to donate to the Servo project with public acknowlegement of your support.
If you’re interested in this kind of sponsorship, please contact us at <a href="mailto:join@servo.org">join@servo.org</a>.</p>
<figure class="_fig"><div class="_flex">
    <div>
        <div><strong>7349</strong> USD/month</div>
        <div></div>
        <div></div>
        <div><strong>10000</strong></div>
    </div>
    <progress max="10000" value="7349"></progress>
</div></figure>
<p>Use of donations is decided transparently via the Technical Steering Committee’s public <strong><a href="https://github.com/servo/project/blob/main/FUNDING_REQUEST.md">funding request process</a></strong>, and active proposals are tracked in <a href="https://github.com/servo/project/issues/187">servo/project#187</a>.
For more details, head to our <a href="https://servo.org/sponsorship/">Sponsorship page</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK-Based Rockstar Games North Workers Formally Announce Union]]></title>
<description><![CDATA[Rockstar Games has a 2,000-employee studio in Scotland called Rockstar North. And Thursday its workers announced they'd formed a union, reports the gaming news site Aftermath:



The union [part of the wider Independent Workers of Great Britain (IWGB) union] includes workers from Rockstar Games o...]]></description>
<link>https://tsecurity.de/de/3560406/it-security-nachrichten/uk-based-rockstar-games-north-workers-formally-announce-union/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560406/it-security-nachrichten/uk-based-rockstar-games-north-workers-formally-announce-union/</guid>
<pubDate>Sun, 31 May 2026 09:49:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rockstar Games has a 2,000-employee studio in Scotland called Rockstar North. And Thursday its workers announced they'd formed a union, reports the gaming news site Aftermath:



The union [part of the wider Independent Workers of Great Britain (IWGB) union] includes workers from Rockstar Games offices in Leeds, London, Edinburgh, Dundee, and Lincoln, the Rockstar Games Workers Union said in a YouTube video published on Thursday... Last year, Rockstar Games employees told Aftermath that the company's insistence on return-to-office policies was a problem for many workers. 

Rockstar Games, for its part, claimed the policies were related to productivity and security concerns... The video posted Thursday outlines what happened over the past several months, starting with the firing of more than 30 Rockstar Games employees in October 2025 for what the company said was "discussing confidential information in a public forum," a Rockstar Games spokesperson said in a statement to Bloomberg in November. The union disagreed: It said at the time that the workers were gathered in a private Discord server with employees and union organizers — the beginnings of the union announced Thursday. The IWGB is working to fight the firings in court. 

Workers and outside union supporters gathered globally after the employees were fired, in front of Rockstar Games' offices, to protest what the union called union busting by Rockstar Games... "We believe the [firings] were unlawful and retaliatory — connected to the workers' collective activity of organizing at Rockstar," IWGB Game Workers Union co-founder Austin Kelmore told Aftermath at the time. "This action by Rockstar came shortly after reaching 10 percent of eligible workers at Rockstar in the union...." [10% is the threshhold for legal recognition by the U.K. government.]
The workers have received support from government officials; in December, UK Prime Minister Keir Starmer called the firings of the unionizing workers "a deeply concerning case."
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=UK-Based+Rockstar+Games+North+Workers+Formally+Announce+Union+%3A+https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F05%2F31%2F0227212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F05%2F31%2F0227212%2Fuk-based-rockstar-games-north-workers-formally-announce-union%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://games.slashdot.org/story/26/05/31/0227212/uk-based-rockstar-games-north-workers-formally-announce-union?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canvas L: Diese Soundbar soll selbst Audiophile begeistern]]></title>
<description><![CDATA[Soundbars sind üblicherweise keine Produkte für anspruchsvolle Hörer. Letztere setzen eher auf AVR-Systeme. Das will Canvas mit seinem neuen Modell Canvas L ändern. Laut dem dänischen Anbieter handele es sich um den ersten Klangriegel für die audiophile Klientel. Gleichzeitig will...Zum Beitrag: ...]]></description>
<link>https://tsecurity.de/de/3559242/it-nachrichten/canvas-l-diese-soundbar-soll-selbst-audiophile-begeistern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559242/it-nachrichten/canvas-l-diese-soundbar-soll-selbst-audiophile-begeistern/</guid>
<pubDate>Sat, 30 May 2026 17:02:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Soundbars sind üblicherweise keine Produkte für anspruchsvolle Hörer. Letztere setzen eher auf AVR-Systeme. Das will Canvas mit seinem neuen Modell Canvas L ändern. Laut dem dänischen Anbieter handele es sich um den ersten Klangriegel für die audiophile Klientel. Gleichzeitig will...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/canvas-l-diese-soundbar-soll-selbst-audiophile-begeistern/">Canvas L: Diese Soundbar soll selbst Audiophile begeistern</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,43ms -->