<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 06 Aug 2026 08:23:30 +0200</lastBuildDate>
<pubDate>Thu, 06 Aug 2026 08:23:30 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/RSS/1/" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Company of Heroes 3: Final Stand DLC – Yay or Nay (PC)]]></title>
<description><![CDATA[Company of Heroes 3 is a game that’s not strange to mods and people try to add their own spin to the overall gameplay. However, it seems that the devs decided to offer players something completely different in the form of Company of Heroes 3: Final Stand. This is a roguelite, wave-based game mode...]]></description>
<link>https://tsecurity.de/de/3707445/it-security-nachrichten/company-of-heroes-3-final-stand-dlc-yay-or-nay-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707445/it-security-nachrichten/company-of-heroes-3-final-stand-dlc-yay-or-nay-pc/</guid>
<pubDate>Thu, 06 Aug 2026 07:46:35 +0200</pubDate>
<content:encoded><![CDATA[Company of Heroes 3 is a game that’s not strange to mods and people try to add their own spin to the overall gameplay. However, it seems that the devs decided to offer players something completely different in the form of Company of Heroes 3: Final Stand. This is a roguelite, wave-based game mode for Company of Heroes 3, which comes as a standalone release. And on top of that it’s co-op too, which is even better.

Final Stand comes with a bunch of new maps, and what’s great about it is the fact that you can select the map, difficulty and faction. That matters, because you get to narrow down where and how you play, and it all becomes way more interesting and enticing. You can think of Company of Heroes 3: Final Stand as a wave-based, horde game, within the setting of COH3. It sounds a bit crazy, but it works very nicely, and it adds a unique layer of intensity as well.

The concept of this standalone game mode is pretty interesting. You have a base and you are defendi...]]></content:encoded>
</item>
<item>
<title><![CDATA[Aldi Süd bietet bald einen nützlichen Küchenhelfer für nur 2,99 Euro an]]></title>
<description><![CDATA[Dieser handliche Zerkleinerer schont nicht nur die Nerven, sondern auch den Geldbeutel.]]></description>
<link>https://tsecurity.de/de/3707444/it-nachrichten/aldi-sued-bietet-bald-einen-nuetzlichen-kuechenhelfer-fuer-nur-299-euro-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707444/it-nachrichten/aldi-sued-bietet-bald-einen-nuetzlichen-kuechenhelfer-fuer-nur-299-euro-an/</guid>
<pubDate>Thu, 06 Aug 2026 07:46:03 +0200</pubDate>
<content:encoded><![CDATA[Dieser handliche Zerkleinerer schont nicht nur die Nerven, sondern auch den Geldbeutel.]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues iPhone übertrifft alle Rekorde]]></title>
<description><![CDATA[Zum 20. Jubiläum plant Apple offenbar das größte iPhone, das es je gab.]]></description>
<link>https://tsecurity.de/de/3707443/it-nachrichten/neues-iphone-uebertrifft-alle-rekorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707443/it-nachrichten/neues-iphone-uebertrifft-alle-rekorde/</guid>
<pubDate>Thu, 06 Aug 2026 07:46:02 +0200</pubDate>
<content:encoded><![CDATA[Zum 20. Jubiläum plant Apple offenbar das größte iPhone, das es je gab.]]></content:encoded>
</item>
<item>
<title><![CDATA[Günstiger als der Pro-Controller: Drei Alternativen für deine Nintendo Switch 2]]></title>
<description><![CDATA[Der Pro-Controller von Nintendo kostet fast 90 Euro – für mehrere Spieler:innen wird das schnell teuer. Wir stellen dir Modelle vor, die deutlich günstiger sind und trotzdem durch Ergonomie und Funktionalität überzeugen.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3707442/it-nachrichten/guenstiger-als-der-pro-controller-drei-alternativen-fuer-deine-nintendo-switch-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707442/it-nachrichten/guenstiger-als-der-pro-controller-drei-alternativen-fuer-deine-nintendo-switch-2/</guid>
<pubDate>Thu, 06 Aug 2026 07:45:37 +0200</pubDate>
<content:encoded><![CDATA[Der Pro-Controller von Nintendo kostet fast 90 Euro – für mehrere Spieler:innen wird das schnell teuer. Wir stellen dir Modelle vor, die deutlich günstiger sind und trotzdem durch Ergonomie und Funktionalität überzeugen.
<a href="https://t3n.de/news/guenstiger-als-der-pro-controller-drei-alternativen-fuer-deine-nintendo-switch-2-1756561/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sonnenfinsternis in Deutschland: Wo du sie sehen kannst und was du dafür benötigst]]></title>
<description><![CDATA[Am 12. August 2026 ist in Deutschland eine partielle Sonnenfinsternis zu sehen. Wo du die besten Chancen hast, sie zu beobachten, und was du dafür benötigst.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3707441/it-nachrichten/sonnenfinsternis-in-deutschland-wo-du-sie-sehen-kannst-und-was-du-dafuer-benoetigst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707441/it-nachrichten/sonnenfinsternis-in-deutschland-wo-du-sie-sehen-kannst-und-was-du-dafuer-benoetigst/</guid>
<pubDate>Thu, 06 Aug 2026 07:45:36 +0200</pubDate>
<content:encoded><![CDATA[Am 12. August 2026 ist in Deutschland eine partielle Sonnenfinsternis zu sehen. Wo du die besten Chancen hast, sie zu beobachten, und was du dafür benötigst.
<a href="https://t3n.de/news/sonnenfinsternis-deutschland-wo-du-sie-sehen-kannst-1756540/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Direkt auf die XPU: Samsungs zHBM soll HBM5 um Längen schlagen]]></title>
<description><![CDATA[Samsung formuliert mit zHBM ein neues Konzept für High Bandwidth Memory der Zukunft. Der Speicher sitzt dabei nicht wie bisher neben dem Prozessor, sondern direkt auf diesem. Mit kürzeren Leitungswegen und noch mehr Durchsatz soll selbst HBM5 um mehrere Faktoren bei Leistung und Dichte übertroffe...]]></description>
<link>https://tsecurity.de/de/3707440/it-nachrichten/direkt-auf-die-xpu-samsungs-zhbm-soll-hbm5-um-laengen-schlagen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707440/it-nachrichten/direkt-auf-die-xpu-samsungs-zhbm-soll-hbm5-um-laengen-schlagen/</guid>
<pubDate>Thu, 06 Aug 2026 07:45:24 +0200</pubDate>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/4/1/5/2-7a8152889d2daded/article-640x360.f3e83979.jpg"><p>Samsung formuliert mit zHBM ein neues Konzept für High Bandwidth Memory der Zukunft. Der Speicher sitzt dabei nicht wie bisher neben dem Prozessor, sondern direkt auf diesem. Mit kürzeren Leitungswegen und noch mehr Durchsatz soll selbst HBM5 um mehrere Faktoren bei Leistung und Dichte übertroffen werden.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Disney+: TikTok-Creator dürfen mit Marvel- und „Star Wars“-Material arbeiten]]></title>
<description><![CDATA[TikTok-Creator bekommen Zugriff auf Material aus Hunderten Disney-Filmen und -Serien. Ausgewählte Videos daraus landen auch in der Disney+-App.]]></description>
<link>https://tsecurity.de/de/3707439/it-nachrichten/disney-tiktok-creator-duerfen-mit-marvel-und-star-wars-material-arbeiten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707439/it-nachrichten/disney-tiktok-creator-duerfen-mit-marvel-und-star-wars-material-arbeiten/</guid>
<pubDate>Thu, 06 Aug 2026 07:45:19 +0200</pubDate>
<content:encoded><![CDATA[TikTok-Creator bekommen Zugriff auf Material aus Hunderten Disney-Filmen und -Serien. Ausgewählte Videos daraus landen auch in der Disney+-App.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Smarte Bewässerung ohne Internet: Gardena-Pumpe im Praxistest]]></title>
<description><![CDATA[Der Gardena Haus- & Gartenautomat 5000 SilentComfort bietet smarte Gießautomatiken ohne Umweg übers Internet – aber nicht so komfortabel leise wie versprochen.]]></description>
<link>https://tsecurity.de/de/3707438/it-nachrichten/heise-smarte-bewaesserung-ohne-internet-gardena-pumpe-im-praxistest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707438/it-nachrichten/heise-smarte-bewaesserung-ohne-internet-gardena-pumpe-im-praxistest/</guid>
<pubDate>Thu, 06 Aug 2026 07:45:18 +0200</pubDate>
<content:encoded><![CDATA[Der Gardena Haus- &amp; Gartenautomat 5000 SilentComfort bietet smarte Gießautomatiken ohne Umweg übers Internet – aber nicht so komfortabel leise wie versprochen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuer 3D-Speicher: Für den Mac bleibt erst einmal nichts übrig]]></title>
<description><![CDATA[Samsung hat neue Speichertechniken vorgestellt, die schneller, dichter und sparsamer arbeiten sollen. Das klingt zunächst nach guten Nachrichten für alle, die beim Kauf eines Macs inzwischen kurz prüfen müssen, ob mehr Arbeitsspeicher oder ein Kleinwagen günstiger wäre. Die neuen Entwicklungen si...]]></description>
<link>https://tsecurity.de/de/3707424/ios-mac-os/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707424/ios-mac-os/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig/</guid>
<pubDate>Thu, 06 Aug 2026 07:37:06 +0200</pubDate>
<content:encoded><![CDATA[<a href="https://www.ifun.de/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig-285176/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/08/Samsung-Speicher-feature-150x150.jpg" class="alignright tfe wp-post-image" alt="Samsung Speicher Feature" decoding="async"></a><p>Samsung hat neue Speichertechniken vorgestellt, die schneller, dichter und sparsamer arbeiten sollen. Das klingt zunächst nach guten Nachrichten für alle, die beim Kauf eines Macs inzwischen kurz prüfen müssen, ob mehr Arbeitsspeicher oder ein Kleinwagen günstiger wäre. Die neuen Entwicklungen sind allerdings vor allem für KI-Rechenzentren vorgesehen. Auf der Fachmesse Future of Memory and Storage […]</p>
<p>Der Beitrag <a href="https://www.ifun.de/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig-285176/">Neuer 3D-Speicher: Für den Mac bleibt erst einmal nichts übrig</a> wurde zuerst auf <a href="https://www.ifun.de/">ifun.de</a> veröffentlicht.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuer 3D-Speicher: Für den Mac bleibt erst einmal nichts übrig]]></title>
<description><![CDATA[Samsung hat neue Speichertechniken vorgestellt, die schneller, dichter und sparsamer arbeiten sollen. Das klingt zunächst nach guten Nachrichten für alle, die beim Kauf eines Macs inzwischen kurz prüfen müssen, ob mehr Arbeitsspeicher oder ein Kleinwagen günstiger wäre. Die neuen Entwicklungen si...]]></description>
<link>https://tsecurity.de/de/3707423/ios-mac-os/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707423/ios-mac-os/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig/</guid>
<pubDate>Thu, 06 Aug 2026 07:37:06 +0200</pubDate>
<content:encoded><![CDATA[<a href="https://www.ifun.de/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig-285176/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/08/Samsung-Speicher-feature-150x150.jpg" class="alignright tfe wp-post-image" alt="Samsung Speicher Feature" decoding="async"></a><p>Samsung hat neue Speichertechniken vorgestellt, die schneller, dichter und sparsamer arbeiten sollen. Das klingt zunächst nach guten Nachrichten für alle, die beim Kauf eines Macs inzwischen kurz prüfen müssen, ob mehr Arbeitsspeicher oder ein Kleinwagen günstiger wäre. Die neuen Entwicklungen sind allerdings vor allem für KI-Rechenzentren vorgesehen. Auf der Fachmesse Future of Memory and Storage […]</p>
<p>Der Beitrag <a href="https://www.ifun.de/neuer-3d-speicher-fuer-den-mac-bleibt-erst-einmal-nichts-uebrig-285176/">Neuer 3D-Speicher: Für den Mac bleibt erst einmal nichts übrig</a> wurde zuerst auf <a href="https://www.ifun.de/">ifun.de</a> veröffentlicht.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemini beim Auspacken: Google testet KI-Assistenten für die Handy-Einrichtung]]></title>
<description><![CDATA[Wer ein neues Android-Handy aus der Schachtel holt, tippt sich erst einmal durch ein Dutzend Abfragen, von denen die meisten sofort wieder vergessen, aber trotzdem…
Dieser Artikel Gemini beim Auspacken: Google testet KI-Assistenten für die Handy-Einrichtung erschien zuerst auf SmartDroid.de.]]></description>
<link>https://tsecurity.de/de/3707422/android-tipps/gemini-beim-auspacken-google-testet-ki-assistenten-fuer-die-handy-einrichtung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707422/android-tipps/gemini-beim-auspacken-google-testet-ki-assistenten-fuer-die-handy-einrichtung/</guid>
<pubDate>Thu, 06 Aug 2026 07:34:15 +0200</pubDate>
<content:encoded><![CDATA[<img width="2048" height="1238" src="https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2024/02/gemini-hero-scaled.jpg?fit=2048%2C1238&amp;ssl=1" class="attachment-medium size-medium wp-post-image" alt="Gemini Hero" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2024/02/gemini-hero-scaled.jpg?w=2048&amp;ssl=1 2048w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2024/02/gemini-hero-scaled.jpg?resize=1200%2C725&amp;ssl=1 1200w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2024/02/gemini-hero-scaled.jpg?resize=1536%2C928&amp;ssl=1 1536w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2024/02/gemini-hero-scaled.jpg?w=1800&amp;ssl=1 1800w" sizes="(max-width: 2048px) 100vw, 2048px"><p>Wer ein neues Android-Handy aus der Schachtel holt, tippt sich erst einmal durch ein Dutzend Abfragen, von denen die meisten sofort wieder vergessen, aber trotzdem…</p>
<p>Dieser Artikel <a rel="nofollow" href="https://www.smartdroid.de/gemini-beim-auspacken-google-testet-ki-assistenten-fuer-die-handy-einrichtung/">Gemini beim Auspacken: Google testet KI-Assistenten für die Handy-Einrichtung</a> erschien zuerst auf <a rel="nofollow" href="https://www.smartdroid.de/">SmartDroid.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages]]></title>
<description><![CDATA[A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the maintainer account behind the widely used Keyv library, then used that access to push malicious releases across a growing number of projects. Th...]]></description>
<link>https://tsecurity.de/de/3707421/it-security-nachrichten/new-npm-supply-chain-attack-began-with-the-keyv-library-compromised-hundreds-of-popular-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707421/it-security-nachrichten/new-npm-supply-chain-attack-began-with-the-keyv-library-compromised-hundreds-of-popular-packages/</guid>
<pubDate>Thu, 06 Aug 2026 07:31:27 +0200</pubDate>
<content:encoded><![CDATA[<p>A new npm supply chain attack has turned trusted software packages into a route for credential theft. The campaign began after attackers compromised the maintainer account behind the widely used Keyv library, then used that access to push malicious releases across a growing number of projects. The incident matters because npm packages are routinely installed […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-npm-supply-chain-attack/">New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access]]></title>
<description><![CDATA[Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to advanced AI models, including Anthropic Claude and Google Gemini, according to Okta Threat Intelligence. These services rely on fraudulent ...]]></description>
<link>https://tsecurity.de/de/3707420/it-security-nachrichten/hackers-abuse-cloud-startup-credits-to-resell-claude-and-gemini-ai-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707420/it-security-nachrichten/hackers-abuse-cloud-startup-credits-to-resell-claude-and-gemini-ai-access/</guid>
<pubDate>Thu, 06 Aug 2026 07:31:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to advanced AI models, including Anthropic Claude and Google Gemini, according to Okta Threat Intelligence. These services rely on fraudulent or synthetic account registrations to accumulate promotional credits offered by cloud providers. The […]</p>
<p>The post <a href="https://gbhackers.com/hackers-abuse-cloud-startup-credits/">Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers]]></title>
<description><![CDATA[Attackers are using more than 250 fake “download” domains to selectively target Mac users with AMOS and MacSync infostealers, hiding their ClickFix lures behind a sophisticated server-side fingerprinting gate that reveals the payload only to browsers that appear to be genuine macOS systems. The f...]]></description>
<link>https://tsecurity.de/de/3707419/it-security-nachrichten/250-fake-download-domains-target-mac-users-with-amos-and-macsync-infostealers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707419/it-security-nachrichten/250-fake-download-domains-target-mac-users-with-amos-and-macsync-infostealers/</guid>
<pubDate>Thu, 06 Aug 2026 07:31:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Attackers are using more than 250 fake “download” domains to selectively target Mac users with AMOS and MacSync infostealers, hiding their ClickFix lures behind a sophisticated server-side fingerprinting gate that reveals the payload only to browsers that appear to be genuine macOS systems. The front‑end infrastructure relies on algorithmically generated, dictionary‑style names that frequently include […]</p>
<p>The post <a href="https://gbhackers.com/250-fake-download-domains/">250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fraunhofer-Forscher erkennen Deepfakes mit bis zu 91 Prozent Genauigkeit]]></title>
<description><![CDATA[Der Beitrag Fraunhofer-Forscher erkennen Deepfakes mit bis zu 91 Prozent Genauigkeit erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Künstliche Intelligenz erschafft immer realistischere Bilder, die sich vo...]]></description>
<link>https://tsecurity.de/de/3707418/it-security-nachrichten/fraunhofer-forscher-erkennen-deepfakes-mit-bis-zu-91-prozent-genauigkeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707418/it-security-nachrichten/fraunhofer-forscher-erkennen-deepfakes-mit-bis-zu-91-prozent-genauigkeit/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/03/deepfake-erkennung/">Fraunhofer-Forscher erkennen Deepfakes mit bis zu 91 Prozent Genauigkeit</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Künstliche Intelligenz erschafft immer realistischere Bilder, die sich von echten Aufnahmen kaum noch unterscheiden lassen. Das Risiko digitaler Desinformation nimmt dadurch in allen gesellschaftlichen Bereichen zu. Ein neuartiges Verfahren von Fraunhofer-Forschern soll nun Abhilfe schaffen und die Deepfake-Erkennung deutlich verbessern.  Die Zunahme von falschen Aufnahmen im Netz bedroht das allgemeine Vertrauen in die Digitalisierung. Das […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/03/deepfake-erkennung/">Fraunhofer-Forscher erkennen Deepfakes mit bis zu 91 Prozent Genauigkeit</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Aus GigaMobil wird Vodafone Mobil: Was sich jetzt für Selbstständige ändert]]></title>
<description><![CDATA[Der Beitrag Aus GigaMobil wird Vodafone Mobil: Was sich jetzt für Selbstständige ändert erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Vodafone räumt beim Namen auf: Aus „GigaMobil“ wird „Vodafone Mobil“. ...]]></description>
<link>https://tsecurity.de/de/3707417/it-security-nachrichten/aus-gigamobil-wird-vodafone-mobil-was-sich-jetzt-fuer-selbststaendige-aendert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707417/it-security-nachrichten/aus-gigamobil-wird-vodafone-mobil-was-sich-jetzt-fuer-selbststaendige-aendert/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/03/aus-gigamobil-wird-vodafone-mobil-was-sich-jetzt-fuer-selbststaendige-aendert/">Aus GigaMobil wird Vodafone Mobil: Was sich jetzt für Selbstständige ändert</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Vodafone räumt beim Namen auf: Aus „GigaMobil“ wird „Vodafone Mobil“. Mit der Umbenennung kommen neue Tariflogik, frische Konditionen und eine tolle Hardware-Aktion, die für Selbstständige und kleine Unternehmen sofort relevant werden kann. Seit dem 16. Juli 2026 laufen die bisherigen „GigaMobil“-Tarife unter dem neuen Namen Vodafone Mobil. Vodafone selbst kommuniziert die Umbenennung als Teil einer […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/03/aus-gigamobil-wird-vodafone-mobil-was-sich-jetzt-fuer-selbststaendige-aendert/">Aus GigaMobil wird Vodafone Mobil: Was sich jetzt für Selbstständige ändert</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese Länder haben die höchsten Staatsschulden]]></title>
<description><![CDATA[Der Beitrag Diese Länder haben die höchsten Staatsschulden erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Kaum eine Nation auf der Welt kommt heute ohne Schulden aus. Auch Deutschland hat in den letzten Ja...]]></description>
<link>https://tsecurity.de/de/3707416/it-security-nachrichten/diese-laender-haben-die-hoechsten-staatsschulden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707416/it-security-nachrichten/diese-laender-haben-die-hoechsten-staatsschulden/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/03/laender-mit-hoechsten-staatsschulden/">Diese Länder haben die höchsten Staatsschulden</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Kaum eine Nation auf der Welt kommt heute ohne Schulden aus. Auch Deutschland hat in den letzten Jahrzehnten massiv auf Pump gelebt. Die Summen, um die es dabei geht, sprengen teilweise jede Vorstellungskraft. Wir präsentieren in unserem Ranking die Länder mit den höchsten Staatsschulden. Staatsschulden gehören zum politischen Alltag, und die meisten Menschen haben sich […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/03/laender-mit-hoechsten-staatsschulden/">Diese Länder haben die höchsten Staatsschulden</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ohne Kältemittel: Thermoakustische Wärmepumpen heizen mit Schallwellen]]></title>
<description><![CDATA[Der Beitrag Ohne Kältemittel: Thermoakustische Wärmepumpen heizen mit Schallwellen erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Ein niederländisches Start-up will die Wärmepumpe neu erfinden. Statt mit K...]]></description>
<link>https://tsecurity.de/de/3707415/it-security-nachrichten/ohne-kaeltemittel-thermoakustische-waermepumpen-heizen-mit-schallwellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707415/it-security-nachrichten/ohne-kaeltemittel-thermoakustische-waermepumpen-heizen-mit-schallwellen/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/04/thermoakustische-waermepumpen/">Ohne Kältemittel: Thermoakustische Wärmepumpen heizen mit Schallwellen</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Ein niederländisches Start-up will die Wärmepumpe neu erfinden. Statt mit Kompressor und Kältemittel kommt die Technologie mit Schallwellen aus. Bevor sie auf den Markt kommt, erklären wir dir, was thermoakustische Wärmepumpen können und worauf du achten solltest.  Wärmepumpen sind bereits seit einiger Zeit eine beliebte Alternative zu herkömmlichen Heiz- und Kühlsystemen. Allein in Deutschland wurden […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/04/thermoakustische-waermepumpen/">Ohne Kältemittel: Thermoakustische Wärmepumpen heizen mit Schallwellen</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gegen das US-Monopol: Ecosia startet eigenen Suchindex in Deutschland]]></title>
<description><![CDATA[Der Beitrag Gegen das US-Monopol: Ecosia startet eigenen Suchindex in Deutschland erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Google kontrolliert über 80 Prozent der weltweiten Internetsuche und damit a...]]></description>
<link>https://tsecurity.de/de/3707414/it-security-nachrichten/gegen-das-us-monopol-ecosia-startet-eigenen-suchindex-in-deutschland/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707414/it-security-nachrichten/gegen-das-us-monopol-ecosia-startet-eigenen-suchindex-in-deutschland/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/04/ecosia-startet-suchindex-in-deutschland/">Gegen das US-Monopol: Ecosia startet eigenen Suchindex in Deutschland</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Google kontrolliert über 80 Prozent der weltweiten Internetsuche und damit auch, welche Informationen Milliarden Menschen zu sehen bekommen. Sprich: Es gibt kaum Wettbewerb, sondern ein Monopol. Die beiden europäischen Suchmaschinenanbieter Ecosia und Qwant starten jetzt aber ihren gemeinsamen europäischen Suchindex auch in Deutschland. Das wird Google kurzfristig kaum jucken. Doch es braucht genau solche Projekte! […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/04/ecosia-startet-suchindex-in-deutschland/">Gegen das US-Monopol: Ecosia startet eigenen Suchindex in Deutschland</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker-Hype: Nur 1,3 Prozent der von KI entlarvten Schwachstellen ausgenutzt]]></title>
<description><![CDATA[Der Beitrag Hacker-Hype: Nur 1,3 Prozent der von KI entlarvten Schwachstellen ausgenutzt erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Erst OpenAI, dann Anthropic: Innerhalb weniger Wochen räumten die bei...]]></description>
<link>https://tsecurity.de/de/3707413/it-security-nachrichten/hacker-hype-nur-13-prozent-der-von-ki-entlarvten-schwachstellen-ausgenutzt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707413/it-security-nachrichten/hacker-hype-nur-13-prozent-der-von-ki-entlarvten-schwachstellen-ausgenutzt/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/04/hackerangriffe-durch-ki/">Hacker-Hype: Nur 1,3 Prozent der von KI entlarvten Schwachstellen ausgenutzt</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Erst OpenAI, dann Anthropic: Innerhalb weniger Wochen räumten die beiden KI-Unternehmen ein, dass ihre Modelle eigenständig in fremde Systeme eingedrungen sind. Die Aufregung war groß. Das Thema in den Medien präsent. Eine aktuelle Auswertung zeigt aber: In der Praxis hat sich die Bedrohungslage bislang kaum verändert. Haben wir die Kontrolle über Künstliche Intelligenz verloren? Im […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/04/hackerangriffe-durch-ki/">Hacker-Hype: Nur 1,3 Prozent der von KI entlarvten Schwachstellen ausgenutzt</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Frankreich machts vor: Schon ein Solar-Parkplatz spart 32.000 Euro Strom]]></title>
<description><![CDATA[Der Beitrag Frankreich machts vor: Schon ein Solar-Parkplatz spart 32.000 Euro Strom erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Parkplätze könnten riesige Flächen für Solaranlagen bieten. Doch bislang ...]]></description>
<link>https://tsecurity.de/de/3707412/it-security-nachrichten/frankreich-machts-vor-schon-ein-solar-parkplatz-spart-32000-euro-strom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707412/it-security-nachrichten/frankreich-machts-vor-schon-ein-solar-parkplatz-spart-32000-euro-strom/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/05/solar-parkplaetze-potenzial/">Frankreich machts vor: Schon ein Solar-Parkplatz spart 32.000 Euro Strom</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Parkplätze könnten riesige Flächen für Solaranlagen bieten. Doch bislang bleibt dieses Potenzial weitgehend ungenutzt. Dabei könnten Solarüberdachungen nicht nur sauberen Strom erzeugen, sondern auch Unternehmen entlasten und die Ladeinfrastruktur für Elektroautos stärken. Die Bundesregierung hat sich für den Ausbau der Solarenergie in Deutschland ehrgeizige Ziele gesetzt. Denn bis zum Jahr 2030 soll die installierte Photovoltaikleistung […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/05/solar-parkplaetze-potenzial/">Frankreich machts vor: Schon ein Solar-Parkplatz spart 32.000 Euro Strom</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TikTok-Klon aus Berlin: Wedium will soziale Medien wieder sozial machen]]></title>
<description><![CDATA[Der Beitrag TikTok-Klon aus Berlin: Wedium will soziale Medien wieder sozial machen erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Mit Wedium ist ein neues soziales Netzwerk an den Start gegangen, das viel...]]></description>
<link>https://tsecurity.de/de/3707411/it-security-nachrichten/tiktok-klon-aus-berlin-wedium-will-soziale-medien-wieder-sozial-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707411/it-security-nachrichten/tiktok-klon-aus-berlin-wedium-will-soziale-medien-wieder-sozial-machen/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/05/soziales-netzwerk-wedium/">TikTok-Klon aus Berlin: Wedium will soziale Medien wieder sozial machen</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Mit Wedium ist ein neues soziales Netzwerk an den Start gegangen, das vieles besser machen will – diesmal aus Berlin. Die Plattform ist ab sofort in Deutschland, Österreich und der Schweiz verfügbar und setzt auf eine Ausweispflicht, europäische Server und echte Menschen statt Algorithmus-Chaos. Der Ansatz ist zwar sympathisch und in vielen Punkten überfällig. Doch […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/05/soziales-netzwerk-wedium/">TikTok-Klon aus Berlin: Wedium will soziale Medien wieder sozial machen</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das sind die besten Elektroautos in Deutschland – laut ADAC]]></title>
<description><![CDATA[Der Beitrag Das sind die besten Elektroautos in Deutschland – laut ADAC erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Der ADAC hat eine neue Liste mit den derzeit besten E-Autos herausgegeben, die in Deut...]]></description>
<link>https://tsecurity.de/de/3707410/it-security-nachrichten/das-sind-die-besten-elektroautos-in-deutschland-laut-adac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707410/it-security-nachrichten/das-sind-die-besten-elektroautos-in-deutschland-laut-adac/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/05/besten-elektroautos-deutschland/">Das sind die besten Elektroautos in Deutschland – laut ADAC</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Der ADAC hat eine neue Liste mit den derzeit besten E-Autos herausgegeben, die in Deutschland erhältlich sind. Neben der Qualität der Modelle wird auch das Preis-Leistungs-Verhältnis bewertet. Immer mehr Menschen haben Interesse an einem Elektroauto, und entsprechend bringen immer mehr Hersteller neue Modelle auf den Markt. Das bedeutet aber auch, dass die Wahl immer schwieriger […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/05/besten-elektroautos-deutschland/">Das sind die besten Elektroautos in Deutschland – laut ADAC</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum KI-Modelle aus China so viel günstiger sind als ChatGPT]]></title>
<description><![CDATA[Der Beitrag Warum KI-Modelle aus China so viel günstiger sind als ChatGPT erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Obwohl sie sich leistungstechnisch auf einem Niveau zu bewegen scheinen, kosten Spra...]]></description>
<link>https://tsecurity.de/de/3707409/it-security-nachrichten/warum-ki-modelle-aus-china-so-viel-guenstiger-sind-als-chatgpt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707409/it-security-nachrichten/warum-ki-modelle-aus-china-so-viel-guenstiger-sind-als-chatgpt/</guid>
<pubDate>Thu, 06 Aug 2026 07:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/06/warum-chinas-ki-modelle-so-viel-guenstiger-sind/">Warum KI-Modelle aus China so viel günstiger sind als ChatGPT</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Obwohl sie sich leistungstechnisch auf einem Niveau zu bewegen scheinen, kosten Sprachmodelle aus China oft deutlich weniger als ihre Konkurrenz aus den USA. Wie ist das möglich? Tatsächlich steckt hinter dem Preisgefälle eine ganze Reihe an Faktoren. Bei neuen Technologien zählt anfangs oft noch die reine Leistung: Wer das beste Produkt anbietet, gewinnt. Doch relativ […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/06/warum-chinas-ki-modelle-so-viel-guenstiger-sind/">Warum KI-Modelle aus China so viel günstiger sind als ChatGPT</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuausrichtung der IT-Ressourcenverwertung: Von der Entsorgung zur Wertschöpfung]]></title>
<description><![CDATA[Wenn eine Organisation einen Laptop, Server oder Speicher stilllegt, beginnt die Diskussion häufig mit zwei Fragen: Was zahlen Sie uns dafür? Oder was verlangen Sie für die Entsorgung?

Tags: #IT-Recycling | #Ressourcen-Management]]></description>
<link>https://tsecurity.de/de/3707408/it-security-nachrichten/neuausrichtung-der-it-ressourcenverwertung-von-der-entsorgung-zur-wertschoepfung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707408/it-security-nachrichten/neuausrichtung-der-it-ressourcenverwertung-von-der-entsorgung-zur-wertschoepfung/</guid>
<pubDate>Thu, 06 Aug 2026 07:27:31 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/08/Recycling-Verwertung-1920-shutterstock-2675991285.jpg" class="attachment-full size-full wp-post-image" alt="Recycling-Verwertung" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/08/Recycling-Verwertung-1920-shutterstock-2675991285.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/08/Recycling-Verwertung-1920-shutterstock-2675991285-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/08/Recycling-Verwertung-1920-shutterstock-2675991285-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/08/Recycling-Verwertung-1920-shutterstock-2675991285-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/08/Recycling-Verwertung-1920-shutterstock-2675991285-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Neuausrichtung der IT-Ressourcenverwertung: Von der Entsorgung zur Wertschöpfung 1"></p>
    Wenn eine Organisation einen Laptop, Server oder Speicher stilllegt, beginnt die Diskussion häufig mit zwei Fragen: Was zahlen Sie uns dafür? Oder was verlangen Sie für die Entsorgung?

<p>Tags: <a href="https://www.it-daily.net/thema/it-recycling">#IT-Recycling</a> | <a href="https://www.it-daily.net/thema/ressourcen-management">#Ressourcen-Management</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco warnt vor aktiv ausgenutzter FMC-Schwachstelle]]></title>
<description><![CDATA[Statische Zugangsdaten in Cisco Secure Firewall Management Center ermöglichen unbefugten Zugriff auf sensible Daten. Die Schwachstelle wird bereits aktiv ausgenutzt, Hot Fixes stehen bereit.]]></description>
<link>https://tsecurity.de/de/3707406/it-security-nachrichten/cisco-warnt-vor-aktiv-ausgenutzter-fmc-schwachstelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707406/it-security-nachrichten/cisco-warnt-vor-aktiv-ausgenutzter-fmc-schwachstelle/</guid>
<pubDate>Thu, 06 Aug 2026 07:26:57 +0200</pubDate>
<content:encoded><![CDATA[Statische Zugangsdaten in Cisco Secure Firewall Management Center ermöglichen unbefugten Zugriff auf sensible Daten. Die Schwachstelle wird bereits aktiv ausgenutzt, Hot Fixes stehen bereit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CSU will E-Auto-Prämie zugunsten deutscher Hersteller ändern]]></title>
<description><![CDATA[Die CSU will die E-Auto-Förderung so ändern, dass deutsche und europäische Hersteller künftig stärker profitieren. Die CSU fordert eine Überarbeitung der seit Mai geltenden E-Auto-Prämie. Nach Angaben der Partei soll …]]></description>
<link>https://tsecurity.de/de/3707402/it-nachrichten/csu-will-e-auto-praemie-zugunsten-deutscher-hersteller-aendern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707402/it-nachrichten/csu-will-e-auto-praemie-zugunsten-deutscher-hersteller-aendern/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:36 +0200</pubDate>
<content:encoded><![CDATA[<img width="1600" height="1022" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/04/vw-id-polo-header-2.jpg?fit=1600%2C1022&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/04/vw-id-polo-header-2.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/04/vw-id-polo-header-2.jpg?resize=690%2C441&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Die CSU will die E-Auto-Förderung so ändern, dass deutsche und europäische Hersteller künftig stärker profitieren. Die CSU fordert eine Überarbeitung der seit Mai geltenden E-Auto-Prämie. Nach Angaben der Partei soll …]]></content:encoded>
</item>
<item>
<title><![CDATA[Einkommen: Das soll bald gestrichen werden – für etliche Menschen]]></title>
<description><![CDATA[Bislang gibt es bei der Hilfe zur Pflege eine Einkommensgrenze für Angehörige, die den Elternunterhalt regelt. Diese soll jedoch fallen.]]></description>
<link>https://tsecurity.de/de/3707401/it-nachrichten/einkommen-das-soll-bald-gestrichen-werden-fuer-etliche-menschen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707401/it-nachrichten/einkommen-das-soll-bald-gestrichen-werden-fuer-etliche-menschen/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:19 +0200</pubDate>
<content:encoded><![CDATA[Bislang gibt es bei der Hilfe zur Pflege eine Einkommensgrenze für Angehörige, die den Elternunterhalt regelt. Diese soll jedoch fallen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Schnell Geld verdienen? Diesen ungewöhnlichen Job kann fast jeder machen]]></title>
<description><![CDATA[Es gibt Aufgaben, die in kurzer Zeit viel Geld versprechen. Ein Gesuch in Nordrhein-Westfalen erscheint zudem besonders interessant.]]></description>
<link>https://tsecurity.de/de/3707400/it-nachrichten/schnell-geld-verdienen-diesen-ungewoehnlichen-job-kann-fast-jeder-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707400/it-nachrichten/schnell-geld-verdienen-diesen-ungewoehnlichen-job-kann-fast-jeder-machen/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:19 +0200</pubDate>
<content:encoded><![CDATA[Es gibt Aufgaben, die in kurzer Zeit viel Geld versprechen. Ein Gesuch in Nordrhein-Westfalen erscheint zudem besonders interessant.]]></content:encoded>
</item>
<item>
<title><![CDATA[Der beste Gasgrill aus unserem Test ist jetzt im Angebot]]></title>
<description><![CDATA[Findet heraus, welcher Gasgrill Testsieger ist – jetzt kauft ihr das Top-Modell im Angebot mit hohem Rabatt.]]></description>
<link>https://tsecurity.de/de/3707398/it-nachrichten/der-beste-gasgrill-aus-unserem-test-ist-jetzt-im-angebot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707398/it-nachrichten/der-beste-gasgrill-aus-unserem-test-ist-jetzt-im-angebot/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:18 +0200</pubDate>
<content:encoded><![CDATA[Findet heraus, welcher Gasgrill Testsieger ist – jetzt kauft ihr das Top-Modell im Angebot mit hohem Rabatt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: IT-Notfallmanagement: Workshop zu BCM und Notfallplanung]]></title>
<description><![CDATA[IT-Notfallmanagement wird für Unternehmen immer wichtiger, um Störungen und Krisen zu bewältigen. Ein spezialisierter Workshop vermittelt praxisnahe Methoden für mehr Resilienz. (Golem Karrierewelt, Sicherheitslücke)]]></description>
<link>https://tsecurity.de/de/3707397/it-nachrichten/anzeige-it-notfallmanagement-workshop-zu-bcm-und-notfallplanung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707397/it-nachrichten/anzeige-it-notfallmanagement-workshop-zu-bcm-und-notfallplanung/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:04 +0200</pubDate>
<content:encoded><![CDATA[IT-Notfallmanagement wird für Unternehmen immer wichtiger, um Störungen und Krisen zu bewältigen. Ein spezialisierter Workshop vermittelt praxisnahe Methoden für mehr Resilienz. (<a href="https://www.golem.de/specials/golemakademie/">Golem Karrierewelt</a>, <a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211644&amp;page=1&amp;ts=1785993301" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Schrottsammler: USA verbieten Lithium- und Wolfram-Exporte]]></title>
<description><![CDATA[Die USA schützen ihre Rüstungsindustrie vor Rohstoffknappheit. Wer Akku- oder Wolframschrott sammelt, muss ihn künftig an heimische Käufer verkaufen. (Lithium, Politik)]]></description>
<link>https://tsecurity.de/de/3707396/it-nachrichten/schrottsammler-usa-verbieten-lithium-und-wolfram-exporte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707396/it-nachrichten/schrottsammler-usa-verbieten-lithium-und-wolfram-exporte/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:03 +0200</pubDate>
<content:encoded><![CDATA[Die USA schützen ihre Rüstungsindustrie vor Rohstoffknappheit. Wer Akku- oder Wolframschrott sammelt, muss ihn künftig an heimische Käufer verkaufen. (<a href="https://www.golem.de/specials/lithium/">Lithium</a>, <a href="https://www.golem.de/specials/politik-recht/">Politik</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211650&amp;page=1&amp;ts=1785993421" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsungs Foldables: Galaxy Z Fold 8 und Flip 8 brechen Vorbestellrekord]]></title>
<description><![CDATA[Samsung hat mit dem Galaxy Z Fold 8 Ultra, Galaxy Z Fold 8 (Test) und Galaxy Z Flip 8 einen neuen Vorbestellrekord aufgestellt. In Südkorea wurden innerhalb von sieben Tagen 1,44 Millionen Geräte bestellt. Damit übertrifft die neue Foldable-Serie nicht nur ihre Vorgänger, sondern sämtliche bisher...]]></description>
<link>https://tsecurity.de/de/3707395/it-nachrichten/samsungs-foldables-galaxy-z-fold-8-und-flip-8-brechen-vorbestellrekord/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707395/it-nachrichten/samsungs-foldables-galaxy-z-fold-8-und-flip-8-brechen-vorbestellrekord/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:02 +0200</pubDate>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/4/1/5/0-42ac3262c90b02e4/article-640x360.a91a5edd.jpg"><p>Samsung hat mit dem Galaxy Z Fold 8 Ultra, Galaxy Z Fold 8 (Test) und Galaxy Z Flip 8 einen neuen Vorbestellrekord aufgestellt. In Südkorea wurden innerhalb von sieben Tagen 1,44 Millionen Geräte bestellt. Damit übertrifft die neue Foldable-Serie nicht nur ihre Vorgänger, sondern sämtliche bisherigen Galaxy-Smartphones.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Auch KI von Meta hackte sich in eine andere Firma]]></title>
<description><![CDATA[Nach OpenAI und Anthropic räumt nun auch Meta ein, dass sich eigene KI-Software in fremde Systeme gehackt hat.]]></description>
<link>https://tsecurity.de/de/3707394/it-nachrichten/auch-ki-von-meta-hackte-sich-in-eine-andere-firma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707394/it-nachrichten/auch-ki-von-meta-hackte-sich-in-eine-andere-firma/</guid>
<pubDate>Thu, 06 Aug 2026 07:23:00 +0200</pubDate>
<content:encoded><![CDATA[Nach OpenAI und Anthropic räumt nun auch Meta ein, dass sich eigene KI-Software in fremde Systeme gehackt hat.]]></content:encoded>
</item>
<item>
<title><![CDATA[iCloud Private Relay: Sicherheitslücke verrät echte IP-Adresse]]></title>
<description><![CDATA[Eigentlich soll Apples kostenpflichtiger Safari-Dienst genau das Gegenteil von dem tun, was ihm nun vorgeworfen wird: Er soll dich unsichtbar machen, statt dich zu verraten. Doch zwei IT-Sicherheitsforscher, Tommy Mysk und Talal Haj Bakry, haben herausgefunden, dass „iCloud Private Relay“ unter b...]]></description>
<link>https://tsecurity.de/de/3707383/ios-mac-os/icloud-private-relay-sicherheitsluecke-verraet-echte-ip-adresse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707383/ios-mac-os/icloud-private-relay-sicherheitsluecke-verraet-echte-ip-adresse/</guid>
<pubDate>Thu, 06 Aug 2026 07:18:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Eigentlich soll Apples kostenpflichtiger Safari-Dienst genau das Gegenteil von dem tun, was ihm nun vorgeworfen wird: Er soll dich unsichtbar machen, statt dich zu verraten. Doch zwei IT-Sicherheitsforscher, Tommy Mysk und Talal Haj Bakry, haben herausgefunden, dass „iCloud Private Relay“ unter bestimmten Umständen genau das Gegenteil bewirkt. Wer sich also fest darauf verlässt, unerkannt durchs […]</p>
<p>Der Beitrag <a href="https://www.appgefahren.de/icloud-private-relay-sicherheitsluecke-verraet-echte-ip-adresse-403453.html">iCloud Private Relay: Sicherheitslücke verrät echte IP-Adresse</a> erschien zuerst auf <a href="https://www.appgefahren.de/">appgefahren.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Officially ditched my dual boot. My PC is now 100% Windows free]]></title>
<description><![CDATA[submitted by    /u/BaileyJams   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3707382/linux-tipps/officially-ditched-my-dual-boot-my-pc-is-now-100-windows-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707382/linux-tipps/officially-ditched-my-dual-boot-my-pc-is-now-100-windows-free/</guid>
<pubDate>Thu, 06 Aug 2026 07:18:26 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/BaileyJams"> /u/BaileyJams </a> <br> <span><a href="https://www.reddit.com/r/pop_os/comments/1vguuj5/officially_ditched_my_dual_boot_my_pc_is_now_100/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vguuwz/officially_ditched_my_dual_boot_my_pc_is_now_100/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48702 | Linux Kernel up to 5.19.8 ALSA snd_emu10k1_pcm_channel_alloc array index (WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Linux Kernel up to 5.19.8. This affects the function snd_emu10k1_pcm_channel_alloc of the component ALSA. Such manipulation leads to improper validation of array index.

This vulnerability is listed as CVE-2022-48702. The attack must be carri...]]></description>
<link>https://tsecurity.de/de/3707380/sicherheitsluecken/cve-2022-48702-linux-kernel-up-to-5198-alsa-sndemu10k1pcmchannelalloc-array-index-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707380/sicherheitsluecken/cve-2022-48702-linux-kernel-up-to-5198-alsa-sndemu10k1pcmchannelalloc-array-index-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.19.8</a>. This affects the function <code>snd_emu10k1_pcm_channel_alloc</code> of the component <em>ALSA</em>. Such manipulation leads to improper validation of array index.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-48702">CVE-2022-48702</a>. The attack must be carried out from within the local network. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48702 | Linux Kernel up to 5.19.8 ALSA snd_emu10k1_pcm_channel_alloc array index (WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Linux Kernel up to 5.19.8. This affects the function snd_emu10k1_pcm_channel_alloc of the component ALSA. Such manipulation leads to improper validation of array index.

This vulnerability is listed as CVE-2022-48702. The attack must be carri...]]></description>
<link>https://tsecurity.de/de/3707379/sicherheitsluecken/cve-2022-48702-linux-kernel-up-to-5198-alsa-sndemu10k1pcmchannelalloc-array-index-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707379/sicherheitsluecken/cve-2022-48702-linux-kernel-up-to-5198-alsa-sndemu10k1pcmchannelalloc-array-index-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.19.8</a>. This affects the function <code>snd_emu10k1_pcm_channel_alloc</code> of the component <em>ALSA</em>. Such manipulation leads to improper validation of array index.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-48702">CVE-2022-48702</a>. The attack must be carried out from within the local network. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48695 | Linux Kernel up to 5.19.8 mpt3sas lib/refcount.c use after free (Nessus ID 209785 / WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Linux Kernel up to 5.19.8. This vulnerability affects unknown code in the library lib/refcount.c of the component mpt3sas. The manipulation leads to use after free.

This vulnerability is uniquely identified as CVE-2022-48695. The attack ...]]></description>
<link>https://tsecurity.de/de/3707378/sicherheitsluecken/cve-2022-48695-linux-kernel-up-to-5198-mpt3sas-librefcountc-use-after-free-nessus-id-209785-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707378/sicherheitsluecken/cve-2022-48695-linux-kernel-up-to-5198-mpt3sas-librefcountc-use-after-free-nessus-id-209785-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.19.8</a>. This vulnerability affects unknown code in the library <em>lib/refcount.c</em> of the component <em>mpt3sas</em>. The manipulation leads to use after free.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2022-48695">CVE-2022-48695</a>. The attack can only be initiated within the local network. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48695 | Linux Kernel up to 5.19.8 mpt3sas lib/refcount.c use after free (Nessus ID 209785 / WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Linux Kernel up to 5.19.8. This vulnerability affects unknown code in the library lib/refcount.c of the component mpt3sas. The manipulation leads to use after free.

This vulnerability is uniquely identified as CVE-2022-48695. The attack ...]]></description>
<link>https://tsecurity.de/de/3707377/sicherheitsluecken/cve-2022-48695-linux-kernel-up-to-5198-mpt3sas-librefcountc-use-after-free-nessus-id-209785-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707377/sicherheitsluecken/cve-2022-48695-linux-kernel-up-to-5198-mpt3sas-librefcountc-use-after-free-nessus-id-209785-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.19.8</a>. This vulnerability affects unknown code in the library <em>lib/refcount.c</em> of the component <em>mpt3sas</em>. The manipulation leads to use after free.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2022-48695">CVE-2022-48695</a>. The attack can only be initiated within the local network. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27392 | Linux Kernel up to 6.8.1 nvme ns_update_nuse double free (534f9dc7fe49/8d0d2447394b / Nessus ID 243909)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Linux Kernel up to 6.8.1. Impacted is the function ns_update_nuse of the component nvme. Executing a manipulation can lead to double free.

This vulnerability is handled as CVE-2024-27392. The attack can only be done within the local network. Th...]]></description>
<link>https://tsecurity.de/de/3707376/sicherheitsluecken/cve-2024-27392-linux-kernel-up-to-681-nvme-nsupdatenuse-double-free-534f9dc7fe498d0d2447394b-nessus-id-243909/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707376/sicherheitsluecken/cve-2024-27392-linux-kernel-up-to-681-nvme-nsupdatenuse-double-free-534f9dc7fe498d0d2447394b-nessus-id-243909/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.1</a>. Impacted is the function <code>ns_update_nuse</code> of the component <em>nvme</em>. Executing a manipulation can lead to double free.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2024-27392">CVE-2024-27392</a>. The attack can only be done within the local network. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27392 | Linux Kernel up to 6.8.1 nvme ns_update_nuse double free (534f9dc7fe49/8d0d2447394b / Nessus ID 243909)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Linux Kernel up to 6.8.1. Impacted is the function ns_update_nuse of the component nvme. Executing a manipulation can lead to double free.

This vulnerability is handled as CVE-2024-27392. The attack can only be done within the local network. Th...]]></description>
<link>https://tsecurity.de/de/3707375/sicherheitsluecken/cve-2024-27392-linux-kernel-up-to-681-nvme-nsupdatenuse-double-free-534f9dc7fe498d0d2447394b-nessus-id-243909/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707375/sicherheitsluecken/cve-2024-27392-linux-kernel-up-to-681-nvme-nsupdatenuse-double-free-534f9dc7fe498d0d2447394b-nessus-id-243909/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.1</a>. Impacted is the function <code>ns_update_nuse</code> of the component <em>nvme</em>. Executing a manipulation can lead to double free.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2024-27392">CVE-2024-27392</a>. The attack can only be done within the local network. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48674 | Linux Kernel up to 5.15.67/5.19.8 erofs erofs_workgroup_unfreeze use after free (8ddd001cef5e/94c34faaafe7/2f44013e3998 / Nessus ID 214888)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 5.15.67/5.19.8. This affects the function erofs_workgroup_unfreeze of the component erofs. Performing a manipulation results in use after free.

This vulnerability is identified as CVE-2022-48674. The attack can only be pe...]]></description>
<link>https://tsecurity.de/de/3707374/sicherheitsluecken/cve-2022-48674-linux-kernel-up-to-515675198-erofs-erofsworkgroupunfreeze-use-after-free-8ddd001cef5e94c34faaafe72f44013e3998-nessus-id-214888/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707374/sicherheitsluecken/cve-2022-48674-linux-kernel-up-to-515675198-erofs-erofsworkgroupunfreeze-use-after-free-8ddd001cef5e94c34faaafe72f44013e3998-nessus-id-214888/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.15.67/5.19.8</a>. This affects the function <code>erofs_workgroup_unfreeze</code> of the component <em>erofs</em>. Performing a manipulation results in use after free.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-48674">CVE-2022-48674</a>. The attack can only be performed from the local network. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48674 | Linux Kernel up to 5.15.67/5.19.8 erofs erofs_workgroup_unfreeze use after free (8ddd001cef5e/94c34faaafe7/2f44013e3998 / Nessus ID 214888)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 5.15.67/5.19.8. This affects the function erofs_workgroup_unfreeze of the component erofs. Performing a manipulation results in use after free.

This vulnerability is identified as CVE-2022-48674. The attack can only be pe...]]></description>
<link>https://tsecurity.de/de/3707373/sicherheitsluecken/cve-2022-48674-linux-kernel-up-to-515675198-erofs-erofsworkgroupunfreeze-use-after-free-8ddd001cef5e94c34faaafe72f44013e3998-nessus-id-214888/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707373/sicherheitsluecken/cve-2022-48674-linux-kernel-up-to-515675198-erofs-erofsworkgroupunfreeze-use-after-free-8ddd001cef5e94c34faaafe72f44013e3998-nessus-id-214888/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.15.67/5.19.8</a>. This affects the function <code>erofs_workgroup_unfreeze</code> of the component <em>erofs</em>. Performing a manipulation results in use after free.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-48674">CVE-2022-48674</a>. The attack can only be performed from the local network. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27389 | Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1 pstore fs/dcache.c d_invalidate double free (Nessus ID 210815 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1. This issue affects the function d_invalidate of the file fs/dcache.c of the component pstore. Performing a manipulation results in double free.

This vulnerability is known as CVE-2024-27389...]]></description>
<link>https://tsecurity.de/de/3707372/sicherheitsluecken/cve-2024-27389-linux-kernel-up-to-618266226710681-pstore-fsdcachec-dinvalidate-double-free-nessus-id-210815-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707372/sicherheitsluecken/cve-2024-27389-linux-kernel-up-to-618266226710681-pstore-fsdcachec-dinvalidate-double-free-nessus-id-210815-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1</a>. This issue affects the function <code>d_invalidate</code> of the file <em>fs/dcache.c</em> of the component <em>pstore</em>. Performing a manipulation results in double free.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2024-27389">CVE-2024-27389</a>. Access to the local network is required for this attack. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27389 | Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1 pstore fs/dcache.c d_invalidate double free (Nessus ID 210815 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1. This issue affects the function d_invalidate of the file fs/dcache.c of the component pstore. Performing a manipulation results in double free.

This vulnerability is known as CVE-2024-27389...]]></description>
<link>https://tsecurity.de/de/3707371/sicherheitsluecken/cve-2024-27389-linux-kernel-up-to-618266226710681-pstore-fsdcachec-dinvalidate-double-free-nessus-id-210815-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707371/sicherheitsluecken/cve-2024-27389-linux-kernel-up-to-618266226710681-pstore-fsdcachec-dinvalidate-double-free-nessus-id-210815-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1</a>. This issue affects the function <code>d_invalidate</code> of the file <em>fs/dcache.c</em> of the component <em>pstore</em>. Performing a manipulation results in double free.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2024-27389">CVE-2024-27389</a>. Access to the local network is required for this attack. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48697 | Linux Kernel up to 5.19.8 nvmet use after free (WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 4.19.259/5.4.212/5.10.142/5.15.67/5.19.8. The affected element is an unknown function of the component nvmet. The manipulation results in use after free.

This vulnerability is identified as CVE-2022-48697. The attack...]]></description>
<link>https://tsecurity.de/de/3707370/sicherheitsluecken/cve-2022-48697-linux-kernel-up-to-5198-nvmet-use-after-free-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707370/sicherheitsluecken/cve-2022-48697-linux-kernel-up-to-5198-nvmet-use-after-free-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 4.19.259/5.4.212/5.10.142/5.15.67/5.19.8</a>. The affected element is an unknown function of the component <em>nvmet</em>. The manipulation results in use after free.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-48697">CVE-2022-48697</a>. The attack can only be performed from the local network. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48697 | Linux Kernel up to 5.19.8 nvmet use after free (WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 4.19.259/5.4.212/5.10.142/5.15.67/5.19.8. The affected element is an unknown function of the component nvmet. The manipulation results in use after free.

This vulnerability is identified as CVE-2022-48697. The attack...]]></description>
<link>https://tsecurity.de/de/3707369/sicherheitsluecken/cve-2022-48697-linux-kernel-up-to-5198-nvmet-use-after-free-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707369/sicherheitsluecken/cve-2022-48697-linux-kernel-up-to-5198-nvmet-use-after-free-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 4.19.259/5.4.212/5.10.142/5.15.67/5.19.8</a>. The affected element is an unknown function of the component <em>nvmet</em>. The manipulation results in use after free.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-48697">CVE-2022-48697</a>. The attack can only be performed from the local network. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48696 | Linux Kernel up to 5.19.8 regmap_get_spi_bus memory corruption (15ff1f17847c/f5723cfc0193 / WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 5.19.8. Impacted is the function regmap_get_spi_bus. The manipulation leads to memory corruption.

This vulnerability is referenced as CVE-2022-48696. The attack needs to be initiated within the local network. No exploit i...]]></description>
<link>https://tsecurity.de/de/3707368/sicherheitsluecken/cve-2022-48696-linux-kernel-up-to-5198-regmapgetspibus-memory-corruption-15ff1f17847cf5723cfc0193-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707368/sicherheitsluecken/cve-2022-48696-linux-kernel-up-to-5198-regmapgetspibus-memory-corruption-15ff1f17847cf5723cfc0193-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.19.8</a>. Impacted is the function <code>regmap_get_spi_bus</code>. The manipulation leads to memory corruption.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-48696">CVE-2022-48696</a>. The attack needs to be initiated within the local network. No exploit is available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48696 | Linux Kernel up to 5.19.8 regmap_get_spi_bus memory corruption (15ff1f17847c/f5723cfc0193 / WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 5.19.8. Impacted is the function regmap_get_spi_bus. The manipulation leads to memory corruption.

This vulnerability is referenced as CVE-2022-48696. The attack needs to be initiated within the local network. No exploit i...]]></description>
<link>https://tsecurity.de/de/3707367/sicherheitsluecken/cve-2022-48696-linux-kernel-up-to-5198-regmapgetspibus-memory-corruption-15ff1f17847cf5723cfc0193-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707367/sicherheitsluecken/cve-2022-48696-linux-kernel-up-to-5198-regmapgetspibus-memory-corruption-15ff1f17847cf5723cfc0193-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.19.8</a>. Impacted is the function <code>regmap_get_spi_bus</code>. The manipulation leads to memory corruption.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-48696">CVE-2022-48696</a>. The attack needs to be initiated within the local network. No exploit is available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48686 | Linux Kernel up to 5.4.212/5.10.142/5.15.67/5.19.8 nvme-tcp use after free (Nessus ID 207693 / WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.4.212/5.10.142/5.15.67/5.19.8. The impacted element is an unknown function of the component nvme-tcp. Such manipulation leads to use after free.

This vulnerability is documented as CVE-2022-48686. The attack req...]]></description>
<link>https://tsecurity.de/de/3707366/sicherheitsluecken/cve-2022-48686-linux-kernel-up-to-54212510142515675198-nvme-tcp-use-after-free-nessus-id-207693-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707366/sicherheitsluecken/cve-2022-48686-linux-kernel-up-to-54212510142515675198-nvme-tcp-use-after-free-nessus-id-207693-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.4.212/5.10.142/5.15.67/5.19.8</a>. The impacted element is an unknown function of the component <em>nvme-tcp</em>. Such manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-48686">CVE-2022-48686</a>. The attack requires being on the local network. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-48686 | Linux Kernel up to 5.4.212/5.10.142/5.15.67/5.19.8 nvme-tcp use after free (Nessus ID 207693 / WID-SEC-2024-1025)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.4.212/5.10.142/5.15.67/5.19.8. The impacted element is an unknown function of the component nvme-tcp. Such manipulation leads to use after free.

This vulnerability is documented as CVE-2022-48686. The attack req...]]></description>
<link>https://tsecurity.de/de/3707365/sicherheitsluecken/cve-2022-48686-linux-kernel-up-to-54212510142515675198-nvme-tcp-use-after-free-nessus-id-207693-wid-sec-2024-1025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707365/sicherheitsluecken/cve-2022-48686-linux-kernel-up-to-54212510142515675198-nvme-tcp-use-after-free-nessus-id-207693-wid-sec-2024-1025/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.4.212/5.10.142/5.15.67/5.19.8</a>. The impacted element is an unknown function of the component <em>nvme-tcp</em>. Such manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-48686">CVE-2022-48686</a>. The attack requires being on the local network. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27398 | Linux Kernel up to 6.8 Bluetooth sco_sock_timeout use after free (483bc0818182 / Nessus ID 207678)]]></title>
<description><![CDATA[A vulnerability has been found in Linux Kernel up to 6.8 and classified as problematic. Affected by this vulnerability is the function sco_sock_timeout of the component Bluetooth. The manipulation leads to use after free.

This vulnerability is referenced as CVE-2024-27398. The attack needs to be...]]></description>
<link>https://tsecurity.de/de/3707363/sicherheitsluecken/cve-2024-27398-linux-kernel-up-to-68-bluetooth-scosocktimeout-use-after-free-483bc0818182-nessus-id-207678/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707363/sicherheitsluecken/cve-2024-27398-linux-kernel-up-to-68-bluetooth-scosocktimeout-use-after-free-483bc0818182-nessus-id-207678/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is the function <code>sco_sock_timeout</code> of the component <em>Bluetooth</em>. The manipulation leads to use after free.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2024-27398">CVE-2024-27398</a>. The attack needs to be initiated within the local network. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27398 | Linux Kernel up to 6.8 Bluetooth sco_sock_timeout use after free (483bc0818182 / Nessus ID 207678)]]></title>
<description><![CDATA[A vulnerability has been found in Linux Kernel up to 6.8 and classified as problematic. Affected by this vulnerability is the function sco_sock_timeout of the component Bluetooth. The manipulation leads to use after free.

This vulnerability is referenced as CVE-2024-27398. The attack needs to be...]]></description>
<link>https://tsecurity.de/de/3707364/sicherheitsluecken/cve-2024-27398-linux-kernel-up-to-68-bluetooth-scosocktimeout-use-after-free-483bc0818182-nessus-id-207678/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707364/sicherheitsluecken/cve-2024-27398-linux-kernel-up-to-68-bluetooth-scosocktimeout-use-after-free-483bc0818182-nessus-id-207678/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is the function <code>sco_sock_timeout</code> of the component <em>Bluetooth</em>. The manipulation leads to use after free.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2024-27398">CVE-2024-27398</a>. The attack needs to be initiated within the local network. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-52656 | Linux Kernel up to 6.7.10 io_uring privilege escalation (Nessus ID 210815)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Linux Kernel up to 5.4.272/5.10.213/5.15.152/6.1.82/6.7.10. Affected by this vulnerability is an unknown functionality of the component io_uring. Such manipulation leads to privilege escalation.

This vulnerability is listed as CVE...]]></description>
<link>https://tsecurity.de/de/3707362/sicherheitsluecken/cve-2023-52656-linux-kernel-up-to-6710-iouring-privilege-escalation-nessus-id-210815/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707362/sicherheitsluecken/cve-2023-52656-linux-kernel-up-to-6710-iouring-privilege-escalation-nessus-id-210815/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.4.272/5.10.213/5.15.152/6.1.82/6.7.10</a>. Affected by this vulnerability is an unknown functionality of the component <em>io_uring</em>. Such manipulation leads to privilege escalation.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2023-52656">CVE-2023-52656</a>. The attack must be carried out from within the local network. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-52656 | Linux Kernel up to 6.7.10 io_uring privilege escalation (Nessus ID 210815)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Linux Kernel up to 5.4.272/5.10.213/5.15.152/6.1.82/6.7.10. Affected by this vulnerability is an unknown functionality of the component io_uring. Such manipulation leads to privilege escalation.

This vulnerability is listed as CVE...]]></description>
<link>https://tsecurity.de/de/3707361/sicherheitsluecken/cve-2023-52656-linux-kernel-up-to-6710-iouring-privilege-escalation-nessus-id-210815/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707361/sicherheitsluecken/cve-2023-52656-linux-kernel-up-to-6710-iouring-privilege-escalation-nessus-id-210815/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.4.272/5.10.213/5.15.152/6.1.82/6.7.10</a>. Affected by this vulnerability is an unknown functionality of the component <em>io_uring</em>. Such manipulation leads to privilege escalation.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2023-52656">CVE-2023-52656</a>. The attack must be carried out from within the local network. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27393 | Linux Kernel up to 6.9-rc2 page_pool skb_mark_for_recycle memory leak]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 5.15.153/6.1.84/6.6.25/6.8.4/6.9-rc2. The impacted element is the function skb_mark_for_recycle of the component page_pool. The manipulation results in memory leak.

This vulnerability was named CVE-2024-27393. The at...]]></description>
<link>https://tsecurity.de/de/3707360/sicherheitsluecken/cve-2024-27393-linux-kernel-up-to-69-rc2-pagepool-skbmarkforrecycle-memory-leak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707360/sicherheitsluecken/cve-2024-27393-linux-kernel-up-to-69-rc2-pagepool-skbmarkforrecycle-memory-leak/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.15.153/6.1.84/6.6.25/6.8.4/6.9-rc2</a>. The impacted element is the function <code>skb_mark_for_recycle</code> of the component <em>page_pool</em>. The manipulation results in memory leak.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-27393">CVE-2024-27393</a>. The attack needs to be approached within the local network. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27393 | Linux Kernel up to 6.9-rc2 page_pool skb_mark_for_recycle memory leak]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 5.15.153/6.1.84/6.6.25/6.8.4/6.9-rc2. The impacted element is the function skb_mark_for_recycle of the component page_pool. The manipulation results in memory leak.

This vulnerability was named CVE-2024-27393. The at...]]></description>
<link>https://tsecurity.de/de/3707359/sicherheitsluecken/cve-2024-27393-linux-kernel-up-to-69-rc2-pagepool-skbmarkforrecycle-memory-leak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707359/sicherheitsluecken/cve-2024-27393-linux-kernel-up-to-69-rc2-pagepool-skbmarkforrecycle-memory-leak/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.15.153/6.1.84/6.6.25/6.8.4/6.9-rc2</a>. The impacted element is the function <code>skb_mark_for_recycle</code> of the component <em>page_pool</em>. The manipulation results in memory leak.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-27393">CVE-2024-27393</a>. The attack needs to be approached within the local network. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27401 | Linux Kernel up to 6.8 firewire packet_buffer_get user_length buffer overflow (38762a0763c1 / Nessus ID 238008)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.8. Affected is the function packet_buffer_get of the component firewire. Executing a manipulation of the argument user_length can lead to buffer overflow.

The identification of this vulnerability is CVE-2024-274...]]></description>
<link>https://tsecurity.de/de/3707358/sicherheitsluecken/cve-2024-27401-linux-kernel-up-to-68-firewire-packetbufferget-userlength-buffer-overflow-38762a0763c1-nessus-id-238008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707358/sicherheitsluecken/cve-2024-27401-linux-kernel-up-to-68-firewire-packetbufferget-userlength-buffer-overflow-38762a0763c1-nessus-id-238008/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8</a>. Affected is the function <code>packet_buffer_get</code> of the component <em>firewire</em>. Executing a manipulation of the argument <em>user_length</em> can lead to buffer overflow.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2024-27401">CVE-2024-27401</a>. The attack can only be executed locally. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27397 | Linux Kernel up to 6.7.4 nf_tables timestamp information disclosure (383182db8d58/7395dfacfff6 / Nessus ID 208224)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.7.4. Impacted is an unknown function of the component nf_tables. This manipulation of the argument timestamp causes information disclosure.

The identification of this vulnerability is CVE-2024-27397. It ...]]></description>
<link>https://tsecurity.de/de/3707357/sicherheitsluecken/cve-2024-27397-linux-kernel-up-to-674-nftables-timestamp-information-disclosure-383182db8d587395dfacfff6-nessus-id-208224/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707357/sicherheitsluecken/cve-2024-27397-linux-kernel-up-to-674-nftables-timestamp-information-disclosure-383182db8d587395dfacfff6-nessus-id-208224/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.7.4</a>. Impacted is an unknown function of the component <em>nf_tables</em>. This manipulation of the argument <em>timestamp</em> causes information disclosure.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2024-27397">CVE-2024-27397</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27396 | Linux Kernel up to 6.9-rc5 net gtp_dellink use after free]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.9-rc5. Affected by this vulnerability is the function gtp_dellink of the component net. Executing a manipulation can lead to use after free.

This vulnerability is tracked as CVE-2024-27396. The attack is only po...]]></description>
<link>https://tsecurity.de/de/3707356/sicherheitsluecken/cve-2024-27396-linux-kernel-up-to-69-rc5-net-gtpdellink-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707356/sicherheitsluecken/cve-2024-27396-linux-kernel-up-to-69-rc5-net-gtpdellink-use-after-free/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.9-rc5</a>. Affected by this vulnerability is the function <code>gtp_dellink</code> of the component <em>net</em>. Executing a manipulation can lead to use after free.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2024-27396">CVE-2024-27396</a>. The attack is only possible within the local network. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-52654 | Linux Kernel up to 6.6.6 af_unix unix_stream_read_generic privilege escalation (Nessus ID 296058)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Linux Kernel up to 6.6.6. This impacts the function unix_stream_read_generic of the component af_unix. Such manipulation leads to privilege escalation.

This vulnerability is referenced as CVE-2023-52654. The attack needs to be initiated with...]]></description>
<link>https://tsecurity.de/de/3707355/sicherheitsluecken/cve-2023-52654-linux-kernel-up-to-666-afunix-unixstreamreadgeneric-privilege-escalation-nessus-id-296058/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707355/sicherheitsluecken/cve-2023-52654-linux-kernel-up-to-666-afunix-unixstreamreadgeneric-privilege-escalation-nessus-id-296058/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:49 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.6</a>. This impacts the function <code>unix_stream_read_generic</code> of the component <em>af_unix</em>. Such manipulation leads to privilege escalation.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2023-52654">CVE-2023-52654</a>. The attack needs to be initiated within the local network. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rogue KI-Agenten: gefälschte Identitäten beim Hacker-Test in realem Internet entdeckt]]></title>
<description><![CDATA[Laut AISI agierten KI-Agenten in einem Test mehrfach unsanctioniert im realen Internet. Gezieltes Social Engineering mit gefälschten Identitäten ...]]></description>
<link>https://tsecurity.de/de/3707354/hacking/rogue-ki-agenten-gefaelschte-identitaeten-beim-hacker-test-in-realem-internet-entdeckt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707354/hacking/rogue-ki-agenten-gefaelschte-identitaeten-beim-hacker-test-in-realem-internet-entdeckt/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:26 +0200</pubDate>
<content:encoded><![CDATA[Laut AISI agierten KI-Agenten in einem Test mehrfach unsanctioniert im realen Internet. Gezieltes Social Engineering mit gefälschten Identitäten ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Serie von Cyberattacken trifft europäische Händler – Zusammenhang unklar - Retail-News.de]]></title>
<description><![CDATA[Hacker und Programmiercode als Symbol fuer Cyber Crime Foto: depositphotos.com. Key takeaways. ➟ Mehrere europäische Händler melden nahezu ...]]></description>
<link>https://tsecurity.de/de/3707353/hacking/serie-von-cyberattacken-trifft-europaeische-haendler-zusammenhang-unklar-retail-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707353/hacking/serie-von-cyberattacken-trifft-europaeische-haendler-zusammenhang-unklar-retail-newsde/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:26 +0200</pubDate>
<content:encoded><![CDATA[<b>Hacker</b> und Programmiercode als Symbol fuer Cyber Crime Foto: depositphotos.com. Key takeaways. ➟ Mehrere europäische Händler melden nahezu ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Nordkorea-Hacker: 1.640 Unternehmen in 57 Ländern angegriffen - Börse Express]]></title>
<description><![CDATA[Der Sicherheitsforscher Vangelis Stykas hat umfangreiche Cyber-Operationen nordkoreanischer Akteure offengelegt, die sich gegen mindestens 1.640 ...]]></description>
<link>https://tsecurity.de/de/3707352/hacking/nordkorea-hacker-1640-unternehmen-in-57-laendern-angegriffen-boerse-express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707352/hacking/nordkorea-hacker-1640-unternehmen-in-57-laendern-angegriffen-boerse-express/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:26 +0200</pubDate>
<content:encoded><![CDATA[Der Sicherheitsforscher Vangelis Stykas hat umfangreiche Cyber-Operationen nordkoreanischer Akteure offengelegt, die sich gegen mindestens 1.640 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker-Angriffe: Cyberangriffe auf US-Wasserversorgung weiten sich aus]]></title>
<description><![CDATA[Das teilten die Bundespolizei FBI und die Umweltbehörde EPA mit. Ein Teil der Aktivitäten habe den Betrieb von Wasserwerken beeinträchtigt. Nach ...]]></description>
<link>https://tsecurity.de/de/3707351/hacking/hacker-angriffe-cyberangriffe-auf-us-wasserversorgung-weiten-sich-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707351/hacking/hacker-angriffe-cyberangriffe-auf-us-wasserversorgung-weiten-sich-aus/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:26 +0200</pubDate>
<content:encoded><![CDATA[Das teilten die Bundespolizei FBI und die Umweltbehörde EPA mit. Ein Teil der Aktivitäten habe den Betrieb von Wasserwerken beeinträchtigt. Nach ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta-KI hackt bei Test Firma - Sorgen um Sicherheit wachsen - Wirtschaft - SZ.de]]></title>
<description><![CDATA[Die Adresse von Meta in Kalifornien: 1 Hacker Way. (Archivbild) Andrej Sokolow ...]]></description>
<link>https://tsecurity.de/de/3707350/hacking/meta-ki-hackt-bei-test-firma-sorgen-um-sicherheit-wachsen-wirtschaft-szde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707350/hacking/meta-ki-hackt-bei-test-firma-sorgen-um-sicherheit-wachsen-wirtschaft-szde/</guid>
<pubDate>Thu, 06 Aug 2026 07:10:26 +0200</pubDate>
<content:encoded><![CDATA[Die Adresse von Meta in Kalifornien: 1 <b>Hacker</b> Way. (Archivbild) Andrej Sokolow ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Tracking people, training AI.]]></title>
<description><![CDATA[This week, Ben and Ethan discuss two major stories. The first involves an incident where a police officer was abusing his access to Flock camera databases to track a former partner's movement. The second looks at recent research that found that Chinese military research units have been accessing ...]]></description>
<link>https://tsecurity.de/de/3707349/it-security-nachrichten/tracking-people-training-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707349/it-security-nachrichten/tracking-people-training-ai/</guid>
<pubDate>Thu, 06 Aug 2026 07:09:14 +0200</pubDate>
<content:encoded><![CDATA[This week, Ben and Ethan discuss two major stories. The first involves an incident where a police officer was abusing his access to Flock camera databases to track a former partner's movement. The second looks at recent research that found that Chinese military research units have been accessing US frontier AI models to train their own models through a process called model distillation.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses]]></title>
<description><![CDATA[Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect. Newly disclosed flaws in WebKit, the browser engine used across iOS, can allow a website to see a visitor’s real IP address. The exposure weakens a privacy safeguard. The i...]]></description>
<link>https://tsecurity.de/de/3707348/it-security-nachrichten/apple-icloud-private-relay-webkit-flaws-leak-users-real-ip-addresses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707348/it-security-nachrichten/apple-icloud-private-relay-webkit-flaws-leak-users-real-ip-addresses/</guid>
<pubDate>Thu, 06 Aug 2026 07:09:14 +0200</pubDate>
<content:encoded><![CDATA[<p>Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect. Newly disclosed flaws in WebKit, the browser engine used across iOS, can allow a website to see a visitor’s real IP address. The exposure weakens a privacy safeguard. The issue can be triggered when […]</p>
<p>The post <a href="https://cybersecuritynews.com/apple-icloud-private-relay/">Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Cisco SD-WAN Vulnerabilities Enable Access Control Bypass and Path Traversal]]></title>
<description><![CDATA[Cisco has released critical security hardening updates for Cisco Catalyst SD-WAN Software, addressing multiple vulnerabilities that could allow authenticated attackers to bypass access controls and manipulate file paths. Tracked under Cisco advisory cisco-sa-hardening-sdwan-faLcR3K, the flaws car...]]></description>
<link>https://tsecurity.de/de/3707347/it-security-nachrichten/critical-cisco-sd-wan-vulnerabilities-enable-access-control-bypass-and-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707347/it-security-nachrichten/critical-cisco-sd-wan-vulnerabilities-enable-access-control-bypass-and-path-traversal/</guid>
<pubDate>Thu, 06 Aug 2026 07:08:55 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco has released critical security hardening updates for Cisco Catalyst SD-WAN Software, addressing multiple vulnerabilities that could allow authenticated attackers to bypass access controls and manipulate file paths. Tracked under Cisco advisory cisco-sa-hardening-sdwan-faLcR3K, the flaws carry maximum CVSS scores of 9.9 and affect Catalyst SD-WAN installations regardless of device configuration. Impacted environments include on-premises deployments, […]</p>
<p>The post <a href="https://cyberpress.org/critical-cisco-sd-wan-vulnerabilities/">Critical Cisco SD-WAN Vulnerabilities Enable Access Control Bypass and Path Traversal</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks]]></title>
<description><![CDATA[Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access…
Read more →
The post Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3707346/it-security-nachrichten/critical-cisco-sd-wan-flaws-expose-systems-to-access-control-bypass-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707346/it-security-nachrichten/critical-cisco-sd-wan-flaws-expose-systems-to-access-control-bypass-attacks/</guid>
<pubDate>Thu, 06 Aug 2026 07:08:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-cisco-sd-wan-flaws-expose-systems-to-access-control-bypass-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-cisco-sd-wan-flaws-expose-systems-to-access-control-bypass-attacks/">Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Auch KI von Meta hackte sich in eine andere Firma]]></title>
<description><![CDATA[Nach OpenAI und Anthropic räumt nun auch Meta ein, dass sich eigene KI-Software in fremde Systeme gehackt hat.]]></description>
<link>https://tsecurity.de/de/3707345/it-security-nachrichten/auch-ki-von-meta-hackte-sich-in-eine-andere-firma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707345/it-security-nachrichten/auch-ki-von-meta-hackte-sich-in-eine-andere-firma/</guid>
<pubDate>Thu, 06 Aug 2026 07:08:09 +0200</pubDate>
<content:encoded><![CDATA[Nach OpenAI und Anthropic räumt nun auch Meta ein, dass sich eigene KI-Software in fremde Systeme gehackt hat.]]></content:encoded>
</item>
<item>
<title><![CDATA[Non-human identities are 91% of everything active in production]]></title>
<description><![CDATA[A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credent...]]></description>
<link>https://tsecurity.de/de/3707344/it-security-nachrichten/non-human-identities-are-91-of-everything-active-in-production/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707344/it-security-nachrichten/non-human-identities-are-91-of-everything-active-in-production/</guid>
<pubDate>Thu, 06 Aug 2026 07:06:07 +0200</pubDate>
<content:encoded><![CDATA[<p>A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credentials inherits the same cover. Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API … <a href="https://www.helpnetsecurity.com/2026/08/06/non-human-identities-active-in-production/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/non-human-identities-active-in-production/">Non-human identities are 91% of everything active in production</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Suppliers, logins, and AI tools are all becoming attack paths]]></title>
<description><![CDATA[Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity increased by about 4% over the past year. Even tho...]]></description>
<link>https://tsecurity.de/de/3707343/it-security-nachrichten/suppliers-logins-and-ai-tools-are-all-becoming-attack-paths/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707343/it-security-nachrichten/suppliers-logins-and-ai-tools-are-all-becoming-attack-paths/</guid>
<pubDate>Thu, 06 Aug 2026 07:06:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity increased by about 4% over the past year. Even though the increase was smaller than in the previous reporting period, it shows a growing focus on more targeted campaigns. Attackers are investing more time in exploiting trusted access paths and legitimate infrastructure. AI … <a href="https://www.helpnetsecurity.com/2026/08/06/crowdstrike-cyber-threat-trends-report/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/crowdstrike-cyber-threat-trends-report/">Suppliers, logins, and AI tools are all becoming attack paths</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Resolve Error 503 Maximum Threads for Service Reached]]></title>
<description><![CDATA[Key TakeawaysThe "Error 503 Maximum Threads for Service Reached" appears when a website or service gets too many requests at once, which it can't handle safely, so it temporarily rejects new requests to avoid becoming unstable. This error is common with services using Fastly or similar CDNs and a...]]></description>
<link>https://tsecurity.de/de/3707342/it-security-nachrichten/how-to-resolve-error-503-maximum-threads-for-service-reached/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707342/it-security-nachrichten/how-to-resolve-error-503-maximum-threads-for-service-reached/</guid>
<pubDate>Thu, 06 Aug 2026 07:03:57 +0200</pubDate>
<content:encoded><![CDATA[<p>Key TakeawaysThe "Error 503 Maximum Threads for Service Reached" appears when a website or service gets too many requests at once, which it can't handle safely, so it temporarily rejects new requests to avoid becoming unstable. This error is common with services using Fastly or similar CDNs and affects various websites, APIs, and online platforms. […]</p>
<p>The post <a href="https://itechhacks.com/fix-error-503-maximum-threads-service-reached/" data-wpel-link="internal">How to Resolve Error 503 Maximum Threads for Service Reached</a> appeared first on <a href="https://itechhacks.com/" data-wpel-link="internal">iTech Hacks</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Gaming PC Deals: Save Up to $300 on Top Machines From HP, Skytech and More]]></title>
<description><![CDATA[A good gaming PC doesn’t have to break the bank, especially with these bargains on machines with top features like RTX and AMD graphics cards.]]></description>
<link>https://tsecurity.de/de/3707341/it-nachrichten/best-gaming-pc-deals-save-up-to-300-on-top-machines-from-hp-skytech-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707341/it-nachrichten/best-gaming-pc-deals-save-up-to-300-on-top-machines-from-hp-skytech-and-more/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:56 +0200</pubDate>
<content:encoded><![CDATA[A good gaming PC doesn’t have to break the bank, especially with these bargains on machines with top features like RTX and AMD graphics cards.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta AI model hacks another company during testing]]></title>
<description><![CDATA[The headline is wild, but the human failure seems more important here: a testing misconfiguration gave the model internet access, and it then exploited a third-party service. For teams running agentic security evaluations, what containment control should be non-negotiable before a model gets any ...]]></description>
<link>https://tsecurity.de/de/3707340/it-security-nachrichten/meta-ai-model-hacks-another-company-during-testing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707340/it-security-nachrichten/meta-ai-model-hacks-another-company-during-testing/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:55 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The headline is wild, but the human failure seems more important here: a testing misconfiguration gave the model internet access, and it then exploited a third-party service.</p> <p>For teams running agentic security evaluations, what containment control should be non-negotiable before a model gets any network access?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/ClaudiusPapirus"> /u/ClaudiusPapirus </a> <br> <span><a href="https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1vguqbl/meta_ai_model_hacks_another_company_during_testing/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Auch Metas KI führte einen Hack durch]]></title>
<description><![CDATA[Nach den KI-Firmen OpenAI und Anthropic muss auch der Facebook-Konzern Meta einräumen, dass seine KI-Software sich in Computersysteme eines anderen Unternehmens gehackt hat. 

Tags: #KI-Modell | #Meta]]></description>
<link>https://tsecurity.de/de/3707339/it-security-nachrichten/auch-metas-ki-fuehrte-einen-hack-durch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707339/it-security-nachrichten/auch-metas-ki-fuehrte-einen-hack-durch/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:53 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2023/11/Meta-1920-Shutterstock-2066815178-Quelle-Sergei_Elagin-Shutterstock.com_.jpg" class="attachment-full size-full wp-post-image" alt="Meta" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2023/11/Meta-1920-Shutterstock-2066815178-Quelle-Sergei_Elagin-Shutterstock.com_.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2023/11/Meta-1920-Shutterstock-2066815178-Quelle-Sergei_Elagin-Shutterstock.com_-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2023/11/Meta-1920-Shutterstock-2066815178-Quelle-Sergei_Elagin-Shutterstock.com_-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2023/11/Meta-1920-Shutterstock-2066815178-Quelle-Sergei_Elagin-Shutterstock.com_-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2023/11/Meta-1920-Shutterstock-2066815178-Quelle-Sergei_Elagin-Shutterstock.com_-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Auch Metas KI führte einen Hack durch 3"></p>
    Nach den KI-Firmen OpenAI und Anthropic muss auch der Facebook-Konzern Meta einräumen, dass seine KI-Software sich in Computersysteme eines anderen Unternehmens gehackt hat. 

<p>Tags: <a href="https://www.it-daily.net/thema/ki-modell">#KI-Modell</a> | <a href="https://www.it-daily.net/thema/meta-en">#Meta</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft kassiert rund 360 Millionen Euro vom Freistaat Bayern]]></title>
<description><![CDATA[Es sind durchaus beeindruckende Summen, die Bayern jedes Jahr an den US-Giganten Microsoft überweist: Alleine zwischen 2020 und 2025 hat der Freistaat hier mehr als 258 Millionen Euro für Produkte und -Dienstleistungen ausgegeben. 

Tags: #Bayern | #Microsoft]]></description>
<link>https://tsecurity.de/de/3707338/it-security-nachrichten/microsoft-kassiert-rund-360-millionen-euro-vom-freistaat-bayern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707338/it-security-nachrichten/microsoft-kassiert-rund-360-millionen-euro-vom-freistaat-bayern/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:53 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2022/07/Bayern-digital-Shutterstock-643129468-1920.jpg" class="attachment-full size-full wp-post-image" alt="Bayern digital" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2022/07/Bayern-digital-Shutterstock-643129468-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2022/07/Bayern-digital-Shutterstock-643129468-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2022/07/Bayern-digital-Shutterstock-643129468-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2022/07/Bayern-digital-Shutterstock-643129468-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2022/07/Bayern-digital-Shutterstock-643129468-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Microsoft kassiert rund 360 Millionen Euro vom Freistaat Bayern 1"></p>
    Es sind durchaus beeindruckende Summen, die Bayern jedes Jahr an den US-Giganten Microsoft überweist: Alleine zwischen 2020 und 2025 hat der Freistaat hier mehr als 258 Millionen Euro für Produkte und -Dienstleistungen ausgegeben. 

<p>Tags: <a href="https://www.it-daily.net/thema/bayern">#Bayern</a> | <a href="https://www.it-daily.net/thema/microsoft-en">#Microsoft</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway]]></title>
<description><![CDATA[It’s just a remote maintenance function, says Zbtlink]]></description>
<link>https://tsecurity.de/de/3707337/it-security-nachrichten/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707337/it-security-nachrichten/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:43 +0200</pubDate>
<content:encoded><![CDATA[It’s just a remote maintenance function, says Zbtlink]]></content:encoded>
</item>
<item>
<title><![CDATA[I just gave this stick vacuum 5 stars and now it's half off — get the Samsung Jet 95S for just AU$399]]></title>
<description><![CDATA[The Samsung Jet 95S is remarkably easy to recommend even at full price but, at half price, it's even better value with excellent suction and performance.]]></description>
<link>https://tsecurity.de/de/3707336/it-nachrichten/i-just-gave-this-stick-vacuum-5-stars-and-now-its-half-off-get-the-samsung-jet-95s-for-just-au399/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707336/it-nachrichten/i-just-gave-this-stick-vacuum-5-stars-and-now-its-half-off-get-the-samsung-jet-95s-for-just-au399/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:22 +0200</pubDate>
<content:encoded><![CDATA[The Samsung Jet 95S is remarkably easy to recommend even at full price but, at half price, it's even better value with excellent suction and performance.]]></content:encoded>
</item>
<item>
<title><![CDATA[G’day, Alexa+: Amazon's AI-upgraded smart home assistant has finally arrived in Australia — and it's fully fluent in 'Strayan]]></title>
<description><![CDATA[After launching in the US last year, Alexa+ aims to be “smarter, more conversational and more capable” than ever — but at AU$29.99 per month (without Prime), is another agentic AI assistant worth it?]]></description>
<link>https://tsecurity.de/de/3707335/it-nachrichten/gday-alexa-amazons-ai-upgraded-smart-home-assistant-has-finally-arrived-in-australia-and-its-fully-fluent-in-strayan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707335/it-nachrichten/gday-alexa-amazons-ai-upgraded-smart-home-assistant-has-finally-arrived-in-australia-and-its-fully-fluent-in-strayan/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:22 +0200</pubDate>
<content:encoded><![CDATA[After launching in the US last year, Alexa+ aims to be “smarter, more conversational and more capable” than ever — but at AU$29.99 per month (without Prime), is another agentic AI assistant worth it?]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Gaming PC Deals: Save Up to $300 on Top Machines From HP, Skytech and More]]></title>
<description><![CDATA[A good gaming PC doesn’t have to break the bank, especially with these bargains on machines with top features like RTX and AMD graphics cards.]]></description>
<link>https://tsecurity.de/de/3707334/it-nachrichten/best-gaming-pc-deals-save-up-to-300-on-top-machines-from-hp-skytech-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707334/it-nachrichten/best-gaming-pc-deals-save-up-to-300-on-top-machines-from-hp-skytech-and-more/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:17 +0200</pubDate>
<content:encoded><![CDATA[A good gaming PC doesn’t have to break the bank, especially with these bargains on machines with top features like RTX and AMD graphics cards.]]></content:encoded>
</item>
<item>
<title><![CDATA[Today’s NYT Mini Crossword Answers for Thursday, Aug. 6]]></title>
<description><![CDATA[Here are the answers for The New York Times Mini Crossword for Thursday, Aug. 6, 2026.]]></description>
<link>https://tsecurity.de/de/3707333/it-nachrichten/todays-nyt-mini-crossword-answers-for-thursday-aug-6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707333/it-nachrichten/todays-nyt-mini-crossword-answers-for-thursday-aug-6/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:17 +0200</pubDate>
<content:encoded><![CDATA[Here are the answers for The New York Times Mini Crossword for Thursday, Aug. 6, 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[Today’s NYT Mini Crossword Answers for Thursday, Aug. 6]]></title>
<description><![CDATA[Here are the answers for The New York Times Mini Crossword for Thursday, Aug. 6, 2026.]]></description>
<link>https://tsecurity.de/de/3707332/it-nachrichten/todays-nyt-mini-crossword-answers-for-thursday-aug-6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707332/it-nachrichten/todays-nyt-mini-crossword-answers-for-thursday-aug-6/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:17 +0200</pubDate>
<content:encoded><![CDATA[Here are the answers for The New York Times Mini Crossword for Thursday, Aug. 6, 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wordle Hints, Answer and Help for Aug. 6, #1874]]></title>
<description><![CDATA[Here are the hints and answers for Wordle No. 1874 for Aug. 6, 2026.]]></description>
<link>https://tsecurity.de/de/3707331/it-nachrichten/wordle-hints-answer-and-help-for-aug-6-1874/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707331/it-nachrichten/wordle-hints-answer-and-help-for-aug-6-1874/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:17 +0200</pubDate>
<content:encoded><![CDATA[Here are the hints and answers for Wordle No. 1874 for Aug. 6, 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[Aldi verkauft heute einen Helfer für 25 Euro, der perfekt in kleine Küchen passt]]></title>
<description><![CDATA[Wer wenig Platz in der Küche hat, muss nicht auf knusprige Pommes verzichten.]]></description>
<link>https://tsecurity.de/de/3707330/it-nachrichten/aldi-verkauft-heute-einen-helfer-fuer-25-euro-der-perfekt-in-kleine-kuechen-passt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707330/it-nachrichten/aldi-verkauft-heute-einen-helfer-fuer-25-euro-der-perfekt-in-kleine-kuechen-passt/</guid>
<pubDate>Thu, 06 Aug 2026 07:02:00 +0200</pubDate>
<content:encoded><![CDATA[Wer wenig Platz in der Küche hat, muss nicht auf knusprige Pommes verzichten.]]></content:encoded>
</item>
<item>
<title><![CDATA[„Ein Problem, das grundsätzlich unlösbar ist“: Warum KI-Modelle vielleicht nie sicher sein werden]]></title>
<description><![CDATA[Großen Sprachmodellen fällt es schwer, zwischen Prompts, eigenen Reasoning-Schritten und Tool-Verwendung zu unterscheiden. Angreifer:innen können das ausnutzen.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3707329/it-nachrichten/ein-problem-das-grundsaetzlich-unloesbar-ist-warum-ki-modelle-vielleicht-nie-sicher-sein-werden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707329/it-nachrichten/ein-problem-das-grundsaetzlich-unloesbar-ist-warum-ki-modelle-vielleicht-nie-sicher-sein-werden/</guid>
<pubDate>Thu, 06 Aug 2026 07:01:39 +0200</pubDate>
<content:encoded><![CDATA[Großen Sprachmodellen fällt es schwer, zwischen Prompts, eigenen Reasoning-Schritten und Tool-Verwendung zu unterscheiden. Angreifer:innen können das ausnutzen.<a href="https://t3n.de/news/problem-unloesbar-ki-modelle-sicher-1755811/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixel-Smartphones im Höhenflug: Google Pixel wächst deutlich stärker als Samsung und Apple – zusammen]]></title>
<description><![CDATA[Google ist mit den Pixel-Smartphones schon seit einigen Jahren auf der Überholspur und kann auch in der aktuellen Krise überraschend stark profitieren - mehr noch als die beiden Branchen-Primus Apple und Samsung. Ein aktueller Einblick der Marktforscher zeigt uns, dass die Pixel-Smartphones trotz...]]></description>
<link>https://tsecurity.de/de/3707328/it-nachrichten/pixel-smartphones-im-hoehenflug-google-pixel-waechst-deutlich-staerker-als-samsung-und-apple-zusammen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707328/it-nachrichten/pixel-smartphones-im-hoehenflug-google-pixel-waechst-deutlich-staerker-als-samsung-und-apple-zusammen/</guid>
<pubDate>Thu, 06 Aug 2026 07:01:30 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="640" height="386" src="https://www.googlewatchblog.de/wp-content/uploads/google-pixel-smartphones-1024x617.jpg" class="attachment-large size-large wp-post-image" alt="google pixel smartphones" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/google-pixel-smartphones-1024x617.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/google-pixel-smartphones-300x181.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/google-pixel-smartphones-768x463.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/google-pixel-smartphones-640x386.jpg 640w, https://www.googlewatchblog.de/wp-content/uploads/google-pixel-smartphones-800x482.jpg 800w, https://www.googlewatchblog.de/wp-content/uploads/google-pixel-smartphones.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>Google ist mit den <a href="https://www.googlewatchblog.de/2026/08/pixel-11-smartphones-das-ist-das-neue-hilight-leak-verraet-die-moeglichkeiten-von-pixel-glow-screenshot/"><strong>Pixel-Smartphones</strong></a> schon seit einigen Jahren auf der Überholspur und kann auch in der aktuellen Krise überraschend stark profitieren - mehr noch als die beiden Branchen-Primus Apple und Samsung. Ein aktueller Einblick der Marktforscher zeigt uns, dass die Pixel-Smartphones trotz schrumpfenden Markt die Verkaufszahlen um ganze 16 Prozent steigern konnten. Man ist wohl auf dem richtigen Weg.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/08/pixel-smartphones-im-hoehenflug-google-pixel-waechst-staerker-als-samsung-und-apple-zusammen-q2-2026-u/">Pixel-Smartphones im Höhenflug: Google Pixel wächst deutlich stärker als Samsung und Apple – zusammen</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/4bf967a44ef442ac9513289322fa327a"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/4bf967a44ef442ac9513289322fa327a" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/08/pixel-smartphones-im-hoehenflug-google-pixel-waechst-staerker-als-samsung-und-apple-zusammen-q2-2026-u/">Pixel-Smartphones im Höhenflug: Google Pixel wächst deutlich stärker als Samsung und Apple – zusammen</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kioxia GP1: PCIe-6.0-SSD erreicht mit XL-Flash 10 Mio. IOPS]]></title>
<description><![CDATA[Kioxia konkretisiert seine im März angekündigte GP-Serie für KI-Systeme. Die erste SSD namens GP1 nutzt PCIe 6.0 und XL-Flash der zweiten Generation, erreicht bis zu 10 Millionen IOPS und soll GPUs als vergleichsweise günstige Erweiterung des knappen HBM dienen.]]></description>
<link>https://tsecurity.de/de/3707327/it-nachrichten/kioxia-gp1-pcie-60-ssd-erreicht-mit-xl-flash-10-mio-iops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707327/it-nachrichten/kioxia-gp1-pcie-60-ssd-erreicht-mit-xl-flash-10-mio-iops/</guid>
<pubDate>Thu, 06 Aug 2026 07:01:21 +0200</pubDate>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/4/1/4/9-38b0f557a88dbcfb/article-640x360.efc84742.jpg"><p>Kioxia konkretisiert seine im März angekündigte GP-Serie für KI-Systeme. Die erste SSD namens GP1 nutzt PCIe 6.0 und XL-Flash der zweiten Generation, erreicht bis zu 10 Millionen IOPS und soll GPUs als vergleichsweise günstige Erweiterung des knappen HBM dienen.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bayern zahlt rund 360 Millionen Euro an Microsoft]]></title>
<description><![CDATA[Bayerns Verwaltung arbeitet mit Software von Microsoft. Neue Zahlen zeigen, dass der Freistaat in acht Jahren rund 360 Millionen Euro an den Konzern zahlt.]]></description>
<link>https://tsecurity.de/de/3707326/it-nachrichten/bayern-zahlt-rund-360-millionen-euro-an-microsoft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707326/it-nachrichten/bayern-zahlt-rund-360-millionen-euro-an-microsoft/</guid>
<pubDate>Thu, 06 Aug 2026 07:01:21 +0200</pubDate>
<content:encoded><![CDATA[Bayerns Verwaltung arbeitet mit Software von Microsoft. Neue Zahlen zeigen, dass der Freistaat in acht Jahren rund 360 Millionen Euro an den Konzern zahlt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Talk, don’t type: Big Tech bets AI’s future will be spoken]]></title>
<description><![CDATA[OpenAI and Google invest heavily in voice systems as main way to interact with a new generation of AI agents]]></description>
<link>https://tsecurity.de/de/3707312/ai-nachrichten/talk-dont-type-big-tech-bets-ais-future-will-be-spoken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707312/ai-nachrichten/talk-dont-type-big-tech-bets-ais-future-will-be-spoken/</guid>
<pubDate>Thu, 06 Aug 2026 06:42:11 +0200</pubDate>
<content:encoded><![CDATA[OpenAI and Google invest heavily in voice systems as main way to interact with a new generation of AI agents]]></content:encoded>
</item>
<item>
<title><![CDATA[Who needs consultants in the age of AI? ]]></title>
<description><![CDATA[Getting a company to implement recommended changes is a contact sport that only humans can play]]></description>
<link>https://tsecurity.de/de/3707311/ai-nachrichten/who-needs-consultants-in-the-age-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707311/ai-nachrichten/who-needs-consultants-in-the-age-of-ai/</guid>
<pubDate>Thu, 06 Aug 2026 06:42:11 +0200</pubDate>
<content:encoded><![CDATA[Getting a company to implement recommended changes is a contact sport that only humans can play]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare OS goes open source with a record of everything its agents read]]></title>
<description><![CDATA[Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output the platform checks them against the underly...]]></description>
<link>https://tsecurity.de/de/3707300/it-security-nachrichten/cloudflare-os-goes-open-source-with-a-record-of-everything-its-agents-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707300/it-security-nachrichten/cloudflare-os-goes-open-source-with-a-record-of-everything-its-agents-read/</guid>
<pubDate>Thu, 06 Aug 2026 06:35:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output the platform checks them against the underlying data first. An agent builds a live dashboard from a sensitive warehouse table, a coworker opens the dashboard, and the coworker sees nothing unless they could have read … <a href="https://www.helpnetsecurity.com/2026/08/06/cloudflare-os-open-source/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/cloudflare-os-open-source/">Cloudflare OS goes open source with a record of everything its agents read</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Subway App Login or Order Not Working? Fix It Fast]]></title>
<description><![CDATA[Key TakeawaysThe Subway app can face issues like crashing, login problems, empty menus, or payment failures often due to outdated versions, server issues, internet problems, or incorrect location settings. Fixing these involves checking server status, closing and reopening the app, or updating it...]]></description>
<link>https://tsecurity.de/de/3707299/it-security-nachrichten/subway-app-login-or-order-not-working-fix-it-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707299/it-security-nachrichten/subway-app-login-or-order-not-working-fix-it-fast/</guid>
<pubDate>Thu, 06 Aug 2026 06:35:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Key TakeawaysThe Subway app can face issues like crashing, login problems, empty menus, or payment failures often due to outdated versions, server issues, internet problems, or incorrect location settings. Fixing these involves checking server status, closing and reopening the app, or updating it.To resolve common app issues, ensure a stable internet connection, disable any interfering […]</p>
<p>The post <a href="https://itechhacks.com/subway-app-not-working/" data-wpel-link="internal">Subway App Login or Order Not Working? Fix It Fast</a> appeared first on <a href="https://itechhacks.com/" data-wpel-link="internal">iTech Hacks</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SENARA: The Sacrament Review (PC)]]></title>
<description><![CDATA[SENARA: The Sacrament is a creative horror game that embraces the survival horror element, and it puts us in the middle of the ocean, on a large ship as we try to stay alive. It gets a lot of inspiration not only from Ghost Ship and other maritime horror movies, but also the great Cold Fear game ...]]></description>
<link>https://tsecurity.de/de/3707298/it-security-nachrichten/senara-the-sacrament-review-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707298/it-security-nachrichten/senara-the-sacrament-review-pc/</guid>
<pubDate>Thu, 06 Aug 2026 06:34:39 +0200</pubDate>
<content:encoded><![CDATA[SENARA: The Sacrament is a creative horror game that embraces the survival horror element, and it puts us in the middle of the ocean, on a large ship as we try to stay alive. It gets a lot of inspiration not only from Ghost Ship and other maritime horror movies, but also the great Cold Fear game from back in the day. However, it also brings a spin of its own, and combined with elements from a real story, you have an amalgam of ideas that mostly sticks to the landing.

Right off the bat, the game starts off with you being on the cruise ship, you have no idea why or how you got there. Even at the beginning, you have a couple of enemies that try to kill you, and then you slowly start meeting people, like the captain. Then you realize what happened, basically the ship was taken over by a fanatical cult who killed everyone they found on the ship.

The captain tells you to try and trigger the distress beacon in order to call a rescue helicopter. He also lets you know that ...]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Architecture: Moving Past the Washing to the Truth]]></title>
<description><![CDATA[In the current hype cycle, “AI” has become a linguistic junk drawer—a catch-all term that vendors use to mask everything from basic if-then statements to massive neural networks. For the modern enterprise, this “AI Washing” isn’t just annoying, it’s a strategic risk.  To build a resilient, sovere...]]></description>
<link>https://tsecurity.de/de/3707297/unix-server/ai-architecture-moving-past-the-washing-to-the-truth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707297/unix-server/ai-architecture-moving-past-the-washing-to-the-truth/</guid>
<pubDate>Thu, 06 Aug 2026 06:34:37 +0200</pubDate>
<content:encoded><![CDATA[<p>In the current hype cycle, “AI” has become a linguistic junk drawer—a catch-all term that vendors use to mask everything from basic if-then statements to massive neural networks. For the modern enterprise, this “AI Washing” isn’t just annoying, it’s a strategic risk.  To build a resilient, sovereign infrastructure, we have to stop treating AI as […]</p>
<p>The post <a href="https://www.suse.com/c/ai-architecture-moving-past-the-washing-to-the-truth/">AI Architecture: Moving Past the Washing to the Truth</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Günstiger als ein Deutschlandticket: Ikea verkauft das Zubehör, das eurem Stehschreibtisch noch fehlt]]></title>
<description><![CDATA[Warum euer Stehschreibtisch erst mit diesem Detail wirklich Sinn ergibt.]]></description>
<link>https://tsecurity.de/de/3707296/android-tipps/guenstiger-als-ein-deutschlandticket-ikea-verkauft-das-zubehoer-das-eurem-stehschreibtisch-noch-fehlt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707296/android-tipps/guenstiger-als-ein-deutschlandticket-ikea-verkauft-das-zubehoer-das-eurem-stehschreibtisch-noch-fehlt/</guid>
<pubDate>Thu, 06 Aug 2026 06:33:15 +0200</pubDate>
<content:encoded><![CDATA[Warum euer Stehschreibtisch erst mit diesem Detail wirklich Sinn ergibt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Akku-Wechsel für Elektroautos jetzt auch bei Kleinwagen möglich]]></title>
<description><![CDATA[Bislang ist es außerhalb von China üblich, dass Elektroautos bei Strombedarf aufgeladen werden. Entweder mit dem Kabel zuhause oder an einer öffentlichen Ladesäule. NIO wollte…
Dieser Artikel Akku-Wechsel für Elektroautos jetzt auch bei Kleinwagen möglich erschien zuerst auf SmartDroid.de.]]></description>
<link>https://tsecurity.de/de/3707295/android-tipps/akku-wechsel-fuer-elektroautos-jetzt-auch-bei-kleinwagen-moeglich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707295/android-tipps/akku-wechsel-fuer-elektroautos-jetzt-auch-bei-kleinwagen-moeglich/</guid>
<pubDate>Thu, 06 Aug 2026 06:33:12 +0200</pubDate>
<content:encoded><![CDATA[<img width="2048" height="1261" src="https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/08/Firefly-Hero-scaled.jpg?fit=2048%2C1261&amp;ssl=1" class="attachment-medium size-medium wp-post-image" alt="Firefly Hero" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/08/Firefly-Hero-scaled.jpg?w=2048&amp;ssl=1 2048w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/08/Firefly-Hero-scaled.jpg?resize=1200%2C739&amp;ssl=1 1200w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/08/Firefly-Hero-scaled.jpg?resize=1536%2C946&amp;ssl=1 1536w, https://i0.wp.com/www.smartdroid.de/wp-content/uploads/2025/08/Firefly-Hero-scaled.jpg?w=1800&amp;ssl=1 1800w" sizes="(max-width: 2048px) 100vw, 2048px"><p>Bislang ist es außerhalb von China üblich, dass Elektroautos bei Strombedarf aufgeladen werden. Entweder mit dem Kabel zuhause oder an einer öffentlichen Ladesäule. NIO wollte…</p>
<p>Dieser Artikel <a rel="nofollow" href="https://www.smartdroid.de/akku-wechsel-fuer-elektroautos-jetzt-auch-bei-kleinwagen-moeglich/">Akku-Wechsel für Elektroautos jetzt auch bei Kleinwagen möglich</a> erschien zuerst auf <a rel="nofollow" href="https://www.smartdroid.de/">SmartDroid.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Donnerstag: Aus für Google Assistant, Snapchat-Verbot von KI-Videos]]></title>
<description><![CDATA[Gemini als neuer Google-Assistent + Snapchat Spotlight gegen KI + Podcast über Gesundheitsdaten + Cloudflare mit Arbeitsumgebung für KI-Agenten + #heiseshow]]></description>
<link>https://tsecurity.de/de/3707294/it-nachrichten/donnerstag-aus-fuer-google-assistant-snapchat-verbot-von-ki-videos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707294/it-nachrichten/donnerstag-aus-fuer-google-assistant-snapchat-verbot-von-ki-videos/</guid>
<pubDate>Thu, 06 Aug 2026 06:33:02 +0200</pubDate>
<content:encoded><![CDATA[Gemini als neuer Google-Assistent + Snapchat Spotlight gegen KI + Podcast über Gesundheitsdaten + Cloudflare mit Arbeitsumgebung für KI-Agenten + #heiseshow]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27050 | Linux Kernel up to 6.6.22/6.7.10/6.8.1 libbpf OPTS_SET xdp_zc_max_segs out-of-bounds (Nessus ID 249866 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Linux Kernel up to 6.6.22/6.7.10/6.8.1. Affected is the function OPTS_SET of the component libbpf. The manipulation of the argument xdp_zc_max_segs results in out-of-bounds read.

This vulnerability is cataloged as CVE-2024-27050. The attac...]]></description>
<link>https://tsecurity.de/de/3707293/sicherheitsluecken/cve-2024-27050-linux-kernel-up-to-66226710681-libbpf-optsset-xdpzcmaxsegs-out-of-bounds-nessus-id-249866-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707293/sicherheitsluecken/cve-2024-27050-linux-kernel-up-to-66226710681-libbpf-optsset-xdpzcmaxsegs-out-of-bounds-nessus-id-249866-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.22/6.7.10/6.8.1</a>. Affected is the function <code>OPTS_SET</code> of the component <em>libbpf</em>. The manipulation of the argument <em>xdp_zc_max_segs</em> results in out-of-bounds read.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2024-27050">CVE-2024-27050</a>. The attack must originate from the local network. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27053 | Linux Kernel up to 6.8.1 wilc1000 hif.c rcu_dereference_check null pointer dereference (Nessus ID 296193 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.8.1. It has been declared as critical. The affected element is the function rcu_dereference_check of the file drivers/net/wireless/microchip/wilc1000/hif.c of the component wilc1000. Such manipulation leads to null pointer dereference.

This vulne...]]></description>
<link>https://tsecurity.de/de/3707292/sicherheitsluecken/cve-2024-27053-linux-kernel-up-to-681-wilc1000-hifc-rcudereferencecheck-null-pointer-dereference-nessus-id-296193-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707292/sicherheitsluecken/cve-2024-27053-linux-kernel-up-to-681-wilc1000-hifc-rcudereferencecheck-null-pointer-dereference-nessus-id-296193-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is the function <code>rcu_dereference_check</code> of the file <em>drivers/net/wireless/microchip/wilc1000/hif.c</em> of the component <em>wilc1000</em>. Such manipulation leads to null pointer dereference.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2024-27053">CVE-2024-27053</a>. The attack needs to be initiated within the local network. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27061 | Linux Kernel up to 6.6.23/6.7.11 Virtual Address sun8i_ce_cipher_unprepare null pointer dereference (dc60b25540c8/51a7d338c212/183420038444 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.6.23/6.7.11. It has been rated as critical. Affected by this issue is the function sun8i_ce_cipher_unprepare of the component Virtual Address Handler. The manipulation leads to null pointer dereference.

This vulnerability is listed as CVE-2024-27...]]></description>
<link>https://tsecurity.de/de/3707291/sicherheitsluecken/cve-2024-27061-linux-kernel-up-to-66236711-virtual-address-sun8icecipherunprepare-null-pointer-dereference-dc60b25540c851a7d338c212183420038444-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707291/sicherheitsluecken/cve-2024-27061-linux-kernel-up-to-66236711-virtual-address-sun8icecipherunprepare-null-pointer-dereference-dc60b25540c851a7d338c212183420038444-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.23/6.7.11</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is the function <code>sun8i_ce_cipher_unprepare</code> of the component <em>Virtual Address Handler</em>. The manipulation leads to null pointer dereference.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2024-27061">CVE-2024-27061</a>. The attack must be carried out from within the local network. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27388 | Linux Kernel up to 6.8.1 SUNRPC gssx_dec_option_array memory leak (Nessus ID 209785 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 6.8.1. This affects the function gssx_dec_option_array of the component SUNRPC. This manipulation causes memory leak.

This vulnerability appears as CVE-2024-27388. The attacker needs to be present on the local network. Th...]]></description>
<link>https://tsecurity.de/de/3707290/sicherheitsluecken/cve-2024-27388-linux-kernel-up-to-681-sunrpc-gssxdecoptionarray-memory-leak-nessus-id-209785-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707290/sicherheitsluecken/cve-2024-27388-linux-kernel-up-to-681-sunrpc-gssxdecoptionarray-memory-leak-nessus-id-209785-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.1</a>. This affects the function <code>gssx_dec_option_array</code> of the component <em>SUNRPC</em>. This manipulation causes memory leak.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2024-27388">CVE-2024-27388</a>. The attacker needs to be present on the local network. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27058 | Linux Kernel up to 6.6.23/6.7.11/6.8.2/6.9-rc1 shmem_release_dquot denial of service (WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Linux Kernel up to 6.6.23/6.7.11/6.8.2/6.9-rc1. Affected by this vulnerability is the function shmem_release_dquot. The manipulation leads to denial of service.

This vulnerability is documented as CVE-2024-27058. The attack requires ...]]></description>
<link>https://tsecurity.de/de/3707289/sicherheitsluecken/cve-2024-27058-linux-kernel-up-to-6623671168269-rc1-shmemreleasedquot-denial-of-service-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707289/sicherheitsluecken/cve-2024-27058-linux-kernel-up-to-6623671168269-rc1-shmemreleasedquot-denial-of-service-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.23/6.7.11/6.8.2/6.9-rc1</a>. Affected by this vulnerability is the function <code>shmem_release_dquot</code>. The manipulation leads to denial of service.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2024-27058">CVE-2024-27058</a>. The attack requires being on the local network. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27073 | Linux Kernel up to 6.8.1 ttpci budget_av_attach memory leak (Nessus ID 246830 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Linux Kernel up to 6.8.1. Affected by this issue is the function budget_av_attach of the component ttpci. This manipulation causes memory leak.

This vulnerability is handled as CVE-2024-27073. The attack can only be done within the local n...]]></description>
<link>https://tsecurity.de/de/3707288/sicherheitsluecken/cve-2024-27073-linux-kernel-up-to-681-ttpci-budgetavattach-memory-leak-nessus-id-246830-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707288/sicherheitsluecken/cve-2024-27073-linux-kernel-up-to-681-ttpci-budgetavattach-memory-leak-nessus-id-246830-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.1</a>. Affected by this issue is the function <code>budget_av_attach</code> of the component <em>ttpci</em>. This manipulation causes memory leak.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2024-27073">CVE-2024-27073</a>. The attack can only be done within the local network. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27070 | Linux Kernel up to 6.8.1 lib/dump_stack.c f2fs_filemap_fault use after free (8186e16a766d/eb70d5a6c932 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 6.8.1. Affected is the function f2fs_filemap_fault in the library lib/dump_stack.c. The manipulation leads to use after free.

This vulnerability is traded as CVE-2024-27070. Access to the local network is required for thi...]]></description>
<link>https://tsecurity.de/de/3707287/sicherheitsluecken/cve-2024-27070-linux-kernel-up-to-681-libdumpstackc-f2fsfilemapfault-use-after-free-8186e16a766deb70d5a6c932-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707287/sicherheitsluecken/cve-2024-27070-linux-kernel-up-to-681-libdumpstackc-f2fsfilemapfault-use-after-free-8186e16a766deb70d5a6c932-wid-sec-2024-1008/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.1</a>. Affected is the function <code>f2fs_filemap_fault</code> in the library <em>lib/dump_stack.c</em>. The manipulation leads to use after free.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2024-27070">CVE-2024-27070</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64576 | Linux Kernel up to 7.2-rc4 nexthop net/ipv4/nexthop.c nh_res_bucket_migrate extack uninitialized variable (Nessus ID 332760)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc4. Affected is the function nh_res_bucket_migrate of the file net/ipv4/nexthop.c of the component nexthop. Performing a manipulation of the argument extack results in ...]]></description>
<link>https://tsecurity.de/de/3707286/sicherheitsluecken/cve-2026-64576-linux-kernel-up-to-72-rc4-nexthop-netipv4nexthopc-nhresbucketmigrate-extack-uninitialized-variable-nessus-id-332760/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707286/sicherheitsluecken/cve-2026-64576-linux-kernel-up-to-72-rc4-nexthop-netipv4nexthopc-nhresbucketmigrate-extack-uninitialized-variable-nessus-id-332760/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">very critical</a>, has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc4</a>. Affected is the function <code>nh_res_bucket_migrate</code> of the file <em>net/ipv4/nexthop.c</em> of the component <em>nexthop</em>. Performing a manipulation of the argument <em>extack</em> results in use of uninitialized variable.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-64576">CVE-2026-64576</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-66758 | Red Hat Enterprise Linux file-fits plugin integer overflow (Nessus ID 332755)]]></title>
<description><![CDATA[A vulnerability was found in Red Hat Enterprise Linux and classified as very critical. Affected by this vulnerability is an unknown functionality of the component file-fits plugin. Executing a manipulation can lead to integer overflow.

This vulnerability appears as CVE-2026-66758. The attack may...]]></description>
<link>https://tsecurity.de/de/3707285/sicherheitsluecken/cve-2026-66758-red-hat-enterprise-linux-file-fits-plugin-integer-overflow-nessus-id-332755/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707285/sicherheitsluecken/cve-2026-66758-red-hat-enterprise-linux-file-fits-plugin-integer-overflow-nessus-id-332755/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a> and classified as <a href="https://vuldb.com/kb/risk">very critical</a>. Affected by this vulnerability is an unknown functionality of the component <em>file-fits plugin</em>. Executing a manipulation can lead to integer overflow.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-66758">CVE-2026-66758</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-66759 | Red Hat Enterprise Linux ICNS image icns_decompress out-of-bounds (Nessus ID 332755)]]></title>
<description><![CDATA[A vulnerability has been found in Red Hat Enterprise Linux and classified as critical. Affected is the function icns_decompress of the component ICNS image Handler. Performing a manipulation results in out-of-bounds read.

This vulnerability is reported as CVE-2026-66759. The attack is possible t...]]></description>
<link>https://tsecurity.de/de/3707284/sicherheitsluecken/cve-2026-66759-red-hat-enterprise-linux-icns-image-icnsdecompress-out-of-bounds-nessus-id-332755/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707284/sicherheitsluecken/cve-2026-66759-red-hat-enterprise-linux-icns-image-icnsdecompress-out-of-bounds-nessus-id-332755/</guid>
<pubDate>Thu, 06 Aug 2026 06:27:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is the function <code>icns_decompress</code> of the component <em>ICNS image Handler</em>. Performing a manipulation results in out-of-bounds read.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-66759">CVE-2026-66759</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Entwickler sich mit KI versündigen]]></title>
<description><![CDATA[>Im nächtlichen Schein der IDE suhlt sich mancher Dev im KI-Sündenpfuhl.Kateryna Reka | shutterstock.com



Die Normen der Softwareentwicklung sind weiterhin gültig. Zumindest offiziell sind robuste CI/CD-Pipelines, elegante Architekturmuster und wartbarer Code nach wie vor gesetzt.



Wenn wir u...]]></description>
<link>https://tsecurity.de/de/3707283/it-security-nachrichten/wie-entwickler-sich-mit-ki-versuendigen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707283/it-security-nachrichten/wie-entwickler-sich-mit-ki-versuendigen/</guid>
<pubDate>Thu, 06 Aug 2026 06:23:33 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Im nächtlichen Schein der IDE suhlt sich mancher Dev im KI-Sündenpfuhl.</figcaption></figure><p class="imageCredit">Kateryna Reka | shutterstock.com</p></div>



<p class="wp-block-paragraph">Die Normen der <a href="https://www.computerwoche.de/article/3963767/die-grosten-paradoxa-der-softwareentwicklung.html" target="_blank">Softwareentwicklung</a> sind weiterhin gültig. Zumindest offiziell sind robuste CI/CD-Pipelines, elegante Architekturmuster und wartbarer Code nach wie vor gesetzt.</p>



<p class="wp-block-paragraph">Wenn wir unbeobachtet sind, zeigt sich dann in vielen Fällen die Realität: Wir hängen wie entrückte Magier mit manischem Glanz in den Augen über unseren Konsolen und beschwören Modelle und Agenten, um uns voll und ganz dem KI-Rausch hinzugeben.</p>



<p class="wp-block-paragraph">Dabei begehen wir nicht selten Development-Sünden, die <a href="https://de.wikipedia.org/wiki/Frederick_P._Brooks" target="_blank" rel="noreferrer noopener">Fred Brooks</a> die Schamesröte ins Gesicht getrieben hätten. So wie die folgenden sieben. Vorsicht, Ironie – stellenweise.</p>



<h2 class="wp-block-heading">1. Grundlagenwissen für überflüssig halten</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2829721/objektorientierte-programmierung-erklaert.html" target="_blank">Objektorientierte</a> oder <a href="https://www.infoworld.com/article/2263963/what-is-functional-programming-a-practical-guide.html" target="_blank">funktionale Programmierung</a>? <a href="https://de.wikipedia.org/wiki/CAP-Theorem" target="_blank" rel="noreferrer noopener">CAP-Theorem</a>? <a href="https://de.wikipedia.org/wiki/Don%E2%80%99t_repeat_yourself" target="_blank" rel="noreferrer noopener">DRY</a>-Prinzip? Design-Pattern? Können Sie vergessen. Ebenso Frameworks, Runtimes und Deployment-Plattformen.</p>



<p class="wp-block-paragraph">Die KI weiß schließlich ganz genau, was bereits vorhanden ist und welche Tools zu nutzen sind. So haben wir als Entwickler auch mehr mentale Bandbreite, um uns Nebenprojekten zu widmen. Zum Beispiel einem Roman über die KI-Weltherrschaft.</p>



<h2 class="wp-block-heading">2. Dokumentationen links liegen lassen</h2>



<p class="wp-block-paragraph">„<a href="https://de.wikipedia.org/wiki/RTFM" target="_blank" rel="noreferrer noopener">RTFM</a>“ nutzen viele Developer auch heutzutage noch gerne – auch wenn sie selbst eigentlich seit 2023 keine einzige Seite einer Anbieter-Dokumentation mehr gelesen haben. Löst ein Package eine bizarre Exception aus, wird weder der Execution-Pfad überprüft noch erfolgt ein Blick in die Release Notes. Stattdessen werden alle 200 Zeilen des Stack-Trace kopiert und in eine KI geworfen – in der Erwartung, dass diese uns dann löffelweise mit der Lösung füttert.</p>



<p class="wp-block-paragraph">Oder es wird direkt eine <a href="https://www.cowo.de/a/4199997" target="_blank" rel="noreferrer noopener">ADE</a> auf den Fehler angesetzt. Die findet den Fehler und fragt uns dann nur noch, ob die Lösung so korrekt ist. Manche werfen dann eventuell einen Blick auf die Beschreibung dieser Lösung – insofern sie die KI nicht vorher schon auf „Auto-Confirm“ umgestellt haben.</p>



<p class="wp-block-paragraph">So werden wir zu glorifizierten Copy-Paste-Orchestratoren – die einfach nur darauf hoffen, dass der stochastische Papagei hinter dem Prompt die Syntax richtig errät.</p>



<h2 class="wp-block-heading">3. Backend-Struktur ignorieren</h2>



<p class="wp-block-paragraph">KI-berauschte Devs geben manchmal vor, Datenflüsse akribisch designt, relationale Einschränkungen sorgfältig ausgearbeitet und <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">API</a>-Beziehungsgeflechte gewissenhaft abgebildet zu haben. Auch wenn wir eigentlich nur die KI angewiesen haben, ein modernes Deployment-Gerüst zu bauen und dieses mit einer Backend-<a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">Datenbank</a> zu verknüpfen.   </p>



<p class="wp-block-paragraph">Dabei wurden Security-Regeln und Schemata erstellt, die wir unter Umständen nicht vollständig verstehen. Aber solange es funktional aussieht, wird es schon gut gehen. Eventuell wurden auch Infrastructure-as-Code-Skripte generiert, die Cloud-Ressourcen bereitstellen. Sicher wird sich jemand anderes darum kümmern, dass das kein Loch ins Budget frisst. Wahrscheinlich, indem er die Metriken in einen anderen Chatbot einspeist.</p>



<p class="wp-block-paragraph">Ist aber auch egal, weil das Mittagessen wartet.</p>



<h2 class="wp-block-heading">4. Inzestuöses Testing fördern</h2>



<p class="wp-block-paragraph">Test-driven Development war immer schon ein schöner Traum, der – wenn man ihn lebt – in Dependency-Wildwuchs <a href="https://grugbrain.dev/#grug-on-testing" target="_blank" rel="noreferrer noopener">ausarten kann</a>. Es ist also eine super Sache, dass wir heutzutage mit KI fast mühelos eine Testabdeckung von 95 Prozent erreichen können. Warum sollten wir die Maschine das nicht direkt mit übernehmen lassen, wenn sie auch alles andere automatisiert erstellt?</p>



<p class="wp-block-paragraph">So kann man auch jedem der es wissen will (oder der gerade keine Fluchtmöglichkeit hat), das Narrativ von der erstaunlichen Testabdeckung unter die Nase reiben und sich in ausgiebigen Schwärmereien über die automatisierte Qualitätssicherung ergehen. Was dabei geflissentlich verschwiegen wird: Die komplexe Anwendungslogik und die Testsuite wurden von derselben KI generiert. Diese validiert also genau den Code, den sie zuvor zusammengeschustert hat.</p>



<p class="wp-block-paragraph">Daraus entsteht ein hermetisch abgeriegelter Kreislauf der algorithmischen Selbstbeweihräucherung: Die Mocks, Randfälle und Assertions werden zur Echokammer für die ursprünglichen Annahmen des KI-Modells. Die Maschine benotet also ihre eigenen Hausaufgaben und gibt sich dafür eine Eins mit Sternchen.</p>



<p class="wp-block-paragraph">Das wird von einigen von uns allerdings gerne in Kauf genommen, denn wenn der Code verändert werden muss, zaubert die KI auch dafür mühelos neue Tests aus dem Hut.</p>



<h2 class="wp-block-heading">5. KI-Ergebnisse als Strategie ausgeben</h2>



<p class="wp-block-paragraph">Dokumente zu designen, kann KI erstaunlich gut: Diese sind meist apart formatiert, wirken schlüssig und schlagen nahtlos die Brücke zwischen übergeordneten Geschäftszielen und detaillierten technischen Specs. Und: Sie enthalten auch die tollen Sequenz-Diagramme, die das Management so schätzt.</p>



<p class="wp-block-paragraph">Architekturvorschläge, die auf diese Art und Weise entstanden sind, werden regelmäßig in Sprint-Planungs-Meetings präsentiert – und kommen beim Rest des Teams oft gut an. Schließlich weiß auch niemand, dass in den hochgelobten Vorschlag ungefähr vier Sekunden „Mühe“ investiert wurden.</p>



<p class="wp-block-paragraph">Ignoriert wird dabei, dass solche KI-generierten Dokumente gleichermaßen anfällig für fatale Mängel in Bezug auf Scope und Alignment sind, wie von Menschenhand gemachte. Aber wenn das Projekt schon scheitert, war wenigstens das <a href="https://www.computerwoche.de/article/3995075/was-ist-markdown.html" target="_blank">Markdown</a> schön klar und die Bulletpoints echt überzeugend. Das wahre Ausmaß des folgenden Desasters wird zwar erst erkannt, wenn es schon viel zu spät ist – aber immerhin war der Ansatz visionär.</p>



<h2 class="wp-block-heading">6. Heimlich dem Vibe Coding verfallen</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/4034385/9-wege-mit-vibe-coding-zu-scheitern.html" target="_blank">Vibe Coding</a> ist unter Devs in sozialen Kanälen regelmäßig eine Lachnummer. Und auch in Slack-Channels werden regelmäßige augenrollende Emojis verschickt, wenn es um das Thema geht. Nach außen möchten wir alle möglichst professionell wirken.</p>



<p class="wp-block-paragraph">Wenn niemand zusieht, wird dann unter Umständen aber doch der heimlichen Vibe-Coding-Leidenschaft gefröhnt: Unausgereifte Gedanken und ein Drink, sind alles was man braucht, um entspannt dabei zusehen zu können, wie die KI ihre “Coding-Magie” entfaltet.</p>



<p class="wp-block-paragraph">Daraus entsteht dann vielleicht endlich ein funktionierender <a href="https://de.wikipedia.org/wiki/Ultima_(Computerspielreihe)" target="_blank" rel="noreferrer noopener">Ultima-V</a>-Klon oder eine App, um Krypto-Protfolios zu tracken, die nach dem Interface aus „<a href="https://de.wikipedia.org/wiki/Neuromancer-Trilogie" target="_blank" rel="noreferrer noopener">Neuromancer</a>“ aussieht. Und zwar in 30 Sekunden. Das berauscht. Und kann süchtig machen. Leider ganz besonders, wenn man tief in der harten, altmodischen Realität des Programmierhandwerks verwurzelt ist.</p>



<h2 class="wp-block-heading">7. Prompts als Allheilmittel betrachten</h2>



<p class="wp-block-paragraph">Ahnlich wie die Figur von Adam Sandler in „<a href="https://www.imdb.com/de/title/tt5727208/" target="_blank" rel="noreferrer noopener">Der schwarze Diamant</a>“ sind manche Devs davon überzeugt, dass mit der nächsten Runde alles besser wird – nur bezogen auf Prompts. Wenn die Dinge aus dem Ruder laufen, bevorzugen diese regelmäßig, den KI-Prompt zu verfeinern – statt sich selbst dem Komplexitätsdickicht zu widmen.</p>



<p class="wp-block-paragraph">Der gleiche fehlerbehaftete Stack Trace wird dann unerbittlich immer und immer wieder in den Chat gehämmert, das Modell auf einen immer schmaleren Pfad gezwungen – solange, bis der Code endlich keine Fehler mehr ausgibt. Debugging und Variablen-Tracing sind so gut wie nicht mehr existent, Funktionen werden nicht mehr schrittweise geprüft. Stattdessen wird unermüdlich iterativer Druck auf die KI ausgeübt, bis diese kapituliert. Und dann geht’s ab in die Produktion.</p>



<p class="wp-block-paragraph">So fließt am Ende ähnlich viel Zeit und Energie in den Kampf mit dem Bot, wie früher in die manuelle Syntaxerstellung. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4199668/seven-sins-of-the-modern-software-developer.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake-IT-Mitarbeiter: Wie CIOs den Betrug erkennen]]></title>
<description><![CDATA[Die Struktur des Betrugs ist arbeitsteilig. IT-Fachkräfte, Rekruter, Mittelsleute und lokale Helfer suchen gezielt Opfer und erschaffen die Illusion einer Persona.chingyunsong – shutterstock.com



Ein Freelance-Entwickler präsentiert sich mit tadellosem Lebenslauf, sauberem Portfolio und überzeu...]]></description>
<link>https://tsecurity.de/de/3707282/it-security-nachrichten/fake-it-mitarbeiter-wie-cios-den-betrug-erkennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707282/it-security-nachrichten/fake-it-mitarbeiter-wie-cios-den-betrug-erkennen/</guid>
<pubDate>Thu, 06 Aug 2026 06:23:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img width="400px" loading="lazy" src="https://images.cio.de/bdb/3357522/original.jpg?quality=50&amp;strip=all" alt="Anonymer Computer-Hacker mit weißer Maske, 16:9, slider" class="wp-image-3637825"><figcaption class="wp-element-caption">Die Struktur des Betrugs ist arbeitsteilig. IT-Fachkräfte, Rekruter, Mittelsleute und lokale Helfer suchen gezielt Opfer und erschaffen die Illusion einer Persona.</figcaption></figure><p class="imageCredit">chingyunsong – shutterstock.com</p></div>



<p class="wp-block-paragraph">Ein Freelance-Entwickler präsentiert sich mit tadellosem Lebenslauf, sauberem Portfolio und überzeugendem Video-Interview. Trotzdem sitzt am anderen Ende kein einzelner Kandidat, sondern ein Glied in einem staatlich gelenkten Betrugsnetzwerk. Was nach Spionagefilm klingt, hat sich zu einem konkreten Insider-Risiko für Unternehmen entwickelt.</p>



<p class="wp-block-paragraph">Seit Jahren schleusen nordkoreanische Netzwerke IT-Fachkräfte mit falschen, gestohlenen oder geliehenen Identitäten in westliche Unternehmen ein, meist als Remote-Freelancer für Softwareentwicklung, Datenbanken, Cloud-Administration oder App-Projekte. Behörden sprechen von Tausenden weltweit eingesetzten Arbeitskräften.</p>



<p class="wp-block-paragraph">Wie groß einzelne Netzwerke werden können, zeigen inzwischen abgeschlossene Strafverfahren: In einem Fall wurden 309 US-Unternehmen und zwei internationale Firmen getäuscht; das Netzwerk erwirtschaftete mehr als 17 Millionen US-Dollar. Im April 2026 wurden zwei weitere Helfer verurteilt, deren Struktur mit gestohlenen Identitäten Jobs bei mehr als 100 Unternehmen erlangte und über fünf Millionen US-Dollar einnahm.</p>



<p class="wp-block-paragraph">Für CIOs ist das kein akademisches Risiko. Wer regulär eingestellt wurde, erhält reguläre Zugangsdaten und damit unter Umständen Zugriff auf Quellcode, Kundendaten, Entwicklungsumgebungen oder interne Wissensbestände. Genau das macht den Fall gefährlich: Technisch sieht der Zugriff zunächst legitim aus, obwohl Identität, Standort und Zweck der Tätigkeit falsch sein können.</p>



<h2 class="wp-block-heading">Wie das Schema funktioniert</h2>



<p class="wp-block-paragraph">Die Struktur ist arbeitsteilig. IT-Fachkräfte übernehmen die eigentliche Projektarbeit. Rekruter suchen passende Stellen, Mittelsleute beschaffen Identitäten und Konten, andere Personen treten in Interviews auf oder wickeln Verträge und Zahlungen ab. Hinzu kommen lokale Helfer, die Firmenhardware entgegennehmen. Ein Unternehmen kann daher im Bewerbungsgespräch, beim Versand des <a href="https://www.eizo.de/7-jahre-garantie?utm_campaign=26F_BP&amp;utm_medium=intext&amp;utm_source=foundry" target="_blank" rel="noreferrer noopener">Laptops</a> und während der täglichen Zusammenarbeit jeweils mit einer anderen Person oder Rolle aus demselben Netzwerk interagieren.</p>



<p class="wp-block-paragraph">Eine Schlüsselrolle spielen sogenannte <a href="https://www.eizo.de/7-jahre-garantie?utm_campaign=26F_BP&amp;utm_medium=intext&amp;utm_source=foundry" target="_blank" rel="noreferrer noopener">Laptop</a> Farms. Firmenrechner stehen physisch im Land des vermeintlichen Mitarbeiters, werden aber über Fernwartungssoftware oder KVM-Technik (Kernel-based Virtual Machine) aus dem Ausland bedient. Für einfache Standortkontrollen wirkt der Zugriff damit lokal. Gleichzeitig helfen Scheinfirmen, Zahlungsaccounts, Profile auf Jobplattformen und professionell gestaltete Portfolios dabei, die erfundene Biografie konsistent erscheinen zu lassen.</p>



<p class="wp-block-paragraph">Generative KI erhöht die Qualität und Geschwindigkeit dieser Täuschung. Microsoft hat unter anderem KI-bearbeitete Profilbilder, verbesserte Bewerbungsunterlagen und den Einsatz von Stimmveränderungssoftware beobachtet. Ein fehlerfreier Lebenslauf oder ein plausibles Profil ist deshalb kein belastbarer Identitätsnachweis mehr.</p>



<h2 class="wp-block-heading">Warum klassische Prüfungen zu kurz greifen</h2>



<p class="wp-block-paragraph">Ein einmaliger, dokumentenbasierter Background-Check kann bei dieser Betrugsform ins Leere laufen. Er bestätigt im besten Fall, dass die vorgelegten Daten zu einer realen Identität passen. Der Check beantwortet aber nicht automatisch, ob diese Identität der Person im Interview gehört, ob später dieselbe Person arbeitet oder ob dieselben Kontaktdaten bereits in anderen Bewerbungen aufgetaucht sind. Identitätsprüfung muss deshalb als Prozess gedacht werden: vom Recruiting über das Onboarding bis zu risikobasierten Kontrollen während der Beschäftigung.</p>



<p class="wp-block-paragraph">Zusätzliche Blindstellen entstehen bei <a href="https://open.spotify.com/episode/52T9nVRnIb9XJTWYGXuyPE?si=19a074eb33e047cb&amp;utm_source=IT" target="_blank" rel="noreferrer noopener">externen</a> Entwicklern und Personaldienstleistern. Wer das Recruiting an einen Dritten auslagert, gibt damit nicht die Verantwortung für den Systemzugang ab. Unternehmen sollten vertraglich und operativ sicherstellen, dass Dienstleister vergleichbare Prüfstandards anwenden und relevante Auffälligkeiten melden.</p>



<h2 class="wp-block-heading">Warnsignale im Bewerbungsprozess</h2>



<p class="wp-block-paragraph">Behörden und Sicherheitsforscher beschreiben wiederkehrende Muster. Kein einzelnes Merkmal beweist einen Betrug; entscheidend ist die Kombination mehrerer voneinander unabhängiger Signale:</p>



<ul class="wp-block-list">
<li>Kontaktdaten, hier besonders VoIP-Nummern, E-Mail-Adressen oder Zahlungsinformationen, tauchen bei mehreren angeblich unabhängigen Bewerbungen identisch auf.</li>



<li>Lebenslauf, Portfolio und öffentliches Profil passen zeitlich oder inhaltlich nicht zusammen; ganze Textpassagen oder Arbeitsproben finden sich bei anderen Personen wieder.</li>



<li>Der Kandidat weicht einem stabilen Video-Interview aus, Bild und Stimme wirken wiederholt asynchron oder die Person im späteren Arbeitsalltag unterscheidet sich auffällig vom Interview.</li>



<li>Antworten zum aktuellen Standort, zu Ausbildung oder früheren Projekten bleiben trotz fachlicher Nachfragen ungewöhnlich vage oder widersprüchlich.</li>



<li>Kurz vor oder nach Vertragsstart ändern sich Lieferadresse, Bankverbindung oder Zahlungsplattform; Hardware soll an eine andere als die verifizierte Adresse gehen.</li>



<li>Der Kandidat drängt auf einen sehr schnellen Start, fordert weitreichende Rechte vor Abschluss der Prüfungen oder bevorzugt ungewöhnliche Zahlungswege.</li>
</ul>



<h2 class="wp-block-heading">Warnsignale nach dem ersten Arbeitstag</h2>



<p class="wp-block-paragraph">Mit der Einstellung endet die Prüfung nicht. Technische Indikatoren können zeigen, dass der Firmenrechner nur als Zwischenstation dient oder dass mehrere Personen ein Konto nutzen:</p>



<ul class="wp-block-list">
<li>Mehrere Anmeldungen desselben Kontos aus weit auseinanderliegenden Ländern oder IP-Bereichen innerhalb kurzer Zeit.</li>



<li>Nicht genehmigte Fernwartungs- oder Remote-Desktop-Software, auffällige KVM-Geräte sowie Versuche, lokale Administratorrechte zu erhalten.</li>



<li>Ungewöhnliche Browser-Sitzungen, wechselnde Gerätefingerabdrücke oder Arbeitsaktivität, die dauerhaft nicht zum angegebenen Standort und zur Zeitzone passt.</li>



<li>Großflächiges Kopieren von Quellcode oder Dokumenten in private Cloudspeicher, persönliche Repositories oder nicht freigegebene Filesharing-Dienste.</li>



<li>Mehrere parallele Audio- oder Videoverbindungen und wiederkehrende Probleme, die darauf hindeuten, dass Meetings durch Dritte unterstützt werden.</li>
</ul>



<p class="wp-block-paragraph">Auch hier gilt: VPN-Nutzung, Remote-Tools oder ein ungewöhnlicher Arbeitsrhythmus sind für sich genommen kein Beweis. Sie werden erst im Zusammenhang mit Auffälligkeiten aus Recruiting, Hardwareversand und Zahlungsdaten aussagekräftig.</p>



<h2 class="wp-block-heading">Warum der Schaden weit über das Gehalt hinausgeht</h2>



<p class="wp-block-paragraph">Die erste Motivation ist häufig die Einnahme regulärer Gehälter. Doch aus dem legitimen Zugang kann ein zweites Geschäftsmodell entstehen. Das FBI warnt vor dem Abfluss proprietärer Daten und Quellcode sowie vor Erpressung nach der Enttarnung.</p>



<p class="wp-block-paragraph">Hinzu kommen Kosten für Forensik, Rechtsberatung, Wiederherstellung von Systemen und mögliche Meldepflichten. Bei sensiblen Technologien können außerdem Exportkontrollen, Sanktionen und vertragliche Geheimhaltungspflichten berührt sein.</p>



<h2 class="wp-block-heading">Was CIOs konkret tun können</h2>



<p class="wp-block-paragraph">Wirksam ist kein einzelnes Tool, sondern ein Kontrollmodell, das HR, <a href="https://open.spotify.com/episode/52T9nVRnIb9XJTWYGXuyPE?si=19a074eb33e047cb&amp;utm_source=IT" target="_blank" rel="noreferrer noopener">IT</a>, Security, Einkauf und Compliance verbindet. Fünf Maßnahmen reduzieren das Risiko deutlich:</p>



<ul class="wp-block-list">
<li><strong>Rollen nach Risiko staffeln. </strong>Für Tätigkeiten mit Zugriff auf Quellcode, Produktionssysteme, Forschungsdaten oder privilegierte Konten gelten stärkere Prüf- und Freigabeschritte als für risikoarme Rollen.</li>



<li><strong>Identität mehrfach verifizieren. </strong>Dokumente, Kontaktangaben, Ausbildung und frühere Beschäftigung werden über unabhängige Quellen geprüft. Bei Remote-Rollen sollte die Identität beim Interview, beim Onboarding und bei begründetem Anlass erneut bestätigt werden.</li>



<li><strong>Hardware und Zahlungen kontrollieren. </strong>Firmenrechner gehen nur an die verifizierte Adresse. Änderungen von Lieferort, Bankverbindung oder Zahlungsplattform lösen eine erneute Prüfung aus. Systemzugänge werden erst nach Abschluss der vorgesehenen Kontrollen freigeschaltet.</li>



<li><strong>Least Privilege technisch durchsetzen. </strong>Neue Mitarbeitende erhalten zunächst nur die Rechte, die sie tatsächlich benötigen. Nicht freigegebene Fernwartungssoftware wird blockiert; Identitäts-, Endpoint- und Cloud-Logs werden risikobasiert auf ungewöhnliche Muster geprüft.</li>



<li><strong>Dienstleister und Eskalation einbeziehen. </strong>Für Freelancer und Staffing-Partner gelten dieselben Mindeststandards. Ein gemeinsamer Eskalationsweg legt fest, wer bei Auffälligkeiten entscheidet, Beweise sichert und Zugriffe begrenzt.</li>
</ul>



<p class="wp-block-paragraph">Für Unternehmen in Deutschland, Österreich und der Schweiz muss dieses Vorgehen verhältnismäßig und datenschutzkonform ausgestaltet sein. Ziel ist nicht die möglichst umfassende Sammlung von Personendaten, sondern die nachvollziehbare Prüfung relevanter Risiken für eine konkrete Rolle, mit klaren Kriterien, begrenzten Aufbewahrungsfristen und menschlicher Bewertung von Treffern.</p>



<h2 class="wp-block-heading">Wenn sich der Verdacht erhärtet</h2>



<p class="wp-block-paragraph">Ein Verdachtsfall gehört nicht allein ins Recruiting. HR, Security, Legal beziehungsweise Datenschutz und gegebenenfalls Compliance sollten koordiniert vorgehen. Dazu gehören die Sicherung relevanter Protokolle, die kontrollierte Begrenzung von Zugängen, der Wechsel exponierter Schlüssel oder Tokens und die Prüfung, ob Daten in private Repositories oder Cloudkonten abgeflossen sind.</p>



<p class="wp-block-paragraph">Welche Behörden oder Vertragspartner informiert werden müssen, hängt vom Sitz des Unternehmens, den betroffenen Daten und regulatorischen Pflichten ab. Entscheidend ist ein vorbereiteter Incident-Plan, nicht eine improvisierte Konfrontation.</p>



<p class="wp-block-paragraph">Wer sensible Systeme oder Daten verantwortet, kommt an dieser Form von Personalrisiko nicht mehr vorbei. Die Fälle zeigen: Cybersicherheit beginnt nicht erst an der Firewall. Sie beginnt dort, wo eine digitale Identität erstmals Vertrauen, <a href="https://www.eizo.de/7-jahre-garantie?utm_campaign=26F_BP&amp;utm_medium=intext&amp;utm_source=foundry" target="_blank" rel="noreferrer noopener">Hardware</a> und Zugriffsrechte erhält und sie endet nicht mit dem ersten Arbeitstag. (jd)</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 peinliche Fehler im Bewerbungsgespräch]]></title>
<description><![CDATA[sirtravelalot – shutterstock.com



Einen peinlichen Moment im Arbeitsleben hat sicher jeder schon einmal erlebt. Vielleicht hat man sich durch eine sehr wichtige Präsentation gestammelt oder auf einer Unternehmensfeier lautstark ein volles Glas umgeworfen und mit der verschütteten Flüssigkeit im...]]></description>
<link>https://tsecurity.de/de/3707281/it-security-nachrichten/8-peinliche-fehler-im-bewerbungsgespraech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707281/it-security-nachrichten/8-peinliche-fehler-im-bewerbungsgespraech/</guid>
<pubDate>Thu, 06 Aug 2026 06:22:32 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-30-um-20.15.44.png?w=1024" alt="Bewerbungsgespräch" class="wp-image-4203616" width="1024" height="607" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">sirtravelalot – shutterstock.com</p></div>



<p class="wp-block-paragraph">Einen peinlichen Moment im Arbeitsleben hat sicher jeder schon einmal erlebt. Vielleicht hat man sich durch eine sehr wichtige Präsentation gestammelt oder auf einer Unternehmensfeier lautstark ein volles Glas umgeworfen und mit der verschütteten Flüssigkeit im schlimmsten Fall auch noch einen Kollegen getroffen. Besonders schwer wiegen peinliche Fehler dann, wenn man den Wunschjob noch nicht einmal in der Tasche hat. Gerade beim Bewerbungsgespräch kommt es darauf an, einen starken ersten Eindruck zu hinterlassen.</p>



<p class="wp-block-paragraph">Das Online-Karriereportal Careerbuilder hat mehr als 3.000 Arbeitgeber und Personal-Experten sechs häufige Fehler im Bewerbungsgespräch danach bewerten lassen, wie sehr sie dem Kandidaten schaden. Den größten Fehler begehen Kandidaten dann, wenn sie im Gespräch ein Handygespräch annehmen oder eine SMS schreiben, 77 Prozent der Umfrage-Teilnehmer stören sich an diesem Verhalten. Das zweitschlimmste Vergehen ist es, kein Interesse an der ausgeschriebenen Stelle zu zeigen (75 Prozent), das drittschlimmste, sich unangemessen zu kleiden (72 Prozent).</p>



<p class="wp-block-paragraph">Auf Rang vier der schlimmsten Fehler in Bewerbungsgesprächen liegt arrogantes Auftreten, daran stören sich 72 Prozent der befragten Personal-Experten. 67 Prozent der Personaler stören sich daran, wenn ein Bewerber im Gespräch schlecht über den jetzigen oder über frühere Arbeitgeber spricht. Für 63 Prozent der Umfrageteilnehmer ist es ein schlimmes Vergehen, wenn ein Kandidat im Bewerbungsgespräch Kaugummi kaut.</p>



<p class="wp-block-paragraph">Darüber hinaus befragte Careerbuilder die Personal-Experten nach ihren <strong>ungewöhnlichsten Erlebnissen bei Bewerbungsgesprächen</strong>. Die Umfrageteilnehmer berichteten von den folgenden Gesprächssituationen:</p>



<ul class="wp-block-list">
<li>1. Ein Kandidat brachte einen Bewerbungsratgeber zum Gespräch mit.</li>



<li>2. Ein anderer Bewerber fragte: “Wie heißt ihr Unternehmen noch mal?”</li>



<li>3. Bei einem <a href="https://cio.de/article/3663369/101-manieren-fuers-web-2-0.html" target="_blank">Telefoninterview</a> wurde ein Personaler von der Kandidatin in die Warteschleife gestellt. Als die Kandidatin das Gespräch in die Leitung zurückholte, erzählte sie, sie hätte sich in der Zwischenzeit für Freitag für ein Date verabredet.</li>



<li>4. Ein Bewerber trug zum Bewerbungsgespräch eine Pfadfinderuniform und erklärte im Laufe des Gesprächs nicht, weshalb er das tat.</li>



<li>5. Ein Kandidat sprach während des gesamten Bewerbungsgesprächs von sich in der dritten Person.</li>



<li>6. Ein anderer Bewerber zog sich während des Jobinterviews seine Schuhe aus.</li>



<li>7. Ein Bewerber fragte, ob er einen Schluck vom Kaffee des Personalers trinken dürfe.</li>



<li>8. Und schließlich berichtet ein Personaler von einer Kandidatin, die im Gespräch sagte, sie sei sich nicht sicher, ob der angebotene Job es wert sei, dafür das Auto zu starten.</li>
</ul>



<h2 class="wp-block-heading">3 Tipps für ein erfolgreiches Bewerbungsgespräch</h2>



<p class="wp-block-paragraph">“Man mag ja denken, dass ein Bewerber nie und nimmer während eines Jobinterviews einen Anruf annehmen würde, aber wir hören diese Geschichten immer wieder, wenn wir mit Personalern sprechen”, sagt Rosemary Haefner von Careerbuilder. Bei der Masse der <a href="https://www.cio.de/careers/">Bewerber</a> gehe es jedoch nicht darum, solche Fehler zu vermeiden sondern sich von den anderen Bewerbern abzuheben. Haefner gibt die folgenden Ratschläge für ein erfolgreiches Bewerbungsgespräch:</p>



<p class="wp-block-paragraph"><strong>1. Intensiv vorbereiten</strong>: Um auf Fragen zum Unternehmen souverän zu antworten, sollte man sich gut über den Wunscharbeitgeber informieren. Geeignete Quellen dafür sind die Selbstdarstellung auf der Unternehmenswebsite, aktuelle Pressemeldungen und die Vorstellung angebotener Produkte und Dienstleistungen.</p>



<p class="wp-block-paragraph"><strong>2. Optimistisch bleiben</strong>: Egal, wie die Stimmung im Bewerbungsgespräch auf einen wirkt. Haefner rät, positiv zu bleiben und auf keinen Fall schlecht über frühere Arbeitgeber zu sprechen.</p>



<p class="wp-block-paragraph"><strong>3. Beispiele und Ideen vorbereiten</strong>: Am besten überlegt man sich bereits vor dem Interview Anekdoten, die den eigenen Lebenslauf veranschaulichen und zum Beispiel erläutern, wie man in früheren Jobs mit herausfordernden Situationen umgegangen ist. Auch mit Ideen und Vorschlägen für den Wunschjob kann man aus der Masse der Bewerber hervorstechen.</p>



<p class="wp-block-paragraph">Das Online-Karriereportal Careerbuilder sprach für diese Umfrage mit mehr als 3.000 Arbeitgebern und Personal-Experten in den USA.</p>



<p class="wp-block-paragraph">Erzählen Sie mir von einem Vorgang, den Sie für andere dokumentiert haben.</p>



<p class="wp-block-paragraph">Die Antwort zeigt, wie wichtig dem Bewerber Teamwork ist und ob er sein Wissen anderen zugänglich macht.</p>



<p class="wp-block-paragraph">Erzählen Sie mir von einem ihrer bisherigen Projekte.</p>



<p class="wp-block-paragraph">Hier können Bewerber punkten, wenn sie auch auf Herausforderungen, komplexe Aufgaben und Einschränkungen eingehen.</p>



<p class="wp-block-paragraph">Was könnten Sie mir über Details zur Programmierung von … sagen?</p>



<p class="wp-block-paragraph">Die soll zeigen, ob ein Kandidat zu einer Wissenslücke steht oder blufft.</p>



<p class="wp-block-paragraph">Wie würden Sie dieses Thema einem Kollegen erläutern, der kein IT-Experte ist?</p>



<p class="wp-block-paragraph">Hier kann man zeigen, wieviel einem an einem guten Verhältnis von Business und <a href="https://open.spotify.com/episode/52T9nVRnIb9XJTWYGXuyPE?si=19a074eb33e047cb&amp;utm_source=IT" target="_blank" rel="noreferrer noopener">IT</a> liegt.</p>



<p class="wp-block-paragraph">Sie können ein Projekt entweder rechtzeitig und unvollständig oder vollständig, jedoch nach der Deadline, abschließen. Wofür entscheiden Sie sich?</p>



<p class="wp-block-paragraph">Eine gute Antwort wäre zum Beispiel, gemeinsam mit Projektleiter und Team nach der besten Lösung zu suchen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Überlebenstipps für CISOs, die an den CEO berichten]]></title>
<description><![CDATA[Wenn der CISO an den CEO berichtet, sollte Argwohn außen vor bleiben.YAKOBCHUK VIACHESLAV | shutterstock.com



Die Rolle des CISO wird für Unternehmen immer wichtiger. Deshalb nehmen Sicherheitschefs inzwischen immer öfter auch einen Platz am Entscheidertisch ein – und berichten direkt an den CE...]]></description>
<link>https://tsecurity.de/de/3707280/it-security-nachrichten/9-ueberlebenstipps-fuer-cisos-die-an-den-ceo-berichten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707280/it-security-nachrichten/9-ueberlebenstipps-fuer-cisos-die-an-den-ceo-berichten/</guid>
<pubDate>Thu, 06 Aug 2026 06:22:27 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/YAKOBCHUK-VIACHESLAV_shutterstock_1771877123_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="CISO CEO 16z9" class="wp-image-4204930" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn der CISO an den CEO berichtet, sollte Argwohn außen vor bleiben.</figcaption></figure><p class="imageCredit">YAKOBCHUK VIACHESLAV | shutterstock.com</p></div>



<p class="wp-block-paragraph">Die <a href="https://www.computerwoche.de/article/4199400/warum-der-ciso-der-neue-cfo-ist.html" target="_blank">Rolle des CISO</a> wird für Unternehmen immer wichtiger. Deshalb nehmen Sicherheitschefs inzwischen immer öfter auch einen Platz am Entscheidertisch ein – und berichten direkt an den CEO. In dieser Position soll der CISO vor allem dazu beitragen, die Unternehmensstrategie erfolgreich voranzutreiben.</p>



<p class="wp-block-paragraph">Mit dem direkten Berichtsweg zum CEO eröffnet sich für Security-Verantwortliche ein besserer, direkterer Zugang zur Unternehmensleitung, der potenziell auch ihre Einflussmöglichkeiten steigern kann. Das klingt auf den ersten Blick äußerst vorteilhaft. Doch direkt unter dem CEO zu operieren, heißt für CISOs aber auch, neue Perspektiven einnehmen, sich neue Skills aneignen und ihren <a href="https://www.computerwoche.de/article/3492322/cybersecurity-messen-10-kennzahlen-die-cisos-weiterbringen.html" target="_blank">KPI-Fokus</a> stärker auf das Business ausrichten zu müssen.</p>



<p class="wp-block-paragraph">Für diesen Artikel haben wir verschiedene Experten gefragt, wie Sicherheitsentscheider mit „direktem Draht“ zum CEO diese Beziehung optimal ausgestalten können. Nämlich:  </p>



<ul class="wp-block-list">
<li><a href="https://www.linkedin.com/in/georgegerchow/" target="_blank" rel="noreferrer noopener">George Gerchow</a>, Chief Security Officer bei Bedrock Data und Mitglied der IANS-Faculty,</li>



<li><a href="https://www.linkedin.com/in/mattchiodi/" target="_blank" rel="noreferrer noopener">Matt Chiodi</a>, Chief Security Officer bei Cerby,</li>



<li><a href="https://www.cyderes.com/company/about/chris-schueler" target="_blank" rel="noreferrer noopener">Chris Schueler</a>, Chief Executive Officer bei Cyderes, und</li>



<li><a href="https://www.skillsoft.com/blog-authors/greg-fuller" target="_blank" rel="noreferrer noopener">Greg Fuller</a>, Vice President bei Skillsoft.</li>
</ul>



<p class="wp-block-paragraph">Diesen Gesprächen sind die folgenden neun Tipps entsprungen.</p>



<h2 class="wp-block-heading">1. CEO-Perspektive verstehen</h2>



<p class="wp-block-paragraph">Die meisten <a href="https://www.computerwoche.de/article/2822483/die-9-schlimmsten-ceos.html" target="_blank">CEOs</a> erwarten von den ihnen direkt unterstellten Führungskräften, dass diese ihren Zuständigkeitsbereich vollständig eigenverantwortlich wahrnehmen. Ob Cybersecurity, IT-Operations oder Finanzen: Der jeweilige Entscheider ist in den Augen des CEO der Experte auf seinem Gebiet. Der CEO hat natürlich auch eine eigene Meinung, setzt jedoch voraus, dass Sie als CISO letztendlich Führungsverantwortung übernehmen und die Richtung vorgeben.</p>



<p class="wp-block-paragraph">Darüber hinaus erwartet ein CEO von einem CISO, der direkt an ihn berichtet, nicht nur über <a href="https://www.computerwoche.de/article/4196715/7-wege-risk-assessments-an-die-wand-zu-fahren.html" target="_blank">Risiken</a> aufgeklärt zu werden. Vielmehr geht er davon aus, dass Sicherheitsverantwortliche die Security-Perspektive auch mit Umsatzsicherung, Compliance, Kundenvertrauen und operativer Resilienz verknüpfen. Anders ausgedrückt: CEOs wollen einen echten strategischen Partner.</p>



<h2 class="wp-block-heading">2. Führungs-Skills ausbauen</h2>



<p class="wp-block-paragraph">Aus technologischer Sicht sind <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">KI</a>, Machine Learning, Cloud Security, Incident Response, Zero Trust sowie <a href="https://www.computerwoche.de/article/4030328/so-verandert-ki-ihre-grc-strategie.html" target="_blank">GRC</a> die Bereiche, in denen sich Bedrohungen am schnellsten weiterentwickeln – und strategische Führung die größte Hebelwirkung erzeugen kann.</p>



<p class="wp-block-paragraph">Mindestens ebenso wichtig sind jedoch auch „Power-Skills“ wie:</p>



<ul class="wp-block-list">
<li>Kommunikation,</li>



<li>kritisches Denken,</li>



<li>Anpassungsfähigkeit oder</li>



<li>emotionale Intelligenz.</li>
</ul>



<p class="wp-block-paragraph">Dabei trennt die Fähigkeit, komplexe Risiken in Business-Sprache <a href="https://www.computerwoche.de/article/4051211/so-rechtfertigen-sie-ihre-security-investitionen.html" target="_blank">übersetzen zu können</a>, die CISO-Spreu (rein technisch ausgerichtet) vom -Weizen. Auch in den Augen des CEO entscheiden die Skills eines CISO über dessen Effektivität – nicht bloß sein Job-Titel.</p>



<h2 class="wp-block-heading">3. Direktzugang richtig nutzen</h2>



<p class="wp-block-paragraph">Der direkte „Zugang“ zum CEO ermöglicht CISOs auch:</p>



<ul class="wp-block-list">
<li>Einfluss auf die Strategie zu nehmen,</li>



<li>die <a href="https://www.computerwoche.de/article/4142245/resilienz-muss-zentraler-teil-der-sicherheitskultur-werden.html" target="_blank">Resilienzplanung</a> mitzugestalten, und</li>



<li>sicherzustellen, dass Security als geschäftliche Notwendigkeit betrachtet wird und nicht bloß als Kostenstelle.</li>
</ul>



<p class="wp-block-paragraph">Diese Einflussmöglichkeiten sind regelmäßig am größten, wenn der CEO die Cybersicherheit auch als strategischen Hebel versteht und sie nicht zur rein technischen Funktion abwertet.</p>



<p class="wp-block-paragraph">Auf der anderen Seite schafft ein direkter Berichtsweg zwar leichteren Zugang zum CEO, bringt aber auch die Verantwortung mit sich, auf dieser Ebene zu liefern. Sicherheitsentscheider sollten ihre Cyberinitiativen deshalb für die Executive-Ebene so transparent wie möglich gestalten.</p>



<h2 class="wp-block-heading">4. Risk-Assessment-Chancen wahrnehmen</h2>



<p class="wp-block-paragraph">Besonders effektive CISOs betrachten jede Business-Konversation als „getarntes“ Risikogespräch. Dieses Mindset macht den Unterschied zwischen einem großartigen CISO – und einem großartigen Technologen.</p>



<p class="wp-block-paragraph">Indem sie zuerst über das Business und erst nachgelagert über die Security sprechen, können Sicherheitsentscheider zudem das Vertrauen des CEO gewinnen. Dazu empfiehlt es sich, jedes Risiko in Kontext zu Umsatz, Reputation oder regulatorischen Lücken zu setzen. Behalten Sie dabei im Hinterkopf: Der CEO will kein Alarmsystem und erwartet keine Überraschungen, sondern eine klare Einschätzung der wesentlichen Risiken und einen Sicherheitsverantwortlichen, der das Unternehmen <a href="https://www.computerwoche.de/article/4181675/6-kritische-sicherheitslucken-die-cisos-angehen-mussen.html" target="_blank">nicht ausbremst</a>.</p>



<h2 class="wp-block-heading">5. Erfolgreiche Beziehung definieren</h2>



<p class="wp-block-paragraph">Ganz unabhängig vom tatsächlichen Berichtsweg macht es Sinn, das Ziel einer geschäftlichen Beziehung zu definieren – und zwar schriftlich. Denn das schafft anfängliche Klarheit, schließt dabei aber nicht aus, dass sich die definierte Zielsetzung im Zeitverlauf weiterentwickelt.</p>



<p class="wp-block-paragraph">Besonders wichtig ist das für CISOs, die noch neu in <a href="https://www.computerwoche.de/article/2785596/das-muss-ein-chief-information-security-officer-koennen.html" target="_blank">ihrer Position</a> sind. In diesen Fällen hilft die Zieldefinition für Geschäftsbeziehungen beim Alignment – wodurch die Chancen für einen erfolgreichen Einstieg steigen. Die Zielsetzung lässt sich auch gemeinschaftlich erarbeiten.</p>



<h2 class="wp-block-heading">6. Trust und Offenheit priorisieren</h2>



<p class="wp-block-paragraph">Ein CEO muss sich voll und ganz darauf verlassen können, dass der CISO keine Informationen zurückhält. Sicherheitsentscheider benötigen auf der anderen Seite auch ausreichend psychologische Sicherheit, damit schlechte Nachrichten ebenso schnell kommuniziert werden wie gute.</p>



<p class="wp-block-paragraph">Sind diese Voraussetzungen gegeben, verwandelt sich die Security von einer Kostenstelle in einen strategischen Vorteil. CISOs tun deshalb gut daran, klar zu kommunizieren und sich als Teamplayer zu präsentieren, nicht als Einzelkämpfer.</p>



<p class="wp-block-paragraph">Um Trust zu vermitteln, ist es außerdem hilfreich, auch bei Incidents die Ruhe zu bewahren und Menschen als gleichgestellt zu behandeln. Langfristig <a href="https://www.computerwoche.de/article/4179380/der-chef-ist-kundigungsgrund-nummer-1.html" target="_blank">erfolgreiche Führungskräfte</a> kontrollieren nicht alles in Grund und Boden – sie bauen vielmehr Vertrauen auf, bevor sie es benötigen.</p>



<h2 class="wp-block-heading">7. Governance als Wettbewerbsvorteil sehen</h2>



<p class="wp-block-paragraph">Eine starke Partnerschaft zwischen CISO und CEO erfordert auch ein gemeinsames Bekenntnis dazu, <a href="https://www.computerwoche.de/article/4178603/it-security-und-ki-warum-es-auf-die-governance-ankommt.html" target="_blank">Governance</a> als strategischen Wettbewerbsvorteil zu betrachten.</p>



<p class="wp-block-paragraph">Besteht mit Blick auf diesen Grundsatz Einigkeit, kommt die Organisation in die Lage, mit KI innovativ zu sein und dabei parallel unnötigen Risiken aus dem Weg zu gehen. Unter dem Strich steht dann ein Unternehmen, das nicht nur auf Bedrohungen reagiert, sondern resilient operiert.</p>



<h2 class="wp-block-heading">8. Security-Ziele setzen und messen</h2>



<p class="wp-block-paragraph">Ziele zu definieren, ist nicht für erfolgreiche Geschäftsbeziehungen wichtig, sondern auch wenn es um die Cybersecurity selbst geht. Wenn die Erwartungen klar abgesteckt sind, wird auch deutlicher, welche Bereiche dabei besonders im Fokus stehen sollten.</p>



<p class="wp-block-paragraph">Das löst zwar nicht jedes Problem, ist aber speziell CISOs anzuraten, die direkt an den CEO berichten: Eine frühe Abstimmung über mögliche Indikatoren verringert den Druck, der auf dem Sicherheitsentscheider lastet und sorgt dafür, dass keine bösen Überraschungen entstehen können.</p>



<h2 class="wp-block-heading">9. Frustrationstoleranz aufbauen</h2>



<p class="wp-block-paragraph">Beharrlichkeit und die Bereitschaft, sich auch mit unangenehmen Dingen auseinanderzusetzen, um die Sicherheit zu gewährleisten, sind für CISOs, die an den CEO berichten, ebenfalls entscheidend.</p>



<p class="wp-block-paragraph">Ganz generell kann die Rolle einer Führungskraft im Bereich Cybersicherheit <a href="https://www.computerwoche.de/article/4090067/tipps-fur-cisos-die-die-branche-wechseln-wollen.html" target="_blank">undankbar sein</a>: Geht etwas schief, ist der CISO oft der Sündenbock. Ist alles in Ordnung, wird seine Arbeit so gut wie nicht wahrgenommen.</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/4188581/10-survival-tips-for-csos-who-report-to-the-ceo.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Windows-Sicherheitstipps]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Diese Tipps härten Ihr Windows-System. PixieMe | shutterstock.com



Unabhängig davon, ob Sie noch Windows 10 nutzen oder bereits mit Windows 11 arbeiten, können Sie das Sicherheitsniveau Ihres Rechners mit Bordmitteln opti...]]></description>
<link>https://tsecurity.de/de/3707279/it-security-nachrichten/10-windows-sicherheitstipps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707279/it-security-nachrichten/10-windows-sicherheitstipps/</guid>
<pubDate>Thu, 06 Aug 2026 06:21:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Diese Tipps härten Ihr Windows-System. </figcaption></figure><p class="imageCredit">PixieMe | shutterstock.com</p></div>



<p class="wp-block-paragraph">Unabhängig davon, ob Sie noch <a href="https://www.computerwoche.de/article/4012537/verlangerte-windows-10-sicherheit-kostenlos-fur-verbraucher-teuer-fur-unternehmen.html" target="_blank">Windows 10 nutzen</a> oder bereits <a href="https://www.computerwoche.de/article/2827473/windows-11-schneller-machen.html" target="_blank">mit Windows 11 arbeiten</a>, können Sie das Sicherheitsniveau Ihres Rechners mit Bordmitteln optimieren. Wie, das zeigen die folgenden zehn ganz konkreten Tipps, die sich unmittelbar positiv auf die Sicherheit Ihres Systems und Ihrer Daten auswirken.</p>



<h2 class="wp-block-heading">1. PUPs blockieren</h2>



<p class="wp-block-paragraph">Windows kann “potenziell unerwünschte Programme” (Potentially Unwanted Programs; <a href="https://www.bitdefender.de/consumer/support/answer/53406/" target="_blank" rel="noreferrer noopener">PUPs</a>) automatisiert blockieren. Dieser Begriff umschreibt Anwendungen, bei denen es sich aus technischer Perspektive zwar nicht um Malware handelt – die aber unter Umständen unerwünschte Aktionen ausführen, beispielsweise Daten ausspähen oder Werbung einblenden.</p>



<p class="wp-block-paragraph">Um sicherzustellen, dass solche Anwendungen geblockt werden, müssen Sie die entsprechende Option aktivieren. Dazu rufen Sie die App “<strong>Windows Sicherheit</strong>” über das Startmenü auf. Anschließend navigieren Sie über “<strong>App- und Browsersteuerung</strong>” zu “<strong>Zuverlässigkeitsbasierter Schutz</strong>” und aktivieren den Schieberegler unter “<strong>Potenziell unerwünschte Apps werden blockiert</strong>“.  </p>



<h2 class="wp-block-heading">2. Verschlüsselung einsetzen</h2>



<p class="wp-block-paragraph">Bei modernen Windows-PCs wird die Geräteverschlüsselung automatisch aktiviert, sobald Sie sich mit einem Microsoft-Konto verbinden. Um zu überprüfen, ob Ihr Device tatsächlich <a href="https://www.computerwoche.de/article/2650080/faq-was-sie-ueber-verschluesselung-wissen-sollten.html" target="_blank">verschlüsselt wird</a>, suchen Sie im Startmenü nach BitLocker und klicken anschließend auf “<strong>BitLocker verwalten</strong>“.</p>



<p class="wp-block-paragraph">Falls Sie im sich nun öffnenden Fenster feststellen, dass <a href="https://www.computerwoche.de/video/2890109/windows-10-laufwerke-mit-bitlocker-verschlusseln.html" target="_blank">BitLocker</a> nicht aktiviert ist, gibt es dafür zwei mögliche Erklärungen:</p>



<ul class="wp-block-list">
<li>Sie sind mit einem lokalen Konto angemeldet, oder</li>



<li>Sie nutzen ein älteres Gerät, das die Option nicht unterstützt.</li>
</ul>



<p class="wp-block-paragraph">Im ersten Fall hilft der Umstieg auf ein Microsoft-Konto, im zweiten lediglich ein Upgrade auf Windows Professional.  </p>



<h2 class="wp-block-heading">3. Synchronisierungseinstellungen prüfen</h2>



<p class="wp-block-paragraph">Sowohl unter Windows 10 als auch unter Windows 11 liegt Microsoft viel daran, dass <a href="https://www.computerwoche.de/article/2794519/office-365-cloud-speicher-das-muessen-sie-wissen.html" target="_blank">OneDrive</a> Ordner wie Desktop, Dokumente und Bilder automatisch synchronisiert. Das führt dazu, dass deren Inhalt online mit Ihrem Microsoft-Konto verknüpft und zwischen Ihren PCs synchronisiert wird. Das kann praktisch sein – oder nicht erwünscht, je nachdem, mit welcher Art von Daten Sie arbeiten. Falls diese Compliance-Vorgaben unterliegen, kann die Synchronisierungseinstellung die Datensicherheit unterwandern.  </p>



<p class="wp-block-paragraph">Um die Einstellungen zu überprüfen und genau zu definieren, was OneDrive synchronisiert, öffnen Sie die Einstellungen – zum Beispiel über einen Rechtsklick auf das OneDrive-Symbol rechts unten in ihrer Taskleiste. Anschließend klicken Sie unter “<strong>Wichtige PC-Ordner auf OneDrive sichern</strong>” die Schaltfläche “<strong>Sicherung verwalten</strong>“. Im folgenden Fenster “<strong>Ordner auf diesem PC sichern</strong>” können Sie die entsprechenden Einstellungen vornehmen.</p>



<h2 class="wp-block-heading">4. Sicher(er) einloggen</h2>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/3492200/authentifizierungslosungen-10-passwordless-optionen-fur-unternehmen.html" target="_blank">Passwörter</a> sollten wegen ihrer inhärenten Unzulänglichkeiten schon länger aus der Mode gekommen sein. Falls Ihr PC zeitgemäßere, biometrische Authentifizierungsmethoden in Form von <a href="https://www.computerwoche.de/article/2806422/was-ist-windows-hello.html" target="_blank">Windows Hello</a> unterstützt, sollten Sie diese stattdessen nutzen.</p>



<p class="wp-block-paragraph">Um den Login per Fingerabdruck oder Gesichtserkennung zu aktivieren, suchen Sie über das Windows-Startmenü nach “<strong>Anmeldeoptionen</strong>” und richten die für Sie in Frage kommende Option ein. Anschließend freuen Sie sich über komfortablere, schnellere Logins – und mehr Sicherheit.</p>



<h2 class="wp-block-heading">5. Überwachten Ordnerzugriff aktivieren</h2>



<p class="wp-block-paragraph">Um zu verhindern, dass Ransomware Ihre Dateien “in Geiselhaft” nimmt, bietet Windows die Option des überwachten Ordnerzugriffs, die Datenmanipulationen verhindert. Das bietet zusätzlichen Schutz, allerdings ist die Option standardmäßig nicht aktiviert und zieht im Regelfall auch ein wenig Konfigurationsaufwand nach sich.</p>



<p class="wp-block-paragraph">Suchen Sie über die Windows-Startleiste nach “<strong>Überwachter Ordnerzugriff</strong>“, um die Funktion aufzurufen und <a href="https://www.computerwoche.de/article/2800577/so-wappnen-sie-ihren-pc-gegen-erpresser.html" target="_blank">zu konfigurieren</a>.</p>



<h2 class="wp-block-heading">6. Office-Updates sicherstellen</h2>



<p class="wp-block-paragraph">Falls Sie Microsoft-Office-Anwendungen (beziehungsweise <a href="https://www.computerwoche.de/article/3523691/microsoft-365-erklart.html" target="_blank">Microsoft 365</a>) nutzen, sollten Sie unbedingt sicherstellen, dass die verwendeten Versionen mit Sicherheits-Updates versorgt werden. Um zu überprüfen, ob das der Fall ist, öffnen Sie eine entsprechende Anwendung – beispielsweise Word. Hier wählen Sie “<strong>Datei</strong>“, gefolgt von “<strong>Konto</strong>“.</p>



<p class="wp-block-paragraph">Auf der rechten Seite des App-Fensters sehen Sie nun “<strong>Produktinformationen</strong>” und etwas unterhalb den Punkt “<strong>Microsoft 365- und Office-Aktualisierungen</strong>“. Sollten Sie hier lesen “<strong>Updates werden automatisch heruntergeladen und installiert.</strong>“, sind Sie auf der sicheren Seite. Anderenfalls aktivieren Sie die Funktion.</p>



<h2 class="wp-block-heading">7. App-Stati checken</h2>



<p class="wp-block-paragraph">Auch andere Windows-Apps werden nicht unbedingt immer automatisch mit Sicherheitsupdates versorgt. Deshalb sollten Sie zunächst dafür sorgen, dass Apps, die über den <a href="https://www.computerwoche.de/article/2860592/alle-store-apps-und-programme-in-einem-rutsch-aktualisieren.html" target="_blank">Microsoft Store</a> bezogen werden, automatisch aktualisiert werden. Selbst wenn Sie diesen nicht direkt nutzen, können diverse Apps darüber aktualisiert werden. Um die Funktion zu aktivieren, öffnen Sie den Store, klicken auf Ihr Profilbild und rufen die Einstellungen auf. Anschließend stellen Sie sicher, dass die Option “<strong>App Updates</strong>” aktiviert ist.</p>



<p class="wp-block-paragraph">Anschließend können Sie außerdem prüfen, ob sich anfällige, veraltete Anwendungen auf Ihrem System befinden. Dazu stehen diverse Optionen zur Verfügung – zum Beispiel:</p>



<ul class="wp-block-list">
<li>das Windows-Befehlszeilen-Tool <a href="https://learn.microsoft.com/de-de/windows/package-manager/winget/" target="_blank" rel="noreferrer noopener">WinGet</a>, oder</li>



<li>das kostenlose Drittanbieter-Tool <a href="https://patchmypc.com/product/home-updater/" target="_blank" rel="noreferrer noopener">Home Updater</a>.</li>
</ul>



<h2 class="wp-block-heading">8. Kernisolierung aktivieren</h2>



<p class="wp-block-paragraph">Windows verfügt über eine Reihe von Low-Level-Funktionen zur Systemhärtung, die es erschweren sollen den Windows Kernel auszunutzen. Um diese zu aktivieren, rufen Sie die Anwendung “<strong>Windows Sicherheit</strong>” auf und navigieren anschließend zum Punkt “<strong>Gerätesicherheit</strong>“.</p>



<p class="wp-block-paragraph">Sobald Sie eine der hier aufgeführten Sicherheitsfunktionen aktivieren, überprüft Windows, ob diese auf Ihrem System ordnungsgemäß funktioniert. Ist das nicht der Fall – beispielsweise wegen <a href="https://www.computerwoche.de/article/2823351/das-hilft-gegen-driver-ueberblaehung.html" target="_blank">veralteten, inkompatiblen Hardwaretreibern</a> –, erkennt Windows das in der Regel automatisch und deaktiviert die Funktion entsprechend.</p>



<h2 class="wp-block-heading">9. Sandboxing nutzen</h2>



<p class="wp-block-paragraph">Angenommen, Sie möchten (entgegen aller Empfehlungen) auf Ihrem System ein dubioses Programm installieren, sollten Sie dazu in jedem Fall die <a href="https://learn.microsoft.com/de-de/windows/security/application-security/application-isolation/windows-sandbox/" target="_blank" rel="noreferrer noopener">Windows Sandbox verwenden</a>. Allerdings ist diese Funktion den Professional-, Enterprise-, und Education-Editionen von Windows 10 und 11 vorbehalten.</p>



<p class="wp-block-paragraph">Haben Sie die richtige Windows-Version, finden Sie “Windows-Sandbox” über Ihr Startmenü: Suchen Sie nach “<strong>Windows-Features aktivieren und deaktivieren</strong>” und setzen Sie im folgenden Fenster einen Haken beim entsprechenden Eintrag. Falls Sie nicht über eine unterstützte Windows-Version verfügen, können Sie Sandboxing alternativ auch über Drittanbieter-Virtualisierungssoftware wie etwa <a href="https://www.virtualbox.org/" target="_blank" rel="noreferrer noopener">VirtualBox</a> realisieren.</p>



<h2 class="wp-block-heading">10. Exploit-Schutz prüfen</h2>



<p class="wp-block-paragraph">Windows verfügt inzwischen über einen integrierten Exploit-Schutz, der Ihre Programme zusätzlich vor Angriffen schützt. Um die Einstellungen für dieses Feature zu überprüfen, rufen Sie ebenfalls “<strong>Windows-Sicherheit</strong>” auf. Anschließend navigieren Sie zu “<strong>App- und Browsersteuerung</strong>” und rufen die “<strong>Einstellungen für Exploit-Schutz</strong>” auf.</p>



<p class="wp-block-paragraph">Fast alle Optionen sollten hier standardmäßig aktiviert sein. Zu beachten ist dabei, dass die Option “<strong>Zufällige Anordnung für Images erzwingen (obligatorische ASLR)</strong>” zu Problemen mit einigen älteren Anwendungen führen kann, wenn sie aktiviert wird. Es empfiehlt sich deshalb, das nicht zu tun. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/4011864/windows-security.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Peinliche Situationen im Büroalltag: Oft hilft es, über sich selbst zu lachen]]></title>
<description><![CDATA[Jeder kennt sie, die peinlichen Situationen am Arbeitsplatz. Lesen Sie, wie Sie sich herauswinden.
					Foto: fizkes – shutterstock.com




Es bringt nichts, Pannen herunterzuspielen oder zu vertuschen. Oft ist ein offensiver Umgang damit besser, am Ende sitzen schließlich alle im selben Boot. En...]]></description>
<link>https://tsecurity.de/de/3707278/it-security-nachrichten/peinliche-situationen-im-bueroalltag-oft-hilft-es-ueber-sich-selbst-zu-lachen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707278/it-security-nachrichten/peinliche-situationen-im-bueroalltag-oft-hilft-es-ueber-sich-selbst-zu-lachen/</guid>
<pubDate>Thu, 06 Aug 2026 06:21:21 +0200</pubDate>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Jeder kennt sie, die peinlichen Situationen am Arbeitsplatz. Lesen Sie, wie Sie sich herauswinden." title="Jeder kennt sie, die peinlichen Situationen am Arbeitsplatz. Lesen Sie, wie Sie sich herauswinden." src="https://images.computerwoche.de/bdb/3379059/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Jeder kennt sie, die peinlichen Situationen am Arbeitsplatz. Lesen Sie, wie Sie sich herauswinden.</p></figcaption></figure><p class="imageCredit">
					Foto: fizkes – shutterstock.com</p></div>




<p class="wp-block-paragraph">Es bringt nichts, Pannen herunterzuspielen oder zu vertuschen. Oft ist ein offensiver Umgang damit besser, am Ende sitzen schließlich alle im selben Boot. Entschuldigen Sie sich, machen Sie das Beste draus – und geben Sie ruhig einmal zu, dass ihnen etwas unangenehm ist. Sie werden sehen, dass sich die anderen entspannen. Wir haben ein paar typische Situationen herausgesucht, die im geschäftlichen Alltag peinlich sein können.</p>



<h2 class="wp-block-heading"><strong>1. Sie werden gelobt für die Arbeit anderer</strong></h2>



<p class="wp-block-paragraph">Es ist schön, <a href="https://www.computerwoche.de/article/2777558/wertschaetzung-ist-fachkraeften-wichtiger-als-statussymbole.html" title="Wertschätzung" target="_blank">Wertschätzung</a> zu erfahren – für manche sogar so schön, dass sie Lob auch dann einheimsen, wenn es eigentlich anderen gebührt. Dass das nicht geht, ist klar: In solchen Fällen gilt es mutig zu korrigieren und zu sagen: “Danke für die Blumen, liebe Chefin, aber nicht ich, sondern die Kollegin muss heute gefeiert werden. Sie hat wochenlang an dem Projekt gearbeitet und einen unglaublichen Job gemacht. Insofern reiche ich die Blumen gerne weiter!”</p>



<p class="wp-block-paragraph">Man möchte ja auch nicht, dass andere die Lorbeeren für die eigenen Leistungen einstecken. Wer kennt ihn nicht, den lieben Kollegen, der wochenlang während der Projektarbeit vor sich hindämmert, um dann die Präsentation der Ergebnisse an sich zu reißen und damit zu glänzen. </p>



<h3 class="wp-block-heading">Keiner will Aufschneider sein </h3>



<p class="wp-block-paragraph">Es ist wichtig für das eigene Wohlbefinden und auch für die Karriere, <a href="https://www.computerwoche.de/article/2809872/wie-verkaufe-ich-mich-richtig.html" title="sich nicht zu verstecken" target="_blank">sich nicht zu verstecken</a> und die eigenen Leistungen ins rechte Licht zu rücken. Wer sich freiwillig in eine Opferposition begibt, hat schon verloren. Andererseits ist zu viel Offensive auch gefährlich, denn als Aufschneider dazustehen, kann sich kontraproduktiv auswirken.</p>



<p class="wp-block-paragraph">Besonders kompliziert wird die Situation, wenn Sie in einem Vortrag oder einer <a href="https://www.computerwoche.de/article/2763768/so-praesentieren-sie-richtig.html" title="Präsentation" target="_blank">Präsentation</a> von Kollegen Ihre eigenen Ideen wiederfinden, ohne dass Ihre Urheberschaft kenntlich gemacht wird. Eigentlich hätten Sie gerne, dass klar wird, auf welchem Mist die guten Arbeitsergebnisse gewachsen sind, andererseits empfinden Sie es als unangemessen, dies während eines sachbezogen vorgetragenen Vortrags allzu deutlich zu zeigen. Am besten, Sie warten geduldig auf ihre Chance, bei Zwischenfragen oder einer abschließenden Diskussion noch einmal vertieft darzustellen, was SIE sich dabei gedacht haben.</p>



<h2 class="wp-block-heading"><strong>2. Ihr Chef rastet aus und beschimpft sie vor dem Team</strong></h2>



<p class="wp-block-paragraph">In Großraumbüros ist Privatheit nicht gewünscht. Umso schwieriger, wenn jemand Sie laut kritisiert – aus dem Bauch heraus und in Gegenwart anderer. Solange die Vorwürfe nicht persönlich werden, sollten Sie versuchen, die Contenance zu wahren und die Kritik, ob sie nun vom Vorgesetzten oder einem Kollegen kommt, nicht an sich heranzulassen. Auf keinen Fall sollten Sie wütend den Raum verlassen oder sich beleidigt in die Ecke setzen. Besser ist es, sich freundlich für das “Feedback” zu bedanken, sachliche Erklärungen zu finden und Verbesserungsvorschläge zu machen.</p>



<p class="wp-block-paragraph">Besonders unangenehm wird es, wenn sich der übellaunige oder cholerische Vorgesetzte an Ihnen austobt. Wenn rationale Argumente nicht ans Ziel fühlen, kann es in diesem Fall tatsächlich die bessere Strategie sein, den Raum zu verlassen, damit sich die Atmosphäre abkühlen kann. </p>



<h3 class="wp-block-heading">Zeigen Sie klare Kante!</h3>



<p class="wp-block-paragraph">Suchen Sie sich dafür am besten eine kurze Erklärung: ein Termin, ein Telefonat oder Ähnliches. Wichtig ist es, <a href="https://www.computerwoche.de/article/2773635/seid-selbstbewusst-und-formuliert-klar.html" title="sich nicht klein machen zu lassen" target="_blank">sich nicht klein machen zu lassen</a>. Halten Sie Ihren Körper aufrecht und sprechen sie klar und deutlich. So zeigen Sie, dass Sie sich nichts vorzuwerfen haben.</p>



<p class="wp-block-paragraph">Sind die Emotionen abgekühlt, ist es sinnvoll, ein klärendes Gespräch mit dem Vorgesetzten zu suchen. Wenn Sie einen Fehler gemacht haben, der zu dem Streit geführt hat, sollten Sie die Hintergründe und Begleitumstände erklären. Haben Sie es einfach nur mit einem schlecht gelaunten und charakterschwachen Boss zu tun, der seine sonstigen Probleme an Ihnen auslässt, zeigen Sie klare Kante. Machen Sie deutlich, dass der Ton die Musik macht und sie sich nicht alles gefallen lassen – schon gar nicht in Gegenwart Dritter. Hilft das alles nicht, nehmen Sie die nächste Stufe auf der Eskalationsleiter: Eine Beschwerde beim nächsthöheren Chef und gegebenenfalls bei der Mitarbeitervertretung ist fällig.</p>



<h2 class="wp-block-heading"><strong>3. Sie wurden bei einer Lüge erwischt</strong></h2>



<p class="wp-block-paragraph">“Es wird niemals so viel gelogen wie vor der Wahl, während des Krieges und nach der Jagd”, sagte Otto von Bismarck. Ganz offensichtlich hat er das Büro vergessen. Wir alle lügen, und weil es so ist und wir uns dafür schämen, wählen wir gerne verniedlichende Begriffe wie Flunkern, Schwindeln oder einen Bären aufbinden.</p>



<p class="wp-block-paragraph">Was also tun, wenn wir beim Flunkern erwischt wurden? Wenn also das Projekt entgegen unserer Angaben feststeckt, das Mailing fehlerhaft ausgesandt wurde oder die Abrechnung verlorengegangen ist? Regel Nummer eins lautet: Verstricken Sie sich nicht in noch mehr Lügen – in dem hilflosen Versuch, Ihre Spuren zu verwischen. Das geht nicht gut. Sie verlieren den Überblick über ihre <a href="https://www.computerwoche.de/article/2818754/das-kann-it-entscheider-den-kopf-kosten.html" title="Lügengeschichten" target="_blank">Lügengeschichten</a>, und dann wird es richtig unangenehm.</p>



<h3 class="wp-block-heading">Billige Ausreden – keine gute Idee</h3>



<p class="wp-block-paragraph">Gestehen Sie, wenn Sie ertappt wurden, entschuldigen Sie sich aufrichtig und machen Sie das Beste aus der Situation. Die Kollegen verstehen das, sie schwindeln ja auch gelegentlich. Billige Ausreden zu suchen, ist keine gute Idee, aber plausible Erklärungen können hilfreich sein. Vielleicht haben Sie mit Ihrer Lüge ja etwas Positives bezweckt, aber leider nicht erreicht? Zumindest helfen Sie den anderen so, Ihren Standpunkt zu verstehen.</p>



<p class="wp-block-paragraph">Wenn durch Ihre Lügen jemand zu Schaden gekommen ist, müssen Sie die Verantwortung übernehmen und sich um Wiedergutmachung bemühen. Außerdem wichtig: Hören Sie auf zu lügen, sonst ist Ihre Glaubwürdigkeit bald nachhaltig beschädigt. Bewahren Sie sich Ihre kleinen Lügen lieber für den Feierabend daheim oder Ihren Stammtisch auf. Dort ist man bereit, Ihnen zu verzeihen – sofern Ihre Schummeleien unterhaltsam sind.</p>



<h2 class="wp-block-heading"><strong>4. Der Kollege ist nicht “salonfähig”</strong></h2>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Eine Herausforderung: Wie erkläre ich dem Kollegen, dass er sich mehr um seine Hygiene kümmern muss? " title="Eine Herausforderung: Wie erkläre ich dem Kollegen, dass er sich mehr um seine Hygiene kümmern muss? " src="https://images.computerwoche.de/bdb/3379034/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Eine Herausforderung: Wie erkläre ich dem Kollegen, dass er sich mehr um seine Hygiene kümmern muss? </p></figcaption></figure><p class="imageCredit">
					Foto: Antonio Guillem – shutterstock.com</p></div>




<p class="wp-block-paragraph">Körper- und Mundgeruch können in gemeinsamen Büros zu einer echten Qual werden. Das gleiche gilt für mangelnde Hygiene oder <a href="https://www.computerwoche.de/article/2687434/was-ist-business-casual.html" title="unangemessene Kleidung" target="_blank">unangemessene Kleidung</a>. Doch wie sag ich’s dem Kollegen, ohne ihn und mich zu beschämen? Darf ich jemanden, der riecht oder schmuddelig wirkt, ansprechen? Und will ich das überhaupt? Immerhin könnte der Bürofrieden nachhaltig gestört sein.</p>



<p class="wp-block-paragraph">So schwer es fällt: Wenn Ihre Toleranzschwelle überschritten ist, sollten Sie die Person freundlich und unter vier Augen ansprechen. Vielleicht weiß sie gar nicht von ihrer zweifelhaften Aura und ist dankbar für einen solchen Hinweis. Möglicherweise hat er sich schon gewundert, warum sich andere abwenden, und hat nun eine Erklärung: Die Ausdünstungen sind schuld.</p>



<h3 class="wp-block-heading">Ehrliches Feedback lohnt sich</h3>



<p class="wp-block-paragraph">Sagen Sie Ihrem Zimmergenossen, wie schwer es Ihnen fällt, die Sprache auf ein solch heikles Thema zu bringen und dass Sie dieses vertrauliche Gespräch suchen, weil Ihnen an Ihrer guten Beziehung liegt. Vermutlich wird sich der Angesprochene erst einmal beleidigt zurückziehen, aber schon bald dürften Sie Veränderungen im Hygieneverhalten erkennen. Erwarten Sie keine Dankbarkeit, vermutlich wird das Thema nie wieder angesprochen. Ist ja auch nicht nötig, wenn das Problem beseitigt wurde und die Zusammenarbeit funktioniert.</p>



<h2 class="wp-block-heading"><strong>5. Sie haben eine vertrauliche E-Mail an den falschen Adressaten gesendet</strong></h2>



<p class="wp-block-paragraph">Die <a href="https://www.computerwoche.de/article/2632425/die-groessten-e-mail-suenden.html" title="Fülle der jeden Tag abzuarbeitenden E-Mails " target="_blank">Fülle der jeden Tag abzuarbeitenden E-Mails </a>zwingt uns dazu, schnell zu arbeiten. Damit steigt die Fehleranfälligkeit: Man beginnt den Adressaten einzutippen, und die Autovervollständigung sorgt dafür, dass das Feld schnell ausgefüllt wird. Dumm nur, wenn die Mail nicht an Sven Meyer, sondern an Sven Meyer-Holthaus geht – und der auch noch im Vorstand sitzt. Ebenfalls ärgerlich: Sie klicken auf “Antwort an alle” und vergessen dabei, dass der Inhalt Ihrer Mail vielleicht eben doch nicht für alle geeignet ist.</p>



<p class="wp-block-paragraph">Zugegeben, unsere Ratschläge für solche Situationen sind unbefriedigend. Steht etwas Ungemessenes in der E-Mail, können Sie versuchen, diese E-Mail noch zurückzurufen. Vielleicht haben Sie auch einen guten Draht zum Vorzimmer des Chefs, und jemand dort hilft ihnen, die ungeöffnete Post still und heimlich zu beseitigen. </p>



<h3 class="wp-block-heading">Im Ton immer sachlich bleiben</h3>



<p class="wp-block-paragraph">Sie können sich auch überlegen, den Chef zu benachrichtigen und sich zu entschuldigen. Andererseits ist bei vielen Vorgesetzten die Wahrscheinlichkeit groß, dass die Nachricht gar nicht geöffnet wurde. Da wäre es schade, die Aufmerksamkeit darauf gelenkt zu haben.</p>



<p class="wp-block-paragraph">Natürlich tritt das Problem nicht nur gelegentlich in der Konversation mit Vorgesetzten, sondern auch mit anderen Menschen innerhalb und außerhalb des Unternehmens auf. Deshalb ist die einfachste und wichtigste Grundregel, im Ton stets sachlich und geschäftsmäßig zu bleiben. Das macht Sie unangreifbar. Dass sensible Anhänge mit einem Passwort zu schützen sind, ist ohnehin selbstverständlich. Und machen Sie nicht den Fehler, das Passwort zusammen mit dem Anhang in derselben Mail zu verschicken. Wir würden es nicht schreiben, wenn es nicht immer wieder vorkäme.</p>



<h2 class="wp-block-heading"><strong>6. Ein Fehler in der PowerPoint</strong></h2>



<p class="wp-block-paragraph">Die große Präsentation steht an, Sie wollen dem Vorstand die IT-Strategie erklären und fühlen sich bestens vorbereitet. Doch während Ihres Vortrags bemerken Sie einen peinlichen Rechtschreib- oder Logikfehler in Ihrer Präsentation. Zeigen Sie, dass Sie eine coole Socke sind! Ignorieren Sie den Fehler oder – wenn er zu offensichtlich ist – machen sie ein kleinen Scherz darüber.</p>



<p class="wp-block-paragraph">Wir würden uns nicht wundern, wenn gewiefte Präsentatoren absichtlich solche kleinen Fehler in ihre Präsentationen einbauen würden. Eine schlechte Idee wäre es jedenfalls nicht. Schließlich machen uns Fehler menschlich und geben uns die Gelegenheit, einen Moment der persönlichen Nähe zum Publikum herzustellen – nach dem Motto: Ich bin auch nur ein Mensch.</p>



<h2 class="wp-block-heading"><strong>7. Über andere lästern und nicht bemerken, dass diese zuhören</strong></h2>



<p class="wp-block-paragraph">Sie stehen in der Kaffeeküche und ziehen mächtig über einen Kollegen her, ohne zu bemerken, dass der draußen vor der Tür steht und gebannt zuhört. Oder Sie werden nach einem schwierigen Telefonat den Hörer aufs Telefon und fluchen über ihren Gesprächspartner – der aber dummerweise noch in der Leitung ist. Möglichkeiten, sich auf diese Art zu blamieren, gibt es reichlich. Aber wie windet man aus einer solchen Situation heraus?</p>



<p class="wp-block-paragraph">Tatsächlich ist es am klügsten, zu seinen Worten zu stehen und die <a href="https://www.computerwoche.de/article/2743963/wenn-das-mitarbeitergespraech-in-streit-ausartet.html" title="Kritik i" target="_blank">Kritik i</a>n einem milderen und sachlicheren Ton zu wiederholen. Wenn in der Küche gesagt wurde: “Der Meyer hat wirklich die bescheuertste Marketing-Idee aller Zeiten, so erreichen wir nie unsere Ziele”, können Sie dann sagen: “Herr Meyer, entschuldigen Sie bitte den forschen Ton, aber wir müssen wirklich noch einmal über Ihren Marketing-Ansatz reden. Das Beispiel XYZ hat ja deutlich gezeigt, dass wir damit nicht vorankommen werden.”</p>



<p class="wp-block-paragraph">Wie so oft ist es am besten, Kritik immer sachlich-korrekt zu üben. Selbst wenn Ihnen der Kollege nicht zuhört, müssen Sie damit rechnen, dass Dritte Ihre Worte weitertragen. Wie immer gilt also: Bleiben Sie professionell!</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stark in Datensicherheit, schwach in KI-Steuerung - connect-professional]]></title>
<description><![CDATA[Das zeigt eine Befragung von 459 IT-Fachkräften durch das Sicherheitsunternehmen Kiteworks (2026 Data Security and Compliance Risk Report). Und ...]]></description>
<link>https://tsecurity.de/de/3707277/it-security-nachrichten/stark-in-datensicherheit-schwach-in-ki-steuerung-connect-professional/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707277/it-security-nachrichten/stark-in-datensicherheit-schwach-in-ki-steuerung-connect-professional/</guid>
<pubDate>Thu, 06 Aug 2026 06:18:25 +0200</pubDate>
<content:encoded><![CDATA[Das zeigt eine Befragung von 459 IT-Fachkräften durch das Sicherheitsunternehmen Kiteworks (2026 <b>Data Security</b> and Compliance Risk Report). Und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Walmart Deals of the Day: Over $25 Off a Blackstone Griddle to Kick Off Grilling Season]]></title>
<description><![CDATA[Plus, 50% off a pair of Crocs and over-ear JBL headphones on sale for just $50.]]></description>
<link>https://tsecurity.de/de/3707276/it-nachrichten/walmart-deals-of-the-day-over-25-off-a-blackstone-griddle-to-kick-off-grilling-season/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707276/it-nachrichten/walmart-deals-of-the-day-over-25-off-a-blackstone-griddle-to-kick-off-grilling-season/</guid>
<pubDate>Thu, 06 Aug 2026 06:17:52 +0200</pubDate>
<content:encoded><![CDATA[Plus, 50% off a pair of Crocs and over-ear JBL headphones on sale for just $50.]]></content:encoded>
</item>
<item>
<title><![CDATA[The $299 Viture Pro 2 are the company's lightest and most comfortable smartglasses yet]]></title>
<description><![CDATA[Viture is releasing a more compact Mobile Dock Mini for just $99 alongside its new $299 smartglasses.]]></description>
<link>https://tsecurity.de/de/3707275/it-nachrichten/the-299-viture-pro-2-are-the-companys-lightest-and-most-comfortable-smartglasses-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707275/it-nachrichten/the-299-viture-pro-2-are-the-companys-lightest-and-most-comfortable-smartglasses-yet/</guid>
<pubDate>Thu, 06 Aug 2026 06:17:51 +0200</pubDate>
<content:encoded><![CDATA[Viture is releasing a more compact Mobile Dock Mini for just $99 alongside its new $299 smartglasses.]]></content:encoded>
</item>
<item>
<title><![CDATA[Günstiger als ein Deutschlandticket: Ikea verkauft das Zubehör, das eurem Stehschreibtisch noch fehlt]]></title>
<description><![CDATA[Warum euer Stehschreibtisch erst mit diesem Detail wirklich Sinn ergibt.]]></description>
<link>https://tsecurity.de/de/3707274/it-nachrichten/guenstiger-als-ein-deutschlandticket-ikea-verkauft-das-zubehoer-das-eurem-stehschreibtisch-noch-fehlt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707274/it-nachrichten/guenstiger-als-ein-deutschlandticket-ikea-verkauft-das-zubehoer-das-eurem-stehschreibtisch-noch-fehlt/</guid>
<pubDate>Thu, 06 Aug 2026 06:17:39 +0200</pubDate>
<content:encoded><![CDATA[Warum euer Stehschreibtisch erst mit diesem Detail wirklich Sinn ergibt.]]></content:encoded>
</item>
<item>
<title><![CDATA[#heiseshow: E-Autos als Energiepuffer, Smart-Glasses-Verbot, ICQ-Comeback]]></title>
<description><![CDATA[In der #heiseshow: Die EU will bidirektionales Laden für E-Autos verpflichtend machen, Meta Smart Glasses droht ein Verbot und ICQ feiert sein Comeback.]]></description>
<link>https://tsecurity.de/de/3707273/it-nachrichten/heiseshow-e-autos-als-energiepuffer-smart-glasses-verbot-icq-comeback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707273/it-nachrichten/heiseshow-e-autos-als-energiepuffer-smart-glasses-verbot-icq-comeback/</guid>
<pubDate>Thu, 06 Aug 2026 06:16:54 +0200</pubDate>
<content:encoded><![CDATA[In der #heiseshow: Die EU will bidirektionales Laden für E-Autos verpflichtend machen, Meta Smart Glasses droht ein Verbot und ICQ feiert sein Comeback.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now]]></title>
<description><![CDATA[Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical vulnerabilities affecting the platform. The flaws were identified proactively by Cisco’s own engineering team rather than through external reports, and th...]]></description>
<link>https://tsecurity.de/de/3707272/it-security-nachrichten/cisco-patched-multiple-critical-vulnerabilities-in-catalyst-sd-wan-update-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707272/it-security-nachrichten/cisco-patched-multiple-critical-vulnerabilities-in-catalyst-sd-wan-update-now/</guid>
<pubDate>Thu, 06 Aug 2026 06:00:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical vulnerabilities affecting the platform. The flaws were identified proactively by Cisco’s own engineering team rather than through external reports, and the company has confirmed there is no evidence of active exploitation in the wild. Even […]</p>
<p>The post <a href="https://cybersecuritynews.com/cisco-catalyst-sd-wan-vulnerabilities-2/">Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI kann kaufen. Aber kann die Zahlungsinfrastruktur mithalten?]]></title>
<description><![CDATA[Die Verbreitung von Agentic Commerce schreitet derzeit in Deutschland und Österreich voran. 

Tags: #e-Commerce | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3707271/it-security-nachrichten/ki-kann-kaufen-aber-kann-die-zahlungsinfrastruktur-mithalten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707271/it-security-nachrichten/ki-kann-kaufen-aber-kann-die-zahlungsinfrastruktur-mithalten/</guid>
<pubDate>Thu, 06 Aug 2026 05:54:24 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/08/Agentic-Commerce-1920-shutterstock-2728233787.jpg" class="attachment-full size-full wp-post-image" alt="Agentic-Commerce" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/08/Agentic-Commerce-1920-shutterstock-2728233787.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/08/Agentic-Commerce-1920-shutterstock-2728233787-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/08/Agentic-Commerce-1920-shutterstock-2728233787-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/08/Agentic-Commerce-1920-shutterstock-2728233787-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/08/Agentic-Commerce-1920-shutterstock-2728233787-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="KI kann kaufen. Aber kann die Zahlungsinfrastruktur mithalten? 1"></p>
    Die Verbreitung von Agentic Commerce schreitet derzeit in Deutschland und Österreich voran. 

<p>Tags: <a href="https://www.it-daily.net/thema/e-commerce">#e-Commerce</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum KI-Modelle aus China so viel günstiger sind als ChatGPT]]></title>
<description><![CDATA[Der Beitrag Warum KI-Modelle aus China so viel günstiger sind als ChatGPT erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Obwohl sie sich leistungstechnisch auf einem Niveau zu bewegen scheinen, kosten Spra...]]></description>
<link>https://tsecurity.de/de/3707270/it-nachrichten/warum-ki-modelle-aus-china-so-viel-guenstiger-sind-als-chatgpt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707270/it-nachrichten/warum-ki-modelle-aus-china-so-viel-guenstiger-sind-als-chatgpt/</guid>
<pubDate>Thu, 06 Aug 2026 05:53:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/06/warum-chinas-ki-modelle-so-viel-guenstiger-sind/">Warum KI-Modelle aus China so viel günstiger sind als ChatGPT</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Obwohl sie sich leistungstechnisch auf einem Niveau zu bewegen scheinen, kosten Sprachmodelle aus China oft deutlich weniger als ihre Konkurrenz aus den USA. Wie ist das möglich? Tatsächlich steckt hinter dem Preisgefälle eine ganze Reihe an Faktoren. Bei neuen Technologien zählt anfangs oft noch die reine Leistung: Wer das beste Produkt anbietet, gewinnt. Doch relativ […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/08/06/warum-chinas-ki-modelle-so-viel-guenstiger-sind/">Warum KI-Modelle aus China so viel günstiger sind als ChatGPT</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Elektroauto-Fahrer: „Diese Leute sind verrückt“]]></title>
<description><![CDATA[Der US-Markt ist seit dem Amtsantritt von Donald Trump deutlich unattraktiver für Elektroautos geworden und man merkt, dass sich daher auch einige Marken davon distanziert haben und in den USA …]]></description>
<link>https://tsecurity.de/de/3707269/it-nachrichten/elektroauto-fahrer-diese-leute-sind-verrueckt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707269/it-nachrichten/elektroauto-fahrer-diese-leute-sind-verrueckt/</guid>
<pubDate>Thu, 06 Aug 2026 05:53:22 +0200</pubDate>
<content:encoded><![CDATA[<img width="1600" height="1100" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/tesla-model-y-2026-rot-header.jpg?fit=1600%2C1100&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/tesla-model-y-2026-rot-header.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/07/tesla-model-y-2026-rot-header.jpg?resize=690%2C474&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Der US-Markt ist seit dem Amtsantritt von Donald Trump deutlich unattraktiver für Elektroautos geworden und man merkt, dass sich daher auch einige Marken davon distanziert haben und in den USA …]]></content:encoded>
</item>
<item>
<title><![CDATA[Hubschrauber werfen 9.000 alte Weihnachtsbäume über Sumpfgebiet ab – aus gutem Grund]]></title>
<description><![CDATA[New Orleans sammelt seit Jahren ausrangierte Weihnachtsbäume und wirft sie mit dem Hubschrauber gezielt in die Feuchtgebiete Louisianas. Und das nicht, um sie zu entsorgen.
																					Dieser Artikel wurde einsortiert unter 
																	Internet & Netzwelt.]]></description>
<link>https://tsecurity.de/de/3707268/it-nachrichten/hubschrauber-werfen-9000-alte-weihnachtsbaeume-ueber-sumpfgebiet-ab-aus-gutem-grund/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707268/it-nachrichten/hubschrauber-werfen-9000-alte-weihnachtsbaeume-ueber-sumpfgebiet-ab-aus-gutem-grund/</guid>
<pubDate>Thu, 06 Aug 2026 05:52:36 +0200</pubDate>
<content:encoded><![CDATA[New Orleans sammelt seit Jahren ausrangierte Weihnachtsbäume und wirft sie mit dem Hubschrauber gezielt in die Feuchtgebiete Louisianas. Und das nicht, um sie zu entsorgen.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/internet/internet-netzwelt.html">Internet &amp; Netzwelt</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome does not remember the last download path]]></title>
<description><![CDATA[Google Chrome and other web browsers usually remember the last download location if the default save location is disabled. This also applies to apps or software we install on our system. However, some users are complaining that they have to select the download location in Chrome every time they s...]]></description>
<link>https://tsecurity.de/de/3707265/windows-tipps/chrome-does-not-remember-the-last-download-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707265/windows-tipps/chrome-does-not-remember-the-last-download-path/</guid>
<pubDate>Thu, 06 Aug 2026 05:46:21 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="700" height="394" src="https://www.thewindowsclub.com/wp-content/uploads/2026/07/Chrome-does-not-remember-last-download-path.png" class="attachment-full size-full wp-post-image" alt="Chrome does not remember last download path" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/07/Chrome-does-not-remember-last-download-path.png 700w, https://www.thewindowsclub.com/wp-content/uploads/2026/07/Chrome-does-not-remember-last-download-path-500x281.png 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/07/Chrome-does-not-remember-last-download-path-300x169.png 300w" sizes="(max-width: 700px) 100vw, 700px">Google Chrome and other web browsers usually remember the last download location if the default save location is disabled. This also applies to apps or software we install on our system. However, some users are complaining that they have to select the download location in Chrome every time they save a file from the internet. […]</p>
<p>This article <a href="https://www.thewindowsclub.com/chrome-does-not-remember-the-last-download-path">Chrome does not remember the last download path</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53396 | Linux Kernel up to 7.1.2 Nfsd nfsd4_create_file op_dpacl/op_pacl allocation of resources (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability labeled as very critical has been found in Linux Kernel up to 7.1.2. This affects the function nfsd4_create_file of the component Nfsd. The manipulation of the argument op_dpacl/op_pacl results in allocation of resources.

This vulnerability is cataloged as CVE-2026-53396. The att...]]></description>
<link>https://tsecurity.de/de/3707264/sicherheitsluecken/cve-2026-53396-linux-kernel-up-to-712-nfsd-nfsd4createfile-opdpacloppacl-allocation-of-resources-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707264/sicherheitsluecken/cve-2026-53396-linux-kernel-up-to-712-nfsd-nfsd4createfile-opdpacloppacl-allocation-of-resources-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:45:24 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">very critical</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.1.2</a>. This affects the function <code>nfsd4_create_file</code> of the component <em>Nfsd</em>. The manipulation of the argument <em>op_dpacl/op_pacl</em> results in allocation of resources.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-53396">CVE-2026-53396</a>. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53399 | Linux Kernel up to 6.12.95/6.18.38/7.1.2 Nfsd nfsd4_layout_setlease ls_fence_work use after free (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.12.95/6.18.38/7.1.2. This affects the function nfsd4_layout_setlease of the component Nfsd. The manipulation of the argument ls_fence_work leads to use after free.

This vulnerability is traded as CVE-2...]]></description>
<link>https://tsecurity.de/de/3707263/sicherheitsluecken/cve-2026-53399-linux-kernel-up-to-6129561838712-nfsd-nfsd4layoutsetlease-lsfencework-use-after-free-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707263/sicherheitsluecken/cve-2026-53399-linux-kernel-up-to-6129561838712-nfsd-nfsd4layoutsetlease-lsfencework-use-after-free-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:45:24 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">very critical</a>, has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.95/6.18.38/7.1.2</a>. This affects the function <code>nfsd4_layout_setlease</code> of the component <em>Nfsd</em>. The manipulation of the argument <em>ls_fence_work</em> leads to use after free.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-53399">CVE-2026-53399</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53397 | Linux Kernel up to 7.1.2 Nfsd acl_access/acl_default allocation of resources (Nessus ID 330014 / WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Linux Kernel up to 7.1.2. Affected by this issue is the function nfsaclsvc_decode_setaclargs/nfs3svc_decode_setaclargs of the component Nfsd. Executing a manipulation of the argument acl_access/acl_default can lead to allocation of resources.

T...]]></description>
<link>https://tsecurity.de/de/3707262/sicherheitsluecken/cve-2026-53397-linux-kernel-up-to-712-nfsd-aclaccessacldefault-allocation-of-resources-nessus-id-330014-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707262/sicherheitsluecken/cve-2026-53397-linux-kernel-up-to-712-nfsd-aclaccessacldefault-allocation-of-resources-nessus-id-330014-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:45:24 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.1.2</a>. Affected by this issue is the function <code>nfsaclsvc_decode_setaclargs/nfs3svc_decode_setaclargs</code> of the component <em>Nfsd</em>. Executing a manipulation of the argument <em>acl_access/acl_default</em> can lead to allocation of resources.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-53397">CVE-2026-53397</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53398 | Linux Kernel up to 7.1.2 NFSD nfsd4_decode_secinfo_no_name initialization (Nessus ID 330014 / WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Linux Kernel up to 7.1.2. The affected element is the function nfsd4_decode_secinfo_no_name of the component NFSD. Executing a manipulation can lead to improper initialization.

This vulnerability is tracked as CVE-2026-53398. The att...]]></description>
<link>https://tsecurity.de/de/3707261/sicherheitsluecken/cve-2026-53398-linux-kernel-up-to-712-nfsd-nfsd4decodesecinfononame-initialization-nessus-id-330014-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707261/sicherheitsluecken/cve-2026-53398-linux-kernel-up-to-712-nfsd-nfsd4decodesecinfononame-initialization-nessus-id-330014-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:45:24 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.1.2</a>. The affected element is the function <code>nfsd4_decode_secinfo_no_name</code> of the component <em>NFSD</em>. Executing a manipulation can lead to improper initialization.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-53398">CVE-2026-53398</a>. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53401 | Linux Kernel up to 7.1.2/7.2 Fbdev omapfb_mmap use after free (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Linux Kernel up to 7.1.2/7.2. This vulnerability affects the function omapfb_mmap of the component Fbdev. The manipulation leads to use after free.

This vulnerability is documented as CVE-2026-53401. The attack needs to be performed locall...]]></description>
<link>https://tsecurity.de/de/3707260/sicherheitsluecken/cve-2026-53401-linux-kernel-up-to-71272-fbdev-omapfbmmap-use-after-free-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707260/sicherheitsluecken/cve-2026-53401-linux-kernel-up-to-71272-fbdev-omapfbmmap-use-after-free-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:45:23 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.1.2/7.2</a>. This vulnerability affects the function <code>omapfb_mmap</code> of the component <em>Fbdev</em>. The manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-53401">CVE-2026-53401</a>. The attack needs to be performed locally. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53400 | Linux Kernel up to 6.12.94/6.18.37/7.1.2 I2C Core i2c_get_adapter use after free (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.12.94/6.18.37/7.1.2. This vulnerability affects the function i2c_get_adapter of the component I2C Core. The manipulation results in use after free.

This vulnerability is known as CVE-2026-53400. Attacking l...]]></description>
<link>https://tsecurity.de/de/3707259/sicherheitsluecken/cve-2026-53400-linux-kernel-up-to-6129461837712-i2c-core-i2cgetadapter-use-after-free-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707259/sicherheitsluecken/cve-2026-53400-linux-kernel-up-to-6129461837712-i2c-core-i2cgetadapter-use-after-free-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:45:22 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">very critical</a>, was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.94/6.18.37/7.1.2</a>. This vulnerability affects the function <code>i2c_get_adapter</code> of the component <em>I2C Core</em>. The manipulation results in use after free.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-53400">CVE-2026-53400</a>. Attacking locally is a requirement. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Images of the Sun Show Its Surface In the Finest Detail Yet]]></title>
<description><![CDATA[An anonymous reader quotes a report from the Associated Press: Scientists have captured images of the sun's surface in the finest detail yet, revealing a strange and dynamic facade. It's dangerous to look directly at the sun without proper eye protection. But researchers were able to peek at its ...]]></description>
<link>https://tsecurity.de/de/3707258/it-security-nachrichten/new-images-of-the-sun-show-its-surface-in-the-finest-detail-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707258/it-security-nachrichten/new-images-of-the-sun-show-its-surface-in-the-finest-detail-yet/</guid>
<pubDate>Thu, 06 Aug 2026 05:37:04 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from the Associated Press: Scientists have captured images of the sun's surface in the finest detail yet, revealing a strange and dynamic facade. It's dangerous to look directly at the sun without proper eye protection. But researchers were able to peek at its scorching surface with the help of the National Science Foundation's Daniel K. Inouye Solar Telescope, located on the island of Maui in Hawaii.
 
Scientists originally took the images for a different reason: to fine-tune and test the limits of the telescope. But when they looked at the results, they realized they'd photographed the sun's bright outer shell at higher resolution than ever before. What's more, they saw strange feathery patterns rippling across the surface. "That reminds me of famous paintings, like the swirling skies in Van Gogh's Starry Night," said solar physicist Ruizhu Chen with Stanford University, who was not involved with the new research.
 
Researchers saw ripples of instability on the sun's surface caused by bits of magnetized plasma moving past each other at different speeds -- similar to waves that stir when a gust of wind blows over water. It's a well-known phenomenon that guides how fluids move. This has been glimpsed on Earth and other planets like Jupiter and Saturn, but "it has not been observed ever at that level on the solar surface," according to study co-author Friedrich Woger with the National Solar Observatory. The findings were published Wednesday in the journal Nature.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=New+Images+of+the+Sun+Show+Its+Surface+In+the+Finest+Detail+Yet%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F05%2F2226251%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F05%2F2226251%2Fnew-images-of-the-sun-show-its-surface-in-the-finest-detail-yet%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/08/05/2226251/new-images-of-the-sun-show-its-surface-in-the-finest-detail-yet?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An off-grid AI sounds like a great survival assistant, but is better left to roleplaying the zombie apocalypse]]></title>
<description><![CDATA[Would you rather play Russian roulette with an LLM or put your health and safety in the hands of a professional]]></description>
<link>https://tsecurity.de/de/3707257/it-nachrichten/an-off-grid-ai-sounds-like-a-great-survival-assistant-but-is-better-left-to-roleplaying-the-zombie-apocalypse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707257/it-nachrichten/an-off-grid-ai-sounds-like-a-great-survival-assistant-but-is-better-left-to-roleplaying-the-zombie-apocalypse/</guid>
<pubDate>Thu, 06 Aug 2026 05:36:45 +0200</pubDate>
<content:encoded><![CDATA[Would you rather play Russian roulette with an LLM or put your health and safety in the hands of a professional]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta wants to get inside your terminal with its new coding agent]]></title>
<description><![CDATA[Muse Code showcases Muse Spark's fresh software engineering chops]]></description>
<link>https://tsecurity.de/de/3707256/it-nachrichten/meta-wants-to-get-inside-your-terminal-with-its-new-coding-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707256/it-nachrichten/meta-wants-to-get-inside-your-terminal-with-its-new-coding-agent/</guid>
<pubDate>Thu, 06 Aug 2026 05:36:45 +0200</pubDate>
<content:encoded><![CDATA[Muse Code showcases Muse Spark's fresh software engineering chops]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack]]></title>
<description><![CDATA[It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence]]></description>
<link>https://tsecurity.de/de/3707255/it-nachrichten/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707255/it-nachrichten/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack/</guid>
<pubDate>Thu, 06 Aug 2026 05:36:44 +0200</pubDate>
<content:encoded><![CDATA[It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence]]></content:encoded>
</item>
<item>
<title><![CDATA[Aldi verkauft heute ein Gerät, das jeder mindestens einmal im Haushalt haben sollte]]></title>
<description><![CDATA[Wer seinen Trainingsfortschritt messen will, scheitert oft an ungenauen Daten. Genau da kommt das Gadget von Aldi zum Einsatz.]]></description>
<link>https://tsecurity.de/de/3707254/it-nachrichten/aldi-verkauft-heute-ein-geraet-das-jeder-mindestens-einmal-im-haushalt-haben-sollte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707254/it-nachrichten/aldi-verkauft-heute-ein-geraet-das-jeder-mindestens-einmal-im-haushalt-haben-sollte/</guid>
<pubDate>Thu, 06 Aug 2026 05:36:20 +0200</pubDate>
<content:encoded><![CDATA[Wer seinen Trainingsfortschritt messen will, scheitert oft an ungenauen Daten. Genau da kommt das Gadget von Aldi zum Einsatz.]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Networking Quiz: Test Your ss ip curl dig Knowledge]]></title>
<description><![CDATA[Test your Linux networking knowledge with 10 questions covering TCP/IP, DNS, routing, subnetting, and network troubleshooting from beginner to expert.]]></description>
<link>https://tsecurity.de/de/3707251/linux-tipps/linux-networking-quiz-test-your-ss-ip-curl-dig-knowledge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707251/linux-tipps/linux-networking-quiz-test-your-ss-ip-curl-dig-knowledge/</guid>
<pubDate>Thu, 06 Aug 2026 05:31:42 +0200</pubDate>
<content:encoded><![CDATA[Test your Linux networking knowledge with 10 questions covering TCP/IP, DNS, routing, subnetting, and network troubleshooting from beginner to expert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Das Recht auf Nichterreichbarkeit: Führung durch Vorbild]]></title>
<description><![CDATA[Wenn Führungskräfte am Wochenende E-Mails schreiben, wirkt das als stille Erwartung an das gesamte Team, selbst wenn ausdrücklich keine Antwort verlangt wird.

Tags: #Erreichbarkeit | #Führungskräfte | #Thought Leadership]]></description>
<link>https://tsecurity.de/de/3707249/it-security-nachrichten/das-recht-auf-nichterreichbarkeit-fuehrung-durch-vorbild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707249/it-security-nachrichten/das-recht-auf-nichterreichbarkeit-fuehrung-durch-vorbild/</guid>
<pubDate>Thu, 06 Aug 2026 05:18:35 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2023/07/Urlaub-Arbeit-1920-Shutterstock-2056268816.jpg" class="attachment-full size-full wp-post-image" alt="Arbeit im Urlaub" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2023/07/Urlaub-Arbeit-1920-Shutterstock-2056268816.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2023/07/Urlaub-Arbeit-1920-Shutterstock-2056268816-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2023/07/Urlaub-Arbeit-1920-Shutterstock-2056268816-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2023/07/Urlaub-Arbeit-1920-Shutterstock-2056268816-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2023/07/Urlaub-Arbeit-1920-Shutterstock-2056268816-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Das Recht auf Nichterreichbarkeit: Führung durch Vorbild 1"></p>
    Wenn Führungskräfte am Wochenende E-Mails schreiben, wirkt das als stille Erwartung an das gesamte Team, selbst wenn ausdrücklich keine Antwort verlangt wird.

<p>Tags: <a href="https://www.it-daily.net/thema/erreichbarkeit">#Erreichbarkeit</a> | <a href="https://www.it-daily.net/thema/fuehrungskraefte">#Führungskräfte</a> | <a href="https://www.it-daily.net/thema/thought-leadership">#Thought Leadership</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung, SK Hynix test Chinese chip tools as hedge against US risks]]></title>
<description><![CDATA[Samsung and SK Hynix reportedly tested Chinese AMEC chip tools as a hedge against U.S. export controls, though both companies dispute the report.]]></description>
<link>https://tsecurity.de/de/3707248/it-nachrichten/samsung-sk-hynix-test-chinese-chip-tools-as-hedge-against-us-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707248/it-nachrichten/samsung-sk-hynix-test-chinese-chip-tools-as-hedge-against-us-risks/</guid>
<pubDate>Thu, 06 Aug 2026 05:16:57 +0200</pubDate>
<content:encoded><![CDATA[Samsung and SK Hynix reportedly tested Chinese AMEC chip tools as a hedge against U.S. export controls, though both companies dispute the report.]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Google Assistant auf Mobilgeräten wird im September endgültig abgeschaltet]]></title>
<description><![CDATA[Nächsten Monat ist Schluss mit dem Google Assistant auf Android-Smartphones und Smartwatches mit Wear OS. Dann übernimmt Gemini die persönliche Assistenz.]]></description>
<link>https://tsecurity.de/de/3707247/it-nachrichten/der-google-assistant-auf-mobilgeraeten-wird-im-september-endgueltig-abgeschaltet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707247/it-nachrichten/der-google-assistant-auf-mobilgeraeten-wird-im-september-endgueltig-abgeschaltet/</guid>
<pubDate>Thu, 06 Aug 2026 05:16:48 +0200</pubDate>
<content:encoded><![CDATA[Nächsten Monat ist Schluss mit dem Google Assistant auf Android-Smartphones und Smartwatches mit Wear OS. Dann übernimmt Gemini die persönliche Assistenz.]]></content:encoded>
</item>
<item>
<title><![CDATA[Let Your iPhone Wait on Hold for You with Hold Assist]]></title>
<description><![CDATA[It seems like every time you call any major business, institution, facility, government, or corporate office nowadays, you get placed on hold, often for what seems like an eternity. Nobody likes waiting on hold with the annoying and repetitive hold music, but fortunately the iPhone has a wonderfu...]]></description>
<link>https://tsecurity.de/de/3707244/ios-mac-os/let-your-iphone-wait-on-hold-for-you-with-hold-assist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707244/ios-mac-os/let-your-iphone-wait-on-hold-for-you-with-hold-assist/</guid>
<pubDate>Thu, 06 Aug 2026 05:12:47 +0200</pubDate>
<content:encoded><![CDATA[<p>It seems like every time you call any major business, institution, facility, government, or corporate office nowadays, you get placed on hold, often for what seems like an eternity. Nobody likes waiting on hold with the annoying and repetitive hold music, but fortunately the iPhone has a wonderful solution to being stuck on hold, called ... <a class="read-more" href="https://osxdaily.com/2026/08/05/let-your-iphone-wait-on-hold-for-you-with-hold-assist/">Read More</a></p>
<p>The post <a href="https://osxdaily.com/2026/08/05/let-your-iphone-wait-on-hold-for-you-with-hold-assist/">Let Your iPhone Wait on Hold for You with Hold Assist</a> appeared first on <a href="https://osxdaily.com/">OS X Daily</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Made a Plugin to Fix Quod Libet's Playlist Handling]]></title>
<description><![CDATA[Quod Libet is, as far as I've been able to find, the best native Linux music player. My biggest issue with it was the way playlists are handled. Coming from MusicBee on Windows, my playlists were nicely managed and maintained in a folder, which I could then sync to my other devices automatically ...]]></description>
<link>https://tsecurity.de/de/3707243/linux-tipps/i-made-a-plugin-to-fix-quod-libets-playlist-handling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707243/linux-tipps/i-made-a-plugin-to-fix-quod-libets-playlist-handling/</guid>
<pubDate>Thu, 06 Aug 2026 05:10:56 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Quod Libet is, as far as I've been able to find, the best native Linux music player. My biggest issue with it was the way playlists are handled. Coming from MusicBee on Windows, my playlists were nicely managed and maintained in a folder, which I could then sync to my other devices automatically along with the rest of my music library (via syncthing or whatever you use).</p> <p>By default, Quod Libet has a few glaring issues with playlists:</p> <ul> <li>Playlists can be imported but are only maintained in QL's internal files.</li> <li>A plugin is needed to export playlists, and even with the plugin, you must manually export your playlists every time you add or remove a song, or change the order.</li> <li>When a file has been moved or deleted, Quod Libet has no handling for this by default. It simply ignores that song without giving any type of warning or error.</li> <li>Because of the above issues, syncing your playlists and library with other devices is a very manual pain in the neck.</li> </ul> <p>I vibe-coded a plugin to fix all of the above and found it has vastly improved my experience. Please take a look, and hopefully it helps you as it has helped me.</p> <p><a href="https://github.com/Jukebox-Zulu/Quod-Libet-Playlist-Manager-Plugin">https://github.com/Jukebox-Zulu/Quod-Libet-Playlist-Manager-Plugin</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/JukeboxZulu"> /u/JukeboxZulu </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1vgsc18/i_made_a_plugin_to_fix_quod_libets_playlist/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vgsc18/i_made_a_plugin_to_fix_quod_libets_playlist/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 will run better because of the Apple effect, says IDC]]></title>
<description><![CDATA[IDC analyst Jitesh Ubrani says vendors will respond to Apple's $599 MacBook Neo with new silicon, aggressive pricing, and a more efficient Windows 11. Microsoft has already deleted its 32GB RAM docs, launched 8GB Surface devices, and promised RAM optimization by the end of 2026.
The post Windows ...]]></description>
<link>https://tsecurity.de/de/3707242/windows-tipps/windows-11-will-run-better-because-of-the-apple-effect-says-idc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707242/windows-tipps/windows-11-will-run-better-because-of-the-apple-effect-says-idc/</guid>
<pubDate>Thu, 06 Aug 2026 05:08:28 +0200</pubDate>
<content:encoded><![CDATA[<p>IDC analyst Jitesh Ubrani says vendors will respond to Apple's $599 MacBook Neo with new silicon, aggressive pricing, and a more efficient Windows 11. Microsoft has already deleted its 32GB RAM docs, launched 8GB Surface devices, and promised RAM optimization by the end of 2026.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/08/06/windows-11-will-run-better-because-of-the-apple-effect-says-idc/">Windows 11 will run better because of the Apple effect, says IDC</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 will run better because of the Apple effect, says IDC]]></title>
<description><![CDATA[IDC analyst Jitesh Ubrani says vendors will respond to Apple's $599 MacBook Neo with new silicon, aggressive pricing, and a more efficient Windows 11. Microsoft has already deleted its 32GB RAM docs, launched 8GB Surface devices, and promised RAM optimization by the end of 2026.
The post Windows ...]]></description>
<link>https://tsecurity.de/de/3707241/windows-tipps/windows-11-will-run-better-because-of-the-apple-effect-says-idc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707241/windows-tipps/windows-11-will-run-better-because-of-the-apple-effect-says-idc/</guid>
<pubDate>Thu, 06 Aug 2026 05:08:28 +0200</pubDate>
<content:encoded><![CDATA[<p>IDC analyst Jitesh Ubrani says vendors will respond to Apple's $599 MacBook Neo with new silicon, aggressive pricing, and a more efficient Windows 11. Microsoft has already deleted its 32GB RAM docs, launched 8GB Surface devices, and promised RAM optimization by the end of 2026.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/08/06/windows-11-will-run-better-because-of-the-apple-effect-says-idc/">Windows 11 will run better because of the Apple effect, says IDC</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18968 | ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f /tags.php day cross site scripting (EUVD-2026-53683)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting.

This vulnerability is listed as C...]]></description>
<link>https://tsecurity.de/de/3707240/sicherheitsluecken/cve-2026-18968-ttttonyhe-oblog-up-to-3ca6a45a2fcc81f6086751d8af124658720e8f8f-tagsphp-day-cross-site-scripting-euvd-2026-53683/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707240/sicherheitsluecken/cve-2026-18968-ttttonyhe-oblog-up-to-3ca6a45a2fcc81f6086751d8af124658720e8f8f-tagsphp-day-cross-site-scripting-euvd-2026-53683/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/ttttonyhe:oblog">ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f</a>. This issue affects some unknown processing of the file <em>/tags.php</em>. Such manipulation of the argument <em>day</em> leads to cross site scripting.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-18968">CVE-2026-18968</a>. The attack may be performed from remote. In addition, an exploit is available.

This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67531 | Agentfront FrontMCP up to 1.5.6 Codecall Execute getTool sandbox (EUVD-2026-53684)]]></title>
<description><![CDATA[A vulnerability marked as very critical has been reported in Agentfront FrontMCP up to 1.5.6. This impacts the function getTool of the component Codecall Execute. Performing a manipulation results in sandbox issue.

This vulnerability is cataloged as CVE-2026-67531. It is possible to initiate the...]]></description>
<link>https://tsecurity.de/de/3707239/sicherheitsluecken/cve-2026-67531-agentfront-frontmcp-up-to-156-codecall-execute-gettool-sandbox-euvd-2026-53684/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707239/sicherheitsluecken/cve-2026-67531-agentfront-frontmcp-up-to-156-codecall-execute-gettool-sandbox-euvd-2026-53684/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">very critical</a> has been reported in <a href="https://vuldb.com/product/agentfront:frontmcp">Agentfront FrontMCP up to 1.5.6</a>. This impacts the function <code>getTool</code> of the component <em>Codecall Execute</em>. Performing a manipulation results in sandbox issue.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-67531">CVE-2026-67531</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-19026 | HDF Group HDF5 up to 2.3.0 N-Bit Filter H5Znbit.c H5Z__filter_nbit null pointer dereference (EUVD-2026-53685)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in HDF Group HDF5 up to 2.3.0. The impacted element is the function H5Z__filter_nbit of the file H5Znbit.c of the component N-Bit Filter. This manipulation causes null pointer dereference.

This vulnerability is tracked as CVE-2026-19026...]]></description>
<link>https://tsecurity.de/de/3707238/sicherheitsluecken/cve-2026-19026-hdf-group-hdf5-up-to-230-n-bit-filter-h5znbitc-h5zfilternbit-null-pointer-dereference-euvd-2026-53685/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707238/sicherheitsluecken/cve-2026-19026-hdf-group-hdf5-up-to-230-n-bit-filter-h5znbitc-h5zfilternbit-null-pointer-dereference-euvd-2026-53685/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/hdf_group:hdf5">HDF Group HDF5 up to 2.3.0</a>. The impacted element is the function <code>H5Z__filter_nbit</code> of the file <em>H5Znbit.c</em> of the component <em>N-Bit Filter</em>. This manipulation causes null pointer dereference.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-19026">CVE-2026-19026</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-19025 | HDF Group HDF5 up to 2.3.0 Chunk Layout Validation H5Olayout.c H5O__layout_decode divide by zero (EUVD-2026-53686)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in HDF Group HDF5 up to 2.3.0. The affected element is the function H5O__layout_decode of the file H5Olayout.c of the component Chunk Layout Validation. The manipulation results in divide by zero.

This vulnerability is identified as ...]]></description>
<link>https://tsecurity.de/de/3707237/sicherheitsluecken/cve-2026-19025-hdf-group-hdf5-up-to-230-chunk-layout-validation-h5olayoutc-h5olayoutdecode-divide-by-zero-euvd-2026-53686/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707237/sicherheitsluecken/cve-2026-19025-hdf-group-hdf5-up-to-230-chunk-layout-validation-h5olayoutc-h5olayoutdecode-divide-by-zero-euvd-2026-53686/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/hdf_group:hdf5">HDF Group HDF5 up to 2.3.0</a>. The affected element is the function <code>H5O__layout_decode</code> of the file <em>H5Olayout.c</em> of the component <em>Chunk Layout Validation</em>. The manipulation results in divide by zero.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-19025">CVE-2026-19025</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67866 | Systerel S2OPC 1.7.3 Client Wrapper buffer overflow (EUVD-2026-53669)]]></title>
<description><![CDATA[A vulnerability was found in Systerel S2OPC 1.7.3 and classified as problematic. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse/SOPC_StaMac_NewDeleteMonitoredItems of the component Client Wrapper. Such manipulation leads to buffer overflow.

This vulnerability is u...]]></description>
<link>https://tsecurity.de/de/3707236/sicherheitsluecken/cve-2026-67866-systerel-s2opc-173-client-wrapper-buffer-overflow-euvd-2026-53669/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707236/sicherheitsluecken/cve-2026-67866-systerel-s2opc-173-client-wrapper-buffer-overflow-euvd-2026-53669/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/systerel:s2opc">Systerel S2OPC 1.7.3</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects the function <code>LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse/SOPC_StaMac_NewDeleteMonitoredItems</code> of the component <em>Client Wrapper</em>. Such manipulation leads to buffer overflow.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-67866">CVE-2026-67866</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-19024 | HDF Group HDF5 up to 2.1.1 H5Pget_fill_value null pointer dereference (EUVD-2026-53660)]]></title>
<description><![CDATA[A vulnerability has been found in HDF Group HDF5 up to 2.1.1 and classified as problematic. Affected by this issue is the function H5Pget_fill_value. This manipulation causes null pointer dereference.

This vulnerability is handled as CVE-2026-19024. The attack can be initiated remotely. There is...]]></description>
<link>https://tsecurity.de/de/3707235/sicherheitsluecken/cve-2026-19024-hdf-group-hdf5-up-to-211-h5pgetfillvalue-null-pointer-dereference-euvd-2026-53660/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707235/sicherheitsluecken/cve-2026-19024-hdf-group-hdf5-up-to-211-h5pgetfillvalue-null-pointer-dereference-euvd-2026-53660/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/hdf_group:hdf5">HDF Group HDF5 up to 2.1.1</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is the function <code>H5Pget_fill_value</code>. This manipulation causes null pointer dereference.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-19024">CVE-2026-19024</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-19023 | HDF Group HDF5 up to 2.1.0 h5dump render_bin_output null pointer dereference (EUVD-2026-53659)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in HDF Group HDF5 up to 2.1.0. Affected by this vulnerability is the function render_bin_output of the component h5dump. The manipulation results in null pointer dereference.

This vulnerability is known as CVE-2026-19023. It is poss...]]></description>
<link>https://tsecurity.de/de/3707234/sicherheitsluecken/cve-2026-19023-hdf-group-hdf5-up-to-210-h5dump-renderbinoutput-null-pointer-dereference-euvd-2026-53659/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707234/sicherheitsluecken/cve-2026-19023-hdf-group-hdf5-up-to-210-h5dump-renderbinoutput-null-pointer-dereference-euvd-2026-53659/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/hdf_group:hdf5">HDF Group HDF5 up to 2.1.0</a>. Affected by this vulnerability is the function <code>render_bin_output</code> of the component <em>h5dump</em>. The manipulation results in null pointer dereference.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-19023">CVE-2026-19023</a>. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67867 | Systerel S2OPC 1.7.3 Alarm/Conditions Wrapper buffer overflow (EUVD-2026-53670)]]></title>
<description><![CDATA[A vulnerability was found in Systerel S2OPC 1.7.3. It has been classified as critical. This vulnerability affects unknown code of the component Alarm/Conditions Wrapper. Performing a manipulation results in buffer overflow.

This vulnerability was named CVE-2026-67867. The attack may be initiated...]]></description>
<link>https://tsecurity.de/de/3707233/sicherheitsluecken/cve-2026-67867-systerel-s2opc-173-alarmconditions-wrapper-buffer-overflow-euvd-2026-53670/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707233/sicherheitsluecken/cve-2026-67867-systerel-s2opc-173-alarmconditions-wrapper-buffer-overflow-euvd-2026-53670/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/systerel:s2opc">Systerel S2OPC 1.7.3</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the component <em>Alarm/Conditions Wrapper</em>. Performing a manipulation results in buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-67867">CVE-2026-67867</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53389 | Linux Kernel up to 6.12.94/6.18.37/7.1.2 Tcp Ao net/tcp_ao.c tcp_ao_delete_key use after free (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.12.94/6.18.37/7.1.2. It has been declared as very critical. This issue affects the function tcp_ao_delete_key of the file net/tcp_ao.c of the component Tcp Ao. Such manipulation leads to use after free.

This vulnerability is referenced as CVE-202...]]></description>
<link>https://tsecurity.de/de/3707232/sicherheitsluecken/cve-2026-53389-linux-kernel-up-to-6129461837712-tcp-ao-nettcpaoc-tcpaodeletekey-use-after-free-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707232/sicherheitsluecken/cve-2026-53389-linux-kernel-up-to-6129461837712-tcp-ao-nettcpaoc-tcpaodeletekey-use-after-free-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:59 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.94/6.18.37/7.1.2</a>. It has been declared as <a href="https://vuldb.com/kb/risk">very critical</a>. This issue affects the function <code>tcp_ao_delete_key</code> of the file <em>net/tcp_ao.c</em> of the component <em>Tcp Ao</em>. Such manipulation leads to use after free.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-53389">CVE-2026-53389</a>. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53390 | Linux Kernel up to 7.1.2 Ksmbd smb_check_perm_dacl out-of-bounds (Nessus ID 330014 / WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.1.176/6.6.143/6.12.94/6.18.37/7.1.2. It has been rated as critical. Impacted is the function smb_check_perm_dacl of the component Ksmbd. Performing a manipulation results in out-of-bounds read.

This vulnerability is identified as CVE-2026-53390. ...]]></description>
<link>https://tsecurity.de/de/3707231/sicherheitsluecken/cve-2026-53390-linux-kernel-up-to-712-ksmbd-smbcheckpermdacl-out-of-bounds-nessus-id-330014-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707231/sicherheitsluecken/cve-2026-53390-linux-kernel-up-to-712-ksmbd-smbcheckpermdacl-out-of-bounds-nessus-id-330014-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:58 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.1.176/6.6.143/6.12.94/6.18.37/7.1.2</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is the function <code>smb_check_perm_dacl</code> of the component <em>Ksmbd</em>. Performing a manipulation results in out-of-bounds read.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-53390">CVE-2026-53390</a>. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53392 | Linux Kernel up to 6.12.95/6.18.37/7.1.2 Flexfiles ff_layout_alloc_lseg fh_count null pointer dereference (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 6.12.95/6.18.37/7.1.2. Affected is the function ff_layout_alloc_lseg of the component Flexfiles. Such manipulation of the argument fh_count leads to null pointer dereference.

This vulnerability is documented as CVE-2...]]></description>
<link>https://tsecurity.de/de/3707230/sicherheitsluecken/cve-2026-53392-linux-kernel-up-to-6129561837712-flexfiles-fflayoutalloclseg-fhcount-null-pointer-dereference-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707230/sicherheitsluecken/cve-2026-53392-linux-kernel-up-to-6129561837712-flexfiles-fflayoutalloclseg-fhcount-null-pointer-dereference-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:57 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.95/6.18.37/7.1.2</a>. Affected is the function <code>ff_layout_alloc_lseg</code> of the component <em>Flexfiles</em>. Such manipulation of the argument <em>fh_count</em> leads to null pointer dereference.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-53392">CVE-2026-53392</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53393 | Linux Kernel up to 6.12.94/6.18.37/7.1.2 Nfsd nfsd_vfs_write/nfsd_commit writeverf (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Linux Kernel up to 6.12.94/6.18.37/7.1.2. The impacted element is the function nfsd_vfs_write/nfsd_commit of the component Nfsd. The manipulation of the argument writeverf leads to an unknown weakness.

This vulnerability is listed as...]]></description>
<link>https://tsecurity.de/de/3707229/sicherheitsluecken/cve-2026-53393-linux-kernel-up-to-6129461837712-nfsd-nfsdvfswritenfsdcommit-writeverf-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707229/sicherheitsluecken/cve-2026-53393-linux-kernel-up-to-6129461837712-nfsd-nfsdvfswritenfsdcommit-writeverf-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 05:07:56 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.94/6.18.37/7.1.2</a>. The impacted element is the function <code>nfsd_vfs_write/nfsd_commit</code> of the component <em>Nfsd</em>. The manipulation of the argument <em>writeverf</em> leads to an unknown weakness.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-53393">CVE-2026-53393</a>. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome: 1.442 Sicherheitslücken in drei Releases – Google beschleunigt Fixes und Patching]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Google hat für Chrome gleich drei aktuelle Releases insgesamt 1.442 Sicherheitslücken behoben, darunter 370 Fehler im Patch für Chrome 151. Besonders brisant sind sieben als kritisch eingestufte Schwachstellen. Im Umfeld von KI-gestützter Schwachstellenanalyse verknappt Goo...]]></description>
<link>https://tsecurity.de/de/3707228/it-security-nachrichten/chrome-1442-sicherheitsluecken-in-drei-releases-google-beschleunigt-fixes-und-patching/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707228/it-security-nachrichten/chrome-1442-sicherheitsluecken-in-drei-releases-google-beschleunigt-fixes-und-patching/</guid>
<pubDate>Thu, 06 Aug 2026 05:03:34 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-chrome-sicherheitsluecken-dynamisches-patching.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-chrome-sicherheitsluecken-dynamisches-patching.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-chrome-sicherheitsluecken-dynamisches-patching-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-chrome-sicherheitsluecken-dynamisches-patching-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-chrome-sicherheitsluecken-dynamisches-patching-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-chrome-sicherheitsluecken-dynamisches-patching-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-chrome-sicherheitsluecken-dynamisches-patching-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Google hat für Chrome gleich drei aktuelle Releases insgesamt 1.442 Sicherheitslücken behoben, darunter 370 Fehler im Patch für Chrome 151. Besonders brisant sind sieben als kritisch eingestufte Schwachstellen. Im Umfeld von KI-gestützter Schwachstellenanalyse verknappt Google zudem die Zeit zwischen Entdeckung und öffentlicher Beschreibung, während es dynamisches Patching ohne Neustart in Pilotvorhaben […]</p>
<div><a href="https://www.it-boltwise.de/chrome-1-442-sicherheitsluecken-in-drei-releases-google-beschleunigt-fixes-und-patching.html">... den vollständigen Artikel <strong>»Chrome: 1.442 Sicherheitslücken in drei Releases – Google beschleunigt Fixes und Patching«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/chrome-1-442-sicherheitsluecken-in-drei-releases-google-beschleunigt-fixes-und-patching.html">Chrome: 1.442 Sicherheitslücken in drei Releases – Google beschleunigt Fixes und Patching</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Is Wayland and Why Linux Desktops Already Switched]]></title>
<description><![CDATA[Wayland replaced X11 as Linux's display protocol. Learn what Wayland is, why it matters, which desktops use it, and how to check if you are running it.]]></description>
<link>https://tsecurity.de/de/3707215/linux-tipps/what-is-wayland-and-why-linux-desktops-already-switched/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707215/linux-tipps/what-is-wayland-and-why-linux-desktops-already-switched/</guid>
<pubDate>Thu, 06 Aug 2026 04:52:14 +0200</pubDate>
<content:encoded><![CDATA[Wayland replaced X11 as Linux's display protocol. Learn what Wayland is, why it matters, which desktops use it, and how to check if you are running it.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: 5.13.0-alpha.20260806013952]]></title>
<description><![CDATA[Matomo 5.13.0-alpha.20260806013952 (Pre-release)
We recommend to read this FAQ before using a pre-release in a production environment.
Please use the attached archives for installing or updating Matomo.
The source code download is only meant for developers and will require extra work to install i...]]></description>
<link>https://tsecurity.de/de/3707214/downloads/github-5130-alpha20260806013952/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707214/downloads/github-5130-alpha20260806013952/</guid>
<pubDate>Thu, 06 Aug 2026 04:50:04 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>Matomo 5.13.0-alpha.20260806013952 (Pre-release)</h2>
<p>We recommend to read <a href="https://matomo.org/faq/how-to-update/faq_159/" rel="nofollow">this FAQ</a> before using a pre-release in a production environment.</p>
<p>Please use the attached archives for installing or updating Matomo.<br>
The source code download is only meant for developers and will require extra work to install it.</p>
<ul>
<li>Latest stable production release can be found at <a href="https://matomo.org/download/" rel="nofollow">https://matomo.org/download/</a> (<a href="https://matomo.org/docs/installation/" rel="nofollow">learn more</a>) (recommended)</li>
<li>Beta and Release Candidate releases can be found at <a href="https://builds.matomo.org/" rel="nofollow">https://builds.matomo.org/</a> (<a href="https://matomo.org/faq/how-to-update/faq_159/" rel="nofollow">learn more</a>)</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18974 | heshengtao super-agent-party up to 0.4.1 execute_tool_manually Endpoint server.py get_file_content tool_name/tool_params information disclosure (EUVD-2026-53695)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in informat...]]></description>
<link>https://tsecurity.de/de/3707213/sicherheitsluecken/cve-2026-18974-heshengtao-super-agent-party-up-to-041-executetoolmanually-endpoint-serverpy-getfilecontent-toolnametoolparams-information-disclosure-euvd-2026-53695/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707213/sicherheitsluecken/cve-2026-18974-heshengtao-super-agent-party-up-to-041-executetoolmanually-endpoint-serverpy-getfilecontent-toolnametoolparams-information-disclosure-euvd-2026-53695/</guid>
<pubDate>Thu, 06 Aug 2026 04:48:43 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/heshengtao:super-agent-party">heshengtao super-agent-party up to 0.4.1</a>. This affects the function <code>get_file_content</code> of the file <em>server.py</em> of the component <em>execute_tool_manually Endpoint</em>. The manipulation of the argument <em>tool_name/tool_params</em> results in information disclosure.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-18974">CVE-2026-18974</a>. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-6879 | PSF Python up to 3.14.x XPath Element.findall/Element.iterfind/Element.find resource consumption (EUVD-2026-49850)]]></title>
<description><![CDATA[A vulnerability has been found in PSF Python up to 3.14.x and classified as problematic. This affects the function Element.findall/Element.iterfind/Element.find of the component XPath. The manipulation leads to resource consumption.

This vulnerability is uniquely identified as CVE-2026-6879. The...]]></description>
<link>https://tsecurity.de/de/3707212/sicherheitsluecken/cve-2026-6879-psf-python-up-to-314x-xpath-elementfindallelementiterfindelementfind-resource-consumption-euvd-2026-49850/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707212/sicherheitsluecken/cve-2026-6879-psf-python-up-to-314x-xpath-elementfindallelementiterfindelementfind-resource-consumption-euvd-2026-49850/</guid>
<pubDate>Thu, 06 Aug 2026 04:48:42 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/psf:python">PSF Python up to 3.14.x</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects the function <code>Element.findall/Element.iterfind/Element.find</code> of the component <em>XPath</em>. The manipulation leads to resource consumption.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-6879">CVE-2026-6879</a>. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18973 | heshengtao super-agent-party up to 0.4.1 extension_proxy Route server.py sanitize_proxy_url server-side request forgery (EUVD-2026-53694)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request fo...]]></description>
<link>https://tsecurity.de/de/3707211/sicherheitsluecken/cve-2026-18973-heshengtao-super-agent-party-up-to-041-extensionproxy-route-serverpy-sanitizeproxyurl-server-side-request-forgery-euvd-2026-53694/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707211/sicherheitsluecken/cve-2026-18973-heshengtao-super-agent-party-up-to-041-extensionproxy-route-serverpy-sanitizeproxyurl-server-side-request-forgery-euvd-2026-53694/</guid>
<pubDate>Thu, 06 Aug 2026 04:48:41 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/heshengtao:super-agent-party">heshengtao super-agent-party up to 0.4.1</a>. The impacted element is the function <code>sanitize_proxy_url</code> of the file <em>server.py</em> of the component <em>extension_proxy Route</em>. The manipulation of the argument <em>url</em> leads to server-side request forgery.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-18973">CVE-2026-18973</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18970 | Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617 findAll Name sql injection (EUVD-2026-53697)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection.

This vulnera...]]></description>
<link>https://tsecurity.de/de/3707210/sicherheitsluecken/cve-2026-18970-rongzhitong-visual-integrated-command-and-dispatch-platform-up-to-20260617-findall-name-sql-injection-euvd-2026-53697/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707210/sicherheitsluecken/cve-2026-18970-rongzhitong-visual-integrated-command-and-dispatch-platform-up-to-20260617-findall-name-sql-injection-euvd-2026-53697/</guid>
<pubDate>Thu, 06 Aug 2026 04:47:55 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/rongzhitong:visual_integrated_command_and_dispatch_platform">Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617</a>. The affected element is an unknown function of the file <em>/dm/dispatch/user/findAll</em>. Executing a manipulation of the argument <em>Name</em> can lead to sql injection.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-18970">CVE-2026-18970</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67872 | Systerel S2OPC 1.7.3 Queue denial of service (EUVD-2026-53680)]]></title>
<description><![CDATA[A vulnerability has been found in Systerel S2OPC 1.7.3 and classified as problematic. This issue affects some unknown processing of the component Queue. Performing a manipulation results in denial of service.

This vulnerability is known as CVE-2026-67872. Remote exploitation of the attack is pos...]]></description>
<link>https://tsecurity.de/de/3707209/sicherheitsluecken/cve-2026-67872-systerel-s2opc-173-queue-denial-of-service-euvd-2026-53680/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707209/sicherheitsluecken/cve-2026-67872-systerel-s2opc-173-queue-denial-of-service-euvd-2026-53680/</guid>
<pubDate>Thu, 06 Aug 2026 04:47:33 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/systerel:s2opc">Systerel S2OPC 1.7.3</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>Queue</em>. Performing a manipulation results in denial of service.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-67872">CVE-2026-67872</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67870 | open62541 1.5.5 AddReferences ua_services_nodemanagement.c input validation (EUVD-2026-53681)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in open62541 1.5.5. This vulnerability affects unknown code of the file src/server/ua_services_nodemanagement.c of the component AddReferences. Such manipulation leads to improper input validation.

This vulnerability is traded as CVE-2...]]></description>
<link>https://tsecurity.de/de/3707208/sicherheitsluecken/cve-2026-67870-open62541-155-addreferences-uaservicesnodemanagementc-input-validation-euvd-2026-53681/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707208/sicherheitsluecken/cve-2026-67870-open62541-155-addreferences-uaservicesnodemanagementc-input-validation-euvd-2026-53681/</guid>
<pubDate>Thu, 06 Aug 2026 04:47:00 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/open62541">open62541 1.5.5</a>. This vulnerability affects unknown code of the file <em>src/server/ua_services_nodemanagement.c</em> of the component <em>AddReferences</em>. Such manipulation leads to improper input validation.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-67870">CVE-2026-67870</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67869 | open62541 up to 1.5.4 buffer overflow (EUVD-2026-53682)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in open62541 up to 1.5.4. Affected by this vulnerability is an unknown functionality. The manipulation leads to buffer overflow.

This vulnerability is documented as CVE-2026-67869. The attack can be initiated remotely. There is not any exp...]]></description>
<link>https://tsecurity.de/de/3707207/sicherheitsluecken/cve-2026-67869-open62541-up-to-154-buffer-overflow-euvd-2026-53682/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707207/sicherheitsluecken/cve-2026-67869-open62541-up-to-154-buffer-overflow-euvd-2026-53682/</guid>
<pubDate>Thu, 06 Aug 2026 04:46:20 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/open62541">open62541 up to 1.5.4</a>. Affected by this vulnerability is an unknown functionality. The manipulation leads to buffer overflow.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-67869">CVE-2026-67869</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-42170 | GIMP DDS ddsread.c load_layer buffer overflow (Nessus ID 332762)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in GIMP. This vulnerability affects the function load_layer of the file ddsread.c of the component DDS. The manipulation results in buffer overflow.

This vulnerability is known as CVE-2026-42170. It is possible to launch the attack remote...]]></description>
<link>https://tsecurity.de/de/3707206/sicherheitsluecken/cve-2026-42170-gimp-dds-ddsreadc-loadlayer-buffer-overflow-nessus-id-332762/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707206/sicherheitsluecken/cve-2026-42170-gimp-dds-ddsreadc-loadlayer-buffer-overflow-nessus-id-332762/</guid>
<pubDate>Thu, 06 Aug 2026 04:46:06 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/gimp">GIMP</a>. This vulnerability affects the function <code>load_layer</code> of the file <em>ddsread.c</em> of the component <em>DDS</em>. The manipulation results in buffer overflow.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-42170">CVE-2026-42170</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Künstliche Intelligenz: Meta-KI hackt bei Test Firma - Sorgen um Sicherheit wachsen]]></title>
<description><![CDATA[Ein leistungsfähiges Meta-Modell verschafft sich Zugang zum Internet und nutzt eine Sicherheitslücke bei einem Drittanbieter aus. Ähnliche Vorfälle gab es zuletzt bei OpenAI und Anthropic.]]></description>
<link>https://tsecurity.de/de/3707205/it-security-nachrichten/kuenstliche-intelligenz-meta-ki-hackt-bei-test-firma-sorgen-um-sicherheit-wachsen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707205/it-security-nachrichten/kuenstliche-intelligenz-meta-ki-hackt-bei-test-firma-sorgen-um-sicherheit-wachsen/</guid>
<pubDate>Thu, 06 Aug 2026 04:40:49 +0200</pubDate>
<content:encoded><![CDATA[<img src="https://www.sueddeutsche.de/2025/04/15/c7e88c12-3b7f-41cf-aa82-86966ab4c8d0.jpeg?rect=225%2C0%2C3549%2C2662&amp;width=1000&amp;fm=jpg&amp;q=60" data-portal-copyright="Andrej Sokolow/dpa"><p>Ein leistungsfähiges Meta-Modell verschafft sich Zugang zum Internet und nutzt eine Sicherheitslücke bei einem Drittanbieter aus. Ähnliche Vorfälle gab es zuletzt bei OpenAI und Anthropic.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Java 28 starts to take shape]]></title>
<description><![CDATA[Java Development Kit (JDK) 28, a non-LTS (Long-Term Support) or “feature release” of standard Java due in March 2027, has started to take shape. Features listed for JDK 28 now include a preview of value objects, switching the default mode of the Shenandoah garbage collector to generational mode, ...]]></description>
<link>https://tsecurity.de/de/3707204/ai-nachrichten/java-28-starts-to-take-shape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707204/ai-nachrichten/java-28-starts-to-take-shape/</guid>
<pubDate>Thu, 06 Aug 2026 04:36:53 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://openjdk.org/projects/jdk/28/">Java Development Kit (JDK) 28</a>, a non-LTS (Long-Term Support) or “feature release” of standard Java due in March 2027, has started to take shape. Features listed for JDK 28 now include a preview of value objects, switching the default mode of the Shenandoah garbage collector to generational mode, and a preview of strict field initialization in the <a href="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html" data-type="link" data-id="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html">Java Virtual Machine</a> (JVM).</p>



<p class="wp-block-paragraph">As a non-LTS release, JDK 28 will be backed by six months of support by Oracle. </p>



<p class="wp-block-paragraph">The three features currently targeted to JDK 28 include the following:</p>



<ul class="wp-block-list">
<li>Introduce <a href="https://openjdk.org/jeps/401">value objects</a>, which are immutable and lack object identity. Value objects are distinguished by the values of their fields, and can be represented by the JVM in ways that improve performance. A goal of the feature is to give developers a programming model for immutable data in which the <code>==</code> operator, and all other operations, distinguish objects by the values of their fields rather than their identities. Value objects is a <a href="https://openjdk.org/jeps/12">preview language and VM feature</a>.</li>



<li>Switch the default mode of the <a href="https://openjdk.org/jeps/535">Shenandoah Garbage Collector (GC)</a> to the generational mode and deprecate the non-generational mode, with the intent to remove it in a future release. Goals include signaling the intent that future development will focus on generational mode, and reducing the maintenance cost of supporting two different modes. However, it is not a goal to remove non-generational mode at this time.</li>



<li>Introduce <a href="https://openjdk.org/jeps/539">strictly-initialized fields</a> in the JVM. Such fields must be initialized before they are read, thus default values such as <code>0</code> or <code>null</code> are never observed. For strictly-initialized fields that are final, the same value is always observed. A goal is offering designers of JVM-based programming languages a model for field initialization, which has stronger integrity guarantees than the present model. This is a <a href="https://openjdk.org/jeps/12">preview VM feature</a>. </li>
</ul>



<p class="wp-block-paragraph">The predecessor to JDK 28, <a href="https://www.infoworld.com/article/4202901/jdk-27-the-new-features-of-java-27.html">JDK 27</a>, is due September 15. JDK 27 also is a non-LTS release that will be backed by six months of support by Oracle.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude AI + Higgsfield MCP Changes AI Video Generator Automation Forever]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3707203/ai-nachrichten/claude-ai-higgsfield-mcp-changes-ai-video-generator-automation-forever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707203/ai-nachrichten/claude-ai-higgsfield-mcp-changes-ai-video-generator-automation-forever/</guid>
<pubDate>Thu, 06 Aug 2026 04:36:45 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/PrnJB6qfQ1o"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trials and tribulations of trying to get Maya 2022 to run on Mint]]></title>
<description><![CDATA[I have no idea if this is the right space to share, so please forgive me if it isn't. I've recently made the jump from Windows to Mint, and have been slowly going through the process of figuring out how to install all the software I need. I have finally managed to get everything working properly,...]]></description>
<link>https://tsecurity.de/de/3707188/linux-tipps/trials-and-tribulations-of-trying-to-get-maya-2022-to-run-on-mint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707188/linux-tipps/trials-and-tribulations-of-trying-to-get-maya-2022-to-run-on-mint/</guid>
<pubDate>Thu, 06 Aug 2026 04:31:12 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have no idea if this is the right space to share, so please forgive me if it isn't. I've recently made the jump from Windows to Mint, and have been slowly going through the process of figuring out how to install all the software I need.</p> <p>I have finally managed to get everything working properly, so I figured I would share my journey online somewhere, so that it might help some poor soul in the same position as me.</p> <p>(Disclaimer - I've used Claude to summarise everything we went through together, as some of the technical stuff is still genuinely over my head)</p> <p>For starters, I used distrobox to create a Rocky environment to run Maya within, as that is where it is the most "stable" (as stable as Maya can ever be). At first I tried Rocky 9, then realised that Maya 2022 is only supported up to Rocky 8.</p> <h1>1. Installer crashes silently at pkexec / ProcessManager</h1> <p>distrobox enter never creates a real login session, so pkexec/polkit can't authorize anything. Fix — fake pkexec:</p> <p>bash</p> <pre><code>mkdir -p ~/fakebin printf '#!/bin/bash\nexec sudo "$@"\n' &gt; ~/fakebin/pkexec chmod +x ~/fakebin/pkexec echo 'export PATH=~/fakebin:$PATH' &gt;&gt; ~/.bashrc &amp;&amp; source ~/.bashrc1. Installer crashes silently at pkexec / ProcessManager distrobox enter never creates a real login session, so pkexec/polkit can't authorize anything. Fix — fake pkexec: bash mkdir -p ~/fakebin printf '#!/bin/bash\nexec sudo "$@"\n' &gt; ~/fakebin/pkexec chmod +x ~/fakebin/pkexec echo 'export PATH=~/fakebin:$PATH' &gt;&gt; ~/.bashrc &amp;&amp; source ~/.bashrc </code></pre> <h1>2. Endless missing old libraries (libssl.so.10, libpng12, GTK2...)</h1> <p>You're probably on Rocky 9. Maya 2022 only supports EL8. Rebuild on Rocky 8:</p> <p>bash</p> <pre><code>distrobox create --name maya --image quay.io/rockylinux/rockylinux:8 --init --additional-packages systemd </code></pre> <p>This alone kills most dependency issues.</p> <h1>3. Remaining missing libraries</h1> <p>bash</p> <pre><code>sudo dnf install -y epel-release sudo dnf install -y libpng15 libjpeg-turbo libtiff freetype libXpm libXi fontconfig \ libXinerama alsa-lib libXcomposite libXdamage libXrandr libXrender libXtst \ libxkbcommon nspr nss nss-util pciutils-libs libnsl xcb-util-wm xcb-util-image \ xcb-util-renderutil libxkbcommon-x11 libmng libXcursor gtk2 gtk3 at-spi2-atk \ at-spi2-core mesa-libgbm glx-utils compat-openssl10 </code></pre> <p>For anything else: ldd &lt;file&gt;.so | grep "not found" (note: Maya's launcher itself is statically linked, ldd on it just says "not a dynamic executable" — check the actual .so/helper binaries instead).</p> <h1>4. ./Setup exits instantly, no error, exit code 255</h1> <p>Stale lock files from a previous interrupted run. ~/.autodesk and /tmp persist across container rebuilds since ~/ is shared with the host.</p> <p>bash</p> <pre><code>ps aux | grep -iE "setup|installer" | grep -v grep # kill -9 any leftovers rm -f /tmp/autodesk_bs_setup.lock /tmp/autodesk_dda_core.lock rm -rf /tmp/download_dest4. ./Setup exits instantly, no error, exit code 255 Stale lock files from a previous interrupted run. ~/.autodesk and /tmp persist across container rebuilds since ~/ is shared with the host. bash ps aux | grep -iE "setup|installer" | grep -v grep # kill -9 any leftovers rm -f /tmp/autodesk_bs_setup.lock /tmp/autodesk_dda_core.lock rm -rf /tmp/download_dest </code></pre> <h1>5. Installer UI "successfully launched" but no window appears</h1> <p>Missing GTK3/accessibility libs for the installer's own UI process:</p> <p>bash</p> <pre><code>sudo dnf install -y at-spi2-atk gtk3 mesa-libgbm at-spi2-core5. Installer UI "successfully launched" but no window appears Missing GTK3/accessibility libs for the installer's own UI process: bash sudo dnf install -y at-spi2-atk gtk3 mesa-libgbm at-spi2-core </code></pre> <h1>6. Graph Editor won't refresh (redraws only on timeline play / mouse re-entry)</h1> <p>Mesa 23.1.4's radeonsi driver has a repaint-signaling bug on RDNA3 GPUs. Rocky 8 will never get a newer Mesa. Confirmed via LIBGL_ALWAYS_SOFTWARE=1 (works perfectly = hardware GL path is the problem). Fix — VirtualGL, which handles buffer swaps itself instead of trusting the driver:</p> <p>bash</p> <pre><code>sudo dnf install -y epel-release VirtualGL vglrun mayabashsudo dnf install -y epel-release VirtualGL vglrun maya </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/UK_traveller_"> /u/UK_traveller_ </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1vgo0my/trials_and_tribulations_of_trying_to_get_maya/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vgo0my/trials_and_tribulations_of_trying_to_get_maya/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proxmox VE finally suports arm64!]]></title>
<description><![CDATA[submitted by    /u/Pitiful-Welcome-399   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3707187/linux-tipps/proxmox-ve-finally-suports-arm64/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707187/linux-tipps/proxmox-ve-finally-suports-arm64/</guid>
<pubDate>Thu, 06 Aug 2026 04:31:05 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Pitiful-Welcome-399"> /u/Pitiful-Welcome-399 </a> <br> <span><a href="https://forum.proxmox.com/threads/proxmox-virtual-environment-now-available-for-64-bit-arm-arm64.185526/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vgojoi/proxmox_ve_finally_suports_arm64/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distro Fighter: find your Linux distro & desktop]]></title>
<description><![CDATA[I wanted to share a project I built called Distro Fighter (distrofighter.com). It features 32 distros, 16 desktops, a terminal campaign, Versus showdowns and a Distro Wars multiplayer coming soon, all to help users find the right fit Linux distro and desktop and learning Linux while hopefully hav...]]></description>
<link>https://tsecurity.de/de/3707186/linux-tipps/distro-fighter-find-your-linux-distro-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707186/linux-tipps/distro-fighter-find-your-linux-distro-desktop/</guid>
<pubDate>Thu, 06 Aug 2026 04:30:29 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I wanted to share a project I built called Distro Fighter (distrofighter.com). It features 32 distros, 16 desktops, a terminal campaign, Versus showdowns and a Distro Wars multiplayer coming soon, all to help users find the right fit Linux distro and desktop and learning Linux while hopefully having fun.</p> <p>The main focus right now is VS mode just launched tonight, and it is being actively updated. Feel free to check it out, and let me know what you think!: <a href="https://distrofighter.com/versus">https://distrofighter.com/versus</a> 🐧 ❤️ </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/fhritp15"> /u/fhritp15 </a> <br> <span><a href="https://distrofighter.com/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vgp26t/distro_fighter_find_your_linux_distro_desktop/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: Release v0.54.0]]></title>
<description><![CDATA[What's Changed

Changelog for v0.53.0-preview.0 by @gemini-cli-robot in #28507
Changelog for v0.52.0 by @gemini-cli-robot in #28508
chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 by @gemini-cli-robot in #28510
fix(caretaker): sanitize and wrap issue title in untrusted_context ...]]></description>
<link>https://tsecurity.de/de/3707184/downloads/github-release-v0540/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707184/downloads/github-release-v0540/</guid>
<pubDate>Thu, 06 Aug 2026 04:22:37 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>What's Changed</h2>
<ul>
<li>Changelog for v0.53.0-preview.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4952788888" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28507" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28507/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28507">#28507</a></li>
<li>Changelog for v0.52.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4953096720" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28508" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28508/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28508">#28508</a></li>
<li>chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4953713055" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28510" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28510/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28510">#28510</a></li>
<li>fix(caretaker): sanitize and wrap issue title in untrusted_context by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadd28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadd28">@chadd28</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4857767048" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28352" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28352/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28352">#28352</a></li>
<li>chore(caretaker): update vitest to v3.2.4 and add package-lock.json files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadd28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadd28">@chadd28</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4895099126" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28409" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28409/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28409">#28409</a></li>
<li>fix(core): rotate session ID on model fallback to prevent stateful API errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amelidev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amelidev">@amelidev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4933261007" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28469" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28469/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28469">#28469</a></li>
<li>feat(caretaker-triage): post comment before auto-closing issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadd28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadd28">@chadd28</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4897179697" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28411" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28411/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28411">#28411</a></li>
<li>fix(core): enforce HTTPS for GoogleCredentialsAuthProvider to prevent cleartext leakage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amelidev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amelidev">@amelidev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4961806001" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28517" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28517/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28517">#28517</a></li>
<li>fix(core): filter out thought parts from getHistoryTurns when context management is disabled by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4953685047" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28509" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28509/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28509">#28509</a></li>
<li>fix(a2a-server): normalize CRLF line endings to LF in getProposedContent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4972416977" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28531" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28531/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28531">#28531</a></li>
<li>fix(core): enforce explicit tag length and validation in file keychain by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4963548680" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28523" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28523/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28523">#28523</a></li>
<li>chore/release: bump version to 0.54.0-nightly.20260728.gbef611950 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4993889381" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28552" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28552/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28552">#28552</a></li>
<li>feat(pr-generator-db): implement Firestore concurrency dual-locking and test ingestion utilities by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joneba-google/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joneba-google">@joneba-google</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4913845175" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28432" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28432/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28432">#28432</a></li>
<li>feat(pr-generator-agent): implement Antigravity agent runner and prompt templates … by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joneba-google/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joneba-google">@joneba-google</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4914013979" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28434" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28434/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28434">#28434</a></li>
<li>fix(core): skip merged function-response turns when finding the active loop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adamfweidman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adamfweidman">@adamfweidman</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5002115368" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28565" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28565/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28565">#28565</a></li>
<li>fix(patch): cherry-pick <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/google-gemini/gemini-cli/commit/f47d6c6f7a1308d81f9f57acf7d279f0928c5249/hovercard" href="https://github.com/google-gemini/gemini-cli/commit/f47d6c6f7a1308d81f9f57acf7d279f0928c5249">f47d6c6</a> to release/v0.54.0-preview.0-pr-28566 to patch version v0.54.0-preview.0 and create version 0.54.0-preview.1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5032781027" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28609" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28609/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28609">#28609</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.53.1...v0.54.0">v0.53.1...v0.54.0</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DuckDuckGo's new iPhone feature is a privacy win - I recommend getting it now]]></title>
<description><![CDATA[The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.]]></description>
<link>https://tsecurity.de/de/3707183/hacking/duckduckgos-new-iphone-feature-is-a-privacy-win-i-recommend-getting-it-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707183/hacking/duckduckgos-new-iphone-feature-is-a-privacy-win-i-recommend-getting-it-now/</guid>
<pubDate>Thu, 06 Aug 2026 04:18:18 +0200</pubDate>
<content:encoded><![CDATA[The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude AI + Higgsfield MCP Changes AI Video Generator Automation Forever]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3707182/it-security-video/claude-ai-higgsfield-mcp-changes-ai-video-generator-automation-forever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707182/it-security-video/claude-ai-higgsfield-mcp-changes-ai-video-generator-automation-forever/</guid>
<pubDate>Thu, 06 Aug 2026 04:09:53 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/PrnJB6qfQ1o"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inter-Con Security – 276,114 breached accounts]]></title>
<description><![CDATA[In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was…
Read more →
The post Inter-Con Security – 276,114 breached accounts appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3707181/it-security-nachrichten/inter-con-security-276114-breached-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707181/it-security-nachrichten/inter-con-security-276114-breached-accounts/</guid>
<pubDate>Thu, 06 Aug 2026 04:08:26 +0200</pubDate>
<content:encoded><![CDATA[<p>In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/inter-con-security-276114-breached-accounts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/inter-con-security-276114-breached-accounts/">Inter-Con Security – 276,114 breached accounts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)]]></title>
<description><![CDATA[(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></description>
<link>https://tsecurity.de/de/3707180/it-security-nachrichten/isc-stormcast-for-thursday-august-6th-2026-httpsiscsansedupodcastdetail10040-thu-aug-6th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707180/it-security-nachrichten/isc-stormcast-for-thursday-august-6th-2026-httpsiscsansedupodcastdetail10040-thu-aug-6th/</guid>
<pubDate>Thu, 06 Aug 2026 04:08:22 +0200</pubDate>
<content:encoded><![CDATA[(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack]]></title>
<description><![CDATA[It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence]]></description>
<link>https://tsecurity.de/de/3707179/it-security-nachrichten/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707179/it-security-nachrichten/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack/</guid>
<pubDate>Thu, 06 Aug 2026 04:05:01 +0200</pubDate>
<content:encoded><![CDATA[It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence]]></content:encoded>
</item>
<item>
<title><![CDATA[DuckDuckGo's new iPhone feature is a privacy win - I recommend getting it now]]></title>
<description><![CDATA[The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.]]></description>
<link>https://tsecurity.de/de/3707178/it-security-nachrichten/duckduckgos-new-iphone-feature-is-a-privacy-win-i-recommend-getting-it-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707178/it-security-nachrichten/duckduckgos-new-iphone-feature-is-a-privacy-win-i-recommend-getting-it-now/</guid>
<pubDate>Thu, 06 Aug 2026 04:04:41 +0200</pubDate>
<content:encoded><![CDATA[The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.]]></content:encoded>
</item>
<item>
<title><![CDATA[Could Meta Ray-Bans be banned in Europe? EU regulators dial up the pressure on smart glasses — and the rest of the world is watching]]></title>
<description><![CDATA[As EU regulators consider smart glasses restrictions, here are the countries with intelligent eyewear bans.]]></description>
<link>https://tsecurity.de/de/3707177/it-nachrichten/could-meta-ray-bans-be-banned-in-europe-eu-regulators-dial-up-the-pressure-on-smart-glasses-and-the-rest-of-the-world-is-watching/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707177/it-nachrichten/could-meta-ray-bans-be-banned-in-europe-eu-regulators-dial-up-the-pressure-on-smart-glasses-and-the-rest-of-the-world-is-watching/</guid>
<pubDate>Thu, 06 Aug 2026 04:04:33 +0200</pubDate>
<content:encoded><![CDATA[As EU regulators consider smart glasses restrictions, here are the countries with intelligent eyewear bans.]]></content:encoded>
</item>
<item>
<title><![CDATA[DuckDuckGo's new iPhone feature is a privacy win - I recommend getting it now]]></title>
<description><![CDATA[The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.]]></description>
<link>https://tsecurity.de/de/3707176/it-nachrichten/duckduckgos-new-iphone-feature-is-a-privacy-win-i-recommend-getting-it-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707176/it-nachrichten/duckduckgos-new-iphone-feature-is-a-privacy-win-i-recommend-getting-it-now/</guid>
<pubDate>Thu, 06 Aug 2026 04:03:38 +0200</pubDate>
<content:encoded><![CDATA[The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersicherheit: A Security sichert sich 37 Millionen Dollar Finanzierung - ad-hoc-news.de]]></title>
<description><![CDATA[A Security erhält 37 Mio. Dollar von Top-Investoren. Das Startup will damit seine Plattform zur präventiven Identifikation von Angriffspfaden ...]]></description>
<link>https://tsecurity.de/de/3707175/it-security-nachrichten/cybersicherheit-a-security-sichert-sich-37-millionen-dollar-finanzierung-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707175/it-security-nachrichten/cybersicherheit-a-security-sichert-sich-37-millionen-dollar-finanzierung-ad-hoc-newsde/</guid>
<pubDate>Thu, 06 Aug 2026 03:52:01 +0200</pubDate>
<content:encoded><![CDATA[A Security erhält 37 Mio. Dollar von Top-Investoren. Das Startup will damit seine Plattform zur präventiven Identifikation von Angriffspfaden ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Elon Musk’s attempt at an AI Wikipedia hasn’t been updated in months]]></title>
<description><![CDATA[xAI's Grokipedia, an online encyclopedia with AI-generated articles that Elon Musk once promised would be a "massive improvement" over Wikipedia, apparently hasn't been updated since April 24th, according to a report from Lawfare. "As far as we can tell, no entry has changed in more than three mo...]]></description>
<link>https://tsecurity.de/de/3707174/ai-nachrichten/elon-musks-attempt-at-an-ai-wikipedia-hasnt-been-updated-in-months/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707174/ai-nachrichten/elon-musks-attempt-at-an-ai-wikipedia-hasnt-been-updated-in-months/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:53 +0200</pubDate>
<content:encoded><![CDATA[xAI's Grokipedia, an online encyclopedia with AI-generated articles that Elon Musk once promised would be a "massive improvement" over Wikipedia, apparently hasn't been updated since April 24th, according to a report from Lawfare. "As far as we can tell, no entry has changed in more than three months," Lawfare said. Grokipedia launched in v0.1 in […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Report: Passkey security issues could allow account takeover]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3707173/ai-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707173/ai-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:53 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph">This article originally appeared on <a href="https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html" target="_blank">CSOonline</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta says its AI model hacked into another company during testing]]></title>
<description><![CDATA[Company is the third to report such an incident after Anthropic and OpenAI reported breaches during trainingMeta said on Wednesday that one of its AI models hacked ⁠another company during cybersecurity testing, after an error by its testing partner gave the model unintended internet access.The in...]]></description>
<link>https://tsecurity.de/de/3707172/ai-nachrichten/meta-says-its-ai-model-hacked-into-another-company-during-testing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707172/ai-nachrichten/meta-says-its-ai-model-hacked-into-another-company-during-testing/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Company is the third to report such an incident after Anthropic and OpenAI reported breaches during training</p><p>Meta said on Wednesday that one of its AI models hacked ⁠another company during cybersecurity testing, after an error by its testing partner gave the model unintended internet access.</p><p>The incident adds to a ⁠growing list of ⁠cases in ​which AI agents from major developers breached systems at other companies during testing, after Anthropic said last week that some of its models ⁠hacked three companies, and <a href="https://www.theguardian.com/technology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-unprecedented-incident">OpenAI disclosed</a> that an AI agent breached the startup Hugging Face.</p> <a href="https://www.theguardian.com/technology/2026/aug/05/meta-ai-model-hack-training">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts]]></title>
<description><![CDATA[Researchers at security firm Zenity found more than a dozen flaws in AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.]]></description>
<link>https://tsecurity.de/de/3707171/ai-nachrichten/openais-browser-could-be-hijacked-to-spam-your-whatsapp-contacts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707171/ai-nachrichten/openais-browser-could-be-hijacked-to-spam-your-whatsapp-contacts/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:50 +0200</pubDate>
<content:encoded><![CDATA[Researchers at security firm Zenity found more than a dozen flaws in AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree]]></title>
<description><![CDATA[At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.]]></description>
<link>https://tsecurity.de/de/3707170/ai-nachrichten/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707170/ai-nachrichten/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:50 +0200</pubDate>
<content:encoded><![CDATA[At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s SkillOpt Shows Optimized Agent Skill Artifacts Transfer Across Model Scales and Between Codex and Claude Code Harnesses]]></title>
<description><![CDATA[Most coverage of Microsoft's SkillOpt centers on its 52/52 result. The more consequential finding is in Section 4.3: the exported best_skill.md keeps working in environments it was never trained on. A Codex-trained SpreadsheetBench skill lifted Claude Code from 22.1 to 81.8, slightly above the 80...]]></description>
<link>https://tsecurity.de/de/3707169/ai-nachrichten/microsofts-skillopt-shows-optimized-agent-skill-artifacts-transfer-across-model-scales-and-between-codex-and-claude-code-harnesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707169/ai-nachrichten/microsofts-skillopt-shows-optimized-agent-skill-artifacts-transfer-across-model-scales-and-between-codex-and-claude-code-harnesses/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:43 +0200</pubDate>
<content:encoded><![CDATA[<p>Most coverage of Microsoft's SkillOpt centers on its 52/52 result. The more consequential finding is in Section 4.3: the exported best_skill.md keeps working in environments it was never trained on. A Codex-trained SpreadsheetBench skill lifted Claude Code from 22.1 to 81.8, slightly above the 80.4 that harness reached training its own skill. Retention varies sharply by task type — 102% on spreadsheets, 10% on math — which is what makes the result worth reading closely.</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/05/microsoft-skillopt-agent-skill-transfer-portability/">Microsoft’s SkillOpt Shows Optimized Agent Skill Artifacts Transfer Across Model Scales and Between Codex and Claude Code Harnesses</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4699: Sunshine, Moonlight, Playnite !?]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


sunshine / xbox contlers / plex / steam / UWPHook / Bluetoothctl restart / HDMI dongle




https://www.youtube.com/watch?v=FM4FbA4-W_c








UGREEN USB C Hub 5 in 1 Multiport Adapter Revodok 105 4K HDMI, 100W Power Delivery, 3 USB-A Data ...]]></description>
<link>https://tsecurity.de/de/3707168/podcasts/hpr4699-sunshine-moonlight-playnite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707168/podcasts/hpr4699-sunshine-moonlight-playnite/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:39 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
sunshine / xbox contlers / plex / steam / UWPHook / Bluetoothctl restart / HDMI dongle</p>

<p>

<a href="https://www.youtube.com/watch?v=FM4FbA4-W_c" rel="noopener noreferrer" target="_blank">
https://www.youtube.com/watch?v=FM4FbA4-W_c</a>

</p>

<p>

</p>

<p>
UGREEN USB C Hub 5 in 1 Multiport Adapter Revodok 105 4K HDMI, 100W Power Delivery, 3 USB-A Data Ports, USB C Dongle for MacBook Pro/Air, iPad Pro, iMac, iPhone 16 Pro/Pro Max, XPS, Thinkpad</p>

<p>

<a href="https://www.amazon.com/dp/B0BR3M8XHK" rel="noopener noreferrer" target="_blank">
https://www.amazon.com/dp/B0BR3M8XHK</a>

</p>

<p>
Detached Command:</p>

<pre data-language="plain">
@ECHO OFF
cd "C:\backup\gamestream_launchpad"
c:\windows\System32\HdrSwitcher.exe disable
start /MIN gamestream_launchpad.exe 1920 1080 gamestream_playnite.ini
</pre>

<p>

</p>

<pre data-language="plain">
.bindkeys rc 
cat .xbindkeysrc
/bin/bash /home/plex/.local/bin/Plex.sh
/bin/bash /home/plex/.local/bin/Steam.sh
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer on; /home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer brightness 100;xgamma -gamma 1.3
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer on; /home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer brightness 40;xgamma -gamma 1.3
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer on; /home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer brightness 12;xgamma -gamma 1.3
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer off;xgamma -gamma 1.3"
</pre>

<p>

</p>

<pre data-language="plain">
cat /home/plex/.local/bin/Steam.sh
# requires wmctrl -l and xbindkeys
#
# xdotool windowactivate ```xdotool search --name 'window  name'```
# 0
StartSteamLink(){
 echo "restarting bluetooth"
 sudo systemctl restart bluetooth
 echo "Waking Game PC"
 sudo /usr/sbin/etherwake -i enp1s0 -D "d8:bb:c1:a2:2c:0b"
 echo "Starting steamlink"
 killall -9 steamlink
 killall moonlight
 sleep 20
# /snap/bin/moonlight
 /home/plex/.local/bin/Moonlight-6.1.0-x86_64.AppImage    
}
StartSteamLink


</pre>

<p>
SUMMARY:</p>

<ol>

<li>
 Speaker discusses technical challenges with Sun Shine, Moonlight, and Play Night setups.</li>

</ol>

<p>
IDEAS:</p>

<ol>

<li>
 Sun Shine and Moonlight enable remote game streaming.</li>

<li>
 Play Night acts as a multimodal launcher for Steam.</li>

<li>
 Resolution changes cause display issues during gameplay.</li>

<li>
 Proper exit sequence is critical to revert settings.</li>

<li>
 Ultra-wide resolutions are unusable in some configurations.</li>

<li>
 Multiple launchers require separate logins for different games.</li>

<li>
 Environment variables can adjust client dimensions.</li>

<li>
 Background commands improve system stability.</li>

<li>
 Cat named Mojo is mentioned during the discussion.</li>

<li>
 5G networks support slower-paced gaming.</li>

<li>
 Technical glitches include frame drops and latency.</li>

<li>
 Steam accounts are tied to specific game libraries.</li>

<li>
 Detached commands run in the background without user interaction.</li>

<li>
 GameStream Launchpad manages resolution and launcher paths.</li>

<li>
 Magical system behavior simplifies remote gaming.</li>

<li>
 Star Wars and Baldurâ€™s Gate are cited as example games.</li>

<li>
 22nd Millie thing refers to network latency.</li>

<li>
 Multiple Steam accounts complicate game access.</li>

<li>
 Task killing reverts system settings automatically.</li>

<li>
 Cross-platform streaming solutions are highlighted.</li>

</ol>

<p>

</p>

<p>
RECOMMENDATIONS:</p>

<ol>

<li>
 Use environment variables for client resolution adjustments.</li>

<li>
 Exit applications properly to revert settings.</li>

<li>
 Set up detached background commands for stability.</li>

<li>
 Monitor ultra-wide resolution compatibility.</li>

<li>
 Utilize Play Night for Steam account management.</li>

<li>
 Avoid multiple logins for different game libraries.</li>

<li>
 Opt for cross-platform streaming solutions.</li>

<li>
 Check network latency for smooth gameplay.</li>

<li>
 Use bat files for automated task execution.</li>

<li>
 Configure GameStream Launchpad for resolution changes.</li>

<li>
 Prioritize proper task termination to prevent glitches.</li>

<li>
 Test 5G networks for slower-paced gaming.</li>

<li>
 Leverage environment variables for client settings.</li>

<li>
 Ensure all applications exit before shutting down.</li>

<li>
 Use detached commands for background processes.</li>

<li>
 Verify resolution compatibility with ultra-wide displays.</li>

<li>
 Combine Sun Shine and Moonlight for reliable streaming.</li>

<li>
 Log in once for multiple Steam accounts.</li>

<li>
 Address frame drops in low-latency networks.</li>

<li>
 Stream games universally across platforms.</li>

</ol>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4699/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inspired by the floral background @SamsungUS  #withgalaxy]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3707155/videos/inspired-by-the-floral-background-samsungus-withgalaxy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707155/videos/inspired-by-the-floral-background-samsungus-withgalaxy/</guid>
<pubDate>Thu, 06 Aug 2026 03:39:52 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/LhsoM1ask0g"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] LWN.net Weekly Edition for August 6, 2026]]></title>
<description><![CDATA[Inside this week's LWN.net Weekly Edition:
        
        
 Front: Process-builder API; Fedora COI; FUSE io_uring buffer sizes; BPF network namespaces; FUSE plans; BPF libraries; directory creation system call.
             Briefs: AISI hack; JFrog on CVEs; npm worm; AUR adoption; NetBSD 11.0; ...]]></description>
<link>https://tsecurity.de/de/3707154/linux-tipps/lwnnet-weekly-edition-for-august-6-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707154/linux-tipps/lwnnet-weekly-edition-for-august-6-2026/</guid>
<pubDate>Thu, 06 Aug 2026 03:38:02 +0200</pubDate>
<content:encoded><![CDATA[Inside this week's LWN.net Weekly Edition:
        <p>
        </p><ul>
<li> <a href="https://lwn.net/Articles/1086134/">Front</a>: Process-builder API; Fedora COI; FUSE io_uring buffer sizes; BPF network namespaces; FUSE plans; BPF libraries; directory creation system call.
            </li><li> <a href="https://lwn.net/Articles/1086136/">Briefs</a>: AISI hack; JFrog on CVEs; npm worm; AUR adoption; NetBSD 11.0; b4 0.16.0; C-Kermit 11; Rust LLM policy; Servo 0.4.0; Quotes; ...
            </li><li> <a href="https://lwn.net/Articles/1086137/">Announcements</a>: Newsletters, conferences, security updates, patches, and more.
            </li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Resources beta adds PowerPC temp, AMD NPU stats]]></title>
<description><![CDATA[Resources 51 beta, the system monitor Ubuntu now uses, adds AMD NPU stats, PowerPC CPU temps and alternative memory-usage metrics.
You're reading Resources beta adds PowerPC temp, AMD NPU stats, a blog post from OMG! Ubuntu. Do not reproduce elsewhere without permission.]]></description>
<link>https://tsecurity.de/de/3707153/linux-tipps/resources-beta-adds-powerpc-temp-amd-npu-stats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707153/linux-tipps/resources-beta-adds-powerpc-temp-amd-npu-stats/</guid>
<pubDate>Thu, 06 Aug 2026 03:36:29 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2023/10/resources-flatpak-app.jpg?resize=406%2C232&amp;ssl=1" class="attachment-post-list size-post-list wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2023/10/resources-flatpak-app.jpg?w=1280&amp;ssl=1 1280w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2023/10/resources-flatpak-app.jpg?resize=300%2C172&amp;ssl=1 300w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2023/10/resources-flatpak-app.jpg?resize=840%2C480&amp;ssl=1 840w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2023/10/resources-flatpak-app.jpg?resize=350%2C200&amp;ssl=1 350w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2023/10/resources-flatpak-app.jpg?resize=768%2C440&amp;ssl=1 768w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2023/10/resources-flatpak-app.jpg?resize=406%2C232&amp;ssl=1 406w" sizes="(max-width: 406px) 100vw, 406px">Resources 51 beta, the system monitor Ubuntu now uses, adds AMD NPU stats, PowerPC CPU temps and alternative memory-usage metrics.</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/08/resources-51-beta-npu-powerpc-temps">Resources beta adds PowerPC temp, AMD NPU stats</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Kernel Begins Phasing Out the crypto_rng Layer to Simplify Random Number Generation]]></title>
<description><![CDATA[by George Whittaker
      
            Linux kernel developers are moving forward with plans to remove the crypto_rng API layer, a long-standing component of the kernel's cryptographic subsystem. The proposed change is part of a broader effort to simplify the kernel's internal architecture by eli...]]></description>
<link>https://tsecurity.de/de/3707148/unix-server/linux-kernel-begins-phasing-out-the-cryptorng-layer-to-simplify-random-number-generation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707148/unix-server/linux-kernel-begins-phasing-out-the-cryptorng-layer-to-simplify-random-number-generation/</guid>
<pubDate>Thu, 06 Aug 2026 03:32:31 +0200</pubDate>
<content:encoded><![CDATA[<div data-history-node-id="1341450" class="layout layout--onecol">
    <div class="layout__region layout__region--content">
      
            <div class="field field--name-field-node-image field--type-image field--label-hidden field--item">  <img loading="lazy" src="https://www.linuxjournal.com/sites/default/files/nodeimage/story/linux-kernel-begins-phasing-out-the-crypto-rng-layer-to-simplify-random-number-generation.jpg" width="850" height="500" alt="Linux Kernel Begins Phasing Out the crypto_rng Layer to Simplify Random Number Generation" typeof="foaf:Image" class="img-responsive">

</div>
      
            <div class="field field--name-node-author field--type-ds field--label-hidden field--item">by <a title="View user profile." href="https://www.linuxjournal.com/users/george-whittaker" lang="" about="/users/george-whittaker" typeof="schema:Person" property="schema:name" datatype="">George Whittaker</a></div>
      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p>Linux kernel developers are moving forward with plans to <strong>remove the <code>crypto_rng</code> API layer</strong>, a long-standing component of the kernel's cryptographic subsystem. The proposed change is part of a broader effort to simplify the kernel's internal architecture by eliminating redundant code paths and encouraging developers to rely on the kernel's modern random number generation interfaces instead. (<a>phoronix.com</a>)</p>

<p>Although the change happens entirely behind the scenes, it reflects the Linux kernel community's ongoing commitment to reducing technical debt, improving maintainability, and modernizing core infrastructure.</p>

<h2><strong>What Is the <code>crypto_rng</code> Layer?</strong></h2>

<p>The <code>crypto_rng</code> framework is an API within the Linux kernel's Crypto API that provides random number generation services for kernel components.</p>

<p>Historically, it allowed different kernel subsystems and drivers to request random data through a generic cryptographic interface. Over time, however, the kernel's dedicated random number generator has matured considerably, making much of the <code>crypto_rng</code> abstraction unnecessary. (<a href="https://www.kernel.org/doc/html/latest/crypto/index.html?utm_source=chatgpt.com">kernel.org</a>)</p>

<p>Today, developers generally recommend using the kernel's built-in random number generation functions directly instead of routing requests through the older crypto layer.</p>

<h2><strong>Why Developers Want to Remove It</strong></h2>

<p>According to discussions on the Linux kernel mailing list, the <code>crypto_rng</code> layer has become largely redundant.</p>

<p>Modern kernel code already relies on well-established interfaces such as:</p>

<ul><li><code>get_random_bytes()</code></li>
	<li><code>get_random_u32()</code></li>
	<li><code>get_random_u64()</code></li>
</ul><p>These functions are maintained as part of the kernel's primary random number generation subsystem and are widely used throughout Linux. Maintaining an additional abstraction layer increases code complexity without providing significant practical benefits. (<a>phoronix.com</a>)</p>

<p>Removing unnecessary infrastructure also makes the kernel easier to maintain and audit over the long term.</p>

<h2><strong>Simplifying the Crypto API</strong></h2>

<p>The Linux Crypto API has evolved significantly over the years as new algorithms, hardware accelerators, and security features have been introduced.</p>

<p>Kernel maintainers have increasingly focused on:</p></div>
      
            <div class="field field--name-node-link field--type-ds field--label-hidden field--item">  <a href="https://www.linuxjournal.com/content/linux-kernel-begins-phasing-out-cryptorng-layer-simplify-random-number-generation" hreflang="en">Go to Full Article</a>
</div>
      
    </div>
  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie man einen dedizierten CS2-Server startet: Vollständiger Leitfaden [2026]]]></title>
<description><![CDATA[Leistungsstarker PC oder VPS: Dein Server benötigt ausreichende Rechenleistung, besonders wenn du vorhast, mehrere Spieler zu hosten. SteamCMD: Dies ...]]></description>
<link>https://tsecurity.de/de/3707147/windows-server/wie-man-einen-dedizierten-cs2-server-startet-vollstaendiger-leitfaden-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707147/windows-server/wie-man-einen-dedizierten-cs2-server-startet-vollstaendiger-leitfaden-2026/</guid>
<pubDate>Thu, 06 Aug 2026 03:32:21 +0200</pubDate>
<content:encoded><![CDATA[Leistungsstarker PC oder VPS: Dein <b>Server</b> benötigt ausreichende Rechenleistung, besonders wenn du vorhast, mehrere Spieler zu hosten. SteamCMD: Dies ...]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Budgets unter Druck: Lizenz- und Tokenkosten blockieren Geld für IT-Modernisierung]]></title>
<description><![CDATA[... Windows Server 2022 (E-Learning). E-Learning: Failover Clustering mit Windows Server 2022 (E-Learning) · zum Kurs. Microsoft Azure Administration ...]]></description>
<link>https://tsecurity.de/de/3707146/windows-server/it-budgets-unter-druck-lizenz-und-tokenkosten-blockieren-geld-fuer-it-modernisierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707146/windows-server/it-budgets-unter-druck-lizenz-und-tokenkosten-blockieren-geld-fuer-it-modernisierung/</guid>
<pubDate>Thu, 06 Aug 2026 03:32:21 +0200</pubDate>
<content:encoded><![CDATA[... <b>Windows Server</b> 2022 (E-Learning). E-Learning: Failover Clustering mit <b>Windows Server</b> 2022 (E-Learning) · zum Kurs. Microsoft Azure Administration ...]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: 0.147.0-alpha.13]]></title>
<description><![CDATA[Release 0.147.0-alpha.13]]></description>
<link>https://tsecurity.de/de/3707145/downloads/github-01470-alpha13/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707145/downloads/github-01470-alpha13/</guid>
<pubDate>Thu, 06 Aug 2026 03:32:05 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><p>Release 0.147.0-alpha.13</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v2.1.223]]></title>
<description><![CDATA[What's changed

Added owner wildcard entries ("owner/*") to the strictKnownMarketplaces and blockedMarketplaces managed settings for allowing or blocking all marketplace repos under a GitHub org
Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' req...]]></description>
<link>https://tsecurity.de/de/3707144/downloads/github-v21223/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707144/downloads/github-v21223/</guid>
<pubDate>Thu, 06 Aug 2026 03:32:04 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>What's changed</h2>
<ul>
<li>Added owner wildcard entries (<code>"owner/*"</code>) to the <code>strictKnownMarketplaces</code> and <code>blockedMarketplaces</code> managed settings for allowing or blocking all marketplace repos under a GitHub org</li>
<li>Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' requested subagent model is restricted and the parent model runs instead</li>
<li>Added a <code>/teleport</code> hint in cloud sessions showing how to continue locally with <code>claude --teleport &lt;session id&gt;</code></li>
<li>Fixed a Bash permission bypass where a crafted command could hide parts of itself from permission checks</li>
<li>Fixed permission prompts so commands padded with tabs or invisible Unicode can no longer hide part of the command from the approval dialog</li>
<li>Fixed workflow scripts being able to use dynamic <code>import()</code> to run code outside the workflow sandbox</li>
<li>Fixed a permission gap where an agent definition's <code>bypassPermissions</code> mode ignored the org bypass-permissions disable policy</li>
<li>Fixed resuming a session after a mid-session <code>/cd</code> coming back empty</li>
<li>Fixed gateway model discovery hiding Claude models registered under provider-prefixed IDs such as <code>vertex_ai/claude-*</code> or <code>bedrock/anthropic.claude-*</code></li>
<li>Fixed <code>modelOverrides</code> keys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documented</li>
<li>Fixed managed settings: server-delivered settings no longer disable the env block of a machine-local <code>managed-settings.json</code> or MDM profile; admin env now merges per key</li>
<li>Fixed sandboxed commands failing to start on Linux when <code>sandbox.filesystem.denyWrite</code> covers the working directory</li>
<li>Fixed forked background agents getting stuck "already resuming" for the rest of the session when rebuilding the fork's parent prompt failed during resume</li>
<li>Fixed a resumed session failing every turn, or leaving the interactive app on an unresponsive error screen, when its history held a malformed diagnostics attachment</li>
<li>Fixed a rare hang when parsing unusual <code>git push</code> output</li>
<li>Changed <code>CLAUDE_CODE_DISABLE_1M_CONTEXT</code> to hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200K</li>
<li>Changed auto-compact to keep sessions on unrecognized model IDs within the assumed context window instead of letting them grow past it; set <code>CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1</code> to restore the previous behavior</li>
<li>Changed <code>/review</code> to be an alias of <code>/code-review</code>, which reviews the current diff or a PR (<code>/code-review &lt;level&gt; &lt;pr#&gt;</code>); use <code>/code-review ultra</code> for a deep cloud review</li>
<li>Changed <code>/code-review</code> with no effort level to reuse the level you typed last; type a level like <code>/code-review high</code> to change it</li>
</ul></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 2,54ms -->