<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=converting+rxjs+observables+asyncawait%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 17:39:38 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 17:39:38 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=converting+rxjs+observables+asyncawait%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=converting+rxjs+observables+asyncawait%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[17 Things to know for Android developers at Google I/O]]></title>
<description><![CDATA[Posted by Matthew McCullough, VP, Product Management, Android DeveloperToday at Google I/O, we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcemen...]]></description>
<link>https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693511/android-tipps/17-things-to-know-for-android-developers-at-google-io/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:45 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP7OJeCTRC-RN9j39-rULmU26qB-lZoyIZjjDrq07Z7b5GsfHz3q18ftSgcWReGBgIBkp03B6BVghzWllOC38o4jckzzq-e4a8R23ISeegev98zubhGXbIzhTZaqbCTaPLJC2zkxKYvvNspcM4yXkk94f6PEQHpdyMvlpwogicTWQRn3GEksJHOTQDIG4/s2048/GoogleForDevelopers-AndroidText-StrapiMetacard-2048x1323.png">


<div><div class="separator"><div class="separator"><div class="separator"><i>Posted by Matthew McCullough, VP, Product Management, Android Developer</i></div></div></div></div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s4209/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVq21_VInGStxa8CNxcwiU_tpvlkPXci8aDeSb8qUqBe4teuWUN_vIqBf_W64xjTQMBYFyJkdXB-nshsp9DXXEwzUV8-Zn9feQTbuyLk8l98kAlFQqz3_LZrYaEvCukqXCZuY95tmNzrLFqXSviaTTSxflyAkpXJb88cB7mZ7g0x6fdnKzXqY8i1jmhqM/s16000/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"></a></div><div><br></div>Today at <a href="https://io.google/2026/">Google I/O,</a> we announced the many ways we’re powering agentic workflows to increase your productivity and ensure your apps shine across the expanding Android ecosystem. Here’s a recap of 17 of our favorite announcements for Android developers; you can also <a href="https://www.youtube.com/live/KvTRMSa1w4E?si=QBAxNvihPwJCJUuS">see what was announced last week</a> in <a href="https://developer.android.com/events/show">The Android Show: I/O Edition</a>. Stay tuned over the next two days as we dive into all of the topics in more detail!<h2><strong><span>Build High Quality Android Apps Using Agents</span></strong></h2>

  <h3><strong><span>1: Android CLI: helping you build with any agent, LLM, and tool</span></strong></h3>
  <a href="https://goo.gle/CLI_IO26">Android CLI is now stable</a>. It offers programmatic tools that allow any AI agent, including Claude Code, Codex, or Antigravity, to perform core Android tasks much more easily and efficiently. With today’s release, it also provides a bridge to tap directly into the "heavy-lifting" power of Android Studio to give you the production-ready polish needed for professional Android development. By leveraging the new android studio commands, developers can now grant their preferred agents the ability to perform semantic symbol resolution, analyze files for warnings, and even render Jetpack Compose previews. This release also enables official support for "Journeys" through new <a href="https://developer.android.com/tools/agents/android-skills">Android skills</a>, which enables agents to execute end-to-end UI tests under your direction. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.    <p><span></span></p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXrW3yDK9uH_I8MDyVxgYbPAXfrNTJvlMkXhaZFrM1X9ob0LvQbGe_ZC6anUeO_VNd181iptI_MIuEEpX-9GZdf6ZTJCN-WHpPzDCLOeSblo8vrjliSZ0rRrHwIsERWBjbbosP-M_WvA2pva9mF5FWVygAwQbdiW3SLZgJj9TpRIruG4H-ILsvSq_b4dc/w640-h442/agy-android-cli%20(2).png"></div><div class="separator"><span><i>You can now easily install Android CLI for use with Google Antigravity 2.0.</i></span></div><p></p>

  <h3><strong><span>2: Build production-ready apps with ease in Google AI Studio</span></strong></h3>
  Developers and creators can now <a href="http://android-developers.googleblog.com/2026/05/build-android-apps-google-ai-studio.html">build native Android apps, simply with a prompt in Google AI Studio</a>. The apps are built with development best practices like Jetpack Compose, Kotlin, and APIs that leverage our recommended developer patterns. Google AI Studio enables developers to prototype, iterate via an embedded emulator, and deploy to physical devices without heavy local installations. Developers are then able to take those apps and share them to Android devices, as well as share them with others for testing through Google Play Console’s internal testing track. If a developer wants to prepare their app for a wider release, they’re able to take it to Android Studio for advanced debugging, testing, and UI polish. Watch the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>, and tune into the <a href="https://io.google/2026/explore/pa-keynote-7">What’s New in Android tools talk</a> for more information.<br><br><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdRaw1v6rolr4alo0C6AWKdFchsMEQgtOGfmk2Ramb0IoOB7smDcVU3yC7YJMkvVQuCPJ9vQW53tQjaV-5wcgOGzMtFDmb_Jbv40an1kvQdqYburXnsONvLqckKL2MWuShi3XmQEstW761oOLjujOk3FMsh3FyAiy5-Pe7xdTwFdfkWOmEnHhQfUJhtCo/w640-h544/image1.gif"></div><i><div class="separator"><i>Use the embedded Android Emulator to create Android apps in Google AI Studio</i></div></i></div><h2><strong><span>3: Accelerating AI coding assistance with Android Bench</span></strong></h2>
  <a href="http://d.android.com/bench">Android Bench</a> is our LLM leaderboard for Android development challenges. The goal is to accelerate model improvements, so you have more useful options for AI assistance. Many of you have been using open-weight models for AI assistance, so we’re now adding commonly used ones, such as Gemma 4, to the leaderboard, so you can see how LLMs that offer offline access and additional flexibility for power-users measure up. We're continuously working on increasing the difficulty of challenges we’re giving LLMs, to continue encouraging more useful improvements. <h3><strong><span>4: Convert iOS apps to Android with the Migration Assistant in Android Studio</span></strong></h3>
  The Migration Assistant in Android Studio is designed to port apps from platforms like iOS, React Native, or web frameworks to native Android. By simply selecting an existing project, developers can have the agent intelligently map features, convert assets like storyboards and SVGs, and implement Android best practices using Jetpack Compose and our recommended Jetpack libraries. This effectively transforms what used to be weeks of manual porting into a streamlined agentic workflow that only takes hours. We shared a preview of the incoming feature in the <a href="https://www.youtube.com/watch?v=aqmpZocmR8o&amp;list=PLOU2XLYxmsIKL_eEgkKJWDRhYUEvS9eYz&amp;index=23">developer keynote</a>. </div><div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjK7UKI_nzS7gOkDXYONAjCNbQ4eSqlgT8qqMT5D4qf0OjQUNtxj4Urpq-eTROMEDgrqLKGlwMm_lHA7ayG_BC1DkitQI1ZKsF5gYr-mPIxFUsz_8JPcVHFAtnHZoO2CrVjMEvJrqvBz8_WU1I0T1P2diDprR2B47PcA21oS3RLtbgrhmrpiWV-MAw9ks4/w640-h360/image9%20(1).gif"></div><div class="separator"><i>A sneak peek of the Migration Assistant converting an iOS app into a native Android app</i></div>

  <h2><strong><span>Building AI Into Your Apps</span></strong></h2>

  <h3><strong><span>5: Building Intelligent Apps with generative AI</span></strong></h3>
  Generative AI enables you to create apps that are more intelligent, personalized, and agentic than ever before. This year, we introduced the latest advancements in on-device intelligence with a preview of Gemini Nano 4 for tasks like data extraction and summarization. We also expanded cloud capabilities via Firebase AI Logic, allowing developers to leverage Gemini models with robust grounding (including URL, Maps, and web search) to build smarter, more capable assistants. Furthermore, we unveiled our hybrid inference approach and the new <a href="https://goo.gle/ADK_IO26">Agent Development Kit (ADK) for Android</a>, alongside communication protocols like AG-UI and A2UI that simplify the creation of autonomous, agentic experiences. To start integrating these powerful features, explore the <a href="https://developer.android.com/ai">developer documentation</a>, and watch the technical deep dive session where we showcase all these technologies.

  <h3><strong><span>6: Experiment with AppFunctions today</span></strong></h3>
  AppFunctions is an <a href="https://developer.android.com/reference/android/app/appfunctions/package-summary">Android platform API</a> with an accompanying <a href="https://developer.android.com/jetpack/androidx/releases/appfunctions">Jetpack library</a> to simplify building Android MCP integrations. It empowers your apps to behave like on device MCP servers, contributing functions that act as tools for use by agents and assistants. AppFunctions integration with Gemini is currently in a private preview with trusted testers, and you can begin preparing your apps already. You can sign up for the <a href="http://goo.gle/eap-af">Early Access Program</a> and start experimenting using the <a href="http://d.android.com/ai/appfunctions">API guidance</a>, <a href="https://github.com/android/appfunctions">sample</a>, and <a href="https://github.com/android/skills/blob/main/device-ai/appfunctions/SKILL.md">skill</a> today.

  <h2><strong><span>The Future is Adaptive</span></strong></h2>

  <h3><strong><span>7: Android is now Compose First; Views are now in maintenance mode.</span></strong></h3>
  Compose is our standard for UI development, and we are moving to a Compose-first approach for all future guidance and libraries. Building on five years of evolution, the latest releases deliver a more mature toolkit, from the highly customizable Styles API to refined shared element transitions and enhanced input support. These updates allow you to build beautiful, adaptive apps with less code and better performance. Learn more about what Compose-first means for Android Development in <a href="http://android-developers.googleblog.com/2026/05/android-ui-development-is-compose-first.html">our blog post</a>. <br><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq9kh5gxOfSdY2w9ZeKdWropXpqP7rj4KtodIZA5B_j7ujQu-blrsQKKC0lI4VEsEycpLEwsZeJhHaNOY1Xe9DrIHDwVszYfQN0GQlwxz8xoVfg1oiIr9zNlUyqqdCl2M7pyHoHgVvC7omKRthmXNaO3GE5Q15XeZ1ALiugszd8qHxpWuHo2Eh79zYW4M/w640-h416/image5.png"></div><div><div><i>Build Android UI with Compose</i></div><h3><strong><span>8: Building seamless Android experiences across devices with Jetpack Compose</span></strong></h3><div>The Android ecosystem is now <a href="https://goo.gle/AdaptiveApps_IO26">Adaptive by Default</a>, moving fluidly across phones, foldables, tablets, cars, XR, and expanding usages with <a href="https://developer.android.com/googlebook">Googlebook</a> and connected displays. With over 580 million large-screen devices, and users on multiple devices spending up to 14x more on apps, the investment in adaptive design presents a massive opportunity. <a href="https://developer.android.com/compose">Jetpack Compose</a> is the definitive engine for this transition, offering core tools like our latest <a href="http://goo.gle/nav3">Jetpack Navigation 3</a> release, new experimental <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/grid">Grid</a> and <a href="https://developer.android.com/develop/ui/compose/layouts/adaptive/flexbox">FlexBox</a> layouts, enhanced non-touch input support, and <a href="https://developer.android.com/media/camera/camerax">CameraX</a> for correct camera previews across any window size. Furthermore, new <a href="https://developer.android.com/tools/agents/android-skills">skills</a> in Android Studio make updating your existing app to adopt these adaptive patterns easier than ever.

  <img src="https://blogger.googleusercontent.com/img/a/AVvXsEi3DD3G6IUrmOwYh7bMq0uieBvGL8li2W48YnUfQfa3ZXy2kD7QvPorNfAyCSmFlBs4q0csXDqmZjhyGf8UHFE2pUNjvqxLaaJhmm6QpSBumq2YkMHI1jyiTNfh5WQhEEY9hP6vWhcbbwflygdTwYzoIdnuIqoht0S6iGKk4pVCnxL2wVXYBMBlcdeneD8"><i>Notability’s Android debut sets a new standard for premium productivity apps. Built with Jetpack Compose, Navigation 3, and Kotlin Multiplatform, it delivers an intuitive, adaptive experience across devices.</i></div><h3><strong><span>9: Create seamless experiences for Googlebook</span></strong></h3>
  Last week we announced <a href="https://developer.android.com/googlebook">Googlebook</a>, a high-performance laptop that provides a large-screen canvas for your existing apps. Building with adaptive principles today helps ensure your app will work on Googlebook. Get started by reviewing relevant <a href="https://developer.android.com/design/ui/desktop">design guidance</a> and <a href="https://developer.android.com/docs/quality-guidelines/adaptive-app-quality/experiences/desktop">developer guidelines</a> for desktop experiences. Try out the new Desktop Emulator available in the Android Studio Canary to to test your apps for this form factor today.</div><div><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtH3cjiXICi8dNCtQTDV9PTyjt4wPQBl1xA9XGKGU6FmqLRuBm9YyH7HNQsydD6H6F2GIPw2TdUsFyeu2xMFUO2Jk36k5QXjuWNdm_VE8AQftq2w2m0RPFyYfyZjTppSOjzuOEpJMzF08t9V0YZr-xI7mu31uvcRItugwvVxPUBouSmOXt1MsqbB1WPC0/w640-h360/image3.png"></div><div><div><i>New Desktop Android Emulator</i></div><h3><strong><span>10: Unified widget development experience with Jetpack Glance</span></strong></h3>
  Android 17 marks a shift toward a single, Compose-based development model for all widgets. By unifying the experience across mobile, Wear OS, and cars through Jetpack Glance, you can soon scale UI components across the ecosystem with a familiar workflow. <br><br>The breakthrough this year is the integration of RemoteCompose. On mobile and cars, it powers high-fidelity animations, while on Wear OS, it allows Wear Widgets (formerly Tiles) to render complex UI logic natively on remote surfaces. This ensures peak performance on low-power hardware while allowing a cohesive user journey—like checking a flight status on your car dashboard and seeing gate change updates on your wrist.</div><div><br></div><div><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA5s4g4hCW89qdeC2oqrTtxh6q7t9q3-wkOSt3tfVzCT3vhLUd1GMYJrhCjK04O2jyxBGl0R2pclnRq3Kb0f0Td-hV9aukKvZQTfGpGJS6GLK0MqUkpVW_0qiNC1eMGe6NPPhlCHrnQWFYhmbdSzpDnUHh5tjvpmUzZOvY2w_dX1LBnpNctSRmeahXUl4/w640-h320/blog_widgets.gif"></div><div><i>Four widgets are shown cycling through in the Android Auto interface. A clock, a contact card, Google Home favorites and a photo.</i></div><div><i><br></i></div><div><strong><span>11: Expand your reach on the road with Android for Cars</span></strong><br>To help you expand your reach when you build in-car experiences, we're making it easier to build once and deliver your apps to Android Auto and Android Automotive OS. With the latest releases of the Car App Library, you can build customized, distraction-optimized <a href="https://developer.android.com/training/cars/apps/media">templated media apps</a> for both platforms. We're introducing new <a href="https://developer.android.com/design/ui/cars/guides/components/overview">components</a> and template capabilities to give you increased flexibility and more options for laying out content. Parked experiences are expanding too, with immersive video playback coming to Android Auto for phones running Android 17. You can easily adapt your video apps for these parked experiences; <a href="https://docs.google.com/forms/d/e/1FAIpQLSf0z4Nfw8wrloVhlgHDpLgdkg4WXsFj9ni5c1pw0qTvJ3Q4fQ/viewform">apply now to the early access program</a> to publish in these beta categories and learn more about the latest updates in our <a href="http://android-developers.googleblog.com/2026/05/android-for-cars-unifying-platforms-premium-experiences.html">blog</a>.<h3><strong><span>12: Accelerate your development with Android XR Developer Preview 4</span></strong></h3>Inspired by the innovative experiences you’ve built for the platform, we’re continuing to mature our tools with <a href="https://goo.gle/XRSDK_IO26">Developer Preview 4 of the Android XR SDK</a>. A key milestone in this journey is the transition of our core libraries, XR Runtime, Jetpack SceneCore, and ARCore for Jetpack XR, moving to Beta soon to provide a more stable and performant foundation. We are also accelerating hardware access through the <a href="https://goo.gle/Catalyst_IO26">Android XR Developer Catalyst Program</a>, where you can apply for XREAL’s Project Aura, audio glasses, or display glasses developer kits. Watch The latest in Android XR session or <a href="https://goo.gle/XRSDK_IO26">read our blog</a> to see how these updates help you build experiences across the ecosystem.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyjbgGH7RwGkOkQLoXeLd88Vo7cXRjHLBSRokBWkzvYQUrqqbfrTXukM1u_SuGq0-AoXRPoGABpCOF-HMad4-aoNvXjTVyNXgGpbffTlSQMbTaXJva1c2GiUBx1fhC4fCCd0XO9XFzKNzs6edNqo0RAx-p2ZNXy0l-StJh7AxhyphenhyphenrXi-lqe-jXL0n8oprs/w640-h360/Aura%20Geospatial%20Tour%20Demo%20-%20Draft%2001%20(1).gif"></div><i><div><i>Early preview of the Geospatial API  in ARCore for Jetpack XR, enabling high-precision anchoring of digital content to real-world locations.</i></div></i><h3><strong><span>13: Android is your new home for professional-grade media experiences</span></strong></h3>
  Android 17 streamlines the entire media lifecycle with a production-ready toolkit. High-fidelity capture is now simplified with the CameraXViewfinder Composable, which handles complex scaling and responsiveness on foldables and tablets. For post-production, the new Media3 AI Effects library provides a single interface for premium features like Magic Eraser and Studio Sound, automatically optimizing for the device's hardware. <br><br>The pipeline is completed by CodecDB, offering chipset-specific encoding recommendations to eliminate export noise, and a new Scrubbing Mode in ExoPlayer for ultra-smooth seeking. Whether you’re compositing multi-asset edits with Media3 Transformer or using the streamlined CastPlayer API, these updates ensure a professional-grade experience with significantly less development overhead.</div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXXvjrWhhRUXdYJyhuu-Vnf0UP2jKcYhAvUggZJi10kndrixZdx4cD8HEhrWVmavlxAUT5N025Fx1kgOLJP5w83LDUSR3E9YzfIJUuZ3WBedFSBtI_oLgIcxSOYg-s53obwX_8HtYqfxSaz95LVzSiMAdrrwgL4T6TVETwtxxkZV2mSkkAfvYA681zNlc/w640-h542/supercharge%20(1).gif"></div><div class="separator"><i>Low Light Boost and Magic Eraser in action</i></div><h3><strong><span>14: Increase app discovery and engagement on Google TV</span></strong></h3>
  Pointer remotes, which enable motion-controlled input, will be a future way for users to interact with Google TV as it unlocks faster user navigation. App developers can start <a href="https://developer.android.com/training/tv/get-started/hardware#no-touchscreen">declaring support for pointing input</a> to ensure their apps are discoverable on future TVs with pointer remotes. Additionally, the Engage SDK, formerly known as the Video Discovery API, optimizes Resumption, Entitlements, and Recommendations across all Google TV form factors to boost app discovery and engagement. It’s a great time to start onboarding the Engage SDK now, since the legacy Watch Next API, which has been powering your continue watching 1.0 experience, will lose support in the 2nd half of 2027. Get all the details in our <a href="http://android-developers.googleblog.com/2026/05/increase-google-tv-app-discovery.html">blog</a>.</div><div><h3><strong><span>15: Performance: the foundation of a great app experience</span></strong></h3>To help developers navigate memory limits in Android 17, we've launched a suite of optimization tools. The <a href="https://developer.android.com/r8-analyzer">R8 Configuration Analyzer</a> identifies keep rules that are bloating your binary, while <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/how-to-capture">ProfilingManager</a> and the integrated LeakCanary in Android Studio streamline memory leak detection. Furthermore, the new <a href="https://developer.android.com/android-performance-analyzer">Android Performance Analyzer</a> offers advanced AI integration for complex trace analysis and automated SQL query generation to pinpoint performance bottlenecks.     <h2><strong><span>And The Latest on Driving Business Growth </span></strong></h2>

  <h3><strong><span>16: What’s new in Google Play</span></strong></h3>Today's <a href="https://goo.gle/play-io26">updates from Google Play</a> help expand your reach and scale your business with less complexity. We’re redefining Play Store discovery with an immersive, short-form video format called Play Shorts, while expanding your audience beyond the store with app discovery in the Gemini app on Android and web. Plus, we’re introducing powerful new capabilities like agentic catalog management for seamless bulk price and SKU updates, and using Gemini models to enable Play Console  to pre-populate store listings from imported documents—making global localization effortless. </div><div><br><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOB1wGZNYGPgY0ED70X7Dtl2KiFk8kRH4fv3HrXXTWX0-xKkN4Em0mi8QAB0g2w_-4SNcTR4fJazpiQ7XI6-XKeyQniFhULKWNmV8YvyWMuQ9tosvT5ixZ0FOye27DI90R5Tra1eWX3FCX7OrWkgzhvhCD6vtfD8_6-FMfMWDvXoVv3zSTauZwraDGsM4/w640-h360/IO26_BlogInLine_App-discovery-in-Gemini_1920x1080_1605.gif"></div><div><i>Gemini will provide users with app suggestions during a search</i></div>

  <h3><strong><span>17: And of course, Android 17</span></strong></h3>
  Android 17 includes new performance &amp; system architecture improvements (in addition to app memory limits) like a lock-free MessageQueue and a GC with more frequent, less intensive young-generation collections to ensure system-wide stability and smoother UIs. The new <a href="https://developer.android.com/about/versions/17/features/contact-picker">contact picker</a> and <a href="https://developer.android.com/reference/android/content/Intent#ACTION_OPEN_EYE_DROPPER">eyedropper API</a> help minimize the use of sensitive permissions and unnecessary access to user data. <br><br>Review <a href="https://developer.android.com/about/versions/17/behavior-changes-all">the behavior changes</a> to make sure your app is ready for Android 17, including <a href="https://developer.android.com/about/versions/17/behavior-changes-all#bg-audio">background audio hardening</a> and <a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps">SMS OTP protection</a>. Get ready to <a href="https://developer.android.com/about/versions/17/behavior-changes-17">target Android 17</a> (API 37) with changes such as mandatory large-screen resizability, certificate transparency by default, and restricted local network access. You can start testing today by enrolling your device <a href="https://android-developers.googleblog.com/2026/04/the-fourth-beta-of-android-17.html">in the Beta</a> or using the latest 17.0 emulator images. <br><br>One more thing. the third beta of our Android 17 quarterly platform release (QPR1) just came out, and it contains a minor SDK release to support a few features that just couldn't wait for QPR2.

  <h2><strong><span>Check out all of the Android &amp; Play Content at Google I/O </span></strong></h2>
  <p><span face="sans-serif">This was just a preview of some of the updates for Android developers at Google I/O. Tune into <a href="https://io.google/2026/explore/pa-keynote-5">What’s New in Android</a> for the latest news and announcements and <a href="https://io.google/2026/">follow Google I/O</a> for much more over the following week!</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Convert XLS To CSV]]></title>
<description><![CDATA[If you need to convert XLS to CSV, you have come to the right place. CSV is the most cross-platform spreadsheet format, and converting a spreadsheet into CSV format makes sense since most applications support CSV rather than XLS or any other proprietary format. CSV files are lightweight, easy to ...]]></description>
<link>https://tsecurity.de/de/3684576/betriebssysteme/convert-xls-to-csv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684576/betriebssysteme/convert-xls-to-csv/</guid>
<pubDate>Tue, 21 Jul 2026 20:03:25 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you need to convert XLS to CSV, you have come to the right place. CSV is the most cross-platform spreadsheet format, and converting a spreadsheet into CSV format makes sense since most applications support CSV rather than XLS or any other proprietary format. CSV files are lightweight, easy to parse, and compatible with virtually […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/windows-tips/convert-xls-to-csv/">Convert XLS To CSV</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta’s Quest Game Subscribers Will Be Getting Some Xbox Extras]]></title>
<description><![CDATA[Meta’s throwing Xbox cloud gaming Into Its Horizon Plus Quest subscription, and converting its controllers to work with it.]]></description>
<link>https://tsecurity.de/de/3684164/it-nachrichten/metas-quest-game-subscribers-will-be-getting-some-xbox-extras/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684164/it-nachrichten/metas-quest-game-subscribers-will-be-getting-some-xbox-extras/</guid>
<pubDate>Tue, 21 Jul 2026 17:22:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta’s throwing Xbox cloud gaming Into Its Horizon Plus Quest subscription, and converting its controllers to work with it.]]></content:encoded>
</item>
<item>
<title><![CDATA[Small models, sovereign advantage: Why Australia should build its own AI edge]]></title>
<description><![CDATA[For the past three years, the AI conversation has been dominated by scale. Bigger models, bigger compute clusters, bigger headlines. But the next wave of competitive advantage won’t come from who can rent the biggest model; it will come from who can build the smallest one that knows their busines...]]></description>
<link>https://tsecurity.de/de/3683294/it-nachrichten/small-models-sovereign-advantage-why-australia-should-build-its-own-ai-edge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683294/it-nachrichten/small-models-sovereign-advantage-why-australia-should-build-its-own-ai-edge/</guid>
<pubDate>Tue, 21 Jul 2026 12:03:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For the past three years, the AI conversation has been dominated by scale. Bigger models, bigger compute clusters, bigger headlines. But the next wave of competitive advantage won’t come from who can rent the biggest model; it will come from who can build the smallest one that knows their business.</p>



<p class="wp-block-paragraph">That model is the <a href="https://www.cio.com/article/4119259/small-language-models-why-specialized-ai-agents-boost-resilience-and-protect-privacy.html">small language model (SLM)</a>: Compact, purpose-built, trained on an organization’s own data and run under that organization’s own governance. And it is about to become one of the most consequential strategic assets available to both the private and public sector.</p>



<h2 class="wp-block-heading">The problem with renting intelligence</h2>



<p class="wp-block-paragraph">Right now, most organizations consume AI the way they once consumed electricity from a single utility by plugging into a handful of frontier models built by a small number of global vendors. These models are extraordinary generalists. They are also, by design, generic. They are tuned to be safe, broad and useful to everyone, which means they are optimised for no one in particular.</p>



<p class="wp-block-paragraph">That’s a problem for any organization trying to build genuine differentiation. If every competitor in your sector is calling the same foundation model with the same prompts, the model itself is not your edge. Your edge is what only you know, your proprietary data, your institutional judgement, your operating history. A generic model can’t see any of that unless you keep feeding it to them, turn after turn, at cost, with no lasting memory and no guarantee of where that data ends up.</p>



<p class="wp-block-paragraph">An SLM flips that equation. Trained on an organization’s own document libraries, case histories, policy archives, transaction data and operational know-how, it becomes a model that thinks the way your organization thinks, because it was built from your organization’s accumulated judgement. It doesn’t need to be the smartest model in the world. It needs to be the most useful one for you.</p>



<p class="wp-block-paragraph">I’ve seen this play out directly. At one of Australia’s largest integrated tourism and cruise businesses, simultaneously a B2C retailer, a B2B distributor to thousands of agency and wholesale clients globally, an aggregator marketplace for more than 1,800 independent tourism operators, and a cruise operator with offshore shared services spanning finance, customer contact and content management. The constraint wasn’t a lack of access to large general-purpose models. It was that none of them understood the business: 1,800 different operator catalogues, each with its own pricing logic, inventory quirks and content conventions; years of customer contact history with its own vocabulary and escalation patterns; a marketplace search experience that needed to reason over the business’s own product taxonomy, not the open web’s.</p>



<p class="wp-block-paragraph">Models trained and tuned on that proprietary data, operator listings, historical tickets, booking and pricing data delivered results a generic model never could. Domain-tuned content drafting cut operator listing time by 70% and eliminated a 23-day onboarding backlog outright, taking new-operator time-to-live from 23 days to three. A semantic search model trained on the marketplace’s own product catalogue lifted booking conversion by 24%. AI-driven triage trained on the business’s own contact history cut Tier 1 escalations by 34%. None of this came from a smarter foundation model. It came from a smaller, more specific one that knew the business.</p>



<h2 class="wp-block-heading">Why “small” is the strategic choice, not the compromise</h2>



<p class="wp-block-paragraph">There’s a temptation to treat SLMs as the budget option, what you build when you can’t afford a frontier model. That’s the wrong frame. The evidence is already compelling: <a href="https://azure.microsoft.com/en-us/blog/empowering-innovation-the-next-generation-of-the-phi-family/">Microsoft’s Phi-4 family of small models</a>, released in early 2025, demonstrated that a 14-billion-parameter model can match or exceed the performance of models many times its size on complex reasoning and domain-specific tasks while running at a fraction of the compute cost and on-premise, entirely within an organization’s own infrastructure. Smaller, domain-trained models are increasingly outperforming general-purpose giants on narrow, high-value tasks, with far tighter control over data residency, security and explainability.</p>



<p class="wp-block-paragraph">For a CIO or CTO, that combination of lower cost, tighter governance, higher task-specific accuracy is rare enough to demand attention on its own. But the deeper value sits one layer up, at the operating model. An SLM trained on your service history can sit inside claims processing, citizen services, clinical triage, asset maintenance scheduling or M&amp;A due diligence quietly compounding institutional knowledge into a reusable asset rather than letting it walk out the door every time someone retires or resigns.</p>



<p class="wp-block-paragraph">That is the real shift: AI capability stops being a subscription and starts being a balance-sheet asset. It can be valued, protected, audited and improved because it belongs to you.</p>



<h2 class="wp-block-heading">The public sector’s hidden advantage</h2>



<p class="wp-block-paragraph">Nowhere is this more obvious than in government. The public sector sits on some of the richest, least-exploited data and institutional knowledge in the country: Decades of policy outcomes, service delivery history, regulatory precedent, infrastructure records and frontline expertise. Most of it has never been put to systematic use because no commercially available model was ever trusted to touch it, and rightly so.</p>



<p class="wp-block-paragraph">A small, sovereign, purpose-built model changes that calculus. Trained, hosted and governed entirely within government infrastructure, an SLM doesn’t require sensitive citizen or policy data to leave a secure perimeter. The Australian Government has already recognised this direction: <a href="https://www.finance.gov.au/about-us/news/2025/introducing-aps-ai-plan">The APS AI Plan, released in November 2025</a>, commits to expanding the GovAI platform to provide all public servants with secure, sovereign AI tools operating entirely within Australian Government infrastructure. SLMs tuned to individual agency mandates are the logical next step and a more powerful one than any generic government-wide tool can deliver.</p>



<p class="wp-block-paragraph">Rather than each agency independently negotiating with the same handful of overseas vendors, a coordinated approach of common standards for model governance, shared security architecture, common evaluation frameworks and pooled infrastructure investment would let agencies build and reuse SLM capability horizontally, the way shared services and common ICT platforms have been built before. Each agency gets a model genuinely tuned to its mandate, but the security model, audit trail and assurance framework are consistent, government-backed and independently verifiable.</p>



<p class="wp-block-paragraph">Done well, this isn’t just an efficiency play. It’s a sovereignty play. As <a href="https://www.govtechreview.com.au/content/gov-datacentre/article/why-sovereign-ai-is-becoming-a-strategic-priority-in-australia-81646916">GovTech Review has noted</a>, large language models hosted offshore create data flows that extend beyond Australia’s borders in ways that are rarely transparent, a risk that is simply untenable for government. Sovereign, purpose-built models keep Australian public data, public knowledge and the resulting capability uplift inside Australian hands, rather than exporting both the data and the long-term value to offshore platforms.</p>



<h2 class="wp-block-heading">Why this belongs in the innovation budget, not the IT budget</h2>



<p class="wp-block-paragraph">The instinct in many organizations is to treat AI spend as an IT line item, something to be minimised, benchmarked and squeezed for cost efficiency. SLMs deserve a different treatment. They are closer to R&amp;D than infrastructure: An investment in converting accumulated institutional knowledge into a durable, defensible capability.</p>



<p class="wp-block-paragraph">That argument holds in the private sector too. A PE-backed portfolio company, a regulated financial services firm, a healthcare provider — each has years of proprietary operating data sitting idle in case files, transaction logs and service records. An SLM built on that data is a way of turning a sunk cost, decades of operational history, into a forward-looking asset that compounds with every additional case it processes.</p>



<p class="wp-block-paragraph">Boards and executive committees that are still asking “what is our AI strategy?” as a single, undifferentiated question are asking the wrong thing. The better question is: Which parts of our operation are rich enough in proprietary data and judgement to justify owning the model outright, rather than renting someone else’s?</p>



<h2 class="wp-block-heading">The opportunity in front of us</h2>



<p class="wp-block-paragraph">The first wave of enterprise AI adoption was about access: Getting a capable model into people’s hands quickly. The next wave will be about ownership: Who controls the model, who controls the data it was built on, and who captures the long-term value of the institutional knowledge it encodes.</p>



<p class="wp-block-paragraph">Australia, with a public sector rich in data and a private sector with deep vertical expertise in financial services, resources, healthcare and logistics, is well placed to lead on this if it treats small, sovereign models as a genuine national capability question, not a procurement footnote. The organizations, and the country, that move early will not just save money. They will own something their competitors can’t easily replicate: An AI that knows them.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scalding hot AI accelerators have put datacenters in hot water. Two-phase cooling could chill them out]]></title>
<description><![CDATA[Startup Accelsius claims it can achieve up to 14° C cooler GPU temps by by converting a liquid-cooled Dell PowerEdge to run on refrigerants]]></description>
<link>https://tsecurity.de/de/3683292/it-nachrichten/scalding-hot-ai-accelerators-have-put-datacenters-in-hot-water-two-phase-cooling-could-chill-them-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683292/it-nachrichten/scalding-hot-ai-accelerators-have-put-datacenters-in-hot-water-two-phase-cooling-could-chill-them-out/</guid>
<pubDate>Tue, 21 Jul 2026 12:03:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Startup Accelsius claims it can achieve up to 14° C cooler GPU temps by by converting a liquid-cooled Dell PowerEdge to run on refrigerants]]></content:encoded>
</item>
<item>
<title><![CDATA[💚 Our Family's Electrotech Journey 🌞🏡🔌⛽️🚘️ (emf2026)]]></title>
<description><![CDATA[The story of how we went all electric, ditched fossil fuels, disconnected our gas supply and stopped burning stuff, and how you can too.

Our experience of converting a ~100 year old semi-detached house to modern clean living, and electrifying other parts of our lifestyle, such as travelling with...]]></description>
<link>https://tsecurity.de/de/3678185/it-security-video/our-familys-electrotech-journey-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678185/it-security-video/our-familys-electrotech-journey-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 17:18:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The story of how we went all electric, ditched fossil fuels, disconnected our gas supply and stopped burning stuff, and how you can too.

Our experience of converting a ~100 year old semi-detached house to modern clean living, and electrifying other parts of our lifestyle, such as travelling without flying.

Advice on switching to (and charging) electric vehicles, solar panels and home batteries, insulation, induction hobs and heat pumps. Mistakes made, lessons learned, what we'd do differently next time and how much it saves us.

How to monitor, control and automate your low carbon tech with open energy monitor and home assistant. Tips for making things work together well and play nicely with each other. The perils of cloud integrations and vendors shutting down systems.

Also covering self-built (and bought) air quality monitors for citizen science and environmental monitoring of the changes in air pollution. How to make projects such as Sensor Community and pull the data into your local home management system.

Discover how to be greener, healthier, safer, more resilient/secure, spend less money and have fun geeking out on it along the way.

Learn from our real-world experience in this electrifying talk.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/82-our-familys-electrotech-journey]]></content:encoded>
</item>
<item>
<title><![CDATA[Converting your Android Auto to wireless is easy with an adapter]]></title>
<description><![CDATA[Cutting the cord in your car is a simple upgrade.]]></description>
<link>https://tsecurity.de/de/3678095/it-nachrichten/converting-your-android-auto-to-wireless-is-easy-with-an-adapter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678095/it-nachrichten/converting-your-android-auto-to-wireless-is-easy-with-an-adapter/</guid>
<pubDate>Sat, 18 Jul 2026 15:47:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cutting the cord in your car is a simple upgrade.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple just made Windows games run much faster on Mac]]></title>
<description><![CDATA[Apple’s Game Porting Toolkit 4 beta has delivered a major performance boost for Windows games running on Mac, giving Apple Silicon users a much better gaming experience without requiring new hardware. Early tests on an M4 Pro MacBook Pro show that demanding titles such as Grand Theft Auto V and R...]]></description>
<link>https://tsecurity.de/de/3674297/ios-mac-os/apple-just-made-windows-games-run-much-faster-on-mac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674297/ios-mac-os/apple-just-made-windows-games-run-much-faster-on-mac/</guid>
<pubDate>Thu, 16 Jul 2026 19:36:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s Game Porting Toolkit 4 beta has delivered a major performance boost for Windows games running on Mac, giving Apple Silicon users a much better gaming experience without requiring new hardware. Early tests on an M4 Pro MacBook Pro show that demanding titles such as Grand Theft Auto V and Red Dead Redemption 2 now run faster and more smoothly than they did with the previous version.



Game Porting Toolkit helps developers test Windows games on macOS by translating DirectX 11 and DirectX 12 graphics commands into Apple’s Metal API. Although Apple designed the tool for developers, many Mac users also use it to play games that do not have official macOS versions.



GTA V performance jumps by 66 percent



Macworld’s Filipe Esposito tested Game Porting Toolkit 4 beta on an M4 Pro MacBook Pro with 24GB of RAM and found a clear improvement in frame rates.




“GTA V jumped from roughly 106 frames per second under GPTK 3 to around 176 fps with GPTK 4 beta. That’s an increase of about 66%.”




The game ran at 2K resolution with medium to high settings, while Red Dead Redemption 2 increased from around 60 fps to nearly 75 fps under the same conditions.



Esposito also said the latest beta “fundamentally changed the experience” of playing demanding Windows games on Mac. The gains come mainly from better translation technology, which reduces the workload involved in converting Windows instructions for Apple Silicon.



Game Porting Toolkit 4 still cannot match native macOS performance in every game, but these results show that Apple has made strong progress. Better compatibility and higher frame rates now give developers more reason to consider bringing Windows games to Mac.]]></content:encoded>
</item>
<item>
<title><![CDATA[Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management]]></title>
<description><![CDATA[Written by: Jules Czarniak

Introduction 
As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. 
To keep pace, many security teams are exploring how to integrate la...]]></description>
<link>https://tsecurity.de/de/3673775/it-security-nachrichten/demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnerability-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673775/it-security-nachrichten/demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnerability-management/</guid>
<pubDate>Thu, 16 Jul 2026 16:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Jules Czarniak</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction </span></h3>
<p><span>As highlighted in the </span><a href="https://cloud.google.com/security/resources/m-trends"><span>Mandiant M-Trends 2026 report</span></a><span>, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. </span></p>
<p><span>To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes introduces new architectural risks. </span></p>
<p><span>In response to customer inquiries about how to safely integrate AI capabilities into vulnerability management workflows, this blog provides actionable guidance from Mandiant Consulting about how to establish operational guardrails for AI assisted vulnerability management, including several detailed scenarios. What each of these examples show is that security teams can accelerate workflows with AI while also upholding the structural integrity of their environments. We suggest that combining AI capabilities with deterministic controls and human intelligence in strategic ways maximizes benefits and reduces risk. </span></p>
<h3><span>Establish Operational Guardrails to Safely Deploy AI Agents</span></h3>
<p><span>To safely adopt advanced AI capabilities without introducing unpredictable failures into deployment pipelines, organizations should ground their approach in established industry standards. While guidelines like the </span><a href="https://www.nist.gov/itl/ai-risk-management-framework" rel="noopener" target="_blank"><span>NIST AI Risk Management Framework (RMF)</span></a><span> and the </span><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/" rel="noopener" target="_blank"><span>OWASP Top 10 for LLMs</span></a><span> provide comprehensive baselines for identifying risks, operationalizing these controls requires a structural blueprint.</span></p>
<p><span>Frameworks like </span><a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"><span>Google’s Secure AI Framework (SAIF)</span></a><span> </span><a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"><span>and</span></a><a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/1018686.pdf" rel="noopener" target="_blank"><span> </span><span>Google’s approach to secure AI Agents</span></a><span> provide a practical path forward, demanding that organizations extend existing deterministic controls directly into the AI execution environment. When deploying AI agents, security teams should navigate specific operational and structural risks:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Pre-agent data security and Defense-in-Depth:</strong><span> Agents should not be able to access personally identifiable information (PII), protected health information (PHI), or other sensitive data. Organizations should enforce data security before the prompt reaches the model. This includes strictly using non-production environments populated with synthetic data for testing. For production, security teams should deploy a hybrid defense-in-depth model. This includes Layer 1 deterministic policy engines acting as chokepoints, alongside Layer 2 reasoning-based defenses like specialized guard models (such as </span><a href="https://docs.cloud.google.com/model-armor/overview"><span>Model Armor</span></a><span> or similar provider-agnostic guardrails) to filter out sensitive data and block malicious prompt injections before they reach the agent layer. Crucially for vulnerability discovery, security teams should treat the codebase itself as an untrusted input. Threat actors can embed indirect prompt injections within source code comments or third-party dependencies (e.g., hidden instructions telling the agent to ignore vulnerabilities or exfiltrate environment variables), making input sanitation a requirement even for internal scanning.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cloud provider limitations and zero data retention (ZDR):</strong><span> Many cloud and LLM providers block or throttle automated offensive security probing by default to prevent abuse. Organizations should establish clear rules of engagement and authorized testing agreements to navigate acceptable use policies. Furthermore, organizations should enforce strict zero data retention (ZDR) agreements with their LLM providers to guarantee that proprietary code and discovered vulnerabilities are never used to train external models.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Workload isolation:</strong><span> Agent workloads should execute in strictly isolated, unprivileged containers with dynamically limited privileges. By relying on robust sandboxing to prevent privilege escalation, if an agent hallucinates a destructive command or is hijacked via prompt injection, the blast radius remains contained.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Red Teaming:</strong><span> Before deploying autonomous vulnerability scanners that can dynamically spin up sandboxes and execute code, organizations should subject the AI agents themselves to human-led red teaming as part of comprehensive assurance efforts. This validates the agent's resilience against jailbreaks, recursive logic loops, and complex prompt injections, ensuring the security tooling does not become the attack vector.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Least-Privileged Machine Identities and Human Controllers:</strong><span> While workloads should be isolated, agents inherently require privileges to generate pull requests and commit code. Security teams should ensure these agents operate under distinct, strictly scoped machine identities that tie back to human controllers to ensure accountability and user consent. Organizations should use short-lived, just-in-time (JIT) tokens bound exclusively to the specific repository and branch under review. T</span><span>his enforces the principle of limited agent powers and ensures that even if an agent’s container is compromised via prompt injection, the threat actor cannot pivot to modify adjacent enterprise codebases.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Supply chain resilience for skills:</strong><span> As developers augment AI with third-party skills and model context protocol (MCP) servers, security teams should treat these integrations as untrusted supply chain components. MCP plugins introduce the risk of supply chain poisoning, where a previously benign integration is silently updated with malicious dependencies. Additionally, security teams should evaluate the underlying agent orchestration frameworks themselves (e.g., LangChain, AutoGen) for inherent vulnerabilities, such as session memory poisoning or recursive loop hijacking.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Toxic flow analysis (TFA) and Observable Actions:</strong><span> The objective of TFA is to monitor data paths at runtime, ensuring agents do not exfiltrate sensitive internal context to unvetted external endpoints. Agent actions, inputs, reasoning, and outputs must be fully observable and transparently logged. While implementing dynamic taint tracking for LLMs remains a complex architectural challenge, organizations should clearly separate this runtime observability from static supply chain controls. Integrating threat intelligence to hash and vet incoming agent tools provides a necessary baseline for verifying integrity </span><span>before</span><span> deployment. However, because static controls cannot address behavior post-deployment, mitigating data exfiltration ultimately requires active runtime monitoring and secure, centralized logging to trace and restrict the actual flow of data.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image1.max-1000x1000.png" alt="Demystifying AI image1">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="u6hlz">Figure 1: Visual representation of an isolated AI agent environment using SAIF mechanisms</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>By operationalizing these tools within frameworks that demand verifiable integrity and structural resilience, organizations can safely bridge the gap between AI velocity and enterprise defense.</span></p>
<h3><span>The need for human-led threat modeling</span></h3>
<p><span>While LLMs excel at identifying syntax patterns, source code itself rarely contains the full picture of unwritten business intent. Some organizations attempt to solve this by connecting LLM agents to internal wikis, design documents, and issue trackers using retrieval-augmented generation (RAG).</span></p>
<p><span>While RAG gives the model access to external business context, it is not a perfect fix. Corporate documentation is frequently stale, contradictory, or incomplete. An AI agent might retrieve an outdated architecture diagram and confidently hallucinate a secure path that no longer exists in production. Because LLM agents struggle to resolve conflicting, undocumented human assumptions, human-led threat modeling remains a critical security control across both legacy applications and modern agent workflows.</span></p>
<p><span>Security teams should apply threat modeling during both the pre-build system design phase to establish a secure foundation, and during post-build architecture reviews. While an AI agent might successfully identify a poorly configured internal endpoint locally, a human threat modeler asks the structural question: </span><span>why does that microservice possess broad database read permissions in the first place?</span><span> </span></p>
<p><span>Identifying architectural vulnerabilities requires reasoning about business risk, data sensitivity, and operational constraints. To structure this process, organizations can use industry frameworks like PASTA (Process for Attack Simulation and Threat Analysis) or service offerings like the </span><a href="https://services.google.com/fh/files/misc/ds-threat-modeling-security-service-en.pdf" rel="noopener" target="_blank"><span>Mandiant Threat Modeling Security Service</span></a><span> to map trust boundaries, uncover structural design flaws, and prioritize compensating controls. Securing fundamental architecture through human oversight is a necessary component when relying on automated agents to find bugs in a poorly designed system.</span></p>
<p><span>Once these AI agents are safely sandboxed, as guided by SAIF, and the architecture is verified through threat modeling, organizations can typically apply them to two different problem spaces: Enterprise Vulnerability Management (to assist in managing the volume of known CVEs in commercial off-the-shelf (COTS) software and infrastructure) and Product Security (to identify vulnerabilities in 1st-party (1P) code).</span></p>
<h3><span>Track 1: Enterprise Vulnerability Management</span></h3>
<h4><span>Foundational security and discovery </span></h4>
<p><span>While the second track of this post explores how AI agents can uncover complex zero-days in custom code, organizations should manage the scale of enterprise infrastructure in tandem with these AI deployments. Even as new AI capabilities dominate headlines, organizations should still address foundational security challenges, such as secrets sprawl, unmanaged service accounts, missing FIDO2 MFA, and legacy VPN concentrators. Although vulnerability exploitation was the primary initial infection vector in intrusions Mandiant investigated last year, threat actors consistently rely on missing foundational controls and unpatched edge devices to secure and escalate their foothold after exploiting a vulnerability.</span></p>
<p><span>Furthermore, AI cannot replace foundational visibility. As security teams deploy AI agents, they should simultaneously close these tactical entry points by maximizing dynamic discovery capabilities like External Attack Surface Management (EASM), Cloud Security Posture Management (CSPM), and Continuous Threat Exposure Management (CTEM). In hybrid and cloud environments, tools like </span><a href="https://cloud.google.com/wiz?e=48754805"><span>Wiz</span></a><span> can be used to map this initial footprint.</span></p>
<h3><span>Risk-based vulnerability management </span></h3>
<p><span>Vulnerability management teams are already overwhelmed by the current volume of findings generated by traditional scanners. As organizations scale dynamic discovery tools, such as EASM, CSPM and CTEM, alongside automated AI agents, this influx of findings will compound the problem. To manage this influx, telemetry from these diverse discovery methods must first be normalized and deduplicated. This normalized data serves two purposes: it feeds directly into the risk engine, and it acts as a live overlay to correct stale records in the configuration management database (CMDB). By evaluating the deduplicated vulnerabilities alongside this newly updated asset context and frontline threat intelligence, the RBVM engine calculates a custom risk score that allows security teams to dynamically prioritize remediation.</span></p>
<p><span>A mature RBVM methodology calculates a customized risk score on a 0 to 100 scale using a weighted average. A sample formula for calculating this risk-based score is:</span></p>
<p><span>Final Score = (W_1 * S_vuln) + (W_2 * S_asset) + (W_3 * S_threat)</span></p>
<p><span>The variables and weights (W) are customized to the organization's risk appetite (for example, 0.20 for vulnerability, 0.40 for asset, and 0.40 for threat, summing to 1.0), while the underlying variables (S) are scored on a 0 to 100 scale and defined as follows:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Vulnerability severity (S_vuln): </strong><span>The inherent technical severity of the flaw. This is calculated by taking the CVSS Base Score (which natively accounts for confidentiality, integrity, and availability impact) and multiplying it by 10.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Asset context (S_asset): </strong><span>A combined metric of exposure and data sensitivity. Scores range from 100 for internet-facing assets holding customer data, down to 25 for internal-only assets with no sensitive data. To translate this impact into monetary terms for non-technical stakeholders, organizations can incorporate Factor Analysis of Information Risk (FAIR) principles into this metric. However, this approach requires highly accurate, continuously updated financial data that many enterprises struggle to maintain at scale.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Threat context (S_threat): </strong><span>The real-world urgency of the vulnerability. Scores range from 100 if actively exploited by threat actors relevant to the organization's profile, 75 if a proof-of-concept exists or if it is a vulnerability class easily exploited by autonomous AI agents, down to 25 if the exploit is theoretical and highly complex. Organizations should also map the Exploit Prediction Scoring System (EPSS) probability percentage directly into this variable. This allows the threat score to automatically scale up or down as real-world exploitation telemetry shifts, aligning static vulnerability data with active threat intelligence.</span></p>
</li>
</ul>
<p><span>An asset's customized risk score should directly influence internal remediation service-level agreements (SLAs), unless external compliance-driven mandates, such as CISA Binding Operational Directives (BODs), or relevant equivalents, override internal prioritization. A risk-driven and threat-intelligence-driven vulnerability prioritization methodology will help organizations focus resources on managing and mitigating the most critical security vulnerabilities first. This is an area where LLMs can support the vulnerability management process, particularly by helping teams synthesize unstructured threat intelligence to surface relevant risk contexts more efficiently. Enforcing strict SLOs for patching, while requiring formal risk acceptance documentation for any patching exceptions, will help reduce the number of vulnerabilities available to threat actors and increase the visibility of outstanding risks across the organization. Furthermore, organizations should integrate RBVM data directly into their security orchestration, automation, and response (SOAR) platforms for automated alert enrichment.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image5.max-1000x1000.png" alt="Demystifying AI image5">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ce5s1">Figure 2: Integration points of a risk-based vulnerability management (RBVM) program.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Containment and Observability</span></h3>
<p><span>Modern architecture blueprints must prioritize attack surface reduction under the assumption that vulnerabilities will inevitably be exploited. Moving away from traditional perimeter defenses, organizations should align with zero trust principles, ensuring that security boundaries are established around every asset, workload, and identity.</span></p>
<p><span>A component of this alignment is the implementation of strong authentication principles. Organizations should eliminate implicit trust by enforcing continuous, context-aware authentication and authorization. Utilizing Zero Trust Network Access (ZTNA) solutions, such as Identity-Aware Proxies (IAP), shields critical management interfaces (e.g., SSH, RDP) and internal systems from direct internet exposure, granting access only to verified identities and compliant devices.</span></p>
<p><span>For public-facing applications and APIs, attack surface reduction involves deploying Layer 7 inspection at the load balancer or API gateway level. This hardening layer enforces strict schema validation, intercepting and neutralizing malformed inbound traffic and potential exploits before they can interact with internal application logic.</span></p>
<p><span>Securing the software supply chain is equally vital in modern blueprints, and organizations should align with frameworks like </span><a href="https://slsa.dev/spec/v0.1/levels" rel="noopener" target="_blank"><span>Supply-chain Levels for Software Artifacts (SLSA)</span></a><span> across both dependency and build tracks. Security policies should mandate that third-party dependencies are routed through a centralized artifact repository equipped with automated curation services, such as </span><a href="https://cloud.google.com/security/products/assured-open-source-software"><span>Google Assured Open Source Software (OSS)</span></a><span> or an equivalent solution, preventing untrusted code from entering the development lifecycle. Furthermore, maturing toward advanced SLSA build levels (e.g., SLSA level 3) through the implementation of isolation, ephemerality and reproducibility requirements via  ephemeral compute infrastructure for CI/CD runners reduces the likelihood of attacker persistence by ensuring environments are short-lived and automatically cycled.</span></p>
<p><span>To complement these pre-build controls, runtime observability should be established across all production workloads. This requires monitoring both infrastructure-level behavior and the specific runtime libraries actively executing in production, which surfaces true exploitable risk far beyond a static Software Bill of Materials. In tandem with monitoring workloads, organizations should secure how they authenticate by implementing workload identity federation. By removing static credentials and instead using short-lived tokens backed by strong cryptographic identity verification, organizations can reduce the risk of credential theft and unauthorized lateral movement.</span></p>
<p><span>Within the internal environment, microsegmentation should be enforced to break down flat networks into granular security zones. Routing application traffic through a Secure Access Service Edge (SASE) architecture integrates network routing directly with robust identity controls, rendering internal services completely invisible to unauthenticated users and containing threats to their initial point of entry.</span></p>
<p><span>Finally, automated containment and incident response within a zero trust framework must rely on deterministic, auditable tooling. Endpoint detection and response (EDR) platforms and SOAR playbooks should handle high-fidelity containment tasks through hardcoded execution logic. While AI tools accelerate triage and policy recommendation, actual execution capabilities must remain restricted to well-defined, pre-tested workflows to maintain total architectural predictability.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image8.max-1000x1000.png" alt="Demystifying AI image8">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ak3zc">Figure 3: Structural containment and observability architecture</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Track 2: Product Security &amp; Development (1P Code)</span></h3>
<h4><span>Deterministic and probabilistic tooling</span></h4>
<p><span>Integrating LLM agents into vulnerability management and security workflows requires recognizing the differences between deterministic and probabilistic tooling. Traditional SAST and DAST tools utilize fixed methodologies to evaluate vulnerabilities through structural code parsing or definitive runtime observations. LLMs, however, evaluate source code by processing tokens simultaneously to calculate statistical and semantic relationships, rather than tracing deterministic execution tracks.</span></p>
<p><span>While techniques like Chain of Thought (CoT) prompting allow models to bridge this gap by decomposing complex code paths into intermediate reasoning steps, this process remains bounded by architectural limitations. Even when a model possesses a context window large enough to ingest entire repositories, it may experience attention degradation across long inputs, often failing to correctly weight intervening validation or sanitization logic within the prompt. For example, if a variable is tainted on line 10 but sanitized on line 500, attention degradation can cause the model to lose track of the sanitization logic. Furthermore, when enterprise codebases require chunking to fit within context limits, the resulting fragmentation may cause the model to lose track of end-to-end data flows.</span></p>
<p><span>Consequently, probabilistic engines are effective at uncovering localized, static anomalies, such as hardcoded credentials or outdated dependencies, but frequently misjudge complex vulnerabilities split across fragmented chunks or extended context windows. Notable exceptions occur when these probabilistic models are coupled with deterministic feedback loops. For instance, when analyzing C++ memory corruption, an LLM can be equipped with a test harness to iteratively execute code and definitively prove a crash. While these dynamic validation applications are detailed in subsequent sections, the baseline limitation for static analysis across standard enterprise codebases remains: models struggle to consistently evaluate dispersed logic.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image4.max-1000x1000.png" alt="Demystifying AI image4">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ak3zc">Figure 4: Deterministic SAST scanners vs. probabilistic LLMs</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Binary and architectural oracles</span></h3>
<p><span>Many security programs are moving toward agent workflows where an agent autonomously spins up a test environment and uses tools to execute payloads and verify its findings. This is a promising approach, but it is important to understand where it is most effective.</span></p>
<p><span>Agent workflows perform well against bug classes with binary and observable oracles, meaning the system provides an objective, 'crash or no crash' feedback loop. For example, if a model is hunting for memory corruption in a C++ kernel, a successful exploit is undeniable: the payload executes, and a resulting crash definitively proves the vulnerability. This explains why the industry is currently seeing a surge in AI-discovered vulnerabilities across memory-unsafe targets like web browsers and operating systems.</span></p>
<p><span>However, enterprise software is heavily dominated by vulnerabilities that require architectural oracles for validation. Vulnerabilities like authorization bypasses, complex business logic flaws, and indirect server-side request forgeries require an understanding of business context and cross-service trust boundaries. If an agent's payload fails to produce a clear outcome, it can't reliably distinguish whether the vulnerability is a hallucination or if it simply constructed the payload incorrectly. An agent's malformed payload might even crash an unrelated background process and cause the model to hallucinate a success and report a false confirmation. Complex enterprise architecture contains unwritten business intent that a probabilistic engine can't inherently know.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image3.max-1000x1000.png" alt="Demystifying AI image3">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 5: Evaluating vulnerabilities against binary vs. architectural oracles</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Targeted deployment and human impact</span></h3>
<p><span>Organizations adopting LLMs for vulnerability discovery face a massive staffing challenge. LLMs can generate findings significantly faster than human engineers can triage them. If every LLM-generated alert requires manual review, security teams will quickly face burnout and/or suffer alarm fatigue.</span></p>
<p><span>Rather than indiscriminately pointing agents at all available codebases and risking an influx of unverified output, security teams need a selective deployment strategy. Mature programs should maintain SAST and DAST for baseline hygiene and deterministic rule enforcement, and reserve intensive agent audits for high-impact components with clear binary oracles.</span></p>
<p><span>Organizations can prioritize agent audits on systems where the technology's strengths align with the broader risk profile:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Memory-unsafe codebases:</strong><span> Legacy or high-performance components written in memory-unsafe languages such as C, C++, or Assembly are strong candidates for LLM audits. These languages are susceptible to memory corruption flaws, such as buffer overflows and use-after-free conditions. Because these vulnerabilities trigger definitive failure states like segmentation faults, they work well with automated sandboxes where agents can compile the code with memory sanitizers and write proof-of-concept inputs. This approach is also effective for auditing the native extensions where safe languages call unsafe internal libraries, such as Python C extensions or the Java Native Interface (JNI).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Systems highly exposed to outside content:</strong><span> First-party data ingestion pipelines, custom API gateways, or proprietary edge proxies. A prerequisite here is direct access to the source code, this strategy is strictly for internally developed or fully open-source codebases where the organization can inspect the logic. Because these systems directly parse untrusted internet traffic, targeting their source code for LLM-driven audits yields the highest risk-reduction ROI.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Shared internal libraries and utilities: </strong><span>Core serialization/deserialization packages, common utility functions, and custom middleware wrappers (such as internal message-queue parsers) maintained in-house. Because the enterprise owns the source code for these shared building blocks, agent tools can easily hook into them within automated test harnesses to fuzz inputs and catch low-level logic or parsing bugs with high fidelity.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Foundational security boundaries:</strong><span> Internally developed centralized authentication services, custom OAuth providers, and internal credential brokers. While testing complex identity boundaries generates higher logic-based noise, having full access to the source code allows teams to pair agents with deterministic checks to safely triage findings, given that the blast radius of an authentication failure justifies the human effort.</span></p>
</li>
</ul>
<p><span>To filter the noise generated by LLMs, organizations should establish routing rules. Require the agent to generate a fully reproducible, deterministic test harness (such as a compiled binary or a Python test script) that attempts to prove the exploit. This harness must execute automatically in an isolated, monitored sandbox. If the sandbox execution fails (due to a syntax error or a failed exploit), the ticket is discarded, sparing human resources. However, organizations should enforce execution timeouts and iteration limits on these test harnesses. Without hard limits, an autonomous agent attempting to prove a vulnerability can fall into an infinite loop: writing a script, failing, rewriting, and failing again, exhausting API token budgets and compute resources against a single dead-end vulnerability, creating significant cost overruns without advancing the security review. To manage these expenses, organizations should incorporate FinOps principles to balance the compute and API costs of LLM audits against the traditional expenses of manual triage.</span></p>
<p><span>However, a successful execution in the sandbox does not guarantee an actionable, high-priority risk. In practice, autonomous agents frequently produce working PoCs for genuine technical flaws that are ultimately irrelevant; or warrant a lower remediation priority within the context of the system's threat model. For example, the agent might successfully exploit an unreachable dead-code path, or trigger a bug that requires administrative access to execute and yields no further escalation of privilege. Therefore, a human engineer should be assigned to review and prioritize the ticket only if the sandbox registers a successful execution, validating environmental context, reachability, and true business impact as part of the review.</span></p>
<p><span>This workflow reduces the volume of alerts, but it is important to understand that the security team's workload does not disappear. The engineer's primary job shifts from manually hunting for the initial vulnerability to auditing the LLM-generated proof to ensure it represents a meaningful risk rather than an unexploitable or contextually irrelevant finding. Leadership should properly staff and train teams for this new reality. Deploying LLM agents does not remove the need for skilled practitioners; it redirects their workload toward complex validation. Equally important is training teams to recognize the risk of false negatives. A hyper-focus on filtering AI-generated noise can create a false sense of security. If an exploit relies on a novel technique or a zero-day vulnerability that was not heavily weighted in the model's training data, the agent will likely scan right past it in silence. LLMs augment discovery, but they do not guarantee exhaustive coverage.</span></p>
<p><span>When integrating LLMs into SAST triage pipelines, human engineers should also verify the broader architectural integrity. Prompting an LLM with specific SAST warnings can induce contextual narrowing, where the agent becomes hyper-fixated on resolving a localized syntax error and misses broader architectural flaws existing in the same file. Furthermore, if the agent's mandate extends beyond discovery to automated remediation (such as writing and proposing code fixes), this human-in-the-loop validation becomes critical to ensure the LLM does not inadvertently introduce new regressions or bypass intended business logic.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image_20.max-1000x1000.png" alt="Demistiying Image 6 New">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 6: Flowchart outlining the targeted LLM deployment and triage workflow.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Remediation and hardening</span></h3>
<h4><span>LLM-assisted code remediation</span></h4>
<p><span>A primary goal of integrating large language models (LLMs) into the software development lifecycle is automated remediation. To achieve this, organizations are deploying these capabilities through two primary execution methods: directly within the integrated development environment (IDE) or as a centralized pipeline runner. Examples include </span><a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/" rel="noopener" target="_blank"><span>CodeMender</span></a><span>, although as of time of writing, it is not publicly available.</span></p>
<h4><strong>IDE-integrated method</strong><span> </span></h4>
<p><span>This method shifts remediation as far left as possible by operating as an active pair-programmer. Tools running continuous static analysis in the background of the IDE surface vulnerabilities directly to the developer via editor diagnostics like inline indicators or hover tooltips.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Localized scope:</strong><span> The developer can trigger the LLM agent to analyze the localized data flow and generate a targeted patch (such as implementing parameterized SQL queries). By constraining the LLM to localized, syntax-level fixes, the scope of the change remains contained. This prevents the agent from attempting sprawling, multi-file refactors that frequently break complex architectural logic.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Human-in-the-loop:</strong><span> The developer reviews the AI-generated patch before the code is committed.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Managing false positives:</strong><span> Local IDE agents allow developers to manage false positives dynamically. Suppressing alerts anchored to specific line text reduces alert fatigue and preserves developer trust.</span></p>
</li>
</ul>
<h4><strong>CI/CD runner method</strong><span> </span></h4>
<p><span>The runner method executes asynchronously within the CI/CD pipeline to use an LLM to review committed code and automatically propose remediation.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Restricted execution and deterministic validation: </strong><span>Asking a centralized runner to automatically rewrite a complex, multi-file authorization flaw directly in the main branch introduces a high risk of breaking logic errors. To mitigate this, agents must be restricted to generating pull requests (PRs). Once a PR is generated, it must automatically execute standard regression suites alongside the deterministic test harness. By rerunning the initial PoC against the patched code, the workflow repurposes the exploit script as a validation oracle to prove the vulnerability has been remediated. A human engineer then reviews the PR to validate the architectural logic before merging.</span></p>
</li>
</ul>
<p><span>In all cases security teams should define a clear boundary between the two methods rather than rely on a single approach. IDE agents provide immediate, syntax-level support. They catch and resolve low-complexity errors locally before developers commit code. Centralized CI/CD runners handle broader organizational baselines. They propose complex, repository-wide fixes for vulnerabilities that bypass local environments.</span></p>
<h4><strong>Post-deployment controls</strong><span> </span></h4>
<p><span>Even with human review and deterministic test harnesses, AI-generated patches can still introduce logic regressions in production. Organizations should implement strict post-deployment controls:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Automated rollbacks:</strong><span> Treating LLM-generated code with the same post-deployment scrutiny as any major architectural change ensures that if an unforeseen regression traverses the CI/CD pipeline, the environment can revert to a known good state.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Mitigating model drift:</strong><span> Relying on managed AI services introduces the ongoing risk of model drift. To prevent silent weight updates from breaking test harnesses, organizations need to pin specific model API versions to frozen releases. When a pinned version reaches its end-of-life, organizations will face a forced migration. Mitigating this pipeline fragility requires combining model pinning with deterministic regression suites.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Compliance and auditability:</strong><span> If an AI agent automatically closes a security ticket or generates a patch in the CI/CD pipeline, organizations should maintain immutable audit logs to satisfy frameworks like SOC 2 ,PCI-DSS, FedRAMP, and CMMC. National security deployments must also account for data sovereignty requirements. This logging should record the specific model version that proposed the fix, the deterministic test results that validated it, and the human engineer who approved the merge. Furthermore, because emerging legislation like the EU AI Act emphasizes human oversight for high-risk applications, security teams should carefully evaluate how autonomous remediation workflows align with these evolving global regulatory standards.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Screenshot_2026-07-15_at_10.24.22PM.max-1000x1000.png" alt="demistifying image 7">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 7: Flowchart demonstrating the difference between local IDE AI remediation and centralized CI/CD pipeline remediation.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Leveraging LLMs in vulnerability management is a multi-layer solution: Integrating it requires separating workflows by layer. At the enterprise infrastructure level, Risk-Based Vulnerability Management (RBVM) and exposure management are necessary to process the volume of findings and configuration drift. At the product and code security level, LLM-enabled vulnerability assessment and remediation must operate alongside foundational deterministic controls, such as SAST and DAST, to audit custom, open-source, or third-party code.</span></p>
<p><span>Although LLMs can help manage technical debt and accelerate vulnerability discovery, they do not replace secure-by-design principles. The fact that LLM agents are proving exceptionally capable at identifying and exploiting localized memory corruption in memory-unsafe codebases, alongside other primary vectors, should serve as a wake-up call. </span></p>
<p><span>As a long-term strategy aligned with </span><a href="https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI_SOFTWARE_MEMORY_SAFETY.PDF" rel="noopener" target="_blank"><span>NSA guidance on Software Memory Safety</span></a><span>, organizations need to phase memory-safe languages into new internal development. LLMs are beginning to expand what is possible here by reducing the manual labor required for code migration. Converting existing C or C++ codebases to Rust has historically been unrealistic due to the large volume of engineering hours needed. While fully automated translation is not a turn-key solution, using LLMs to assist engineers with the bulk of the conversion can make these long-term migrations operationally viable. Beyond internal efforts, organizations should use procurement requirements to incentivize vendors to reduce their reliance on memory-unsafe languages and establish secure configuration defaults over time. Bridging the gap between AI velocity and enterprise defense means building an automated pipeline to manage the current backlog, while architecting systems where entire classes of vulnerabilities and misconfigurations are eliminated by design.</span></p>
<h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Google Threat Intelligence Group (GTIG) and other broader Google teams.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI recommendations are becoming ecommerce’s most valuable source of traffic]]></title>
<description><![CDATA[New data suggests visitors referred by AI tools are converting at significantly higher rates than those arriving through traditional search.]]></description>
<link>https://tsecurity.de/de/3670366/it-nachrichten/why-ai-recommendations-are-becoming-ecommerces-most-valuable-source-of-traffic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670366/it-nachrichten/why-ai-recommendations-are-becoming-ecommerces-most-valuable-source-of-traffic/</guid>
<pubDate>Wed, 15 Jul 2026 12:47:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New data suggests visitors referred by AI tools are converting at significantly higher rates than those arriving through traditional search.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK charges five persons linked to fraud platform behind more than a million scam calls]]></title>
<description><![CDATA[Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are charged with offenc...]]></description>
<link>https://tsecurity.de/de/3667468/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667468/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</guid>
<pubDate>Tue, 14 Jul 2026 11:38:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are charged with offences that include conspiracy to supply articles for use in fraud, transferring and converting criminal property, and, for Zakkaria Sehailia, failing to comply with a notice to … <a href="https://www.helpnetsecurity.com/2026/07/14/russian-coms-nca-charges-scam-calls/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/russian-coms-nca-charges-scam-calls/">UK charges five persons linked to fraud platform behind more than a million scam calls</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4682: Behind the Keyboard: A Cybersecurity Operator’s Real-World Workflow]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.










SUMMARY


The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolation, virtual machine troubleshooting, AI-assisted scripting, and network tunneling methods utilized during active securi...]]></description>
<link>https://tsecurity.de/de/3666605/podcasts/hpr4682-behind-the-keyboard-a-cybersecurity-operators-real-world-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666605/podcasts/hpr4682-behind-the-keyboard-a-cybersecurity-operators-real-world-workflow/</guid>
<pubDate>Tue, 14 Jul 2026 02:03:31 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<h1>

</h1>

<h1>

</h1>

<h1>
SUMMARY</h1>

<p>
The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolation, virtual machine troubleshooting, AI-assisted scripting, and network tunneling methods utilized during active security assessments.</p>

<h1>
ONE-SENTENCE TAKEAWAY</h1>

<p>
Isolate browser environments, utilize automation scripts, and verify network paths before starting security tests to avoid workflow interruptions.</p>

<h1>
TOOLS</h1>

<ul>

<li>

<strong>
Talon Voice</strong>
 – Open-source voice recognition software enabling hands-free computer control and command execution.</li>

<li>

<strong>
Obsidian</strong>
 – Local-first markdown note-taking application supporting secure, AI-friendly knowledge management.</li>

<li>

<strong>
AutoHotkey</strong>
 – Windows scripting utility for creating custom macros and remapping keyboard inputs.</li>

<li>

<strong>
Chrome Debug Commands</strong>
 – Browser developer tools allowing direct inspection of extensions, cookies, and storage.</li>

<li>

<strong>
Whisper Diarization</strong>
 – Audio processing script that separates speaker tracks and converts recordings to searchable text.</li>

<li>

<strong>
Hyper-V / WSL</strong>
 – Microsoft virtualization platforms enabling isolated guest environments and Linux subsystem integration.</li>

<li>

<strong>
OpenConnect / OpenVPN</strong>
 – Command-line tunneling clients used for establishing secure, split-tunnel network connections.</li>

<li>

<strong>
Jamboree Framework</strong>
 – Portable PowerShell environment that dynamically provisions development tools without altering system paths.</li>

<li>

<strong>
MOBA Portable</strong>
 – Feature-rich terminal emulator supporting static/dynamic tunnels, auto-reconnect, and embedded X-server capabilities.</li>

<li>

<strong>
Nmap</strong>
 – Network discovery and security auditing tool utilized for comprehensive port scanning and service detection.</li>

</ul>

<h2>
00:00:00 Ergonomic Workspace Configuration</h2>

<p>
Configures physical workstation elements to reduce strain during extended testing sessions. Proper alignment prevents repetitive stress injuries while maintaining focus on technical tasks.</p>

<ul>

<li>

<strong>
Monitor Positioning</strong>
 – Displays should align with eye level to maintain neutral neck posture; the speaker notes their curved 49-inch screen sits slightly high due to chair adjustments.</li>

<li>

<strong>
Split Keyboard Layout</strong>
 – Utilizes a Freestyle 2 mechanical keyboard, allowing natural shoulder-width arm placement and reducing wrist deviation during prolonged typing.</li>

<li>

<strong>
Postural Adaptation</strong>
 – Acknowledges that ergonomic equipment requires matching body alignment; elbow rests should sit between hip and shoulder height for optimal leverage.</li>

</ul>

<h2>
01:45:00 Voice Control &amp; Note Synchronization</h2>

<p>
Utilizes auditory input methods and localized knowledge bases to streamline documentation workflows. Separating secure work notes from casual observations prevents data contamination.</p>

<ul>

<li>

<strong>
Talon Voice Integration</strong>
 – Runs continuously to handle navigation, text entry, and application switching without manual keyboard interaction.</li>

<li>

<strong>
Obsidian Migration</strong>
 – Transitions from cloud-based keep apps to local markdown files, enabling direct querying by local AI models while maintaining offline accessibility.</li>

<li>

<strong>
Note Categorization</strong>
 – Divides information into secure work records and insecure personal logs, ensuring clean data pipelines for future retrieval and analysis.</li>

</ul>

<h2>
03:50:00 Browser Extension Management &amp; Security Isolation</h2>

<p>
Separates web browsing activities from primary work processes to minimize attack surfaces. Running dedicated user profiles prevents plugin conflicts and credential leakage.</p>

<ul>

<li>

<strong>
Jailed User Accounts</strong>
 – Creates restricted system profiles that only launch the browser, isolating extensions from core workstation operations.</li>

<li>

<strong>
Shared Folder Synchronization</strong>
 – Establishes a single directory path bridging work and browsing users, allowing seamless file transfers without cross-contamination.</li>

<li>

<strong>
Extension Audit Process</strong>
 – Leverages Chrome debug commands to enumerate installed plugins, verifying functionality before deployment on target networks.</li>

</ul>

<h2>
06:15:00 Training Optimization &amp; Audio Processing</h2>

<p>
Accelerates mandatory compliance viewing through speed manipulation and automated transcription. Converting video content into searchable text enables rapid information retrieval.</p>

<ul>

<li>

<strong>
Global Speed Control</strong>
 – Increases playback rates up to sixteen times normal speed, drastically reducing time spent on repetitive corporate training modules.</li>

<li>

<strong>
Whisper Diarization Pipeline</strong>
 – Downloads video tracks, separates speaker voices, and generates timestamped transcripts for quick reference during assessments.</li>

<li>

<strong>
Download Management</strong>
 – Employs multi-threaded swarm downloaders and classic turbo managers to handle bulk media retrieval without interrupting active workflows.</li>

</ul>

<h2>
10:40:00 Virtualization &amp; Network Tunneling Protocols</h2>

<p>
Establishes isolated testing environments using Windows virtual machines while managing connectivity constraints. Proper session handling prevents unexpected disconnections during remote engagements.</p>

<ul>

<li>

<strong>
Enhanced Session Mode</strong>
 – A Hyper-V feature providing higher resolution and shared clipboard functionality; disabling it is required before initiating certain VPN clients to avoid routing conflicts.</li>

<li>

<strong>
Split Tunneling Mechanics</strong>
 – Routes specific traffic through the virtual network while keeping local resources accessible, preventing complete internet loss during connection tests.</li>

<li>

<strong>
Certificate Verification</strong>
 – Identifies self-signed SSL mismatches early in the process, documenting them as preliminary findings before proceeding with authentication steps.</li>

</ul>

<h2>
15:30:00 Macro Automation &amp; Input Remapping</h2>

<p>
Remaps frequently used keyboard shortcuts to reduce physical strain and accelerate command execution. Running scripts with elevated privileges ensures reliable input registration across virtual environments.</p>

<ul>

<li>

<strong>
Caps Lock Repurposing</strong>
 – Converts the caps lock key into a primary modifier, assigning copy/paste functions to adjacent letters for faster workflow navigation.</li>

<li>

<strong>
Physical Typing Macros</strong>
 – Simulates keystrokes with deliberate delays, allowing seamless data entry into restricted VM consoles that block standard clipboard operations.</li>

<li>

<strong>
Administrator Execution Requirement</strong>
 – Highlights that macro scripts must run with elevated privileges to successfully inject inputs across different desktop sessions.</li>

</ul>

<h2>
20:15:00 Portable Development Environments &amp; Python Management</h2>

<p>
Deploys lightweight scripting frameworks that dynamically provision necessary tools without modifying host configurations. Verifying package contents prevents dependency conflicts during testing.</p>

<ul>

<li>

<strong>
Jamboree Framework</strong>
 – A PowerShell-driven utility that downloads and configures development stacks on demand, resetting environment variables to maintain system cleanliness.</li>

<li>

<strong>
NuGet Package Filtering</strong>
 – Queries Microsoft's repository API to retrieve specific Python versions, ensuring compatibility with legacy tunneling scripts.</li>

<li>

<strong>
Binary Verification Process</strong>
 – Checks extracted archives for bundled <code>
pip.exe</code>
 or <code>
pip3.exe</code>
 executables, eliminating manual module installation steps during rapid deployments.</li>

</ul>

<h2>
28:40:00 AI-Assisted Scripting &amp; Debugging Workflows</h2>

<p>
Generates and refines PowerShell functions through iterative conversational prompts. Validating AI output against actual system behavior prevents silent configuration errors.</p>

<ul>

<li>

<strong>
Vibe Coding Approach</strong>
 – Relies on continuous feedback loops with language models to draft, minimize, and debug automation scripts in real-time.</li>

<li>

<strong>
Parameter Standardization</strong>
 – Enforces strict formatting rules for PowerShell commands, avoiding hardcoded paths and ensuring cross-environment compatibility.</li>

<li>

<strong>
Temporary Storage Management</strong>
 – Monitors extraction directories to prevent disk saturation, redirecting large package downloads away from constrained system partitions.</li>

</ul>

<h2>
35:10:00 Terminal Emulation &amp; Advanced Tunneling Strategies</h2>

<p>
Facilitates complex network routing through dedicated terminal applications. Configuring dynamic and static tunnels enables reliable reverse connections for remote assessments.</p>

<ul>

<li>

<strong>
MOBA Portable Configuration</strong>
 – Utilizes an INI-based tunnel manager that automatically maintains connections across changing IP addresses or Wi-Fi networks.</li>

<li>

<strong>
Reverse Shell Routing</strong>
 – Establishes outbound channels back to the tester, then proxies all subsequent traffic through those connections for consistent monitoring.</li>

<li>

<strong>
Proxy Chain Integration</strong>
 – Forces non-proxy-aware applications to route through Burp Suite or custom interceptors using Windows utility wrappers like Priboxy.</li>

</ul>

<h2>
42:30:00 Final Connectivity Testing &amp; Engagement Wrap-Up</h2>

<p>
Executes comprehensive port scans to verify target accessibility before documenting findings. Acknowledging workflow detours ensures realistic time management during active engagements.</p>

<ul>

<li>

<strong>
Nmap Verification</strong>
 – Runs full-port scans with verbose output to confirm host responsiveness and identify open services prior to credential testing.</li>

<li>

<strong>
Connection Refusal Documentation</strong>
 – Captures screenshot evidence of failed routing attempts, providing clear proof of network restrictions for client reporting.</li>

<li>

<strong>
Workflow Reflection</strong>
 – Recognizes that exploratory debugging adds value but requires time boundaries; balancing thoroughness with engagement scope maintains professional efficiency.</li>

</ul>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4682/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with Angular: Introducing the modern reactive workflow]]></title>
<description><![CDATA[Angular is a cohesive, all-in-one reactive framework for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to...]]></description>
<link>https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Angular is a cohesive, all-in-one <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">reactive framework</a> for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, many of those issues <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">were addressed in Angular 19</a>. Modern Angular is built around the <a href="https://blog.angular-university.io/angular-signals">Signals API</a> and minimal formality, while still delivering a one-stop-shop that includes dependency injection and integrated routing.</p>



<p class="wp-block-paragraph">Angular is popular with the enterprise because of its stable, curated nature, but it is becoming more attractive to the wider developer community thanks to its more <a href="https://www.infoworld.com/article/3802707/angular-team-unveils-strategy-for-2025.html">community engaged development philosophy</a>. That, along with its recent technical evolution, make Angular one of the most interesting projects to watch right now.</p>



<h2 class="wp-block-heading">Why choose Angular?</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html">Choosing a JavaScript development framework</a> sometimes feels like a philosophical debate, but it should be a practical decision. Angular is unique because it is strongly opinionated. It doesn’t just give you a view layer; it provides a complete toolkit for building web applications.</p>



<p class="wp-block-paragraph">Like other reactive frameworks, Angular is built around its reactive engine, which lets you bind state (variables) to the view. But if that’s all you needed, one of the smaller, more focused frameworks would be more than enough. What Angular has that some of these other frameworks don’t is its ability to use data binding to automatically synchronize data from your user interface (UI) with your JavaScript objects. Angular also leverages dependency injection and inversion of control to help structure your application and make it easier to test. And it contains more advanced features like server-side rendering (SSR) and static-site generation (SSG) within itself, rather than requiring you to engage a <a href="https://www.infoworld.com/article/3831686/plug-and-play-web-development-with-astro-js.html">meta-framework</a> for either style of development.</p>



<p class="wp-block-paragraph">While Angular might not be your top choice for every occasion, it’s an excellent option for larger projects that require features you won’t get with a more lightweight framework.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Catching up with Angular 19</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Angular</h2>



<p class="wp-block-paragraph">With those concepts in mind, let’s set up Angular in your development environment. After that, we can run through developing a web application with Angular. To start, make sure you have Node and NPM installed. From the command line, enter:</p>



<pre class="wp-block-code"><code>$ node -v
$ npm -v</code></pre>



<p class="wp-block-paragraph">Next, you can use the Angular CLI to launch a new app:</p>



<pre class="wp-block-code"><code>$ ng new iw-ng</code></pre>



<p class="wp-block-paragraph">You can use the defaults in your responses to the interactive prompts shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular1.png?w=1024" alt="A screenshot of a new project setup in the Angular command-line interface." class="wp-image-4123771" width="1024" height="413" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">We now have a basic project layout in the new directory, which you can import into an IDE (such as <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html" data-type="link" data-id="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">VS Code</a>) or edit directly.</p>



<p class="wp-block-paragraph">Looking at the project layout, you might notice it is fairly lean, a break from Angular projects of the past. The most important parts are:</p>



<ul class="wp-block-list">
<li><code>src/main.ts</code>: This is the main entry point. In older versions of Angular, this file had to bootstrap a module, which then bootstrapped a component. Now, it avoids any verbose syntax, calling bootstrapApplication with your root component directly.</li>



<li><code>src/index.html</code>: The main HTML page that hosts your application. This is the standard index.html that serves all root requests in a web page and contains the  tag where your Angular component will render. It is the “body” that the “spirit” of your code animates.</li>



<li><code>src/app/app.ts</code>: The root component of your application. This single file defines the view logic and the component metadata. In the new “standalone” world, it manages its own imports, meaning you can see exactly what dependencies it uses right at the top of the file. (This is the <code></code> root element that appears in <code>src/index.html</code>.)</li>



<li><code>src/app/app.config.ts</code>: This file is new in modern Angular and replaces the old A<code>ppModule providers</code> array. It is where you configure global services, like the router or HTTP client.</li>



<li><code>angular.json</code>: The configuration file for the CLI itself. It tells the build tools how to process your code, though you will rarely need to touch this file manually anymore.</li>
</ul>



<p class="wp-block-paragraph">Here is the basic flow of how the engine renders these components:</p>



<ol start="1" class="wp-block-list">
<li><strong>The arrival (HTML)</strong>: The browser receives <code>index.html</code>. The <code></code> tag is there, but it’s empty.</li>



<li><strong>The unpacking (JavaScript)</strong>: The browser sees the <code></code> tags at the bottom of the HTML and downloads the JavaScript bundles (your compiled code) from <code>src/app/app.ts</code>.</li>



<li><strong>The assembly (Bootstrap)</strong>: The browser runs that JavaScript. The code “wakes up,” finds the <code></code> tag in the DOM, and dynamically inserts your title, buttons, and lists.</li>
</ol>



<p class="wp-block-paragraph">This flow will be different if you are using server-side rendering (SSR), but we’ll leave that option aside for now. Now that you’ve seen the basic architecture, let’s get into the code.</p>



<h2 class="wp-block-heading">Developing your first web app in Angular</h2>



<p class="wp-block-paragraph">If you open <code>src/app/app.ts</code> (more info <a href="http://app.ts/">here</a>) the component definition looks like this:</p>



<pre class="wp-block-code"><code>import { Component, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  protected readonly title = signal('iw-ng');
}</code></pre>



<p class="wp-block-paragraph">Before we dissect the code, let’s run the app and see what it produces:</p>



<pre class="wp-block-code"><code>$ ng serve</code></pre>



<p class="wp-block-paragraph">You should see a page like this one at <code>localhost:4200</code>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular2.png?w=1024" alt="A screenshot of a Hello, World! app built with Angular." class="wp-image-4123772" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Returning to the <code>src/app.ts</code> component, notice that there are three main parts of the definition: the class, the metadata, and the view. Let’s unpack these separately.</p>



<h3 class="wp-block-heading">The class (export class App)</h3>



<p class="wp-block-paragraph">Export class <code>App</code> is vanilla TypeScript that holds your component’s data and logic. In our example, <code>title = signal(‘iw-ng’)</code> defines a piece of reactive state. Unlike older versions of Angular where data was just a plain property, here we use a <a href="https://www.solidjs.com/tutorial/introduction_signals">signal</a>. Signals are wrappers around values that notify the template precisely when they change, enabling fine-grained performance.</p>



<h3 class="wp-block-heading">The metadata (@Component)</h3>



<p class="wp-block-paragraph">The <code>@Component</code> decorator tells Angular it is dealing with a component, not just a generic class. There are several elements involved in the decorator’s communication with the engine:</p>



<ul class="wp-block-list">
<li><code>selector: 'app-root'</code>: Defines the custom HTML tag associated with any given component. Angular finds <code></code> in your <code>index.html</code> and renders the component there.</li>



<li><code>imports</code>: In the new Angular era, dependencies are explicit. You list exactly what a component needs (like <code>RouterOutlet</code> or other components) here, rather than hiding them in a separate module file.</li>



<li><code>templateUrl</code>: Points to the external HTML file that defines the view.</li>
</ul>



<h3 class="wp-block-heading">The view (the template)</h3>



<p class="wp-block-paragraph">This is the visual part of the component, defined in <code>app.html</code>. It combines standard HTML with Angular’s template syntax. (JSX handles this part for React-based apps.)</p>



<p class="wp-block-paragraph">We can modify <code>src/app/app.html</code> to see how these three elements work together. To start, delete the default content and add the following:</p>



<pre class="wp-block-code"><code><h1>Hello, {{ title() }}</h1>
</code></pre>



<p class="wp-block-paragraph">The double curly braces <code>{{ }}</code> are called <a href="https://angular.dev/guide/templates/binding">interpolation</a>. Notice the parentheses in <code>title()</code>. We are reading the “title” signal value by calling its function. If you were to update that signal programmatically (e.g., <code>this.title.set('New Value')</code>), the text on the screen would update instantly.</p>



<h2 class="wp-block-heading">Angular’s built-in control flow</h2>



<p class="wp-block-paragraph">Old-school Angular required “structural directives” like <code>*ngIf</code> and <code>*ngFor</code> logic control. These were powerful but required importing <code>CommonModule</code> and learning a specific micro-syntax. Modern Angular uses a built-in control flow that looks like standard JavaScript (similar to other Reactive platforms).</p>



<p class="wp-block-paragraph">To see the new control flow in action, let’s add a list to our component. Update <code>src/app/app.ts</code> as follows, leaving the rest of the file the same:</p>



<pre class="wp-block-code"><code>export class App {
  protected readonly title = signal('iw-ng');
  protected readonly frameworks = signal(['Angular', 'React', 'Vue', 'Svelte']);
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">While we’re at it, let’s also update <code>src/app/app.html</code> to render this new list (don’t worry about <code></code> for now; it just tells Angular where to render the framing template):</p>



<pre class="wp-block-code"><code><button>Toggle List</button>

@if (showList()) {
  <ul>
    @for (tech of frameworks(); track tech) {
      <li>{{ tech }}</li>
    }
  </ul>
} @else {
  <p>List is hidden</p>
}

</code></pre>



<p class="wp-block-paragraph">The app will now display a list that can be toggled for visibility:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular3.png?w=1024" alt="Screenshot of a list that can be toggled on and off for visibility." class="wp-image-4123773" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">This syntax is cleaner and easier to read than the old <code>*ngFor</code> loops:</p>



<ul class="wp-block-list">
<li><code>@if</code> conditionally renders the block if the signal’s value is true.</li>



<li><code>@for</code> iterates over the array. The track keyword is required for performance (it tells Angular how to identify unique items in the list).</li>



<li><code>(click)</code> is an <a href="https://angular.dev/guide/templates/event-listeners">event binding</a>. It lets us run code (the <code>toggleList</code> method) when the user interacts with the button.</li>
</ul>



<h2 class="wp-block-heading">Services: Managing business logic in Angular</h2>



<p class="wp-block-paragraph">Components focus on the view (i.e., what you see). For the business logic that backs the application functionality, we use services.</p>



<p class="wp-block-paragraph">A service is just a class that can be “injected” into a component that needs it. This is Angular’s famous dependency injection system. It allows you to write logic once and reuse it anywhere. It’s a slightly different way of thinking about how an application is wired together, but it gives you real organizational benefits over time.</p>



<p class="wp-block-paragraph">To generate a service, you can use the CLI:</p>



<pre class="wp-block-code"><code>$ ng generate service frameworks</code></pre>



<p class="wp-block-paragraph">This command creates a <code>src/app/hero.ts</code> file. In modern Angular, we define services using the <code>@Injectable</code> decorator. Currently, the <code>src/app/hero.ts</code> file just has this:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root',
})
export class Frameworks {
  
}</code></pre>



<p class="wp-block-paragraph">Open the file and add a simple method to return our data:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root', // Available everywhere in the app
})
export class Frameworks {
  getList() {
    return ['Angular', 'React', 'Vue', 'Svelte'];
  }
}</code></pre>



<p class="wp-block-paragraph">The providedIn: <code>'root'</code> metadata is important, it tells Angular to create a single, shared instance of this service for the entire application (you might recognize this as an instance of the <a href="https://en.wikipedia.org/wiki/Singleton_pattern">singleton pattern</a>).</p>



<h3 class="wp-block-heading">Using the service</h3>



<p class="wp-block-paragraph">In the past, we had to list dependencies in the constructor. Modern Angular offers a cleaner way: the <code>inject()</code> function. Subsequently, we can refactor our <code>src/app/app.ts</code> to get its data from the service instead of hardcoding it:</p>



<pre class="wp-block-code"><code>import { Component, inject, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';
import { Frameworks } from './frameworks'; // Import the service

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  private frameworksService = inject(Frameworks); // Dependency Injection
  
  protected readonly title = signal('iw-ng');
  
  // Initialize signal with data directly from the service
  protected readonly frameworks = signal(this.frameworksService.getList());
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">Dependency injection is a powerful pattern. The component doesn’t need to know where the list came from (it could be coming from an API, a database, or a hard-coded array); it just asks the service for what it needs. This pattern adds a bit of extra work up front, but it delivers a more flexible, organized codebase as the app grows in size and complexity.</p>



<h2 class="wp-block-heading">Routers and routes</h2>



<p class="wp-block-paragraph">Once your application grows beyond a single view, you need a way to navigate between different screens. In Angular, we use the built-in router for this purpose. In our example project, <code>src/app/app.routes.ts </code>is the dedicated home for the router config. Let’s follow the steps for creating a new route.</p>



<p class="wp-block-paragraph">First, we define the route. When you open <code>src/app/app.routes.ts</code>, you will see an exported routes array. This array contains the available routes for your app. Each string name resolves to a component that handles rendering that route. In effect, this is the map of your application’s landscape.</p>



<p class="wp-block-paragraph">In a real application, you’d often have “framing template” material in the root of the app (like the navbar) and then the routes fill in the body content. (Remember that by default, Angular is designed for single-page apps, where navigation does reload the screen, but swaps content.)</p>



<p class="wp-block-paragraph">For now, let’s just get a sense of how the router works. First, create a new component so we have a destination to travel to. In your terminal, run:</p>



<pre class="wp-block-code"><code>$ ng generate component details</code></pre>



<p class="wp-block-paragraph">This will generate a simple <code>details</code> component in the <code>src/app/details</code> directory.</p>



<p class="wp-block-paragraph">Now we can update <code>src/app/app.routes.ts</code> to include this new path. We will also add a “default” path that redirects empty requests to the home view, ensuring the user always lands somewhere:</p>



<pre class="wp-block-code"><code>import { Routes } from '@angular/router';
import { App } from './app'; // Matches src/app/app.ts
import { Details } from './details/details'; // Matches src/app/details/details.ts

export const routes: Routes = [
  { path: '', redirectTo: '/home', pathMatch: 'full' },
  { path: 'home', component: App },
  { path: 'details', component: Details },
];</code></pre>



<p class="wp-block-paragraph">Now if you visit <code>localhost:4200/home</code>, you’ll get the message from the <code>details</code> component: “Details works!”</p>



<p class="wp-block-paragraph">Next, we’ll use the <code>routerLink</code> directive to move between views without refreshing the page. In <code>src/app/app.html</code>,  we create a navigation bar that sits permanently at the top of the page (the “stationary” element), while the router swaps the content below it (the “impermanent” element):</p>



<pre class="wp-block-code"><code><nav>
  <a>Home</a> | 
  <a>Details</a>
</nav>

<hr>

</code></pre>



<p class="wp-block-paragraph">And with that, the application has a navigation flow. The user clicks, the URL updates, and the content transforms, all without the jarring flicker of a browser reload.</p>



<h2 class="wp-block-heading">Parametrized routes</h2>



<p class="wp-block-paragraph">The last thing we’ll look at is handling route parameters, where the route accepts variables in the path. To manage this kind of dynamic data, you define a route with a variable, marked by a colon. Open <code>src/app/app.routes.ts</code> and add a dynamic path:</p>



<pre class="wp-block-code"><code>export const routes: Routes = [
  // ... existing routes
  { path: 'details/:id', component: Details }, 
];</code></pre>



<p class="wp-block-paragraph">The <code>:id</code> is a placeholder. Whether the URL is <code>/details/42</code> or <code>/details/108</code>, this router will receive it because it matches the path. Inside the details component, we have access to this parameter (using the <a href="https://angular.dev/api/router/ActivatedRoute">ActivatedRoute</a> service or the new <a href="https://angular.dev/api/router/withComponentInputBinding">withComponentInputBinding</a>). We can use that value to retrieve the data we need (like using it to recover a detail item from a database).</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">We have seen the core elements of modern Angular: Setting up the environment, building reactive components with signals, organizing logic with services, and tying it all together with interactive routing.</p>



<p class="wp-block-paragraph">Deploying these pieces together is the basic work in Angular. Once you get comfortable with it, you have an extremely powerful platform at your fingertips. And, when you are ready to go deeper, there is a whole lot more to explore in Angular, including:</p>



<ul class="wp-block-list">
<li>State management: Beyond signals, Angular has support for managing complex, application-wide state.</li>



<li>Forms: Angular has a robust system for handling user input.</li>



<li>Signals: We only scratched the surface of signals here. Signals offer a powerful, fine-grained way to manage state changes.</li>



<li>Build: You can learn more about producing production builds.</li>



<li><a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">RxJS</a>: Takes reactive programming to the next level.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Semi-Trailer Trucks Test Converting Into Plug-In Hybrids]]></title>
<description><![CDATA[Long-time Slashdot reader necro81 writes: There are several companies, such as Tesla, trying to make semi trucks fully electric. The capital cost for such a truck, and the MW-scale infrastructure to recharge it, may be a hard sell for some operators. [IEEE Spectrum notes that's a charging infrast...]]></description>
<link>https://tsecurity.de/de/3664070/it-security-nachrichten/semi-trailer-trucks-test-converting-into-plug-in-hybrids/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664070/it-security-nachrichten/semi-trailer-trucks-test-converting-into-plug-in-hybrids/</guid>
<pubDate>Mon, 13 Jul 2026 04:23:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Long-time Slashdot reader necro81 writes: There are several companies, such as Tesla, trying to make semi trucks fully electric. The capital cost for such a truck, and the MW-scale infrastructure to recharge it, may be a hard sell for some operators. [IEEE Spectrum notes that's a charging infrastructure "that most freight corridors do not yet reliably provide."] But some companies are instead adding batteries and an electric motor to the semi-trailers that trucks haul behind them. 

"The Nivalis Powered Trailer Kit centers on an electric axle [rated at 50 kilowatts-peak]... capable of both propulsion assistance and regenerative braking. It draws on a 60-kilowatt-hour, 400-volt lithium-ion battery pack charged from three sources: the axle itself during braking and deceleration, a full-rooftop array of photovoltaic panels generating up to 3.7 kilowatts-peak, and a 32-amp, three-phase AC grid connection available during parking stops."
 

This approach is more akin to a plug-in hybrid: the truck may still be diesel-powered, but the electric assist from the trailer allows the truck to run more efficiently. Replacing diesel with kWh can save operators money while also reducing emissions. This incremental approach may be more accessible and less capital-intensive than replacing the truck itself. 
From the article:

The driver's only window into the system is a small display readable from the cab's side mirror that shows the system status and battery charge level. Nothing about the trailer's handling or licensing requirements changes. The partners project savings of up to 7,000 liters of diesel per trailer per year, which is enough to keep about 19 tonnes of carbon dioxide out of the air... 

 Trailer Dynamics, an Aachen-based company, has conducted field tests with BMW Logistics, DB Schenker, Duvenbeck, and Volkswagen Konzernlogistik, reporting average fuel savings of around 40% for diesel tractor combinations, substantially higher than the up to 18% reduction implied by the Nivalis projection... Trailer Dynamics prices its system between €145,000 and €195,000 and targets a payback period of no more than five years. Nivalis targets five to six years at current costs.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Semi-Trailer+Trucks+Test+Converting+Into+Plug-In+Hybrids%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F13%2F0121226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F13%2F0121226%2Fsemi-trailer-trucks-test-converting-into-plug-in-hybrids%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/13/0121226/semi-trailer-trucks-test-converting-into-plug-in-hybrids?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Marcant Gegen Rechts]]></title>
<description><![CDATA[A YouTube channel content creator has made a living in Germany covering and converting Nazi marches. A documentary explains how he saw an opportunity to talk kids out of joining the AfD.]]></description>
<link>https://tsecurity.de/de/3658090/it-security-nachrichten/marcant-gegen-rechts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658090/it-security-nachrichten/marcant-gegen-rechts/</guid>
<pubDate>Thu, 09 Jul 2026 21:36:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A YouTube channel content creator has made a living in Germany covering and converting Nazi marches. A documentary explains how he saw an opportunity to talk kids out of joining the AfD.]]></content:encoded>
</item>
<item>
<title><![CDATA[Datalab Lift vs the Field: How a 9B Schema-First Extractor Compares with NuExtract3, LlamaExtract, Marker, and Docling]]></title>
<description><![CDATA[Datalab’s Lift is a focused document extraction tool with a specific promise: give it a PDF or image plus a JSON Schema, and it returns schema-shaped JSON directly. Instead of converting a document to Markdown first and then asking another model to extract fields, Lift reads rendered page images ...]]></description>
<link>https://tsecurity.de/de/3656317/ai-nachrichten/datalab-lift-vs-the-field-how-a-9b-schema-first-extractor-compares-with-nuextract3-llamaextract-marker-and-docling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656317/ai-nachrichten/datalab-lift-vs-the-field-how-a-9b-schema-first-extractor-compares-with-nuextract3-llamaextract-marker-and-docling/</guid>
<pubDate>Thu, 09 Jul 2026 10:03:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Datalab’s Lift is a focused document extraction tool with a specific promise: give it a PDF or image plus a JSON Schema, and it returns schema-shaped JSON directly. Instead of converting a document to Markdown first and then asking another model to extract fields, Lift reads rendered page images and attempts to emit the final […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/09/datalab-lift-vs-the-field-how-a-9b-schema-first-extractor-compares-with-nuextract3-llamaextract-marker-and-docling/">Datalab Lift vs the Field: How a 9B Schema-First Extractor Compares with NuExtract3, LlamaExtract, Marker, and Docling</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Convert your Google Slides to videos in 7 additional languages]]></title>
<description><![CDATA[Google Vids already lets you convert your Slides content into Vids with AI-generated scripts, voiceovers, background music, and animations for presentations and accounts in English.We’re now expanding support to French, German, Italian, Japanese, Korean, Portuguese, and Spanish. Getting startedAd...]]></description>
<link>https://tsecurity.de/de/3655165/web-tipps/convert-your-google-slides-to-videos-in-7-additional-languages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655165/web-tipps/convert-your-google-slides-to-videos-in-7-additional-languages/</guid>
<pubDate>Wed, 08 Jul 2026 20:27:13 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://docs.google.com/videos/create?usp=blog" target="_blank">Google Vids</a> already lets you <a href="https://support.google.com/docs/answer/15577408?hl=en-GB" target="_blank">convert your Slides content into Vids</a> with AI-generated scripts, voiceovers, background music, and animations for presentations and accounts in English.</p><p>We’re now expanding support to French, German, Italian, Japanese, Korean, Portuguese, and Spanish. </p><h3>Getting started</h3><p></p><ul><li><b>Admins: </b>There is no admin control for this feature.</li><li><b>End users: </b>There is no end user setting for this feature. Visit the Help Center to learn more about <a href="https://support.google.com/docs/answer/15577408?hl=en" target="_blank">converting Google Slides into Google Vids</a>.</li></ul><p></p><h3>Rollout pace</h3><p></p><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release domains:</a> Gradual rollout (up to 15 days for feature visibility) started on June 30, 2026</li><li><a href="https://support.google.com/a/answer/172177" target="_blank">Scheduled Release domains:</a> Full rollout (1–3 days for feature visibility) starting on July 20, 2026</li></ul><p></p><h3>Availability</h3><p></p><ul><li><b>Business: </b>Business Starter, Standard, and Plus</li><li><b>Enterprise: </b>Enterprise Starter, Standard, and Plus</li><li><b>Education:</b> Education Plus</li><li><b>Consumer:</b> Google AI Pro and Ultra</li><li><b>Other Editions: </b>Enterprise Essentials and Enterprise Essentials Plus; Nonprofits</li><li><b>Education Add-ons: </b>Google AI Pro for Education; Teaching and Learning</li><li><b>Other Add-ons:</b> AI Expanded Access</li></ul><p></p><h3>Resources</h3><p></p><ul><li>Google Help: <a href="https://support.google.com/docs/answer/15577408" target="_blank">Convert Google Slides into Google Vids</a></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Superconducting Thruster Harnesses Earth's Magnetic Field In First Orbital Test]]></title>
<description><![CDATA[New Zealand startup Zenno Astronautics has completed the first orbital test of its "Supertorquer," a shoebox-sized superconducting magnet system that uses solar power and Earth's magnetic field to help control a satellite without fuel. The company says the technology could eventually support fuel...]]></description>
<link>https://tsecurity.de/de/3654118/it-security-nachrichten/superconducting-thruster-harnesses-earths-magnetic-field-in-first-orbital-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654118/it-security-nachrichten/superconducting-thruster-harnesses-earths-magnetic-field-in-first-orbital-test/</guid>
<pubDate>Wed, 08 Jul 2026 13:22:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New Zealand startup Zenno Astronautics has completed the first orbital test of its "Supertorquer," a shoebox-sized superconducting magnet system that uses solar power and Earth's magnetic field to help control a satellite without fuel. The company says the technology could eventually support fuel-free satellite maneuvers, docking, deep-space trajectory changes, and even magnetic radiation shielding for astronauts. Space Magazine reports: The tests began shortly after Mira's launch in November last year aboard the SpaceX Transporter 12 mission and saw the shoebox-size device perform with flying colors, Zenno Astronautics CEO and founder Max Arshavsky, told Space.com. "It's a technology that allows a spacecraft to not tumble violently in space and point in the right direction," Arshavsky said. "The unit has multiple super-conducting magnets that are positioned in different axes. When we power up the magnets, they generate a magnetic field, which interacts with Earth's magnetic field, and because we can control the magnetic field on the satellite, we can control the way in which it turns with respect to Earth."
 
Superconducting magnets are made of coils of superconducting wire that have zero electrical resistance and can therefore conduct much larger currents than normal wires. That larger current translates into a greater magnetic force. There is, however, a catch: Superconducting materials need to be cooled to extremely low temperatures to gain their wonder properties. [...] The unit housing the superconducting magnets is wrapped in layers of insulation and fitted with a heat pump that removes all the excess heat from the system. Every time the satellite needs a push, the superconducting coils power up, drawing energy from a battery charged by the satellite's solar panels.
 
"It's converting solar energy straight into useful work," Arshavsky said. "Energy is the one thing that is abundant in space, and you can use it to energize the magnet to create a magnetic acceleration device. It gives you acceleration without fuel." In the future, Zenno Astronautics plans to launch larger systems that could enable spacecraft to dock in space or conduct close proximity operations using just the power of their solar-powered superconducting magnets. Arshavsky envisions powerful magnets that could, in the future, propel spacecraft on missions to the moon and Mars using only solar power.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Superconducting+Thruster+Harnesses+Earth's+Magnetic+Field+In+First+Orbital+Test%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F07%2F2327219%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F07%2F2327219%2Fsuperconducting-thruster-harnesses-earths-magnetic-field-in-first-orbital-test%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/07/2327219/superconducting-thruster-harnesses-earths-magnetic-field-in-first-orbital-test?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Nitro Automate: Intelligent document automation for enterprise AI workflows]]></title>
<description><![CDATA[From contracts and invoices to onboarding forms and compliance records, document-heavy processes consume significant time and resources across enterprise organizations.



While AI has introduced new opportunities for automation, many organizations still struggle with one fundamental challenge: A...]]></description>
<link>https://tsecurity.de/de/3652814/it-nachrichten/introducing-nitro-automate-intelligent-document-automation-for-enterprise-ai-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652814/it-nachrichten/introducing-nitro-automate-intelligent-document-automation-for-enterprise-ai-workflows/</guid>
<pubDate>Tue, 07 Jul 2026 23:48:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>From contracts and invoices to onboarding forms and compliance records, document-heavy processes consume significant time and resources across enterprise organizations.</p>



<p>While <a href="https://www.gonitro.com/nitro-ai?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored">AI</a> has introduced new opportunities for automation, many organizations still struggle with one fundamental challenge: A lot of important business information is trapped inside PDFs, forms, and other documents.</p>



<p><a href="https://www.gonitro.com/automate?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored"><strong>Nitro Automate</strong></a><strong> solves this problem.</strong></p>



<p>Designed for enterprise-level document volume, Nitro Automate is an intelligent document automation platform that combines document processing, workflow automation, and AI-powered integrations to help teams eliminate manual document tasks and automate business processes. It’s fast to deploy, built to work anywhere your team handles PDFs, and can start delivering value almost immediately.</p>



<h2 class="wp-block-heading">Nitro Automate is intelligent document automation for today’s enterprises</h2>



<p>Nitro Automate extends Nitro’s document productivity solutions—<a href="https://www.gonitro.com/pdf?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows">Nitro PDF,</a> <a href="https://www.gonitro.com/sign?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored">Nitro Sign</a>, <a href="https://www.gonitro.com/smart-redact?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored">Nitro Smart Redact</a>—going beyond document creation, editing, and signing to address the challenge of managing document operations across the AI agents, workflows, and systems your teams rely on.</p>



<p>Instead of depending on employees to move documents between systems, extract data manually, or manage repetitive workflows, Nitro Automate lets you automate tasks throughout the document lifecycle, including:</p>



<ul class="wp-block-list">
<li>Process, convert, reshape, transform, convert, compress, and secure PDFs</li>



<li>Document generation and assembly</li>



<li><a href="https://www.gonitro.com/resources/goodbye-copy-pasting-how-nitro-automates-table-and-form-data-extraction?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored">Data extraction from forms</a> and documents</li>



<li>Workflow automation and orchestration</li>



<li>eSignature workflow automation</li>



<li>Document security and redaction</li>



<li><a href="https://www.gonitro.com/integrations?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored">Integration</a> with enterprise applications</li>
</ul>



<h2 class="wp-block-heading">Key capabilities of Nitro Automate</h2>



<p>Nitro Automate works at two levels.</p>



<p>At the team and department level, it combines document automation, AI-powered data extraction, and workflow orchestration to eliminate manual document work entirely for high-volume processes.</p>



<p>At the individual level, it accelerates essential document tasks that still require human judgment, such as reviewing, approving, or routing documents.</p>



<p>Across both levels, enterprise integrations make document data accessible to every stakeholder, whether they’re automating a process or working through it directly.</p>



<p><strong>Here are four ways Nitro Automate transforms document-intensive workflows.</strong></p>



<h3 class="wp-block-heading"><a></a>Eliminate many manual PDF tasks</h3>



<p>Despite significant investments in digitalization, many core business workflows, like employee onboarding, contract review, and invoice processing, still depend on employees manually performing routine document tasks before work can move forward. These tasks include:</p>



<ul class="wp-block-list">
<li>Converting files to the right format</li>



<li>Splitting or merging PDFs</li>



<li>Extracting specific content</li>



<li>Applying security settings</li>



<li>Preparing final document packages</li>
</ul>



<p>Individually, each task takes only a few minutes. But repeated across hundreds or thousands of documents, they add up to hours of low-value manual work embedded inside otherwise automated workflows. Nitro Automate removes these manual document steps from core business workflows entirely, so employees are no longer a required step between one process stage and the next.</p>



<p>These activities may seem insignificant when viewed individually, but when thousands of documents are at play, they can create substantial operational overhead. Nitro Automate helps automate these processes through reusable workflows that can run behind the scenes to support business operations.</p>



<p>That means that your teams can focus on higher-value work while improving process consistency and reducing the risk of errors.</p>



<h3 class="wp-block-heading">Automate eSignature workflows beyond the signature</h3>



<p>In many organizations, obtaining an electronic signature is only one step in a larger workflow.</p>



<p>For example, a contract may require document generation, internal approvals, signature collection, storage, reporting, and follow-up actions. Similar workflows exist across industries, such as HR, procurement, legal, finance, and customer operations.</p>



<p>Nitro Automate helps organizations automate these processes by integrating document preparation, routing, approvals, and Nitro Sign workflows into a single automated experience.</p>



<p>Instead of managing signatures manually across disconnected tools, teams can create workflows that automatically move documents through each stage of the lifecycle, resulting in faster turnaround times, improved visibility, and fewer bottlenecks.</p>



<h3 class="wp-block-heading"><a></a>Unlock data trapped in documents</h3>



<p>One of Nitro Automate’s most valuable capabilities is how it transforms unstructured document content into actionable business data.</p>



<p>Critical information is often stored inside contracts, invoices, applications, forms, and other documents. Accessing that information traditionally requires manual review and extraction. Nitro Automate uses AI to identify, capture, and structure document data so it can be used by downstream systems and workflows to accelerate processes, such as:</p>



<ul class="wp-block-list">
<li>Invoice and accounts payable automation</li>



<li>Employee onboarding</li>



<li>Contract management</li>



<li>Customer intake</li>



<li>Compliance reporting</li>



<li>Claims and case management</li>
</ul>



<h3 class="wp-block-heading">Build document workflows that work in the AI era</h3>



<p>As enterprises move beyond AI copilots that assist with individual tasks and begin deploying AI agents that can execute multi-step workflows autonomously, document automation is becoming an increasingly important part of AI strategy.</p>



<p>Many AI systems can analyze information and generate recommendations, but they often require specialized tools to execute document-related tasks. Nitro Automate addresses this challenge by providing flexible integration options that support both human- and AI-driven workflows.</p>



<p>For example, business teams can build their own automations using low-code and no-code tools, while developers can easily integrate Nitro Automate into existing applications and workflows using APIs.</p>



<p>Nitro Automate is also compatible with the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol (MCP)</a>, an emerging open source standard that allows AI agents to securely access external tools and services. Through MCP, <a href="https://www.gonitro.com/automate/mcp?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored">AI agents can use </a><a href="https://www.gonitro.com/automate/mcp?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows" rel="sponsored">Nitro’s document automation </a>solution to interact with documents inside business workflows, making Nitro Automate a document execution layer for enterprise AI initiatives.</p>



<h2 class="wp-block-heading">Nitro Automate: A new approach to enterprise document operations</h2>



<p>If your organization is investing in automation and AI, it’s important to recognize that document-intensive processes are one of the largest opportunities for operational improvement.</p>



<p>Nitro Automate bridges the gap between documents, workflows, enterprise systems, and AI agents by bringing together document processing, eSignature automation, data extraction, and workflow orchestration.</p>



<p>Ready to discover how Nitro Automate helps create intelligent workflows that can scale alongside the next generation of enterprise AI?</p>



<p><a href="https://www.gonitro.com/contact-sales/nitro-automate?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=Introducing+Nitro+Automate%3A+Intelligent+Document+Automation+for+Enterprise+AI+Workflows">Speak with a Nitro Automation Expert</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Modernizing legacy IT with AI without triggering regulatory risk]]></title>
<description><![CDATA[AI is accelerating modernization projects that previously required months of analysis. But in highly regulated organizations, an uncomfortable reality quickly emerges: The risk is no longer in converting the code, but in demonstrating that the new version still does exactly what the old one did.
...]]></description>
<link>https://tsecurity.de/de/3651034/it-security-nachrichten/modernizing-legacy-it-with-ai-without-triggering-regulatory-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651034/it-security-nachrichten/modernizing-legacy-it-with-ai-without-triggering-regulatory-risk/</guid>
<pubDate>Tue, 07 Jul 2026 11:36:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI is accelerating modernization projects that previously required months of analysis. But in highly regulated organizations, an uncomfortable reality quickly emerges: The risk is no longer in converting the code, but in demonstrating that the new version still does exactly what the old one did.</p>



<p>Almost every management committee has made the same decision this year: to apply artificial intelligence to their systems. And almost all discover the same thing when they delve into the details: AI is easy to add to the periphery — a chatbot, a copilot, a dashboard — and very difficult to integrate where it really matters, which is the legacy core. In banking, insurance, and much of the public sector, that core is still COBOL on a mainframe, with decades of patches and documentation that, to put it mildly, is incomplete.</p>



<p>That’s precisely where the regulatory risk lies. And that’s where most projects go off the rails.</p>



<p>I’ve spent three decades in regulated sectors, and the pattern repeats itself. The IT team approaches modernization as a delivery problem — deliver quickly, close tickets, move to production — when in a regulated sector, the problem is compliance. Success isn’t measured by what you deliver, but by what you can defend. Changing that mindset is half the battle.</p>



<h2 class="wp-block-heading">The mirage of COBOL translated</h2>



<p>The promise is enticing. Today, a language model can read thousands of lines of COBOL, document them, explain them, and propose an equivalent in Java or Python in a fraction of the time it would take a human team. It works. I’ve seen it accelerate analyses that previously took weeks.</p>



<p>The problem isn’t the code. The problem is the business rules that no one ever wrote down. In a migration project in a highly regulated banking environment, the biggest risk wasn’t in the routines, but in a calculation exception that had been running for 15 years and wasn’t documented anywhere: It existed only in the code and in the mind of a now-retired analyst. When you ask a model to “translate” that, it doesn’t translate; it fills in the gap with what statistically seems correct. And it does so with impeccable certainty.</p>



<p>On a dashboard, a hallucination is a troublesome error. In a financial institution’s calculation engine, it’s a compliance incident, a customer complaint, and potentially a penalty from the regulator.</p>



<p>The temptation, precisely because the tool is so fast, is to skip the slow part: reconstructing that logic with someone who understands it. That’s the worst possible decision. The speed of AI is seductive precisely at the point where making a mistake is most costly.</p>



<h2 class="wp-block-heading">What the regulator expects — and what changed in May</h2>



<p><a href="https://www.csoonline.com/article/570091/eus-dora-regulation-explained-new-risk-management-requirements-for-financial-firms.html">DORA</a> has been in effect since January 2025 and is very clear: operational resilience, ICT asset management, business continuity, and third-party risk control. Modernizing the core addresses all four areas simultaneously. NIS2 adds the security and notification layer. And the AI ​​Regulation introduces its own framework when the system you deploy is high-risk.</p>



<p>Although DORA, <a href="https://www.csoonline.com/article/3568787/eus-nis2-directive-for-cybersecurity-resilience-enters-full-enforcement.html">NIS2</a>, and the EU AI ​​Regulation pursue different objectives, they share a common requirement: the ability to demonstrate control, traceability, and accountability over deployed systems. This is the link between the three frameworks, and it’s what a modernization project must protect from day one.</p>



<p>It’s important to clear up a recent misunderstanding here. With the <a href="https://data.europa.eu/en/news-events/news/eu-digital-omnibus-update-simplifying-europes-digital-rulebook" target="_blank" rel="nofollow">Digital Omnibus</a> agreement of May 2026, the high-risk obligations of Annex III are postponed until December 2027. Many executives have interpreted the headline — “EU delays AI Law” — as a reprieve. This is a dangerous interpretation. Transparency obligations still apply in August 2026, synthetic content marking comes into effect in December 2026, and, most importantly, the underlying risk remains unchanged. An erroneous automated decision in 2026 still falls under the GDPR, under sector-specific regulations, and under the jurisdiction of the relevant supervisor. The deadline has been moved; the responsibility has not.</p>



<h2 class="wp-block-heading">How to do it without triggering the risk</h2>



<p>I don’t have a magic formula, but I do have five principles that I apply to every project of this type:</p>



<ol class="wp-block-list">
<li><strong>Inventory before modernizing.</strong> You can’t secure or migrate what hasn’t been mapped. Assets, dependencies, data flows: If that map doesn’t exist, the first deliverable of the project is to build it, not write code.</li>



<li><strong>The AI </strong><strong>​​proposes, a person validates.</strong> The model accelerates the analysis and the first draft of the transformation. The critical business rule is confirmed by an engineer who understands the business, not the model. Where there is no one who understands it, it is reconstructed with the business area before anything is changed.</li>



<li><strong>End-to-end traceability.</strong> Every AI-generated transformation must be recorded: what went in, what went out, who approved it, and why. That’s not bureaucracy; it’s exactly what the auditor will ask for, and it’s what makes a change defensible.</li>



<li><strong>Be careful where you put the code.</strong> Dumping kernel source code into an external model is a data transfer and a confidentiality issue more than a technical one. DORA requires control over the third party; GDPR requires control over the data. This decision is made at the beginning of the project, not after it’s finished.</li>



<li><strong>Govern shadow AI.</strong> If the organization doesn’t offer a safe way to use AI, teams will use it anyway, on their own and without oversight. Governance isn’t about prohibition but about providing an enabled path.</li>
</ol>



<h2 class="wp-block-heading">Technological leadership has changed</h2>



<p>In a regulated sector, the CIO’s challenge is no longer simply to modernize legacy systems, but to do so in a way that withstands the scrutiny of auditors, regulators, and risk committees.</p>



<p>Leading one of these projects is no longer about coordinating deliveries; it’s about making the transformation defensible. It means saying no to a shortcut that would save two weeks but leave a gap without traceability. It means treating governance as an accelerator — because a well-documented change is approved faster — and not a brake.</p>



<p>AI is an extraordinary tool for organizations to overcome their legacy technical debt. But in banking, insurance, or public administration, uncontrolled speed is not an advantage: It’s a liability that surfaces at first inspection. Modernizing quickly can be a competitive advantage; modernizing with traceability, control, and defense capabilities is what makes it sustainable.</p>



<p>Therefore, I summarize what I’ve learned over the years as the following: A secure solution isn’t the slowest or the most expensive; it’s the one that survives the first audit.</p>



<p><em><a href="https://joseenrique.es/" rel="nofollow">José Enrique Ibarra</a> is Interim CIO and AI Project Manager, with three decades of experience leading IT in regulated sectors—banking, insurance, energy, and public administration. His focus is on governing digital transformation and AI adoption under the AI </em><em>​​Regulation, DORA, NIS2, GDPR, ISO 27001, and the Spanish National Security Framework (ENS), ensuring it withstands the scrutiny of auditors and regulators. He leads AI Forge, his applied AI initiative. He resides in Almería.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ECMAScript 2026 specification approved]]></title>
<description><![CDATA[ECMA International has approved ECMAScript 2026, the 17th edition of the specification for the JavaScript programming language. The standards organization approved the specification on June 30. 



ECMAScript 2026 adds methods for math, iterators, arrays, maps, encoding, and JSON. The additions i...]]></description>
<link>https://tsecurity.de/de/3650428/ai-nachrichten/ecmascript-2026-specification-approved/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650428/ai-nachrichten/ecmascript-2026-specification-approved/</guid>
<pubDate>Tue, 07 Jul 2026 05:48:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>ECMA International has approved ECMAScript 2026, the 17th edition of the specification for the <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> programming language. The standards organization approved the specification on <a href="https://ecma-international.org/news/ecma-international-approves-new-standards-14/">June 30</a>. </p>



<p>ECMAScript 2026 adds methods for math, iterators, arrays, maps, encoding, and JSON. The additions include  <code>Math.sumPrecise</code> for summing an <a href="https://tc39.es/ecma262/#sec-iterable-interface">iterable</a> of numbers of varying magnitude while minimizing precision loss; <code>Iterator.concat</code> for sequencing <a href="https://tc39.es/ecma262/#sec-iterator-interface">iterators</a>; <code>Array.fromAsync</code> for constructing arrays from <a href="https://tc39.es/ecma262/#sec-asynciterable-interface">async iterables</a> and other async sources; <code>Error.isError</code> for identifying error objects; methods to <code>Map.prototype</code> and <code>WeakMap.prototype</code> for providing a default value to use during retrieval when a key is not already present; methods to <code>Uint8Array</code> for converting to and from strings of hexadecimal-based and base64-encoded binary data; a parameter to <code>JSON.parse</code> revivers to access the matched segment of JSON source; and <code>JSON.rawJSON</code> for fine control over <code>JSON.stringify</code> output for primitive values.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation]]></title>
<description><![CDATA[A self-hosted CTI-to-detection workbench for ATT&CK mapping, IOC investigation, malware analysis, asset attack-surface mapping, attack simulation, and detection engineering validation.IntroductionAdversaryGraph started as a practical question:How can a security team move from threat intelligence ...]]></description>
<link>https://tsecurity.de/de/3646308/hacking/adversarygraph-v50-from-cti-mapping-to-attack-simulation-and-siem-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646308/hacking/adversarygraph-v50-from-cti-mapping-to-attack-simulation-and-siem-validation/</guid>
<pubDate>Sun, 05 Jul 2026 08:22:34 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A self-hosted CTI-to-detection workbench for ATT&amp;CK mapping, IOC investigation, malware analysis, asset attack-surface mapping, attack simulation, and detection engineering validation.</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pE4s-eX1wFWMUOsnozr16w.png"></figure><h3>Introduction</h3><p>AdversaryGraph started as a practical question:</p><p><strong>How can a security team move from threat intelligence to detection engineering without losing the evidence trail?</strong></p><p>Most CTI workflows produce useful text, but the next steps are often manual. An analyst reads a report, extracts behaviors, maps them to MITRE ATT&amp;CK, compares them with known actors, enriches IOCs, writes detection ideas, and then asks a detection engineer to validate whether telemetry actually exists in the SIEM.</p><p>That gap is where a lot of defensive work slows down.</p><p>AdversaryGraph v5.0 is my attempt to make that workflow more operational. It is not only a CTI visualization project. It is a self-hosted analyst workbench that connects:</p><ul><li><strong>Report and telemetry analysis.</strong></li><li><strong>ATT&amp;CK technique mapping.</strong></li><li><strong>Group, campaign, and report similarity.</strong></li><li><strong>IOC enrichment and investigation.</strong></li><li><strong>Malware analysis workflows.</strong></li><li><strong>Asset attack-surface mapping.</strong></li><li><strong>Attack simulation.</strong></li><li><strong>SIEM forwarding and validation.</strong></li><li><strong>Analyst-ready documentation and reports.</strong></li></ul><p>The main addition in release 5.0 is <strong>Attack Simulation</strong>: a controlled ATT&amp;CK validation workspace where an analyst can select a technique, run approved lab scenarios, inspect target-side telemetry, forward logs to a SIEM collector, and use an AI assistant to generate coherent multi-phase attack-chain drills.</p><p>This article explains what is new in v5.0, how the architecture works, what the platform can do today, and how I expect analysts and detection engineers to use it.</p><p>Project links:</p><ul><li>Project landing page: <a href="https://1200km.com/adversarygraph/">https://1200km.com/adversarygraph/</a></li><li>Documentation: <a href="https://1200km.com/adversarygraph-docs/">https://1200km.com/adversarygraph-docs/</a></li><li>GitHub: <a href="https://github.com/anpa1200/adversarygraph">https://github.com/anpa1200/adversarygraph</a></li><li>Release v5.0.0: <a href="https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0">https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0</a></li></ul><h3>Table of Contents</h3><ul><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e399"><strong>Getting Started</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cea9"><strong>The Problem: CTI Often Stops Before Validation</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#dfa8"><strong>What AdversaryGraph Is</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cb81"><strong>Core Capabilities Before v5.0</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#873f"><strong>What Is New in v5.0</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#bca9"><strong>TTP-First Simulation Workflow</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#b2a4"><strong>Real Lab Telemetry for Web Scenarios</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#251c"><strong>SIEM Forwarding</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#a5cc"><strong>AI Attack Assistant</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#3d3e"><strong>Coherent Kill Chains, Not Random Events</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#2f06"><strong>Explain Attack</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#f317"><strong>Named Scenario Library</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#144f"><strong>Safety Boundaries</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cd7c"><strong>How This Fits Detection Engineering</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e7d0"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#6252"><strong>Example Use Case: Password Spray Detection</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#231b"><strong>Example Use Case: Web Recon to Exploit-Shaped Telemetry</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#8a5c"><strong>Example Use Case: Malware Findings to Detection Validation</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#dbfb"><strong>Example Use Case: Asset Inventory to Attack Surface</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#8e80"><strong>What This Release Is Not</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#ff3a"><strong>What Makes v5.0 Different</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e399"><strong>Getting Started</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#22f6"><strong>Final Thoughts</strong></a></li></ul><h3>The Problem: CTI Often Stops Before Validation</h3><p>A typical CTI-to-detection workflow looks like this:</p><ol><li>Read an external report, internal incident report, malware note, or intelligence summary.</li><li>Extract behaviors: PowerShell, scheduled tasks, credential dumping, public-facing application exploitation, exfiltration, persistence, discovery, and so on.</li><li>Map those behaviors to MITRE ATT&amp;CK.</li><li>Compare them with known actor and campaign profiles.</li><li>Identify relevant IOCs.</li><li>Write hunting hypotheses and detection logic.</li><li>Ask whether the SIEM actually receives the required telemetry.</li><li>Test rules with sample logs, lab traffic, or purple-team activity.</li></ol><p>The hard part is not just mapping. The hard part is preserving the chain from <strong>evidence</strong> to <strong>technique</strong> to <strong>telemetry</strong> to <strong>detection validation</strong>.</p><p>If the SIEM parser is broken, the detection will not fire.</p><p>If the event structure is wrong, the rule will not match.</p><p>If the test event is too synthetic, the validation result is misleading.</p><p>If the ATT&amp;CK mapping is not tied back to evidence, the report becomes hard to defend.</p><p>AdversaryGraph v5.0 focuses on this full chain.</p><h3>What AdversaryGraph Is</h3><p>AdversaryGraph is a self-hosted CTI-to-detection platform. It combines a public research interface with a Docker-based private platform.</p><p>The public site is useful for exploration: ATT&amp;CK matrix navigation, group research, public technique context, and project documentation.</p><p>The self-hosted platform is where private work belongs: AI-assisted report analysis, stored investigations, IOC enrichment, malware-analysis workflows, asset inventories, attack simulation, SIEM validation, and API-driven workflows.</p><p>The high-level workflow is:</p><ol><li><strong>Ingest</strong> reports, logs, IOCs, malware findings, asset inventory, or feed data.</li><li><strong>Map</strong> behaviors to ATT&amp;CK with evidence and confidence.</li><li><strong>Enrich</strong> IOCs, actors, campaigns, malware families, and references.</li><li><strong>Validate</strong> coverage using lab telemetry and SIEM forwarding.</li><li><strong>Report</strong> findings in analyst-ready form.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*sMubTyaMt5F9zU2t.png"></figure><h3>Core Capabilities Before v5.0</h3><p>Release 5.0 builds on a broader platform. The major existing modules are still part of the release and matter because Attack Simulation is designed to connect to them.</p><p><strong>All capabilities here:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/capabilities/">Platform Capabilities | AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><h4>AI-Assisted ATT&amp;CK Mapping</h4><p>Analysts can paste text or upload reports and ask the configured LLM provider to extract ATT&amp;CK candidates. The platform supports multiple provider options, including Claude, OpenAI, Gemini, MiniMax, and local OpenAI-compatible gateways.</p><p>The important part is not simply “ask AI for TTPs.” The useful part is that mappings are treated as analyst-assistance data:</p><ul><li>Techniques are shown with evidence.</li><li>Confidence is visible.</li><li>Output can be reviewed before operational use.</li><li>Extracted TTPs can be pushed into the Navigator.</li><li>Results can be compared with groups, campaigns, and stored reports.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*YMWb4u7m0Ogpsb6T.png"></figure><h4>ATT&amp;CK Navigator and Group Context</h4><p>The Navigator is the central workspace for technique review. It supports Enterprise, Mobile, ICS, and ATLAS-style workflows. Analysts can search techniques, build layers, overlay group context, import/export layers, and move selected TTPs into comparison and reporting workflows.</p><p>This matters because many teams already think in ATT&amp;CK, but their toolchain is split between reports, spreadsheets, diagrams, SIEM rules, and ticketing systems. AdversaryGraph tries to keep the matrix connected to the rest of the investigation.</p><h4>Group, Campaign, and Report Similarity</h4><p>AdversaryGraph uses TTP overlap as a way to generate hypotheses. It compares selected behavior against ingested group profiles, campaigns, and stored report libraries.</p><p>This is intentionally framed as similarity, not attribution.</p><p>TTP overlap can help prioritize research. It can suggest which actor profiles or campaigns deserve review. It is not proof that a specific actor is responsible for an intrusion.</p><h4>IOC Investigation</h4><p>The IOC workflow lets analysts pivot from observable data into reputation and relationship context. IPs, domains, URLs, hashes, and other observables can be investigated with feed context and ATT&amp;CK leads.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*SHhDv7Qw2exVtviQ.png"></figure><h4>Malware Analysis</h4><p>The Malware Analysis module connects static triage, hash checks, unpacking, strings, decompilation/debug views, runtime-gated analysis, and AI summaries back to the CTI workflow.</p><p>The point is not to replace a reverse engineer. The point is to help analysts preserve malware-derived evidence and map it into ATT&amp;CK, IOCs, and investigation outputs.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*W0QBOK9La3Q3mirM.png"></figure><h4>Asset Attack-Surface Mapping</h4><p>AdversaryGraph can ingest asset inventory input, normalize assets, score exposure, propose likely entry points, and map asset-driven ATT&amp;CK candidates.</p><p>This is useful when the question is not “what did the attacker do?” but “what could an attacker realistically try against my exposed environment?”</p><p>Examples:</p><ul><li>Public web applications.</li><li>VPN and identity services.</li><li>Exposed admin panels.</li><li>Cloud assets.</li><li>Remote management services.</li><li>High-value internal systems.</li><li>Scanner and CMDB exports.</li></ul><h3>What Is New in v5.0</h3><p>The headline feature is <strong>Attack Simulation</strong>.</p><p>Attack Simulation is designed for defensive validation and detection engineering. It lets analysts work from a TTP-first interface, run safe simulations, inspect telemetry, and forward events to a SIEM.</p><p>This is not an exploitation framework. It does not run malware. It does not execute arbitrary commands against arbitrary user targets. It is a controlled validation workspace for authorized lab scenarios and source-shaped telemetry drills.</p><p>The v5.0 release adds:</p><ul><li>A new Attack Simulation workspace.</li><li>ATT&amp;CK-style matrix selection for runnable simulations.</li><li>Dedicated configuration pages per selected TTP.</li><li>Built-in lab web target for web-focused scenarios.</li><li>Target-side real-time log viewing.</li><li>SIEM forwarding to HTTP(S) collectors.</li><li>Saved recent SIEM destinations.</li><li>AI Attack Assistant.</li><li>“Challenge Me” mode.</li><li>Complicated multi-source attack-chain scenarios.</li><li>25 named coherent scenario templates.</li><li>Attack-chain graph.</li><li>Explain Attack panel.</li><li>Source-shaped Windows, Sysmon, EDR, DNS, proxy, firewall, web, and WAF event generation for SIEM parser and rule validation.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*6nP-gwkSId3d917_.png"></figure><h3>TTP-First Simulation Workflow</h3><p>The workflow starts with the ATT&amp;CK matrix.</p><p>Runnable simulation cells are visible directly in the matrix, and related TTP pages can link back into the simulation workflow. This keeps the analyst oriented around ATT&amp;CK instead of hiding simulations behind unrelated forms.</p><p>The basic flow is:</p><ol><li>Open Attack Simulation.</li><li>Choose a TTP from the matrix.</li><li>Open the dedicated simulation page.</li><li>Review what the scenario does.</li><li>Review telemetry source and event structure.</li><li>Run the lab scenario or AI-assisted telemetry drill.</li><li>Inspect logs in real time.</li><li>Forward selected logs to the SIEM.</li><li>Confirm whether detections fired.</li><li>Record validation gaps.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*1RZJyK6gkRejmuv0.png"></figure><p>Each scenario explains:</p><ul><li>What happens.</li><li>What adversary behavior is represented.</li><li>Which system emits telemetry.</li><li>Which event structures are expected.</li><li>What the detection should focus on.</li><li>Which telemetry is production-like and which is a lab canary.</li><li>What the validation gaps are.</li></ul><p>That explanation is important. A simulation without context is just noise. A simulation with context becomes a detection-engineering exercise.</p><h3>Real Lab Telemetry for Web Scenarios</h3><p>One major design goal was to avoid fake “log generation” for web scenarios where a real lab target can safely produce logs.</p><p>For web-focused simulations, the Docker deployment includes an attack-lab-web target. The AdversaryGraph API sends real HTTP requests to that lab web server over the Docker network. The target server writes its own logs.</p><p>The analyst can then inspect real target-side telemetry such as:</p><ul><li>NGINX access logs.</li><li>NGINX error logs.</li><li>Application authentication logs.</li><li>WAF/security-style logs.</li><li>Structured web JSONL telemetry.</li><li>Run-specific JSONL logs.</li><li>Merged attacked-server events.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*CPDdyF-3kyqCleFB.png"></figure><p>This is different from simply printing a row that looks like an access log. The request is sent to the lab server, and the server emits the log.</p><p>Supported web-focused scenarios include:</p><ul><li>HTTP and TLS service fingerprinting.</li><li>Public application probing.</li><li>Path discovery.</li><li>Sensitive file and configuration path access.</li><li>Directory traversal canaries.</li><li>SQL injection-shaped requests.</li><li>XSS-shaped requests.</li><li>SSRF-shaped requests.</li><li>Command-injection-shaped requests.</li><li>Web-shell access canaries.</li><li>Upload and download scenarios.</li><li>Failed-login flows.</li><li>Brute-force patterns.</li><li>Password spray.</li><li>User enumeration.</li><li>Beacon-like web traffic.</li><li>Exfiltration-shaped traffic.</li></ul><p>The key phrase is “attack-shaped canary.” The goal is to generate realistic defensive telemetry without exploiting a real target or executing harmful payloads.</p><h3>SIEM Forwarding</h3><p>Validation is incomplete if the event never reaches the SIEM.</p><p>The v5.0 SIEM forwarding panel sends selected Attack Simulation telemetry to HTTP(S) collectors. This can be used with Logstash HTTP input, Splunk HEC-style collectors, XpoLog/Logeye listeners, or custom webhook receivers.</p><p>Supported controls include:</p><ul><li>Full URL or raw host:port/path destination.</li><li>Direct destination mode.</li><li>Docker host gateway routing.</li><li>Automatic route selection.</li><li>Raw original line per request.</li><li>JSON event per request.</li><li>JSON Lines.</li><li>Batch envelope.</li><li>No auth.</li><li>Bearer token auth.</li><li>Token auth.</li><li>Basic auth.</li><li>Custom token header.</li><li>Source selection: access, auth, endpoint, WAF/security, error, structured JSONL, run JSONL, or all attacked-server events.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*DYOx-cPX4OK1g66v.png"></figure><p>The platform also keeps the last 10 non-secret SIEM destinations for reuse. This is useful during repeated parser testing, rule tuning, and dashboard validation.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*vpv4bXcWuUgvV4Hx.png"></figure><p>Credentials are not stored as part of the saved destination history. The saved address is intended to reduce typing friction, not to become a secret store.</p><h3>AI Attack Assistant</h3><p>The AI Attack Assistant is one of the main additions in v5.0.</p><p>It helps generate detection-engineering drills by building correlated telemetry stories around selected behavior.</p><p>The assistant supports three modes:</p><ol><li><strong>Selected TTP</strong>: generate a focused validation flow around the technique currently selected in the Attack Simulation page.</li><li><strong>Threat actor</strong>: generate a scenario inspired by a threat actor’s known behavior and ATT&amp;CK profile.</li><li><strong>Challenge Me</strong>: generate a blind multi-phase detection challenge for the analyst.</li></ol><p>There is also a <strong>Complicated attack</strong> option. When enabled, the assistant builds longer multi-source flows across telemetry types such as:</p><ul><li>Windows Security Event Log.</li><li>Sysmon.</li><li>EDR process and file telemetry.</li><li>DNS logs.</li><li>Proxy logs.</li><li>Firewall traffic logs.</li><li>Web access logs.</li><li>WAF/security logs.</li><li>Authentication logs.</li></ul><p>The goal is not to normalize everything into one generic schema. For complicated scenarios, the assistant should preserve source/vendor-shaped event patterns so the SIEM parser and rule logic are tested more realistically.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*R2jz_jH_4T-N9__R.png"></figure><h3>Coherent Kill Chains, Not Random Events</h3><p>A detection drill should not be a random list of suspicious events.</p><p>In v5.0, complicated scenarios are built as coherent attack chains. The chain has ordered phases, each phase has a reason, and each phase emits events that should correlate with the surrounding activity.</p><p>For example, a password-spray-to-foothold scenario may include:</p><ol><li>Username enumeration.</li><li>Multiple failed authentication attempts.</li><li>One successful logon after failures.</li><li>Endpoint discovery from the authenticated host.</li><li>Suspicious tool transfer.</li><li>Persistence or lateral discovery.</li></ol><p>That is much more useful than a single failed-login event.</p><p>The Attack Chain Graph makes this visible.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*-bkB_LbIx9r5Ro35.png"></figure><p>Each phase can show:</p><ul><li>Phase number.</li><li>ATT&amp;CK technique.</li><li>Telemetry source.</li><li>Event format.</li><li>Event count.</li><li>Detection goal.</li><li>Supporting tags.</li></ul><p>This helps the analyst understand whether the generated activity is a plausible kill chain or just a bag of indicators.</p><h3>Explain Attack</h3><p>When “Challenge Me” or a complex AI-generated scenario is used, the platform includes an <strong>Explain Attack</strong> action.</p><p>This panel explains:</p><ul><li>What the scenario is trying to simulate.</li><li>Why each phase appears in the chain.</li><li>Which telemetry sources matter.</li><li>What the analyst should search for.</li><li>What detections should fire.</li><li>Which false positives or tuning points should be considered.</li><li>What success criteria should be used.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*H7lfS2NaR1B5hvEV.png"></figure><p>This is useful for training and validation. It turns generated events into an exercise that a SOC analyst, detection engineer, or CTI analyst can actually follow.</p><h3>Named Scenario Library</h3><p>Release 5.0 includes a library of named coherent scenarios.</p><p>Examples include:</p><ul><li>Web App to Endpoint Compromise.</li><li>Password Spray to Valid Account Foothold.</li><li>SQL Injection to Data Theft.</li><li>Recon to Web Shell Persistence.</li><li>Valid Account to LSASS Access.</li><li>Password Spray to Exfiltration.</li><li>XSS Canary to Session Abuse.</li><li>SSRF Metadata Probe to C2.</li><li>Ransomware Precursor Chain.</li><li>Living-off-the-Land Transfer and Execution.</li><li>Internal Discovery After Foothold.</li><li>Web Enumeration to Password Spray.</li><li>Public App Exploit to Persistence.</li><li>Credential Dump to Cloud Upload.</li><li>Signed Binary Proxy to C2.</li><li>FIN7-style web, identity, and persistence flow.</li><li>APT29-style identity and PowerShell flow.</li><li>Lazarus-style delivery and exfiltration flow.</li><li>Noisy red-team drill.</li><li>Stealthy low-volume intrusion chain.</li><li>WAF bypass retry chain.</li><li>Service account abuse.</li><li>External recon to credential access.</li><li>C2 telemetry validation.</li><li>Persistence control validation.</li></ul><p>These are not meant to prove that a real actor attacked you. They are templates for detection validation and training. They help answer questions like:</p><ul><li>Does my SIEM parse this source?</li><li>Does my correlation rule see the sequence?</li><li>Does the detection alert only on one event or on the chain?</li><li>Can analysts reconstruct the story from logs?</li><li>Which telemetry source is missing?</li><li>Where do false positives appear?</li></ul><h3>Safety Boundaries</h3><p>Attack Simulation must be safe by design.</p><p>The v5.0 module follows several boundaries:</p><ul><li>It does not execute malware.</li><li>It does not run arbitrary commands.</li><li>It does not exploit arbitrary external targets.</li><li>Web simulation traffic is limited to predefined benign canaries against the local lab target.</li><li>SIEM forwarding sends generated Attack Simulation telemetry.</li><li>Unsafe URL schemes and metadata/link-local destinations are blocked.</li><li>Credentials used for forwarding are used only for the current request and are not stored.</li></ul><p>This matters because the target user is a defender. The feature is built for detection engineering, parser validation, SOC drills, and authorized lab workflows.</p><h3>How This Fits Detection Engineering</h3><p>Detection engineering is not only writing rules. It is a lifecycle:</p><ol><li>Understand the adversary behavior.</li><li>Map it to ATT&amp;CK or another behavior model.</li><li>Identify required telemetry.</li><li>Confirm that telemetry exists.</li><li>Confirm that parsing works.</li><li>Write detection logic.</li><li>Test the logic with realistic events.</li><li>Tune false positives.</li><li>Document assumptions and gaps.</li><li>Re-test when infrastructure or parsers change.</li></ol><p>AdversaryGraph v5.0 tries to support this lifecycle directly.</p><p>The CTI modules help with steps 1 and 2.</p><p>IOC and malware modules help enrich the investigation context.</p><p>Asset attack-surface mapping helps identify relevant entry points.</p><p>Attack Simulation helps with steps 3 through 8.</p><p>Reports and docs help with steps 9 and 10.</p><h3>Architecture Overview</h3><p>The self-hosted platform is built around a browser frontend and API backend.</p><p>At a high level:</p><ul><li>Frontend: React/Vite user interface.</li><li>Backend: FastAPI service.</li><li>Database: PostgreSQL for stored investigations and platform data.</li><li>Background jobs: Redis/Celery where needed.</li><li>ATT&amp;CK data: synchronized from MITRE sources.</li><li>AI providers: operator-configured providers such as Claude, OpenAI, Gemini, MiniMax, or local OpenAI-compatible services.</li><li>Malware workflow: MalwareGraph-backed analysis components.</li><li>Attack lab: Docker-based target services for controlled telemetry generation.</li><li>SIEM forwarding: HTTP(S) delivery to configured collectors.</li></ul><p>For the v5.0 web simulation flow, the important architectural distinction is:</p><p>AdversaryGraph does not simply invent an access log line for the UI. It sends real HTTP requests to the lab web target, and the lab web target emits server-side logs.</p><p>For AI-generated complicated scenarios, the goal is different. The assistant generates source-shaped telemetry for SIEM parser and detection validation. This is not proof of compromise, and it is not a replacement for live lab execution. It is a defensive validation tool for testing ingestion, parsers, correlation, dashboards, and analyst workflows.</p><h3>Example Use Case: Password Spray Detection</h3><p>A common detection engineering task is password spray validation.</p><p>The analyst wants to know:</p><ul><li>Do we ingest authentication failures?</li><li>Are usernames parsed correctly?</li><li>Can we count failures across many users?</li><li>Can we detect one source trying one password against many accounts?</li><li>Can we correlate a later successful login?</li><li>Can we connect the successful login to endpoint activity?</li></ul><p>With AdversaryGraph v5.0, the workflow becomes:</p><ol><li>Select a credential-access or brute-force related TTP.</li><li>Choose the password spray scenario.</li><li>Run the lab or AI-assisted flow.</li><li>Observe authentication-related events.</li><li>Forward the events to the SIEM.</li><li>Confirm the parser.</li><li>Confirm the rule.</li><li>Review the chain graph.</li><li>Use Explain Attack to document what should have happened.</li><li>Record gaps.</li></ol><p>The important part is the chain. A single 4625-like event is not enough. A realistic validation should include many failures, many users, timing, source consistency, and possibly one later success.</p><h3>Example Use Case: Web Recon to Exploit-Shaped Telemetry</h3><p>For a web application detection scenario, the analyst may want to test:</p><ul><li>Path discovery.</li><li>Sensitive file probing.</li><li>SQL injection-shaped requests.</li><li>XSS-shaped requests.</li><li>SSRF-shaped requests.</li><li>WAF canary classification.</li><li>Access-log parser behavior.</li><li>SIEM dashboards for web attacks.</li></ul><p>AdversaryGraph can run approved web canaries against the lab web target, then show the real target-side logs in the UI.</p><p>This lets the detection engineer validate more than a rule. It validates whether the web tier emits usable logs and whether the SIEM receives enough context to detect the behavior.</p><h3>Example Use Case: Malware Findings to Detection Validation</h3><p>The malware module can produce findings such as:</p><ul><li>Suspicious imports.</li><li>Strings.</li><li>Packed sample indicators.</li><li>Function-level behavior.</li><li>Potential IOCs.</li><li>ATT&amp;CK candidates.</li><li>AI-assisted summaries.</li></ul><p>Those findings can feed detection engineering:</p><ul><li>Which API calls should we monitor?</li><li>Which command lines or process patterns matter?</li><li>Which persistence mechanisms appear?</li><li>Which network indicators are useful?</li><li>Which behaviors should become validation scenarios?</li></ul><p>AdversaryGraph’s value is that malware findings do not stay isolated in a reverse-engineering note. They can be connected back to ATT&amp;CK and validation planning.</p><h3>Example Use Case: Asset Inventory to Attack Surface</h3><p>Asset inventories often live in spreadsheets, CMDB exports, or scanner output. The security team may know what exists, but not how to translate that into likely ATT&amp;CK entry points.</p><p>The Asset Attack Surface module helps with:</p><ul><li>Normalizing assets.</li><li>Identifying exposed services.</li><li>Scoring exposure.</li><li>Mapping likely entry points.</li><li>Proposing ATT&amp;CK candidates.</li><li>Creating saved cases.</li></ul><p>This connects directly to Attack Simulation because a high-risk public web application or VPN service should map to validation scenarios around external discovery, exploitation attempts, credential attacks, and logging coverage.</p><h3>What This Release Is Not</h3><p>It is important to define what v5.0 is not.</p><p>It is not an autonomous attack platform.</p><p>It is not a malware execution system.</p><p>It is not a replacement for a full cyber range.</p><p>It is not attribution proof.</p><p>It is not a guarantee that a detection works in production.</p><p>It is an analyst-assistance and validation platform. Its output should be reviewed by qualified analysts and detection engineers before operational use.</p><h3>What Makes v5.0 Different</h3><p>The main difference is the connection between CTI and validation.</p><p>Many tools stop at one of these points:</p><ul><li>Visualize ATT&amp;CK.</li><li>Extract TTPs.</li><li>Store IOCs.</li><li>Generate sample logs.</li><li>Run a lab attack.</li><li>Forward events.</li></ul><p>AdversaryGraph tries to connect these into one workflow:</p><ol><li>Understand the behavior.</li><li>Map it.</li><li>Enrich it.</li><li>Simulate it safely.</li><li>Observe telemetry.</li><li>Send it to the SIEM.</li><li>Explain what happened.</li><li>Document what passed and what failed.</li></ol><p>That is the direction I want the platform to continue moving.</p><h3>Getting Started</h3><p>If you want to explore the public interface:</p><p><a href="https://1200km.com/threat-matrix/">AdversaryGraph Web - Public ATT&amp;CK Workspace for AdversaryGraph | 1200km</a></p><p><strong>If you want the full private platform:</strong></p><pre>git clone https://github.com/anpa1200/adversarygraph.git<br>cd adversarygraph<br>cp .env.example .env<br>docker compose up</pre><p><strong>Then open:</strong></p><pre>http://localhost:3000</pre><p><strong>Read the full documentation here:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/">AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><p><strong>Attack Simulation guide:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/attack-simulation/">Attack Simulation | AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><p><strong>Project page:</strong></p><p><a href="https://1200km.com/adversarygraph/">AdversaryGraph AI - CTI-to-Detection Platform</a></p><p><strong>GitHub release:</strong></p><p><a href="https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0">Release AdversaryGraph v5.0.0 · anpa1200/adversarygraph</a></p><h3>Final Thoughts</h3><p>AdversaryGraph v5.0 is a step toward a more complete CTI-to-detection workflow.</p><p>The platform is still built around a simple idea: intelligence should not end as a static report. It should become a mapped, enriched, validated, and explainable defensive workflow.</p><p>With Attack Simulation, SIEM forwarding, real lab telemetry, AI-assisted scenario generation, and attack-chain explanation, v5.0 moves AdversaryGraph closer to that goal.</p><p>The next challenge is to continue improving realism: more telemetry sources, more lab targets, better parser validation, stronger scenario libraries, and deeper connections between malware analysis, asset exposure, and detection engineering.</p><p>If you work in CTI, SOC operations, detection engineering, malware analysis, or purple-team validation, I would be glad to hear feedback.</p><p>Project:</p><p><a href="https://github.com/anpa1200/adversarygraph">https://github.com/anpa1200/adversarygraph</a></p><p>Documentation:</p><p><a href="https://1200km.com/adversarygraph-docs/">https://1200km.com/adversarygraph-docs/</a></p><p>Live workspace:</p><p><a href="https://1200km.com/threat-matrix/">AdversaryGraph Web - Public ATT&amp;CK Workspace for AdversaryGraph | 1200km</a></p><p>Main page:</p><p><a href="https://1200km.com/">Andrey Pautov - CTI &amp; Detection Engineering</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=21873b2a6c39" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39">AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sony already invested $34 million to repurpose its EU PlayStation disc factory]]></title>
<description><![CDATA[Sony is converting its PlayStation disc factory into a plant for optical microlenses.]]></description>
<link>https://tsecurity.de/de/3643359/it-nachrichten/sony-already-invested-34-million-to-repurpose-its-eu-playstation-disc-factory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643359/it-nachrichten/sony-already-invested-34-million-to-repurpose-its-eu-playstation-disc-factory/</guid>
<pubDate>Fri, 03 Jul 2026 13:18:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sony is converting its PlayStation disc factory into a plant for optical microlenses.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic launches Claude Sonnet 5 at a steep discount to its top model as the company races toward a blockbuster IPO]]></title>
<description><![CDATA[Anthropic today released Claude Sonnet 5, a new AI model that the company says delivers near-flagship performance at mid-tier prices — a move designed to give cost-conscious enterprise developers access to powerful agentic capabilities just as the San Francisco-based AI lab barrels toward an init...]]></description>
<link>https://tsecurity.de/de/3636601/it-nachrichten/anthropic-launches-claude-sonnet-5-at-a-steep-discount-to-its-top-model-as-the-company-races-toward-a-blockbuster-ipo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636601/it-nachrichten/anthropic-launches-claude-sonnet-5-at-a-steep-discount-to-its-top-model-as-the-company-races-toward-a-blockbuster-ipo/</guid>
<pubDate>Tue, 30 Jun 2026 20:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> today released <a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a>, a new AI model that the company says delivers near-flagship performance at mid-tier prices — a move designed to give cost-conscious enterprise developers access to powerful agentic capabilities just as the San Francisco-based AI lab barrels toward an initial public offering that will test whether the private market's staggering AI valuations can survive public scrutiny.</p><p>The release, which Anthropic describes as "<a href="https://www.anthropic.com/news/claude-sonnet-5">the most agentic Sonnet model ye</a>t," makes Sonnet 5 the default model for users on Anthropic's Free and Pro plans, while also making it available to Max, Team, and Enterprise customers. Introductory <a href="https://platform.claude.com/docs/en/about-claude/pricing">API pricing</a> is set at $2 per million input tokens and $10 per million output tokens through August 31, after which it rises to $3 and $15 respectively — still well below the $5 input and $25 output pricing of Anthropic's top-of-the-line Opus 4.8.</p><p>The strategic logic is unmistakable: Anthropic is trying to democratize access to capabilities that until very recently only its most expensive models could deliver, while building the kind of broad-based developer adoption that will look attractive in an <a href="https://www.anthropic.com/news/confidential-draft-s1-sec">S-1 filing</a>.</p><h2><b>Sonnet 5 benchmarks show the mid-tier model closing in on Anthropic's flagship Opus</b></h2><p><a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a> posts major gains over its predecessor, <a href="https://www.anthropic.com/news/claude-sonnet-4-6">Sonnet 4.6</a>, across every evaluation Anthropic disclosed. On <a href="https://www.swebench.com/">SWE-bench Pro</a>, an agentic coding benchmark, Sonnet 5 scores 63.2% compared with Sonnet 4.6's 58.1% — a jump that brings it within striking distance of Opus 4.8's 69.2%. On <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a>, another coding evaluation, the gap narrows further: 80.4% for Sonnet 5 versus 67.0% for Sonnet 4.6 and 82.7% for Opus 4.8.</p><p>In multidisciplinary reasoning, as measured by <a href="https://agi.safe.ai/">Humanity's Last Exam</a>, Sonnet 5 scores 43.2% without tools and 57.4% with tools — the latter figure essentially matching Opus 4.8's 57.9%. On computer use tasks evaluated through OSWorld-Verified, Sonnet 5 reaches 81.2%, up from 78.5%. And on <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2</a>, a knowledge-work benchmark, it scores 1,618 — surpassing Opus 4.8's 1,615 and far exceeding Sonnet 4.6's 1,395.</p><p>The pattern across these evaluations tells a consistent story: <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a> doesn't merely inch forward from its predecessor. It vaults into a performance tier that overlaps substantially with Anthropic's flagship model, while costing roughly 60% less per token at standard pricing and even less during the introductory period.</p><h2><b>Enterprise partners say Sonnet 5's agentic AI capabilities finish jobs that previous models abandoned</b></h2><p>The emphasis on agentic capabilities — the ability to plan, use tools like browsers and terminals, and execute multi-step workflows autonomously — reflects where the AI industry's center of gravity has shifted in 2026. Enterprises are no longer simply asking chatbots questions; they are deploying AI systems that can navigate complex software environments, execute multi-step coding tasks, and operate with minimal human supervision.</p><p>Early access partners painted a picture of a model that doesn't just start tasks but finishes them. Sualeh Asif, co-founder of Cursor, the AI-powered code editor that has become a bellwether for developer tool adoption, said that "with Claude Sonnet 5, agents stay on plan, follow our conventions, and ship clean multi-step changes, all at an efficient cost." Daniel Shepard, a senior engineer at Zapier, described handing the model a two-part automation job — updating Salesforce account tiers and sending a launch announcement — that "used to stall halfway" with previous models but now completes end to end.</p><p>These testimonials matter because they describe exactly the kind of reliability gap that has kept many enterprises from moving agentic AI from pilot programs to production deployments. A model that gets 80% of the way through a complex task before stalling creates more problems than it solves; one that reliably completes the full workflow changes the economics of automation. Anthropic also introduced cost-performance curves showing that developers can now adjust effort levels across <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a> and <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a> to find the optimal balance of cost and accuracy for their specific use case — a granularity that reflects growing sophistication in how enterprises consume AI services.</p><h2><b>An updated tokenizer boosts Sonnet 5 performance but could quietly raise costs for some workloads</b></h2><p>One technical detail <a href="https://www.anthropic.com/news/claude-sonnet-5">buried in the announcement's footnotes</a> deserves attention: Sonnet 5 uses an updated tokenizer that changes how the model processes text, similar to the change Anthropic introduced with Opus 4.7.</p><p>The tradeoff is that the same input can map to roughly 1.0 to 1.35 times as many tokens depending on content type. Anthropic says the introductory pricing is calibrated to make the transition "roughly cost-neutral," but enterprise customers running high-volume workloads will want to benchmark their specific use cases carefully before assuming their bills won't change.</p><h2><b>Anthropic says Sonnet 5 is safer than its predecessor, but its most capable models still lead on alignment</b></h2><p>Anthropic's safety disclosures reveal a nuanced picture. The company reports that <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a> shows lower rates of hallucination and sycophancy than <a href="https://www.anthropic.com/news/claude-sonnet-4-6">Sonnet 4.6</a>, is better at refusing malicious requests, and is more resistant to prompt injection attacks in agentic contexts. On Anthropic's automated behavioral audit — which tests for a wide range of misaligned behaviors including cooperation with misuse and deception — Sonnet 5 scored lower (meaning safer) overall than Sonnet 4.6.</p><p>However, Sonnet 5 showed "somewhat higher rates of misaligned behavior" compared with the more capable <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a> and Anthropic's <a href="https://www.anthropic.com/claude/mythos">Claude Mythos Preview</a>, the company's powerful but tightly restricted cybersecurity-focused model. On a Firefox 147 exploit development evaluation created in collaboration with Mozilla, neither Sonnet model could develop a working exploit — both scored 0.0% — though Sonnet 5 showed a slightly higher partial success rate (13.2%) than Sonnet 4.6 (8.8%). Both remain far below Opus 4.8 (68.8% working exploits) and Mythos 5 (88.4%).</p><p>Because of these incremental gains in cyber-adjacent capabilities, Anthropic launched Sonnet 5 with cyber safeguards enabled by default — real-time systems that detect and block dangerous cybersecurity usage. The safeguards mirror those on Opus 4.7 and 4.8 but are less restrictive than those applied to <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Fable 5</a>, the latest Mythos-class model that <a href="https://www.bloomberg.com/news/videos/2026-06-10/the-opening-trade-6-10-2026-video">Bloomberg reported</a> on June 10 is "blocked from responding to queries related to cybersecurity and biology." Organizations enrolled in <a href="https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude">Anthropic's Cyber Verification Program</a> automatically receive the same access on Sonnet 5 without needing to reapply.</p><h2><b>From $14 billion to $47 billion in revenue: Sonnet 5 arrives as Anthropic's IPO narrative takes shape</b></h2><p>The <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a> launch arrives at what may be the most consequential moment in Anthropic's short history. The company confidentially filed its IPO prospectus with the SEC in early June, setting up what CNBC has described as "<a href="https://www.cnbc.com/2026/06/05/tech-download-anthropic-ipo-ai-valuations.html">the most scrutinized public offering in tech history</a>."</p><p>The financial trajectory has been extraordinary. In February, Anthropic raised $30 billion at a <a href="https://www.anthropic.com/news/anthropic-raises-30-billion-series-g-funding-380-billion-post-money-valuation">$380 billion valuation</a>, with the company reporting $14 billion in annualized revenue that had "grown more than tenfold in each of the past three years," as <a href="https://www.theguardian.com/technology/2026/feb/12/anthropic-funding-round">The Guardian reported</a>. </p><p>By late May, Anthropic had closed a <a href="https://www.anthropic.com/news/series-h">$65 billion Series H round at a $965 billion</a> post-money valuation — co-led by Altimeter Capital, Sequoia Capital, and others — with a revenue run rate that had crossed $47 billion. Harrison Rolfes, an analyst at PitchBook, <a href="https://www.cnbc.com/2026/06/05/tech-download-anthropic-ipo-ai-valuations.html">told CNBC</a> that the number that will "either validate or collapse the entire narrative the private markets have been pricing for three years" won't be the valuation or revenue, but gross margin — a figure no outside observer has yet seen.</p><p>In this context, <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a> serves a dual purpose. For developers, it offers genuine capability improvements at competitive prices. For Anthropic's IPO narrative, it demonstrates the company can deliver a compelling product at a price tier that could drive the kind of broad adoption Wall Street rewards — high-volume, recurring API revenue from thousands of enterprise customers.</p><h2><b>Government deals and growing competition define the market Sonnet 5 enters</b></h2><p>The timing also aligns with Anthropic's aggressive push into institutional contracts. Just yesterday, California Governor Gavin Newsom announced a first-of-its-kind partnership providing <a href="https://www.gov.ca.gov/2026/06/29/governor-newsom-announces-a-first-of-its-kind-partnership-providing-anthropic-tools-to-state-agencies-and-improving-services-for-californians/">Claude to all state agencies at a 50% discount</a>, with free workforce training.</p><p>Kate Jensen, Anthropic's Head of Americas, called it an effort to "put Claude to work for the people who keep this state running." The deal — which extends to California's cities and counties — represents exactly the kind of durable, recurring adoption that could anchor revenue well beyond the developer community.</p><p>But Anthropic's release lands in an increasingly crowded field. OpenAI, which <a href="https://openai.com/index/accelerating-the-next-phase-ai/">raised a $122 billion round in March</a> at an $852 billion valuation, is pursuing its own IPO. Elon Musk's SpaceX, which merged with xAI, priced its IPO at <a href="https://www.cnbc.com/2026/06/03/spacex-ipo-stock-price-roadshow-musk.html">$135 per share with a $1.77 trillion valuation</a>. Google, Meta, and a growing wave of well-funded competitors — including Asian AI startups that, as the Wall Street Journal has reported, are developing Mythos-like cybersecurity capabilities — are all vying for the same enterprise market.</p><p>Gil Luria, head of technology research at D.A. Davidson, told CNBC that while Anthropic "<a href="https://www.cnbc.com/2026/06/05/tech-download-anthropic-ipo-ai-valuations.html">appears to have the lead</a>" in frontier AI models, "much of their current usage is for trials and experimentation and that may not sustain." That observation cuts to the heart of the challenge facing every frontier AI lab: converting experimental developer usage into durable, production-grade revenue.</p><h2><b>The real test for Sonnet 5 isn't benchmarks — it's whether cheaper AI can sustain a trillion-dollar story</b></h2><p>Sonnet 5's positioning — offering near-Opus performance at Sonnet prices — is a direct play for that conversion. Enterprise customers experimenting with expensive Opus-class models may find that Sonnet 5 delivers sufficient quality for production workloads at a price point that finance teams can approve at scale. If it works, it could accelerate the shift from experimentation to deployment that every AI company needs to justify its valuation.</p><p>Three things will determine whether <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a> matters beyond the initial benchmark charts. Real-world agentic reliability is the first: benchmarks measure capability, but production deployments measure consistency, and the true test will come when thousands of developers push the model through messy, unpredictable workflows at scale.</p><p>The tokenizer economics are the second: the updated tokenizer's 1.0 to 1.35x token expansion could quietly erode the pricing advantage for certain workloads, and enterprise customers should run their own cost analyses rather than relying on headline per-token prices. The third is the IPO narrative itself: when Anthropic's S-1 eventually becomes public, investors will scrutinize whether the Sonnet tier — cheaper but high-volume — or the Opus tier — expensive but high-margin — drives the bulk of revenue and, critically, gross profit.</p><p>As <a href="https://www.cnbc.com/2026/06/05/tech-download-anthropic-ipo-ai-valuations.html">PitchBook's Rolfes told CNBC</a>, the 2026 IPO window "either becomes the most consequential IPO cycle since the dot-com era or the most expensive lesson in narrative-versus-fundamentals that public markets have ever taught."</p><p>Anthropic is betting that a model good enough to rival its flagship and cheap enough to run at scale is the product that closes the gap between those two outcomes. The public markets will soon decide whether they agree.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meituan open sources LongCat-2.0, the 1.6T, near-frontier agentic coding model that's been leading OpenRouter — trained entirely on Chinese chips]]></title>
<description><![CDATA[A few hours ago, Chinese delivery app company Meituan officially unveiled LongCat-2.0 on GitHub, Hugging Face, and its native platform, unmasking the model as the computational engine behind "Owl Alpha," the anonymous stealth model that has spent the last two months commanding global developer ch...]]></description>
<link>https://tsecurity.de/de/3634858/it-nachrichten/meituan-open-sources-longcat-20-the-16t-near-frontier-agentic-coding-model-thats-been-leading-openrouter-trained-entirely-on-chinese-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634858/it-nachrichten/meituan-open-sources-longcat-20-the-16t-near-frontier-agentic-coding-model-thats-been-leading-openrouter-trained-entirely-on-chinese-chips/</guid>
<pubDate>Tue, 30 Jun 2026 09:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A few hours ago, Chinese delivery app company <a href="https://longcat.chat/blog/longcat-2.0/">Meituan officially unveiled LongCat-2.0 </a>on <a href="https://github.com/meituan-longcat/LongCat-2.0">GitHub</a>, <a href="https://huggingface.co/meituan-longcat/LongCat-2.0/blob/main/LICENSE">Hugging Face</a>, and its native platform, unmasking the model as the computational engine behind "Owl Alpha," the anonymous stealth model that has spent the last two months commanding global developer charts on OpenRouter. </p><p>Developed to fundamentally disrupt closed-source enterprise dominance in autonomous software engineering, the 1.6-trillion-parameter Mixture-of-Experts (MoE) system brings a native 1-million-token context window to the public domain under a highly permissive, enterprise grade, commercially viable MIT license. </p><p>Commercial access to the architecture introduces a highly aggressive pricing tier, deploying a mechanism where all context-cache hits are processed completely<i> free of charge</i>, running alongside a time-limited "<a href="https://longcat.chat/platform/docs/TokenPack.html">Token Pack</a>" flash-sale paradigm. There's also a typical <a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">"pay-as-you-go" API</a> for non-cache hits standard priced at $0.75/$2.95 per million tokens in/out.</p><p>However, a limited-time promotional discount aggressively slashes these operational expenditures down to $0.30 per million tokens for uncached input and $1.20 per million tokens for output, both on the cheaper-end of top performing models globally. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p><b>LongCat-2.0 — limited-time promo</b></p></td><td><p><b>$0.30</b></p></td><td><p><b>$1.20</b></p></td><td><p><b>$1.50</b></p></td><td><p><b></b><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html"><b>LongCat</b></a><b></b></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>LongCat-2.0 — standard</b></p></td><td><p><b>$0.75</b></p></td><td><p><b>$2.95</b></p></td><td><p><b>$3.70</b></p></td><td><p><b></b><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html"><b>LongCat</b></a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot AI</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$1.00</p></td><td><p>$6.00</p></td><td><p>$7.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>What makes the release a definitive inflection point for global tech infrastructure is its operational independence: the massive model was trained entirely on a cluster of over 50,000 domestic Chinese Application-Specific Integrated Circuits (ASICs), proving that near-frontier AI models can be scaled successfully without relying on the typical U.S. Nvidia GPUs that have, to date, powered much of the global generative AI frontier model training effort. </p><p>This successful deployment of alternative silicon signals a profound structural shift. If Chinese conglomerates can consistently iterate trillion-parameter architectures using homegrown ASICs rather than general-purpose GPUs, it would seem to threaten Nvidia's dominance in this sector. </p><p>Crucially, this technological pivot arrives precisely as Washington pressures top-tier American labs to restrict access to their latest models. Following a U.S. governmental request,<a href="https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov"> OpenAI was forced to limit access to its new GPT-5.6 models</a>, while Anthropic was previously also <a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do">ordered by the U.S. </a>to restrict access to its latest Claude Fable 5 / Mythos 5 models, which it took entirely offline in response. At the same time, a growing chorus of <a href="https://www.axios.com/2026/06/29/trump-ai-model-release-delays-tech-backlash">technologists</a>, <a href="https://thehill.com/policy/technology/5925364-ai-regulation-anthropic-trump-administration/">activists</a>, and industry experts warn that these defensive regulatory maneuvers have inadvertently backfired. By locking down Western closed-source models and driving up API costs, the U.S. government has left a wide operational window for global developers seeking affordable, high-performance alternatives like those found in Chinese open source models such as Meituan LongCat-2.0.</p><p>The raw operational metrics backed up the developer enthusiasm: during its unbranded residency on <a href="https://openrouter.ai/openrouter/owl-alpha">OpenRouter, Owl Alpha</a> accounted for approximately 10.1 trillion monthly tokens—averaging 559 billion tokens per day—representing a 242% month-over-month explosion in volume that propelled it into the platform's global top three.</p><p>By the time Meituan stepped forward to claim the architecture, the model had already secured the top ranking on the Hermes Agent workspace, second place on Claude Code deployments, and third place across international OpenClaw environments.</p><h2><b>Technology: Engineering the 1M-Token Sparse Context</b></h2><p>At the core of LongCat-2.0 lies an aggressive optimization of Mixture-of-Experts (MoE) sparsity, scaling total parameters to 1.6 trillion while limiting active computation to an average of 48 billion parameters per token.</p><p>Depending on the structural complexity of a query, the model’s dynamic activation ranges from 33 billion to 56 billion parameters. This design implements a "Zero-Compute Experts" framework, ensuring that routine execution elements pass through lighter subnetworks, entirely eliminating the idle computational overhead that typically penalizes ultra-dense models.</p><p>To sustain a functional 1-million-token context window without incurring catastrophic hardware bottlenecks, Meituan introduced LongCat Sparse Attention (LSA). Designed as an evolutionary iteration of DeepSeek Sparse Attention, LSA resolves the quadratic scoring costs and memory fragmentation that typically plague fine-grained sparse mechanisms through three distinct, orthogonal vectors:</p><ul><li><p><b>Streaming-aware Indexing (SI):</b> This system restructures the token selection pipeline by blending hardware-aligned contiguous data reads with dynamic random selection. By converting fragmented memory access into highly predictable, sequential blocks, the system achieves coalesced High Bandwidth Memory (HBM) utilization and elevated effective bandwidth.</p></li><li><p><b>Cross-Layer Indexing (CLI):</b> Leveraging the empirical reality that attention saliency remains highly stable across adjacent hidden layers, CLI amortizes calculation costs. A single indexing pass successfully guides multiple consecutive layers during inference, a capability reinforced by cross-layer distillation throughout the training phase.</p></li><li><p><b>Hierarchical Indexing (HI):</b> This approach applies a coarse-to-fine, two-stage scoring layout. The indexer performs a rapid, approximate block-level recall to filter candidates, before running fine-grained token selection exclusively on the remaining population.</p></li></ul><p>Furthermore, Meituan integrated an N-gram Embedding module inherited from its lighter model lines. By expanding parameter allocation in sparse dimensions completely orthogonal to the MoE expert layout, the architecture appends 135 billion parameters to a 5-gram token combination framework. </p><p>This expands the core embedding space by roughly 100-fold, allowing the model to capture dense local token relationships and accelerate large-batch inference operations by reducing memory Input/Output (I/O) bottlenecks.</p><h2><b>Product: Post-Training, MOPD Framework and Benchmark Performance</b></h2><p>While generalist large language models prioritize fluid, conversational interfaces, LongCat-2.0 focuses explicitly on multi-step engineering tasks, tool integration, and automated repository manipulation — agentic tasks, in other words. </p><p>In standardized assessments, LongCat-2.0 registers an empirical 59.5 on SWE-bench Pro, surpassing GPT-5.5's benchmark of 58.6. The model further establishes its agentic specialization by marking a 70.8 on Terminal-Bench 2.1, a 77.3 on SWE-bench Multilingual, and a 73.2 on the general corporate workflow simulator FORTE.</p><p>This precise operational behavior is achieved through a structural post-training layer called Multi-Teacher Optimization via Mixture of Specialized Experts (MOPD). Rather than blending raw human feedback into a singular reward function, the MOPD architecture segregates post-training optimization into three independent, highly focused expert clusters.</p><ul><li><p>The <b>Agent Experts</b> are fine-tuned strictly for structural execution, specializing in precise tool invocation, multi-turn API parameter parsing, and self-correcting loop mechanisms to avoid execution stagnation.</p></li><li><p>The <b>Reasoning Experts</b> are optimized in isolation to advance multi-hop logic, complex chain-of-thought engineering, mathematics, and high-level STEM problem-solving.</p></li><li><p>The <b>Interaction Experts</b> focus entirely on human alignment, instruction-following nuances, factual grounding to suppress hallucinations, and maintaining rigid safety guardrails without diminishing the model's overall utility.</p></li></ul><p>By segregating these vectors during post-training, LongCat-2.0 prevents functional degradation. A dynamic gate-routing mechanism then seamlessly fuses these specialized behaviors at runtime, allowing the final model to coordinate deep reasoning, stable tool execution, and safe user interaction simultaneously</p><p>While LongCat-2.0 generally trails premium frontier systems like Claude Opus 4.8 across broad general-agent benchmarks such as FORTE and BrowseComp, it explicitly punches above its weight in software engineering. </p><p>What makes this open-weight architecture special is its hyper-focus on autonomous development; it manages to narrowly exceed OpenAI's proprietary GPT-5.5 on the rigorous software engineering benchmark SWE-bench Pro (scoring 59.5 against 58.6), proving it is highly capable and fiercely competitive for complex coding tasks despite a leaner computational footprint.</p><h2><b>Commercial Framework: Pay-As-You-Go vs. Flash-Sale Token Packs</b></h2><p>Meituan's deployment strategy introduces a specialized commercial model that splits network access between conventional real-time API billing and structured "Token Packs". </p><p>For traditional enterprise integration, standard top-up accounts are available, deducting operational capital in real time based directly on token input and generation metrics.</p><p>However, to accommodate the unpredictable compute bursts characteristic of autonomous development agents, Meituan launched a structured Token Pack framework. Purchased as fixed, one-time volumetric allocations valid for a strict 30-day window, these packages stack directly on top of an organization's existing baseline API account. </p><p>To manage network load across its ASIC clusters, Meituan releases these high-volume packages via limited flash sales four times daily, precisely at 10:00, 16:00, 21:00, and 23:00 Beijing Time on a first-come, first-served basis.The economic standout of this framework is the zero-charge processing of context cache hits. </p><p>In massive agentic environments where a coding assistant must repeatedly read, reference, and modify the same multi-million-token code repository over an extended session, standard architectures penalize developers by charging full pricing for repeated input context. </p><p>Under Meituan's infrastructure, only cache-miss inputs and final token generations consume the package quota. This architecture completely alters the operational cost economics of large-scale agent software development, enabling deep iterative context exploration without compounding costs.</p><h2><b>Licensing: Open-Source Structural Freedom</b></h2><p>By registering the LongCat-2.0 repository under the open-source MIT License, Meituan positions the architecture with maximum legal flexibility for enterprise integration. </p><p>In contrast to copyleft paradigms like the GNU General Public License (GPL)—which legally obligates developers to open-source any derivative frameworks or internal software that links to the code—the MIT license permits near-unrestricted freedom.</p><p>For corporate engineering teams, this legal standard ensures that LongCat-2.0 can be deeply modified, compiled, and hard-coded directly into closed-source commercial applications, proprietary dev tools, and internal automation backends. </p><p>Corporations can fork the repository, optimize the internal LSA mechanisms for private databases, and sell the resulting software stack to end users without any obligation to disclose their proprietary intellectual property or structural enhancements.</p><h2><b>Meituan's Evolution: From Delivery Super App to AI Powerhouse</b></h2><p>Founded in March 2010 by serial entrepreneur <a href="https://www.howtheybegan.com/founders/wang-xing">Wang Xing</a>, Meituan initially launched as a Groupon-style daily deals website before rapidly evolving into one of China’s dominant “super apps”. </p><p>Following a massive 2015 merger with Dianping, the Beijing-based tech giant solidified a dominant market share over the country's urban delivery corridors, bridging local consumer reviews, instant retail, hotel bookings, and food delivery. Operating as a publicly traded powerhouse on the Hong Kong Stock Exchange, Meituan claims over 770 million annual transacting users and supports a network of more than 14.5 million merchants. </p><p>However, faced with intense domestic market competition, severe margin compression, and a sliding profit margin, the company aggressively pivoted its strategy beyond logistics. Meituan publicly committed to investing "billions" into artificial intelligence and domestic chip capabilities to revitalize its technology-driven offerings. </p><p>This strategic shift into the global AI race began materializing in late 2025 with the release of LongCat-Flash, a 560-billion-parameter Mixture-of-Experts foundation model, followed quickly by the advanced reasoning model LongCat-Flash-Thinking. By open-sourcing these frontier-class models under enterprise-friendly licenses, Meituan signaled its ambition to become a foundational player in global AI infrastructure rather than remaining strictly a regional e-commerce and delivery giant. </p><h2><b>Enterprise Implications: Autonomous Operational Workflows</b></h2><p>For modern enterprises, the release of LongCat-2.0 unlocks clear operational strategies across software engineering, system operations, and long-form data interpretation. </p><p>The combination of an open-weight, MIT-licensed model with an expansive 1-million-token context window means organizations can bypass the data privacy concerns and recurring overhead associated with hosting proprietary third-party APIs.In large-scale enterprise development environments, teams can leverage the model's specialized Agent Experts to orchestrate autonomous codebase migrations. </p><p>Instead of dedicating hundreds of developer hours to manually rewriting legacy application frameworks, engineers can pass an entire enterprise repository along with modern SDK documentation directly into the 1-million-token context window. LongCat-2.0 can map the dependencies, execute the repository-level structural updates, compile the new codebase, and catch compilation and execution bugs autonomously within local sandbox environments before generating a final pull request.</p><p>The model's architectural separation via the MOPD gate-routing mechanism yields significant advantages for strict enterprise compliance. By routing specific operational queries through isolated expert clusters, a financial institution or healthcare firm can deploy deep logic and mathematical reasoning passes without risking factual hallucination or violating strict safety bounds. </p><p>The Interaction Experts function as an implicit guardrail layer, suppressing errors and enforcing instruction-following protocols without degrading the raw processing power of the internal Reasoning Experts. Combined with the zero-cost caching model, enterprises can maintain hyper-focused autonomous software networks that can repeatedly inspect corporate data pools, continuously maintaining and optimizing internal infrastructure at a fraction of standard operational costs.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA]]></title>
<description><![CDATA[Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by...]]></description>
<link>https://tsecurity.de/de/3634705/it-security-nachrichten/ukraine-makes-history-with-first-83m-seized-crypto-transfer-to-arma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634705/it-security-nachrichten/ukraine-makes-history-with-first-83m-seized-crypto-transfer-to-arma/</guid>
<pubDate>Tue, 30 Jun 2026 08:22:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Seized Crypto Assets" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Seized-Crypto-Assets-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA 1"></p><div class="qMYqUG_convSearchResultHighlightRoot">
<div class="" data-turn-id-container="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-6" data-is-intersecting="true"><section class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn-id="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-6" data-turn-id-container="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-6" data-testid="conversation-turn-14" data-turn="assistant">
<div class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)">
<div class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content="">
<div class="flex max-w-full flex-col gap-4 grow">
<div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;]:mt-1" dir="auto" tabindex="0" data-message-author-role="assistant" data-message-id="555dfcf9-25cf-4be4-b837-1f783563af3f" data-message-model-slug="gpt-5-5" data-turn-start-message="true">
<div class="flex w-full flex-col gap-1 empty:hidden">
<div class="markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling">
<p data-start="667" data-end="1157"><a href="https://thecyberexpress.com/?s=Ukraine" target="_blank" rel="nofollow noopener">Ukraine</a> has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an <a href="https://thecyberexpress.com/doj-indicts-alleged-qakbot-malware/" target="_blank" rel="noopener">international hacking group</a> accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States.</p>
<p data-start="1159" data-end="1385">According to Ukrainian authorities, the transferred <a href="https://thecyberexpress.com/cryptocurrency-mixing-service-bitcoin-seized/" target="_blank" rel="noopener">cryptocurrency</a> is valued at more than 372 million hryvnias and represents a milestone in the country's efforts to manage digital assets linked to criminal investigations.</p>

<h3 data-section-id="cfu7r9" data-start="1387" data-end="1446"><strong><span role="text">Seized Crypto Assets Moved to ARMA After Court Order</span></strong></h3>
<p data-start="1448" data-end="1654">The State Bureau of Investigation said the transfer was completed as part of an ongoing criminal investigation conducted in cooperation with the DVB of the National Police and U.S. law enforcement agencies.</p>
<p data-start="1656" data-end="1899">Investigators determined that the virtual assets were stored in <a href="https://thecyberexpress.com/tools-to-prevent-breaches-in-e-wallets/" target="_blank" rel="noopener">crypto wallets</a> controlled by a member of the organized hacking group. Following a court order, more than 8.3 million USDT was transferred to ARMA's official crypto wallet.</p>
<p data-start="1901" data-end="2131">Authorities <a href="https://dbr.gov.ua/news/dbr-zabezpechilo-peredachu-v-upravlinnya-arma-areshtovanih-kriptoaktiviv-na-ponad-372-mln-griven" target="_blank" rel="nofollow noopener">said</a> this is the first practical case in Ukraine where seized digital assets have been transferred to ARMA for management, demonstrating the country's ability to handle new categories of assets within the legal system.</p>

<h3 data-section-id="18qo9rh" data-start="2133" data-end="2201"><strong>Investigation Links Cryptocurrency to International Hacking Group</strong></h3>
<p data-start="2203" data-end="2385">According to investigators, members of the international hacking group carried out large-scale <a href="https://thecyberexpress.com/?s=cyberattacks" target="_blank" rel="noopener">cyberattacks</a> against individuals and companies in Europe and the United States.</p>
<p data-start="2387" data-end="2610">The investigation alleges the group stole confidential information, demanded ransom payments, and laundered criminal proceeds in Ukraine through the purchase of residential properties, vehicles, and other high-value assets.</p>
<p data-start="2612" data-end="2711">Authorities estimate that the criminal group's activities caused losses exceeding $100 million.</p>
<p data-start="2713" data-end="2849">As part of the pre-trial investigation, four members of the group, including its alleged organizer, were detained and placed in custody.</p>

<h3 data-section-id="172frqj" data-start="2851" data-end="2892"><strong>More Than $11 Million in Assets Seized</strong></h3>
<p data-start="2894" data-end="3047">The investigation resulted in the <a href="https://thecyberexpress.com/bitcoin-queen-convicted-in-uk/" target="_blank" rel="noopener">cryptocurrency seizure </a>and the confiscation of additional assets with a combined value exceeding $11.1 million.</p>
<p data-start="3049" data-end="3269">According to the State Bureau of Investigation, the seized property includes residential buildings, apartments, vehicles, approximately $1 million in cash, and digital assets <a href="https://arma.gov.ua/en/news/typical/arma-vpershe-priynyalo-v-upravlinnya-areshtovani-kriptoaktivi-na-gamanets-agentstva-nadiyshlo-ponad-83-mln-usdt" target="_blank" rel="nofollow noopener">equivalent to more than $8.3 million</a>.</p>
<p data-start="3271" data-end="3375">The Office of the Prosecutor <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28877">General</a> is providing procedural oversight for the criminal proceedings.</p>

<h3 data-section-id="1ow5zh5" data-start="3377" data-end="3434"><strong>Authorities Plan to Convert Crypto Into Military Bonds</strong></h3>
<p data-start="3436" data-end="3580">The State Bureau of Investigation said that after converting the cryptocurrency into fiat currency, authorities plan to purchase military bonds.</p>
<p data-start="3582" data-end="3778">According to the agency, the initiative is intended to support Ukraine's economy during martial law while ensuring that assets obtained through criminal activity are redirected for state purposes.</p>
<p data-start="3780" data-end="3938">Officials described countering transnational <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28876">cybercrime</a> and ensuring effective mechanisms for the seizure and management of criminal assets as key priorities.</p>

<h3 data-section-id="xzz3x2" data-start="3940" data-end="3980"><strong>ARMA Expands Digital Asset Management</strong></h3>
<p data-start="3982" data-end="4103">ARMA said receiving the cryptocurrency marks an important step in the evolution of Ukraine's asset management system.</p>
<p data-start="4105" data-end="4358">The agency stated that the successful transfer reflects coordinated efforts between the State Bureau of Investigation and the Office of the Prosecutor General, enabling the execution of the court's decision and preserving the value of the seized assets.</p>
<p data-start="4360" data-end="4599">ARMA added that it is continuing to develop mechanisms for managing all categories of seized property, including real estate, corporate rights, and virtual assets, to ensure their preservation in the interests of the state and society.</p>
<p data-start="4601" data-end="4877" data-is-last-node="" data-is-only-node="">The agency said the case demonstrates that as cybercriminals increasingly use digital technologies to conceal illicit proceeds, authorities must also strengthen their ability to manage and preserve cryptocurrency and other digital assets seized during criminal investigations.</p>

</div>
</div>
</div>
</div>
</div>
</div>
</section></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oh, behave! How Gemini can reshape the web for the way you work]]></title>
<description><![CDATA[Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.



Sure, services like Google’s Gemini and its contemporaries can be useful in certain limited, specific areas for productivity purposes. But working with them can also be pre...]]></description>
<link>https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</guid>
<pubDate>Mon, 29 Jun 2026 13:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.</p>



<p>Sure, services like Google’s Gemini and its contemporaries <a href="https://www.computerworld.com/article/4007736/gemini-android.html">can be useful</a> in <a href="https://www.computerworld.com/article/3845447/google-workspace-how-to-use-gemini-ai-side-panel.html">certain limited, specific areas</a> for productivity purposes. But working with them can also be pretty disheartening and overwhelming — from <a href="https://www.computerworld.com/article/4047909/burned-out-by-bots-prompt-fatigue-in-workplace.html">prompt fatigue</a> and an onslaught of <a href="https://www.cio.com/article/4077448/ai-workslop-the-new-productivity-killer-only-training-can-stop.html" target="_blank">AI workslop</a> to the fear of <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html">lost jobs</a> and even just the simple <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">inconsistencies and inaccuracies</a> these systems are <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">so prone to providing</a>. (And that’s to say nothing of <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">the ever-increasing creepy factor</a> that often accompanies this type of technology.)</p>



<p>More and more, it seems the most significant impact of these systems is in <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">areas like coding</a>, where AI is allowing ambitious tech-heads to <a href="https://www.fastcompany.com/91528164/claude-code-vibe-code-word-processor" target="_blank" rel="noreferrer noopener">create their own custom programs</a> with limited to no programming knowledge (but <a href="https://www.fastcompany.com/91345791/vibecoding-replit-debugging-claude" target="_blank" rel="noreferrer noopener">a <em>lot</em> of time, vision, and patience</a>) — as well as allowing accomplished coders to produce products more quickly by letting AI do the dirty work and then spending <em>their</em> time <a href="https://www.computerworld.com/article/4066260/why-we-need-human-developers.html">guiding, tweaking, and correcting its output</a>.</p>



<p>That’s all well and good, but the reality is that most of us mere mortals are never gonna mess with anything that daunting. That doesn’t, however, mean we can’t enjoy a slice of the custom-coding pie and the productivity advantages it offers — on a much simpler but still supremely useful level.</p>



<p>The average-worker answer lies in an oft-overlooked middle-ground possibility these AI chatbots possess to help us create relatively basic but extremely high-potential custom browser extensions. As their name suggests, these simple little programs run entirely in your browser — the same exact sorts of add-ons you’d typically find and install in a marketplace like <a href="https://chromewebstore.google.com/" target="_blank" rel="noreferrer noopener">Google’s Chrome Web Store</a>.</p>



<p>But with Gemini or any other similar genAI platform, you can dream up your <em>own </em>web-improving extension and turn it into reality in a matter of minutes — simply by describing your goal and then guiding the AI gently along the way. And given how much time most of us spend on the web these days, that opens up a tantalizing series of doors for taking total control of your work environment.</p>



<p>Hate all the extraneous bells and whistles gunking up the Google Docs interface? Gemini can create a Chrome extension that removes them. Annoyed by a glitchy web app? Ask Gemini for an extension that makes some under-the-hood improvements. The possibilities are endless.</p>



<p>Let me show you how exactly it works, how easy it is to approach and master, and how many work-enhancing possibilities are out there just waiting to be created.</p>



<h2 class="wp-block-heading"><a></a>The ins and outs of Gemini’s custom Chrome extensions</h2>



<p>First things first: You don’t need any special tools or subscriptions to make this happen. For the purposes of this article, we’ll focus on Google’s Gemini for the creation and the standard desktop Chrome browser for the installation — but the same basic process would work with most any AI chatbot, if you happen to prefer ChatGPT or Claude, as well as with any extension-supporting, <a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium-compatible browser</a> (a list that includes everything from Microsoft Edge to Brave, <a href="https://www.computerworld.com/article/4148888/8-advanced-ways-vivaldi-boosts-your-productivity.html">Vivaldi</a>, and beyond).</p>



<p>Google offers a dizzying array of <a href="https://blog.google/products-and-platforms/products/google-one/google-ai-subscriptions/" target="_blank" rel="noreferrer noopener">Gemini modes and options</a> and an equally overwhelming series of <a href="https://gemini.google/subscriptions/" target="_blank" rel="noreferrer noopener">AI subscription plans</a> that control how much you can use those capabilities, but you don’t need to worry about any of that to create custom Chrome extensions. You might sometimes see better results if you switch your Gemini model to “Pro” or your Gemini <em>thinking level</em> to “Extended” — designations that even Gemini itself has trouble deciphering (believe me, I asked!) — but just using the default Gemini settings with a free Google account will generally work quite well.</p>



<p>Getting going with a custom Chrome extension is as simple as <a href="https://gemini.google.com/" target="_blank" rel="noreferrer noopener">opening up a new Gemini chat</a> and telling the system what you want it to cook up for you. The hardest part is deciding what you want and what’d be helpful for you — something we’ll explore more in a moment, via specific examples and suggestions. Once you’ve got that, you can just ask Gemini to create a Chrome extension that’ll accomplish what you’re envisioning, with as much specificity as possible about what it’ll do and how it’ll look.</p>



<p>Gemini will spit back a series of plain-text code chunks with instructions to copy each cluster and paste it into a new plain text file with a certain specific name — things like “manifest.json,” “content.js,” and “styles.css.” All you’ll do is use the on-screen button to copy each segment, then open up any simple text editor (like Windows Notepad, macOS TextEdit, or any number of <a href="https://browserpad.org/" target="_blank" rel="noreferrer noopener">simple online text editors</a>) and paste the text in, then save it under the name Gemini gives you.</p>



<p>You’ll need to put all the files into a single isolated folder on your computer, and then you can go into Chrome, type <strong>chrome:extensions </strong>into its address bar, and install your shiny new creation by:</p>



<ul class="wp-block-list">
<li>Flipping the toggle next to “Developer mode” in the upper-right corner of the screen into the on and active position, if it isn’t already</li>



<li>Clicking the “Load unpacked” button</li>



<li>And selecting the folder you just created in the pop-up that appears</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-01-chrome-extension-controls.jpg?quality=50&amp;strip=all&amp;w=1024" alt="chrome extension controls including developer mode toggle and load unpacked button" class="wp-image-4185233" width="1024" height="114" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Chrome’s “Developer Mode” toggle and “Load unpacked” button are the keys to importing any extension you create.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>And that’s pretty much it: No complicated compiling or program publishing — the extension you envisioned will be alive and working right in your browser and ready to use.</p>



<p>Now, odds are, it won’t be <em>exactly</em> what you wanted in its first iteration, and you’ll have to go back to Gemini to request several rounds of updates and corrections. Each time, Gemini will create a new set of code chunks, and you simply overwrite the text in each file with its corresponding new code chunk.</p>



<p>It’s still a bit of a process. But you’ll rarely spend more than an hour on something simple and maybe a few hours on something especially multifaceted and specific, and whatever you create will then work to your advantage indefinitely from that point onward, on any computer where you install it.</p>



<p>Before we dive into specific slivers of inspiration, let’s just note the hopefully obvious asterisk that this’ll work only if you’re <em>either </em>(a) using a personal computer that isn’t associated with an organization or (b) using a work-connected computer where custom Chrome extensions are permitted. In either scenario, you’ll want to use your own best judgment to ensure that whatever you’re adding into your browser won’t expose any corporate data or cause your IT comrades any alarm if they see you using it in your workday.</p>



<p>With most common examples, though — including all the ones we’re about to go over — you shouldn’t have any problem or cause for concern.</p>



<p>Capisce? Capisce. Let’s get into it.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #1: The interface fixer</h2>



<p>Our first custom Chrome extension category is the one that won me over to this practice initially and has been the most shapeshifting for my own browser-based workflow — and that’s the simple-seeming but transformational ability to have AI remake any web app you rely on to remove unneeded elements and redesign the interface to <em>your</em> exact specifications.</p>



<p>The best example I can show you is what I did with my completely homemade, Gemini-created Docs Zen extension. Google Docs, to put it mildly, has devolved into <a href="https://www.computerworld.com/article/1723650/google-docs-cheat-sheet-how-to-get-started.html#work">a cluttered mess</a>. There are so many on-screen elements I never use and, ironically enough, irrelevant AI elements I’d rather not have in my hair. I just want a calm, simple, minimalist environment for writing — with Google’s second-to-none syncing, universal access, and collaboration systems beneath it.</p>



<p>So rather than try to reinvent the wheel, I described to Gemini all the elements I wanted to remove from Docs and all the ways I wanted to rethink how its interface appeared for me.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-02-initial-prompt.jpg?quality=50&amp;strip=all" alt="prompt asking gemini to make a chrome extension called docs fixer that minimizes and simplifies the google docs interface" class="wp-image-4185238" width="1007" height="621" sizes="auto, (max-width: 1007px) 100vw, 1007px"><figcaption class="wp-element-caption"><p>My original request to Gemini, followed by rounds of expansions and revisions (and eventually also a more poetic name).</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I went back and forth with numerous iterations and kept coming up with interesting new additions to further flesh out and improve the experience — and I ended up with a delightful setup that gives me a distraction-free view of my writing space with a simple toggle to reveal the main Docs menus and a palette icon that allows me to switch from one eye-pleasing theme to another.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="620" height="161" sizes="auto, (max-width: 620px) 100vw, 620px"&gt;<figcaption class="wp-element-caption"><p>Google Docs with my custom Docs Zen extension — a true delight for daily writing.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>My setup deliberately doesn’t include comments or other collaborative elements, as I’m mostly writing by myself these days — but when I do need those elements, the eye icon in the upper-right corner of the screen disables my custom adjustments and takes me back to the standard Docs interface. I can then click the eye icon again in <em>that</em> environment to switch back.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-google-docs-toggle-620.gif" alt="animated screenshot of toggling between simplified and full google docs interface" class="wp-image-4185725" width="620" height="117" sizes="auto, (max-width: 620px) 100vw, 620px"><figcaption class="wp-element-caption"><p>My custom extension includes a simple on-off toggle for times when I need the full Docs setup.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I used Gemini to create something similar for <a href="https://www.computerworld.com/article/1712947/what-is-trello-a-guide-to-atlassians-collaboration-and-work-management-tool.html">Trello</a>, with which I also have a love-hate relationship — loving the foundational functions and easy access everywhere but hating the interface that’s <a href="https://www.computerworld.com/article/3832819/atlassian-refocuses-trello-on-individual-task-management.html">lost focus</a>, gained bloat, and gotten noticeably clunky and slow over time.</p>



<p>With the same sort of step-by-step, plain-English guidance, I was able to transform Trello from this…</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-05-trello-before.jpg?quality=50&amp;strip=all" alt="screenshot of busy default trello interface" class="wp-image-4185239" width="999" height="639" sizes="auto, (max-width: 999px) 100vw, 999px"><figcaption class="wp-element-caption"><p>Trello, in its typical current-day state.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>…into <em>this</em>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-06-trello-after.jpg?quality=50&amp;strip=all" alt="screenshot of trello interface simplified by custom chrome extension written by gemini" class="wp-image-4185234" width="997" height="641" sizes="auto, (max-width: 997px) 100vw, 997px"><figcaption class="wp-element-caption"><p>Trello, with my custom modifications in place.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I couldn’t even begin to recount the number of superfluous features and elements I’ve removed, along with revamping the overall interface to make it both more efficient and more visually pleasing to my eye.</p>



<p>Whether it’s a web app you rely on regularly or even just a website you open often, the possibilities are practically endless for the ways you can reshape it and mold it to make it work better <em>for you</em>.</p>



<p>Speaking of which…</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #2: The feature creator</h2>



<p>In addition to the surface-level adjustments and feature removals in my aforementioned Trello-enhancing extension, I also <em>added in </em>several components — such as one-click buttons for archiving or moving cards — and I managed to speed up the site by making some under-the-hood adjustments Gemini suggested when I asked about its choppy performance. The same sort of concept can apply to any web-based interface you’re using, if there are any options that are annoyingly buried within menus, shortcuts that’d make your life easier, or other improvements you’ve longed to see.</p>



<p>You can also consider some simple standalone extensions for giving yourself on-demand features that aren’t necessarily associated with any one specific website but could be useful in plenty of productivity scenarios. For instance:</p>



<ul class="wp-block-list">
<li>I do a fair amount of basic image editing and frequently find myself needing to reference a hex color code that corresponds with a particular brand color, and I always end up having to open up a new tab and look in a note somewhere to find the code I need. Well, no more: I used Gemini to create a super-simple custom color code pop-up where I can store all the colors I need and then copy any of ’em onto my clipboard with a single click. <em>Major </em>time-saver.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-07-color-palette.jpg?quality=50&amp;strip=all" alt="screenshot of color palette selector - a custom chrome extension created by gemini " class="wp-image-4185237" width="478" height="555" sizes="auto, (max-width: 478px) 100vw, 478px"><figcaption class="wp-element-caption"><p>All the color codes I need are now never more than a couple clicks away.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<ul class="wp-block-list">
<li>I’m also constantly converting time zones, either for meetings with clients or colleagues or for trying to wrap my head around publishing systems that insist on using random time zones with no meaning to me. It’s infinitely easier for me to manage now, thanks to the custom Chrome extension I made that shows the current time in all the zones I need most often — as well as allowing me to put any <em>other </em>time into any field and have all the other zones instantly adjust to match. It also offers a brilliant plain-text conversion box where I can just type things like “1pm-3pm PT in MT” and have it cough back up an instant answer for any conversion I need.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-08-time-zone-converter.jpg?quality=50&amp;strip=all" alt="screenshot of time zone converter  - a custom chrome extension created by gemini " class="wp-image-4185235" width="432" height="542" sizes="auto, (max-width: 432px) 100vw, 432px"><figcaption class="wp-element-caption"><p>My custom time zone conversion extension comes in handy countless times a day.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Maybe what you want is the ability to interact with data on different websites more easily — to be able to save any table on a page in front of you as a CSV file, mayhap, or even to save any text you highlight on a page into a new Google Docs document. Whatever the case may be, Gemini can handle it — and that superpower that you’ve always wished for but never found the right tool to make possible can actually now be yours.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #3: The browser expander</h2>



<p>Our final category of custom Chrome extensions to consider moves beyond the web itself and into your actual browser. The browser is essentially the modern-day desktop, after all — and for the first time now, you can expand and enhance it in all sorts of interesting ways.</p>



<p>Some specific examples, to get your brain-motor whirring:</p>



<ul class="wp-block-list">
<li>You could walk Gemini through creating a smart auto-snooze system for your open browser tabs, both to clear clutter and help with <a href="https://www.computerworld.com/article/1666806/easy-steps-to-make-chrome-faster-and-more-secure.html">Chrome’s performance</a>. It could save any tab that hasn’t been touched in a certain amount of time to your local storage and then give you a simple searchable “Archive Dashboard” where you can find all those auto-closed tabs and re-open ’em as needed.</li>



<li>With the right guidance, Gemini could give you a custom browser research panel — where any info you highlight on a page gets beamed over into a sidebar-style panel that serves as a running scratchpad of notes from the day.</li>



<li>Or, if you find yourself often needing to see two tabs together side by side, you could have Gemini cook up a custom extension that instantly detaches any tab in front of you and puts it into a new tab window in a perfectly sized and spaced pattern. One keyboard shortcut could make that move happen, while another keyboard shortcut could recombine the two tabs into a single centered window.</li>
</ul>



<p>As with all the other ideas we’ve gone over, all you’ve gotta do is ask — and now, with the right inspiration in mind, you’re ready to get your custom extension adventures going and start bending the web to <em>your</em> will.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a state-of-the-art development platform with Backstage]]></title>
<description><![CDATA[Key takeaways




Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.



Point-to-point ...]]></description>
<link>https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.</li>



<li>Point-to-point integrations become a maintenance burden. Many organizations end up with a “messy middle” where Backstage is connected directly to <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html" data-type="link" data-id="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html" data-type="link" data-id="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> tools through custom wiring that’s fragile and hard to evolve.</li>



<li>Abstractions are the interface between developers and infrastructure. Developers work with components, endpoints, and dependencies. Platform engineers work with environments, pipelines, and component types. The platform compiles both into Kubernetes resources.</li>



<li>A control plane bridges the gap. It sits between the portal and runtime, compiling abstractions into infrastructure, enforcing policies consistently, reconciling drift, and aggregating runtime state back to the portal.</li>



<li>Good abstractions enable advanced capabilities. Unified observability, automated guardrails, and AI agents that can reason about and act on your platform. All becomes possible when you have well-defined concepts and a control plane that understands both sides.</li>
</ul>



<p>…</p>



<h2 class="wp-block-heading">Start with Backstage</h2>



<p>If you’re building an <a href="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html" data-type="link" data-id="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html">internal developer platform</a>, Backstage is certainly part of your architecture. It solved the discovery problem and became the default choice for developer portals.</p>



<p>Before Backstage, developers navigated wikis, spreadsheets, and tribal knowledge just to find who owned a service or how to spin up a new one. Backstage brought structure: a unified catalog, a plugin ecosystem, and golden-path templates that actually got adopted.</p>



<p><a href="https://github.com/backstage/backstage" data-type="link" data-id="https://github.com/backstage/backstage">Backstage</a> is a Cloud Native Computing Foundation (CNCF) project with one of the most active contributor communities in the ecosystem. When organizations evaluate developer portals, Backstage is the starting point.</p>



<p>However, many teams discover something after deployment: Backstage provides a portal, not a platform. A portal organizes information. A platform owns execution: deployments, environments, policies, observability, and runtime operations.</p>



<p>Backstage assumes that the execution layer exists beneath it. That layer is where most of the complexity lives, and it’s what this article is about.</p>



<h2 class="wp-block-heading"><a></a>What a developer platform actually is</h2>



<p>A developer platform or an internal developer platform is a self-service framework you build to help developers build, deploy, and manage applications independently.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_01_developer_platform.png" alt="Image_01_developer_platform" class="wp-image-4189088" width="1024" height="307" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>Most organizations already have an organically grown version of this:</p>



<ul class="wp-block-list">
<li>Developer commits code</li>



<li>CI pipeline builds and pushes images to a registry</li>



<li>Pipeline updates a GitOps repo containing Helm charts or Kubernetes manifests</li>



<li>Argo CD or Flux syncs those manifests to clusters</li>
</ul>



<p>You may have this workflow running today. The question is whether it’s a pipeline stitched together with scripts and tribal knowledge, or a platform with consistent abstractions and self-service capabilities.</p>



<h2 class="wp-block-heading"><a></a>What usually happens after adopting Backstage</h2>



<p>How do you add Backstage to this setup? The common approach is for developers to maintain Backstage entity files (primarily component and API entities) alongside the source code. Then you configure the built-in entity provider in Backstage to scan source code repositories to populate the catalog. Eventually, you’ll end up with a portal with all your systems, components, APIs, and other resources. So far, so good.</p>



<p>Once developers start using the portal, you’ll be hit with a consistent flow of feature requests:</p>



<ul class="wp-block-list">
<li>“I see my component in the catalog, but is it actually running?” You configure the Kubernetes plugin and link components to their corresponding manifests. Now developers can see pod status, deployment state, and replica counts.</li>



<li>“I need logs, metrics, and traces related to my component.” You integrate your observability stack or developers context-switch to Grafana, Datadog, or whatever you’re running. Either way, more wiring.</li>



<li>“Can I create new components from here?” You build Backstage templates that scaffold repos with the right structure, Backstage entities, Helm charts, and CI pipelines, all of which encode your organization’s best practices. Now you’re maintaining golden paths in templates, separately from the runtime configuration that actually enforces them.</li>
</ul>



<p>Each request is reasonable and achievable, but they add up.</p>



<h2 class="wp-block-heading"><a></a>The messy middle</h2>



<p>Eventually, you end up with a platform held together by point-to-point connections. Every new capability requires new wiring. Every upgrade risks breaking something. You spend more time maintaining integrations than building features.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_02_messy_middle.png" alt="Image_02_messy_middle" class="wp-image-4189092" width="1024" height="893" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>You would never design a production system with this many point-to-point dependencies. Why accept it for your platform?</p>



<h2 class="wp-block-heading"><a></a>Treat the platform as a product, but also as a system</h2>



<p>Organically grown systems get you started, but once you commit to Backstage as your portal, you need a product mindset. Start from developer experience, understand their pain points, then design a system that addresses them coherently.</p>



<p>A platform is also a system. Approach it the way you would approach any production system you’re building. You wouldn’t design a back-end service without thinking about separation of concerns, clear interfaces, and extensibility.</p>



<p>The same principles apply here:</p>



<ul class="wp-block-list">
<li>Separation of concerns: Don’t mix developer-facing abstractions with infrastructure implementation. Keep them separate so you can evolve each independently.</li>



<li>Clear interfaces: Define explicit abstractions. Developers and platform engineers should interact with well-defined concepts rather than implementation details scattered across Helm charts and CI scripts.</li>



<li>Extensibility: Requirements keep changing. If every new capability requires custom wiring, you’ll spend more time maintaining than improving. Design for extension from the start.</li>
</ul>



<p>The difference between a pile of integrations and a platform is architecture. Get the system design right, and new capabilities slot in cleanly. Get it wrong, and every feature request becomes a maintenance burden.</p>



<h2 class="wp-block-heading">The missing layer beneath Backstage</h2>



<p>Moving from an organically grown pipeline to an actionable developer platform is a big leap. You probably have CI/CD pipelines that work, a Kubernetes cluster running workloads, and a Backstage catalog describing what exists.</p>



<p>The questions are:</p>



<ul class="wp-block-list">
<li>How do you transform an informational portal into one with a platform under the hood?</li>



<li>How do you bridge the gap between what the catalog describes and what’s actually running?</li>



<li>How do you enforce golden paths beyond initial scaffolding?</li>



<li>How do you design a platform that evolves with your organization’s needs?</li>
</ul>



<p>What’s missing is a connective layer between Backstage and your runtime, something that makes the portal operational rather than just informational. Let’s look at the key architectural elements to consider when designing that layer and the whole platform.</p>



<h2 class="wp-block-heading"><a></a>Start with abstractions</h2>



<p>One of the main goals of a developer platform is to reduce cognitive load. The platform should meet developers where they are and speak their language, not Kubernetes’.</p>



<p>Every organization has its own vocabulary, but the Backstage system model is a good starting point. It may not cover everything, but you can extend it with custom entities. The key is that developers work with high-level concepts while the platform compiles them into Kubernetes resources. Developers are abstracted away from the underlying details, but they can still see what’s happening underneath.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td><td><strong>Backstage mapping</strong></td></tr><tr><td>Project</td><td>A cloud-native application composed of multiple components. It is also a unit of isolation.</td><td>System</td></tr><tr><td>Component</td><td>A deployable unit, such as web services, APIs, workers, or scheduled tasks.</td><td>Component</td></tr><tr><td>Endpoint</td><td>A network-accessible interface exposed by a component. </td><td>API</td></tr><tr><td>Resource</td><td>External infrastructure such as databases, queues, and caches.</td><td>Resource</td></tr><tr><td>Dependency</td><td>A component’s reliance on endpoints or resources.</td><td>consumesAPI, dependsOn</td></tr></tbody></table> </div></figure>



<p>These are not just static abstractions; they also have associated runtime semantics. The following diagram illustrates runtime representations of these concepts.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_03_cell_diagram.png" alt="Image_03_cell_diagram" class="wp-image-4189100" width="1024" height="905" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>In the workload cluster, a project becomes an isolation boundary for all of its components. The platform translates this into Kubernetes namespaces and network policies that enforce the boundary, not just document it.</p>



<p>Endpoint visibility determines which endpoints can talk to which. A project-scoped endpoint gets network policies that block traffic from outside the project. An organization-scoped endpoint is exposed to internal traffic but remains behind the internal gateway. An external endpoint gets routed through the public gateway with appropriate authentication. Developers declare visibility; the platform generates the policies.</p>



<p>Dependencies work the same way. When a component declares a dependency on an endpoint, the platform injects the URL and other environment variables required to connect to the dependency. It configures the network policies for both directions, egress from the calling endpoint and ingress to the target endpoint. Without the declared dependency, egress is blocked by default. The dependency graph you see above reflects actual permitted traffic flow, not just intended relationships.</p>



<h2 class="wp-block-heading"><a></a>You need platform abstractions, too</h2>



<p>Developer abstractions help your developers. Platform abstractions help you.</p>



<p>While developers work with components, endpoints, and dependencies, you need a different vocabulary to design and operate the platform itself. These abstractions let you and your team define standards, enforce policies, and create structure without writing low-level configurations for every scenario.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td></tr><tr><td>Namespace</td><td>A logical grouping of users and resources, typically aligned to a company, business unit, or team. Defines ownership and access boundaries.</td></tr><tr><td>Data plane</td><td>A Kubernetes cluster that hosts one or more deployment environments. You can have multiple data planes for isolation, regional distribution, or scaling.</td></tr><tr><td>Environment</td><td>A runtime context, such as dev, test, staging, or prod, where workloads are deployed and executed. Environments carry their own policies and resource configurations.</td></tr><tr><td>Pipeline</td><td>A defined process that governs how work, such as builds, deployments, promotions, or any automated workflows, flows through the platform. Encodes your operational processes as a platform primitive.</td></tr><tr><td>Component type</td><td>Defines a category of workload—Service, Worker, Cron, Job.</td></tr><tr><td>Trait</td><td>A reusable capability that attaches to any component, such as autoscaling, resilience, observability, and security policies. Compose behaviors without duplicating configuration.</td></tr></tbody></table> </div></figure>



<p>These abstractions separate platform concerns from application concerns. Developers don’t need to know which cluster their code runs on or how environments are wired together. They deploy to “staging” or “prod,” and you define what those terms mean.</p>



<h2 class="wp-block-heading"><a></a>The missing layer is a control plane</h2>



<p>The control plane is where abstractions become real. It sits between the portal and your workload clusters, translating developer intent into infrastructure configuration.</p>



<p>You can think of it as a compiler that targets Kubernetes clusters, converting higher-level abstractions into what Kubernetes and its underlying frameworks understand. It can also apply platform-wide rules during this compilation. Resource limits, security requirements, etc., can be enforced consistently, not merely documented and hoped for.</p>



<p>But compilation is only half the job. The control plane also reconciles continuously. It monitors drift between the declared and actual states. When they diverge, it corrects. Your abstractions remain the source of truth; the control plane enforces them over time.</p>



<h2 class="wp-block-heading"><a></a>Programmability is not optional</h2>



<p>One of the key aspects of this control plane is programmability. If you want your platform to evolve, the control plane needs to be extensible. Different teams have different requirements. New capabilities emerge. You can’t anticipate everything up front.</p>



<p>This means allowing customization of how abstractions compile to Kubernetes manifests. But extensibility without guardrails is dangerous. You need programmability that preserves your invariants. The goal is constrained flexibility, open enough to evolve, structured enough to stay coherent.</p>



<h2 class="wp-block-heading"><a></a>Observable abstractions make the portal useful</h2>



<p>The control plane also aggregates runtime state and associates it with your abstractions. This is what makes the portal useful. Without this, developers piece together information from different tools: Kubernetes dashboard for pod status, Argo CD for the deployment state, Grafana for metrics, Jaeger for traces. Each tool knows part of the story; none shows the full picture.</p>



<p>With the control plane aggregating state, the portal tells a connected story. When a developer opens a component page in Backstage, they see:</p>



<ul class="wp-block-list">
<li>Deployed environments and their status</li>



<li>Current replicas and resource usage</li>



<li>Recent deployments and who triggered them</li>



<li>Logs, metrics, and traces that are scoped to that component, in each environment</li>



<li>Dependencies and their health</li>
</ul>



<p>No context-switching. No reconstructing which pod belongs to which service in which cluster. The abstraction is the anchor; everything else attaches to it.</p>



<p>This only works because the control plane understands both sides. It compiled the abstractions to Kubernetes, so it knows how to map runtime data back. Information flows in both directions. Downward: developer intent flows through the control plane and becomes running workloads. Upward: runtime state flows back through the control plane and appears in the portal.</p>



<p>This is what makes the portal actionable. It’s not just displaying information; it’s connected to a system that can act.</p>



<h2 class="wp-block-heading"><a></a>Data plane: keep it simple</h2>



<p>The data plane is where your workloads actually run. In most cases, this means one or more Kubernetes clusters. The data plane doesn’t know about your abstractions. It understands Kubernetes primitives such as pods, deployments, services, and ingresses. The control plane’s job is to compile your higher-level concepts into these primitives and apply them.</p>



<p>The data plane does one thing: it runs what the control plane tells it to run. The intelligence lives in the control plane; the execution happens in the data plane.</p>



<h2 class="wp-block-heading">Where AI fits into the platform</h2>



<p>AI is now part of every platform conversation, but the architectural question is where it actually belongs.</p>



<p>The abstractions and control plane you’ve built create the foundation. You have well-defined concepts such as components, endpoints, and dependencies. You have a runtime state aggregated and tied to those concepts. You have a connected view of your system. AI agents can definitely leverage this.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform users</h3>



<p>AI agents should be able to interact with your platform as first-class participants. This requires exposing platform capabilities through interfaces that agents can use, such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, APIs with clear semantics, user-friendly CLIs, and skills that map to platform operations.</p>



<p>These capabilities of the platform enable agents to create components, trigger builds and deployments, query environment status, and reason about dependencies. They help you and your developers become more productive.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform capabilities</h3>



<p>You can also embed agents inside your platform to help your teams’ day-to-day operations. Here are some examples of agents you can develop:</p>



<ul class="wp-block-list">
<li>SRE agents: Analyze logs, metrics, and traces to surface likely root causes. Instead of developers digging through dashboards, the agent correlates signals and suggests where to look.</li>



<li>FinOps agents: Help teams understand and optimize resource costs across environments and components.</li>



<li>Architect agents: Assist with system design decisions, such as dependency analysis, capacity planning, and migration impact assessment.</li>
</ul>



<p>These agents work because they have access to the control plane’s unified view. They see abstractions, runtime state, and observability data in one place, the same connected story developers see in the portal.</p>



<p>The pattern holds. Good abstractions make everything easier, including AI.</p>



<h2 class="wp-block-heading"><a></a>OpenChoreo as a reference implementation</h2>



<p><a href="https://github.com/openchoreo/openchoreo" data-type="link" data-id="https://github.com/openchoreo/openchoreo">OpenChoreo</a> is an open-source developer platform for Kubernetes. It was recently accepted into the CNCF as a sandbox project. OpenChoreo implements the architecture described in this article: developer abstractions backed by a control plane, a Backstage-powered portal, integrated CI/CD and GitOps, and observability wired to your abstractions.</p>



<p>If you’re building this architecture yourself, OpenChoreo is worth studying as a reference, even if you don’t adopt it directly. The project demonstrates how these pieces fit together: how abstractions compile into Kubernetes resources, how runtime state flows back to the portal, and how guardrails are enforced during compilation.</p>



<p>You can use OpenChoreo as a complete platform, or install its Backstage plugins into your existing portal and use just the control plane layer. Either way, the underlying patterns are what matter. The architecture is the idea. OpenChoreo is one way to implement it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_04_multi_plane_architecture.png?w=1024" alt="image_04_multi_plane_architecture" class="wp-image-4189109" width="1024" height="552" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">A useful mental model: multi-plane architecture</h2>



<p>OpenChoreo separates concerns across five planes:</p>



<ol class="wp-block-list">
<li>Experience plane: Where developers, platform engineers, and SREs interact with the platform via the Backstage-powered portal, CLI, GitOps, or AI agents.</li>



<li>Control plane: The brain that translates high-level abstractions (components, APIs, environments, pipelines) into Kubernetes manifests. Programmable through component types and traits, so you can extend it without forking or writing low-level controllers. Continuously reconciles the runtime state back into those abstractions.</li>



<li>Data plane: Where workloads run. Enforces the semantics of your abstractions, such as project isolation, traffic policies, and security boundaries. These aren’t just configurations; the platform guarantees them.</li>



<li>Observability plane: Feeds metrics, logs, and traces back through the same abstractions developers already understand, requiring no translation.</li>



<li>Workflow plane (optional): Handles builds using Cloud Native Buildpacks and Argo Workflows by default.</li>
</ol>



<p>These planes work together but remain separate concerns. You can reason about each independently, evolve them at different rates, and deploy them flexibly: a single cluster with namespace isolation for dev/test, fully separated multi-cluster setups for production, or hybrid topologies that colocate planes like Control and CI for cost efficiency.</p>



<h2 class="wp-block-heading"><a></a>AI and OpenChoreo</h2>



<p>OpenChoreo is being built to treat AI agents as first-class participants. In OpenChoreo 1.0, external agents can interact with the platform via MCP servers, agent skills, or the CLI to generate and edit component configurations, reason about releases and environments, and more. The built-in SRE Agent is a first example of this. It analyzes logs, metrics, and traces from your deployments and uses LLMs to surface likely root causes and actionable insights.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_05_external_internal_agents_openchoreo.png?w=1024" alt="Image_05_external_internal_agents_openchoreo" class="wp-image-4189115" width="1024" height="584" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">From portal to platform</h2>



<p>Backstage solved the portal problem. It gave you a unified interface for catalogs, documentation, and golden paths. But a portal isn’t a platform. There’s a gap between what developers see and what’s actually running, and that’s where you get stuck. You fill it with point-to-point integrations, custom plugins, and scripts that become their own maintenance burden.</p>



<p>The pattern that works is portal, control plane, data plane: </p>



<ul class="wp-block-list">
<li>A portal that gives developers ready access to catalogs, documentation, and templates.</li>



<li>A control plane that compiles platform abstractions, reconciles drift, and aggregates runtime state.</li>



<li>A data plane that runs workloads and enforces guarantees.</li>
</ul>



<p>Whether you build this yourself or you adopt something like OpenChoreo, the architecture matters more than the tools. Get the layers right, and new capabilities slot in cleanly. Get them wrong, and every feature request becomes a project.</p>



<p>Backstage gives you the front door. The real platform begins behind it.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mistral launches OCR 4, turning document extraction into a full enterprise AI play]]></title>
<description><![CDATA[Mistral AI on Tuesday released OCR 4, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generati...]]></description>
<link>https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</guid>
<pubDate>Wed, 24 Jun 2026 23:48:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://mistral.ai/">Mistral AI</a> on Tuesday released <a href="https://mistral.ai/news/ocr-4/">OCR 4</a>, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generation of optical character recognition technology in roughly 15 months and lands at a moment when the company's pitch for European AI sovereignty has never been more commercially relevant.</p><p>The model supports 170 languages across 10 language groups, accepts PDF, DOC, PPT, and OpenDocument formats, and can be deployed as a single container on an organization's own infrastructure — a capability Mistral is positioning directly at enterprises in regulated industries that cannot route sensitive documents through U.S.-jurisdiction cloud APIs.</p><p>"Mistral OCR 4 extracts and structures content from a wide range of documents," the company said in its announcement. "Where previous generations focused on converting a page into clean text and tables, OCR 4 returns a structured representation of the document."</p><p>The model is <a href="https://docs.mistral.ai/resources/cookbooks?useCase=OCR">available immediately</a> through the <a href="https://mistral.ai/pricing/">Mistral API</a>, Document AI in <a href="https://mistral.ai/products/studio/">Mistral Studio</a>, <a href="https://aws.amazon.com/sagemaker/ai/">Amazon SageMaker</a>, and <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a>, with <a href="https://www.snowflake.com/en/blog/engineering/enterprise-scale-document-ai/">Snowflake Parse Document</a> support coming soon. Pricing starts at $4 per 1,000 pages, dropping to $2 per 1,000 pages through a batch API discount.</p><div></div><h2><b>OCR 4 treats every document as a semantic map, not a wall of text</b></h2><p>The central engineering shift in <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is structural. Rather than outputting a flat stream of extracted text — the paradigm that has defined OCR for decades — the model returns a layered representation in which every block is localized with a bounding box, classified by type (title, table, equation, signature, and others), and scored for confidence at both the page and word level.</p><p>Mistral says bounding boxes were its most-requested capability. The reason is straightforward: without location data, downstream systems cannot trace an extracted fact back to its source on a specific page. That traceability gap has been a persistent friction point for enterprises building retrieval-augmented generation (RAG) pipelines, compliance workflows, or any application where "where did this number come from?" is a question that needs an auditable answer.</p><p>Block classification addresses a related problem. A paragraph tagged as a "title" can segment a document into hierarchical chunks for semantic search. A block tagged as a "table" can be routed to a structured-data pipeline rather than a text summarizer. A block tagged as a "signature" can trigger a redaction workflow in a compliance system.</p><p>These are not novel ideas in isolation, but packaging them as first-class outputs of the OCR model itself — rather than requiring a separate layout-analysis stage — removes an integration layer that enterprise teams have historically had to build and maintain themselves.</p><p>The confidence scores serve a dual purpose. At scale, they allow organizations to programmatically route low-confidence regions to human reviewers and auto-approve high-confidence extractions, building what the industry calls human-in-the-loop verification without requiring a person to review every page of every document. In production systems, OCR is rarely the end goal — it is the first step in a larger pipeline.</p><p>Developers building RAG systems, agent workflows, or document automation often spend more time reconstructing layout and structure than on the downstream AI logic itself. OCR 4 aims to eliminate that reconstruction step, and if it delivers on that promise, the value accrues not just in OCR cost savings but in reduced engineering hours across the entire document pipeline.</p><h2><b>Independent reviewers preferred Mistral's output 72 percent of the time, but benchmarks tell a complicated story</b></h2><p>Mistral reports that <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> achieved a 72% average win rate in a head-to-head human evaluation against leading competitors, conducted by independent annotators across more than 600 real-world documents in over 12 languages. The model also achieved the top overall score on <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench</a> at 85.20 and scored 93.07 on <a href="https://github.com/opendatalab/OmniDocBench">OmniDocBench</a>.</p><p>But the company itself urges caution in interpreting those numbers. In its release, Mistral took the unusual step of auditing and publicly disclosing the specific types of scoring artifacts it encountered, including ground-truth errors in the reference annotations, equivalent LaTeX notation scored as mismatches, column-reading-order assumptions, and header/footer attribution issues. "We therefore treat the aggregate score as directional rather than definitive," the company said — a notably transparent stance from a vendor announcing a product.</p><p>That transparency is well-timed. On the public <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench leaderboard</a>, some researchers have noted that OCR 4 currently ranks third, behind open models like Chandra OCR 2. And some open-weight models self-report higher OmniDocBench composite scores — <a href="https://huggingface.co/PaddlePaddle/PaddleOCR-VL-1.6">PaddleOCR-VL-1.6</a> claims 96.33 — though those results have not been independently reproduced on the public leaderboard.</p><p>Early enterprise feedback has been favorable nonetheless. Aidan Donohue, an AI engineer at financial AI firm Rogo, said the company benchmarked OCR 4 against leading agentic document parsers on a chart-dense financial QA dataset and "reached equivalent accuracy at roughly 8x lower cost and 17x lower latency." Ivan Mihailov, an AI engineer at intellectual property management firm Anaqua, said OCR 4 is "roughly 4x faster per page than our incumbent provider." </p><p>Enterprise buyers, however, should run their own evaluations rather than relying on any vendor's benchmark numbers. The practical question is not which model scores highest on a leaderboard, but which model produces the fewest errors on your specific documents, in your specific languages, at a price and latency that fit your workflow.</p><h2><b>The Anthropic export ban gave Mistral's sovereignty pitch the proof point it needed</b></h2><p>Mistral's release lands in a geopolitical context that could hardly be more favorable for its strategic positioning.</p><p>On June 12, <a href="https://www.anthropic.com/news/fable-mythos-access">Anthropic was forced to disable all access to its newest AI models</a>, Fable 5 and Mythos 5, after the U.S. Commerce Department used national security export controls to bar the company from distributing the models to any foreign national. Enterprise clients in finance, healthcare, SaaS, and critical infrastructure found their core intelligence services abruptly disabled, without prior warning or effective recourse. As of June 24, both models remain offline, with <a href="https://kalshi.com/markets/kxfablerestore/fable-restored/kxfablerestore-27">prediction markets giving only 57% odds of restoration</a> before July 1.</p><p>That episode validated a warning Mistral CEO Arthur Mensch has been sounding for over a year. As Business Insider reported, <a href="https://www.businessinsider.com/anthropic-model-access-mistral-opportunity-ai-sovereignty-2026-6">Mensch warned at London Tech Week</a> in June 2025 about American AI companies "having the keys" for their models, calling it a scenario where European companies are "giving leverage to their providers." He added: "At some point, you need to be able to turn it off or turn it on, and you don't want to leave it to another country."</p><p>The argument gained further urgency as Mensch's broader sovereignty pitch escalated in recent months. As reported by CNBC in late May, <a href="https://www.cnbc.com/2026/05/28/mistral-arthur-mensch-design-chips-ai-data-centers.html">Mensch told the outlet</a>: "Europe is lagging behind when it comes to [the] buildout of infrastructure, and so we are investing to close that gap." </p><p>At the same time, <a href="https://www.reuters.com/business/media-telecom/mistral-defends-ai-use-warfare-rebuts-pope-criticism-2026-05-28/">Mensch pushed back against Pope Leo XIV's call for AI to be "disarmed,"</a> arguing that Europe cannot afford to fall behind U.S. tech giants. "We're all for ​peace, but if you look at our rivals and adversaries in the world, they're using artificial ​intelligence … we do need to have our own capabilities," Mensch told reporters.</p><p>OCR 4's single-container, self-hosted deployment model is the product-level expression of that argument. A U.S.-headquartered provider offering EU data residency means documents are stored in Frankfurt but governed by U.S. law. Mistral, incorporated in France and operating under EU jurisdiction, offering on-premise containerized deployment, means documents never leave the customer's infrastructure at all. The <a href="https://artificialintelligenceact.eu/article/99/">EU AI Act's fine enforcement provisions</a> take effect August 2, adding regulatory pressure to the compliance calculus for European enterprises evaluating document AI vendors.</p><h2><b>Baidu's free, open-weight OCR model arrived one day earlier — and the contrast is revealing</b></h2><p>Mistral's release did not arrive in isolation. Just one day before <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> launched, Baidu shipped <a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> on June 22 — a 3-billion-parameter MIT-licensed model that tackles one of the most persistent pain points in document AI: parsing entire PDFs and multi-page scans in a single forward pass, without chunking the input or stitching the output back together afterward.</p><p>Baidu's model uses a technique called <a href="https://arxiv.org/html/2606.23050v1">Reference Sliding Window Attention (R-SWA)</a> that, as a top <a href="https://news.ycombinator.com/item?id=48643426">Hacker News commenter explained</a>, splits the AI's focus into two paths: maintaining full attention on the original document image while restricting memory of generated text to a tight, moving window. The result is constant KV cache size and the ability to transcribe 40-plus pages in a single forward pass. The model gathered <a href="https://github.com/baidu/Unlimited-OCR">1,800 GitHub stars</a> in its first 24 hours and racked up more than <a href="https://news.ycombinator.com/item?id=48643426">479 upvotes on Hacker News</a>, where the discussion thread ran to 109 comments.</p><p>The two releases frame what some analysts are calling the June 2026 document-AI split: self-hosted long-horizon parsing with open weights versus structured managed extraction with enterprise features.</p><p><a href="https://github.com/baidu/Unlimited-OCR">Baidu's model</a> is free under an MIT license, runs on standard GPU hardware, and has no managed API or enterprise SLA. <a href="https://mistral.ai/news/ocr-4/">Mistral's model</a> is a commercial product with per-page pricing, bounding boxes, confidence scores, block classification, multi-platform distribution, and self-hosted deployment options for enterprise customers. </p><p><a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> may be the better tool for a research team digitizing scanned dissertations on a single GPU. <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is built for the IT procurement process — the world of SLAs, data processing agreements, and compliance audits.</p><p>Beyond Baidu, the broader OCR competitive field includes <a href="https://cloud.google.com/document-ai">Google Document AI</a>, <a href="https://aws.amazon.com/textract/">Amazon Textract</a>, <a href="https://azure.microsoft.com/en-us/products/ai-foundry/tools/document-intelligence">Azure Document Intelligence</a>, <a href="https://www.abbyy.com/vantage/">ABBYY Vantage</a>, and a growing number of open-weight models. </p><p>On the <a href="https://news.ycombinator.com/item?id=48643426">Hacker News thread</a> for Unlimited-OCR, practitioners offered a candid assessment of the state of the art. Joss82, who has worked on document parsing for 10 years, wrote bluntly: "OCR still sucks in 2026." Meanwhile, one user named SyneRyder reported success with Claude for OCR of hundreds of pages of handwritten documents, noting the model delivered results with "no corrections required" and even pointed out a continuity error in the source text. These practitioner reports underscore a key tension in the market: performance varies wildly depending on the specific document type, language, and quality of the source material.</p><h2><b>The real play is not OCR — it is an enterprise AI stack with document intelligence as the on-ramp</b></h2><p>Step back far enough, and <a href="https://mistral.ai/news/ocr-4/">Mistral's OCR 4 release</a> is not really an OCR story. It is an enterprise go-to-market story built on top of a $4.4 billion global intelligent document processing market that is forecast to grow at a 33.1% compound annual growth rate through 2030, according to <a href="https://www.grandviewresearch.com/industry-analysis/intelligent-document-processing-market-report">Grand View Research</a>.</p><p>For Mistral, OCR is a wedge into enterprise AI budgets. The model feeds directly into Mistral's <a href="https://mistral.ai/news/search-toolkit/">Search Toolkit</a>, the company's open-source composable search framework announced at the AI Now Summit. In that architecture, <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> serves as the ingestion layer for retrieval-augmented generation and enterprise search pipelines, converting raw documents into citation-ready, structurally classified input. The logic is clear: once an enterprise adopts OCR 4 for document extraction, Mistral's broader model suite — including Medium 3.5 for reasoning and the Vibe agentic platform for task execution — becomes the natural next step in the stack. </p><p>That pipeline ambition is critical context for understanding Mistral's current fundraising trajectory. Bloomberg recently reported that the company is in early discussions to <a href="https://www.bloomberg.com/news/articles/2026-06-12/france-s-mistral-in-funding-talks-at-about-20-billion-valuation">raise about €3 billion ($3.5 billion)</a> at a valuation of roughly €20 billion — nearly double the €11.7 billion valuation from its September Series C round. To date, Mistral has raised only about $4 billion, a fraction of what its largest U.S. rivals have taken in. OCR 4 and its associated enterprise revenue pipeline are part of how the company plans to justify that higher valuation, with Mistral targeting <a href="https://www.lemonde.fr/en/economy/article/2026/01/22/french-ai-firm-mistral-predicts-revenue-of-1-billion-in-2026_6749706_19.htm">€1 billion in revenue</a> for 2026, up from €200 million in 2025, according to Le Monde.</p><p>Mistral is a company with roughly 1,000 employees and ambitions to compete with labs that have raised 40 times as much capital. It cannot win a general-purpose model arms race against OpenAI and Anthropic. What it can do is build a differentiated enterprise stack around sovereignty, <a href="https://mistral.ai/news/ocr-4/">structured document intelligence</a>, and agentic workflows — and use that stack to capture European enterprise budgets that are increasingly wary of U.S. provider dependency. </p><p>The pricing structure reinforces that strategy: at $2 per 1,000 pages in batch mode, the cost of processing a 100,000-page corporate archive falls to $200, making large-scale digitization projects economically viable in ways they may not have been with token-based vision-language model pricing.</p><p>Whether Mistral can execute that vision at scale — against Google, Amazon, Microsoft, and a surging open-source ecosystem — remains an open question. But the Anthropic export control crisis is still unresolved, European data sovereignty regulations are tightening, and a potential €20 billion funding round is on the horizon. The company is holding an <a href="https://learn.mistral.ai/public/events/ocr4-webinar">OCR 4 production webinar on July 7 at 6:00 PM CET</a>.</p><p>Two weeks ago, the argument for building AI infrastructure outside the reach of U.S. export controls was theoretical. Then the U.S. government flipped a switch, and Anthropic's most advanced models went dark for every non-American on the planet. Mistral did not cause that crisis — but it spent the last year building the product that makes it matter.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[José María Fuster van Bendegem: “Un error típico es reducir la función del CIO a la del CTO”]]></title>
<description><![CDATA[Ingeniero, exdirectivo bancario de primerísimo nivel, académico español… Sin duda, José María Fuster van Bendegem es uno de los perfiles más polifacéticos e interesantes del escenario de la tecnología, la empresa y la ciencia en España. Conocido por haber sido, en el pasado, uno de los CIO más re...]]></description>
<link>https://tsecurity.de/de/3618850/it-nachrichten/jos-mara-fuster-van-bendegem-un-error-tpico-es-reducir-la-funcin-del-cio-a-la-del-cto/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618850/it-nachrichten/jos-mara-fuster-van-bendegem-un-error-tpico-es-reducir-la-funcin-del-cio-a-la-del-cto/</guid>
<pubDate>Tue, 23 Jun 2026 18:18:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ingeniero, exdirectivo bancario de primerísimo nivel, académico español… Sin duda, <strong><a href="https://www.linkedin.com/in/jose-maria-fuster-van-bendegem/" target="_blank" rel="nofollow">José María Fuster van Bendegem</a></strong> es uno de los perfiles más polifacéticos e interesantes del escenario de la tecnología, la empresa y la ciencia en España. Conocido por haber sido, en el pasado, uno de los CIO más relevantes no solo de España sino del mundo, al liderar la transformación tecnológica global de Banco Santander, y por haber sido miembro de varios consejos de administración, como el Banco Español de Crédito, el Banco Santander UK, el Banco Santander Alemania, el Banco Santander USA, Sistemas 4B, Openbank (donde fue presidente) y Universia, Fuster ha destacado, en los últimos años, por una intensa labor científica.</p>



<p>De hecho, tras dejar el sector bancario, el ejecutivo dio un giro de 180 grados a su carrera y se reorientó hacia la ciencia teórica, la epistemología y el apoyo a las instituciones científicas, creando la <a href="https://fundacionsicomoro.org/" target="_blank" rel="nofollow">Fundación Sicómoro</a>, una institución privada sin ánimo de lucro de la que es presidente y que está enfocada en investigar la Teoría de Sistemas y entender la empresa y la sociedad como Sistemas Complejos Adaptativos. Además, Fuster es Académico de Honor de la Real Academia de Ciencias Exactas, Físicas y Naturales de España, como reconocimiento a su labor de mecenazgo y a su esfuerzo por estrechar los lazos entre la ciencia avanzada y la sociedad civil. El experto también ha tenido un papel relevante en el ecosistema emprendedor vinculado a la innovación. Hasta 2021 fue fundador y presidente de la sociedad de capital riesgo Chamberí Ventures y también fundador y CEO de Ecosistemas de Innovación Digitales.</p>



<p>Este ingeniero superior aeronáutico por la Universidad Politécnica de Madrid, Máster Universitario en Epistemología de las Ciencias Naturales y Sociales por la Universidad Complutense de Madrid, Máster en Dirección Financiera y Control por el Instituto de Empresa y Doctor en Filosofía por la Universidad Complutense de Madrid, <strong>forma este año parte del jurado de los próximos <a href="https://event.foundryco.com/cio-100-awards-espana/" rel="nofollow">CIO 50 Awards</a></strong>, la convocatoria de premios de referencia en el país que persigue distinguir a los mejores directivos de sistemas de información (CIO) y los proyectos de TI más innovadores. Los ‘Oscar de la industria de TI’, como se les conoce en todo el mundo, forman parte del proyecto global CIO Awards de la publicación internacional CIO del grupo editorial Foundry. El próximo 30 de junio finaliza el plazo de recepción de candidaturas a estos premios que se entregarán el 8 de octubre en Madrid.</p>



<p>Ante la próxima celebración de los galardones, el experto comparte por escrito con CIO ESPAÑA su visión sobre el liderazgo tecnológico y las claves que, a su juicio, distinguen a las organizaciones que convierten la innovación en resultados tangibles.</p>



<p><strong>Tras una trayectoria tan vinculada a la tecnología y la innovación, ¿qué valor aporta una visión científica al evaluar estas candidaturas?</strong></p>



<p>Para poder contestar a esta pregunta, voy a asumir que una evaluación es objetiva si utiliza criterios observables, medibles y comparables. En tal caso, la primera ventaja que me viene a la mente es que la objetivación reduce sesgos personales y mejora la equidad. Aunque, si aceptamos la validez de la célebre afirmación de Nietzsche de que “no hay hechos, solo interpretaciones, y esta afirmación es también una interpretación” tendríamos que la objetividad absoluta no existe, lo que es innegable es que, para el caso que nos ocupa, la reducción de sesgos subjetivos es evidente.</p>



<p>Si consideramos, como ejemplo, evaluar 50 candidaturas por 10 jueces, basados en el juicio de cada miembro del jurado, dado que cada juez introduciría sus sesgos y prejuicios en cada evaluación, tendríamos 500 casos difícilmente comparables. La evaluación basada en criterios comunes tendría, sin duda, el sesgo representado por los propios criterios de evaluación, pero ese sesgo sería común para todos los participantes, por lo que no atentaría a la equidad. El sesgo del jurado sería de segundo orden, relativo a la interpretación de los criterios, que sería único para cada juez. En definitiva, tendríamos una posible dispersión de criterios producto de 10 distintas interpretaciones, mitigadas en su impacto por ser de segundo orden.</p>



<p>Parece incuestionable que una dispersión de 500 casos de primer orden tiene una probabilidad mucho más alta de atentar a la equidad que una dispersión de 10 casos de segundo orden. Tendríamos un criterio más replicable y verificable, de modo que distintos evaluadores tenderían a llegar a resultados más consistentes. No hay duda de que un juicio experto de calidad, en contra las valoraciones objetivas, es más apropiado para captar la singularidad. Pero dado el número de candidaturas que se manejan, la ventaja de la equidad supera con creces la posible injusticia de no captar un caso singular por no acudir al juicio experto que, no se nos oculta, exigiría la máxima excelencia en la selección de los jueces.</p>



<p></p>



<p><strong>¿Qué aprendizajes de su propia experiencia como CIO de grandes compañías aplica al evaluar las candidaturas?</strong></p>



<p>En mi caso particular, el criterio que he adoptado es tratar de ceñirme al máximo al método objetivo definido para este concurso. Mi experiencia resulta especialmente útil para entender bien el método seleccionado, ya que los conceptos subyacentes me resultan no sólo conocidos, sino también, familiares.</p>



<p> </p>



<p><strong>¿Qué importancia tiene la capacidad de una organización para convertir conocimiento en resultados tangibles?</strong></p>



<p>Voy a partir de los conceptos definidos por el Santa Fe Institute, que es una institución dedicada al estudio de la complejidad y los sistemas complejos. Toda organización se puede conceptualizar como un sistema complejo adaptativo que tiene un “propósito” que va acompañado de un objetivo implícito que podríamos denominar “supervivencia del sistema”.  El conocimiento en una organización, ya sea formal o informal, resulta esencial tanto para conseguir el propósito, como para asegurar la continuidad de la organización en el tiempo, lo que requiere extender el conocimiento más allá de la propia organización, buscando la comprensión del entorno y su dinámica para poder asegurar la adaptación al mismo.</p>



<p>Lo anterior exige construir métricas, más allá de las puramente financieras, para poder gestionar mejor la organización a lo largo del tiempo; esas métricas constituyen la base para lo que podemos llamar “resultados tangibles” si y solo si se incorporan en los sistemas de gestión y la cultura de la organización.</p>



<p>No hay duda de que conseguir todo esto constituye un objetivo esencial para todo CIO que se precie, aunque es evidente que trasciende su papel, pues conseguir el propósito y preservar la organización son asuntos que conciernen a toda la organización en su conjunto.</p>



<p></p>



<p><strong>¿Cómo distingue una innovación puntual de una transformación con impacto sostenido?</strong></p>



<p>En las organizaciones se produce una considerable confusión entre los conceptos de innovación, mejora continua, gestión del cambio y transformación. La propia pregunta lleva implícita esta confusión. Si innovar presupone hacer algo nuevo, de una manera distinta, nos damos cuenta de que una sistemática de mejora continua puede, o no, incluir innovaciones. Por otra parte, poner en marcha cualquier mejora supone implantar cambios, es decir, siempre requiere una gestión del cambio. Además, una sistemática de mejora continua extendida en el tiempo puede resultar profundamente transformadora, aunque esté basada en la acumulación de múltiples pequeños cambios, algunos innovadores y otros no.</p>



<p>Así pues, tenemos que recurrir a otro concepto para poder responder a esta pregunta que es el de la “escala”. Hablamos de transformación cuando pretendemos cambiar la organización completa o un subconjunto importante de ella, independientemente del método que usemos para realizarla. Para que una transformación se pueda considerar exitosa debe producir impactos sostenibles en el tiempo a escala de la organización. La transformación siempre requiere una gobernanza “top down”.</p>



<p>Las innovaciones, incluso las mejoras puntuales, siempre estarán referida a una escala pequeña de la organización. Generalmente son resultado de una dinámica “bottom up”. Solo pueden producir impacto a escala completa si formaran parte de una estrategia de mejora continua que busque la acumulación de muchos cambios puntuales de manera sistemática a lo largo del tiempo y extendida a todas las partes de la organización afectada.</p>



<p></p>



<p><strong>¿Qué tecnologías o tendencias le gustaría ver reflejadas en las candidaturas de los próximos años?</strong></p>



<p>En un plano estrictamente tecnológico, creo que hay que prestar especial atención a las cuestiones siguientes: hibridación de clouds, buscando tanto evitar dependencias catastróficas para el futuro de la empresa, como asegurar mecanismos que protejan la eficiencia futura y eviten mecanismos de lock-in con un elevado coste potencial a futuro; definición de arquitecturas que hagan posible el despliegue de la IA agentiva, incorporando modelos avanzados de monitorización y control; y la utilización de los LLM para el desarrollo de sistemas avanzados. La clave aquí es ser capaz de utilizar el lenguaje natural para incorporar en las soluciones parte de la inteligencia informal que tienen todas las organizaciones.</p>



<p></p>



<p><strong>¿Qué papel cree que juega la inteligencia artificial en las estrategias tecnológicas más avanzadas?</strong></p>



<p>La inteligencia artificial debe comprenderse como una fase más del proceso de digitalización que comenzó la segunda década del siglo XX. La madurez del software basado en redes neuronales ha sido posible gracias al extraordinario incremento de la capacidad de computación, el desarrollo de las redes de comunicaciones digitales, la explosión de datos que recogen conocimiento en formato digital y el desarrollo del software.</p>



<p>Si la entendemos así, resulta tan inevitable como fueron los ordenadores personales a finales del siglo pasado o la Internet a comienzos del siglo XXI. Lo que estamos viviendo es la emergencia de una dimensión digital que se va haciendo omnipresente en nuestras vidas y que está redefiniendo todos los procesos económicos y sociales de una forma que aún no acabamos de captar de manera plena.</p>



<p>Para cualquier organización, la emergencia de esta nueva dimensión a escala planetaria hace aún más importante y urgente incorporar en sus estrategias una quinta dimensión, adicional a las definidas por el espacio y el tiempo, que podemos denominar “dimensión digital” y que viene a complicar (no a simplificar) la formulación de los planes. La razón para ello es que un mundo con cinco dimensiones es mucho más complejo que un mundo con cuatro, considerando además que las restricciones físicas operan de manera distinta en las cuatro dimensiones clásicas respecto a la dimensión digital.</p>



<p></p>



<p><strong>¿Qué tipo de proyectos cree que marcarán la referencia del liderazgo tecnológico en los próximos años?</strong></p>



<p>Tradicionalmente, los CIO operábamos en el marco de modelos de negocio estables que hacían posible concentrar nuestros esfuerzos en mejorar los procesos clave definidos por estos modelos de negocio. Podríamos decir que estábamos concentrados en mejorar las propuestas de valor, haciéndolas más atractivas, robustas, eficientes y mejorando su calidad con un marco conceptual relativamente estable.</p>



<p>Primariamente, se utilizaba información estructurada para realizar procesos que podríamos calificar como internos de la organización, sobre los que se ejercía un completo control. En el futuro veremos el desarrollo de procesos que serán partes de redes débilmente acopladas donde se ejercerá tan sólo un control parcial. El desarrollo de redes hará posible nuevos modelos de nodos y relaciones que dificultarán la estabilidad de los modelos de negocio.</p>



<p> La información no estructurada será cada vez más importante gracias a las posibilidades que ofrece la IA de capturar conocimiento no formalizado, y se producirá una tendencia creciente a compartir información, no necesariamente voluntaria, sino forzada por la presión competitiva y la búsqueda de mejoras de productividad y eficiencia.</p>



<p></p>



<p><strong>¿Qué mensaje enviaría a los CIO que aspiran a liderar la próxima generación de transformación digital?</strong></p>



<p>En primer lugar, se hace necesario reconocer un incremento de la complejidad, tanto en el panorama competitivo de las empresas, como en la enorme cantidad de opciones tecnológicas disponibles, y la creciente dificultad de acceder a talento adecuado para el reto que se presenta.</p>



<p>Dicho esto, un CIO que aspire a liderar la próxima generación de transformación tecnológicas debería trabajar los aspectos siguientes: un profundo conocimiento del sector en el que opera su empresa y los modelos de negocio exitosos en el mismo; un profundo conocimiento de las tecnologías disponibles y sus condiciones de uso; la capacidad de definir los distintos niveles de arquitectura necesarios en su organización así como comprender su madurez y evolución futura; y la flexibilidad para orquestar soluciones, seleccionando los componentes adecuados y combinándolas de manera única para satisfacer las exigencias de los modelos de negocio perseguidos.</p>



<p></p>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>“El problema de gobernar de manera integrada las demandas de la tecnología requiere una comprensión y compromiso de la alta dirección que, en muchos casos, no se produce, haciendo muy difícil la entrega de valor por parte del CIO”</em></strong></p></blockquote></figure>



<p></p>



<p><strong>¿Qué tres decisiones estratégicas definen realmente la calidad de un CIO?</strong></p>



<p>Primero, hay que ser consciente de que el rol primario de un CIO es operativo. En toda organización, las tecnologías de la información deben facilitar la eficiencia económica (más ingresos/ menos costes) y la calidad del funcionamiento, todo ello en un marco controlado de riesgo operacional. La incardinación en la estrategia de la empresa se basa en el hecho de que las tecnologías de la información han ido incrementando su peso en las estrategias empresariales de todo el mundo. La forma en la que el CIO puede contribuir al plan estratégico de la empresa es formulando arquitecturas robustas que lo faciliten.</p>



<p>Las tres decisiones estratégicas más importantes, estarían relacionadas con las tres arquitecturas fundamentales que debe definir una empresa avanzada, partiendo siempre de un marco de negocio bien definido: arquitectura de sistemas, que define el modelo de sistemas clave de la empresa, que hagan posible desarrollar sus procesos, tanto internos como externos y sus métricas clave de gestión; arquitectura de datos, donde se defina cuáles son los datos que constituyen una ventaja competitiva clave para la empresa, ya sean internos o externos y como convertirlos en un activo intangible; y arquitectura tecnológica, que refiere a la combinación de hardware, software y comunicaciones más óptima para operar los planes de la empresa.</p>



<p>Estas decisiones deben ir acompañadas por una reflexión sobre qué capacidades debe construir la empresa, cuales requieren socios estratégicos y cuales son externalizables, buscando optimizar proveedores.</p>



<p>Un CIO que no comprenda la necesidad de definir estas arquitecturas e incardinarlas en la estrategia de la empresa se verá arrastrado, en poco tiempo, a una dinámica compleja de priorización de demandas crecientes dominadas por la presión del día a día.</p>



<p> </p>



<p><strong>¿Qué error estratégico ves repetirse en muchos CIO hoy?</strong></p>



<p>Un típico error es reducir la función del CIO a la del CTO, rehuyendo la comprensión de los negocios y centrando las conversaciones en cuestiones estrictamente tecnológicas. Al hacer esto, dificulta la conversación con las unidades de negocio. Si el cambio tecnológico es realmente necesario, dificulta la adopción al perderse la pedagogía necesaria. Si el cambio tecnológico no es necesario, o tan sólo es “nice to have”, incurre en el riesgo de sobrearquitecturización o de incremento de complejidad innecesaria de las soluciones.</p>



<p>Otro error muy típico es la ausencia de planificación y gobierno en la gestión de los proyectos. Esto lleva a la creación de una especie de mercado persa de proyectos, que producen una proliferación de demandas, un incremento de costos y el riesgo de producir arquitecturas de tipo “spaghetti” que dificultan y hacen ineficiente la gestión futura de la tecnología. El problema de gobernar de manera integrada las demandas de la tecnología requiere una comprensión y compromiso de la alta dirección que, en muchos casos, no se produce, haciendo muy difícil la entrega de valor por parte del CIO.</p>


<div class="text text--no-top-margin"><h2></h2><p></p><p><a class="button button--primary" data-amp-height="40" target="_blank" href="https://es.surveymonkey.com/r/F89SFCM" rel="nofollow">Presente aquí su candidatura a los CIO 50 awards en españa</a></p></div></div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why agentic enterprises need to become learning systems]]></title>
<description><![CDATA[Presented by SplunkEvery day, organizations learn things their AI systems never get to use.A security analyst corrects an AI-generated investigation. A network engineer identifies the root cause of a recurring outage. An observability team discovers that a pattern of latency, logs and infrastruct...]]></description>
<link>https://tsecurity.de/de/3616012/it-nachrichten/why-agentic-enterprises-need-to-become-learning-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616012/it-nachrichten/why-agentic-enterprises-need-to-become-learning-systems/</guid>
<pubDate>Mon, 22 Jun 2026 17:48:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Splunk</i></p><hr><p>Every day, organizations learn things their AI systems never get to use.</p><p>A security analyst corrects an AI-generated investigation. A network engineer identifies the root cause of a recurring outage. An observability team discovers that a pattern of latency, logs and infrastructure changes predicts service degradation. A customer operations team learns which signals indicate an escalation is likely.</p><p>Each moment contains valuable organizational knowledge. But in most enterprises, that knowledge disappears into tickets, dashboards, chat threads, post-incident reviews and the minds of individual experts. It may help solve the immediate problem, but it rarely becomes part of a reusable system that improves future AI-driven decisions.</p><p>That is the next challenge for the agentic enterprise.</p><p>The future will not be defined simply by who has the most capable model or the most autonomous agents. Many organizations will have access to similar frontier models. Many will deploy agents across security, IT, engineering, customer service, and business operations.</p><p>The real differentiator will be whether those agents can learn from the organization around them.</p><p>Not by constantly retraining the underlying model, but by capturing operational experience, converting it into institutional knowledge and making that knowledge available to future agents, workflows, and decisions.</p><p>The agentic enterprise is not just an enterprise that uses AI. It is an enterprise that learns through AI.</p><h2>Agentic enterprises allow AI systems to learn from them</h2><p>The AI conversation has been dominated by model capability: larger context windows, better reasoning, faster inference, stronger tool use, and more sophisticated agentic behavior.</p><p>Those advances matter. But in the enterprise, a model is only one part of the system.</p><p>A model does not automatically know how a specific organization operates. It does not inherently know which remediation step solved last month’s outage, which analyst correction improved a threat investigation, which network signal preceded a service disruption, or which internal policy should override an otherwise plausible recommendation.</p><p>That knowledge belongs to the enterprise.</p><p>For agentic systems to improve, organizations need a way to capture that knowledge and make it reusable. In many cases, that does not require changing the model itself. It requires changing the ecosystem around the model: the knowledge base, retrieval layer, prompts, policies, guardrails, routing logic and workflows that shape how agents behave.</p><p>The model may remain the same. The learning system around it becomes smarter.</p><h2>Feedback loops turn every outcome into a teachable moment for agents</h2><p>Every agentic workflow creates signals.</p><p>An agent receives a request. It retrieves context, reasonsthrough possible actions, calls tools, and generates answers. A human accepts, rejects, or modifies that answer. Downstream systems reveal whether the action worked.</p><p>That entire chain is valuable.</p><p>AI observability gives organizations visibility into what happened: the prompt, response, reasoning path, tool calls, data sources, intermediate steps, failure modes and outcomes. Without that visibility, organizations cannot understand why an agent behaved the way it did, let alone improve it.</p><p>But observability alone is not enough.</p><p>The larger opportunity is to turn observed behavior into institutional knowledge. A trace should not only help a developer and operators debug an agent. It should help the enterprise understand what the agent learned, what the human corrected, what outcome followed, and what should change before the next similar event.</p><p>That is the shift from monitoring AI to teaching AI.</p><p>In the agentic enterprise, feedback loops connect action to outcome, outcome to knowledge and knowledge back to future action.</p><h2>A learning system in practice across security, observability and the network</h2><p>Consider a service experiencing intermittent degradation.</p><p>An observability agent detects unusual latency and error rates. A network agent identifies packet loss across a specific path. A security agent notices that the same time window includes suspicious authentication behavior and unusual traffic from a previously unseen source.</p><p>Individually, each agent has only a partial view. Together, they create a richer operational picture.</p><p>The first time this incident occurs, human experts may need to intervene. A network engineer confirms that packet loss was caused by a misconfigured routing change. A security analyst determines that the suspicious traffic was not an attack, but a side effect of a misrouted internal service. An SRE connects the network event to the application degradation.</p><p>That resolution contains knowledge the organization should not have to relearn.</p><p>A mature agentic learning system would capture the traces, human corrections, topology context, security findings, observability signals and final remediation steps. It would preserve the relationship between those signals: latency pattern, network path, identity behavior, routing change and remediation.</p><p>The next time a similar pattern appears, agents would not start from zero. They could retrieve the prior case, compare current conditions, recommend the proven diagnostic path and escalate with better context.</p><p>The underlying frontier model did not need to be retrained.</p><p>The enterprise learned.</p><h2>The architecture of the learning agentic enterprise</h2><p>A learning-oriented agentic enterprise needs more than a model or chatbot. It needs an architecture that can capture experience, turn it into usable knowledge, connect that knowledge to operational context, and govern how it changes future agent behavior.</p><p><b>Memory </b>preserves what happened: what the agent saw, what it did, where humans intervened, and what outcomes followed.</p><p><b>Knowledge bases</b> turn that experience into reusable guidance, including playbooks, examples, policies, procedures, and evidence.</p><p>A <b>data fabric </b>connects the operational environment. The signals agents need live across logs, metrics, traces, tickets, identity systems, security tools, network telemetry, collaboration platforms, and business applications. A data fabric makes those signals discoverable, correlated, governed, and usable in context.</p><p><b>AI observability </b>explains how agents behave by capturing prompts, tool calls, intermediate steps, responses, feedback, and outcomes. That visibility helps organizations understand where agents succeed, where they fail, and what should improve.</p><p>The <b>control plane</b> governs how learning becomes change: what knowledge is promoted, which prompts or policies are updated, which agents can use new information, what approvals are required, and how changes are audited.</p><p>Together, these capabilities allow AI systems to improve over time in a controlled, trustworthy way that allows the enterprise to learn from its own operations.</p><h2>The organizations that learn fastest will win </h2><p>The next era of AI will not be won by models alone. It will be won by organizations that can capture what they learn from every workflow, expert correction, incident, investigation, and outcome.</p><p>The most advanced agentic enterprises will not simply deploy more agents. They will build systems that allow every agent to benefit from the collective knowledge of the organization.</p><p>That means connecting operational data through a data fabric. It means observing agent behavior deeply enough to understand it. It means preserving experience in memory and institutionalizing it in knowledge bases. It means using a control plane to govern how learning changes agent behavior.</p><p>The future of AI is not a single autonomous agent acting alone. It is an ecosystem of agents, humans, data and controls that learns over time.</p><p>The organizations that build that ecosystem will create AI systems that get better with every interaction. Not because the model is constantly changing, but because the enterprise itself is becoming more intelligent.</p><p><i>Learn more about how </i><a href="https://www.splunk.com/ciscodatafabric"><i>Cisco Data Fabric powered by the Splunk Platform</i></a><i> is accelerating agentic operations.</i></p><p><i>Hao Yang is Vice President AI at Splunk, a Cisco Company.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are turning enterprise apps into decision systems]]></title>
<description><![CDATA[Last year, I worked with an enterprise leadership team that had made significant investments in its piloting of generative AI in areas such as customer service, IT operations, and productivity workflows. On paper, the organization appeared ahead of the curve. Employees were using copilots. Busine...]]></description>
<link>https://tsecurity.de/de/3615236/it-security-nachrichten/how-ai-agents-are-turning-enterprise-apps-into-decision-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615236/it-security-nachrichten/how-ai-agents-are-turning-enterprise-apps-into-decision-systems/</guid>
<pubDate>Mon, 22 Jun 2026 13:05:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Last year, I worked with an enterprise leadership team that had made significant investments in its piloting of generative AI in areas such as customer service, IT operations, and productivity workflows. On paper, the organization appeared ahead of the curve. Employees were using copilots. Business units were experimenting with AI assistants. Executives were tracking AI adoption metrics across departments.</p>



<p>But when we looked at operational performance, very little had actually changed.</p>



<p>Approvals remained slow among different teams. Customer escalation was reliant on manual intervention. There was also still time wasted in resolving disparate data sets prior to making a decision. The use of AI in the environment has been optimized, but not its intelligence within the processes and functions of the enterprise itself.</p>



<p>I have seen this pattern in multiple enterprises in the last year, where these organizations are pursuing AI with vigor but cannot move any faster in their business performance.</p>



<p>The question isn’t one of commitment. Most enterprises already have some form of AI initiative.</p>



<p>The problem here is that most organizations continue to use AI technology as a supporting layer and not as an embedded intelligence in their enterprise operations and applications.</p>



<p>That is precisely why there is a much bigger paradigm shift in AI agents than merely automated processes.</p>



<p>They have started to bring change by converting the enterprise systems into something beyond just systems of records to systems of action coordination.</p>



<h2 class="wp-block-heading">Enterprise applications are evolving beyond systems of record</h2>



<p>Enterprise applications have traditionally been transaction systems for decades.</p>



<p>ERP systems have standardized financial processes, procurements, and supply chains. CRM applications have helped organize information about customers and their interactions. HR systems have streamlined employee-related operations.</p>



<p>All these applications provided a robust basis for operations management.</p>



<p>Yet, they required extensive human involvement in interpreting the information, deciding, coordinating, and responding to any changes.</p>



<p>What is changing now is the involvement of AI agents in the processes described above.</p>



<p>AI-enabled enterprise applications are capable not only of reporting and visualizing but also of:</p>



<ul class="wp-block-list">
<li>Detecting operation irregularities</li>



<li>Interpreting the situation in the broader context of different systems</li>



<li>Suggesting next best actions</li>



<li>Coordinating workflows</li>



<li>Learning</li>
</ul>



<p>During an operational analysis conducted during my practice, a procurement team faced significant challenges because of supply disruptions and manual workflow coordination.</p>



<p>People had to spend hours looking through ERP, inventory, logistics, and finance systems to find appropriate sourcing alternatives and make a decision.</p>



<p>This organization introduced an AI application that detected supply risks, proposed sourcing alternatives, and launched relevant approval procedures according to business logic defined beforehand.</p>



<p>It is essential to note that time savings were achieved not just due to automation.</p>



<p>Many organizations still consider the application of AI to be confined to support for productivity. The real potential lies in making enterprise systems capable of intelligent execution.</p>



<h2 class="wp-block-heading">Why many AI initiatives stall before delivering business value</h2>



<p>One consistent lesson that has been learned throughout the years is that AI implementation is not synonymous with operational transformation.</p>



<p>Companies have tended to implement copilot capabilities relatively easily since they involve providing employees with the capability of assisting them with their tasks like creating content or retrieving knowledge.</p>



<p>However, it is common that such bottlenecks stay the same.</p>



<p>Approvals may still traverse many different systems. Decisions continue to be dependent on disparate data sources. Collaboration between departments remains manual. Information still needs substantial verification prior to taking any action based on a recommendation provided by artificial intelligence.</p>



<p>This problem is increasingly being understood in the industry context. It has been termed “<a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/seizing-the-agentic-ai-advantage" rel="nofollow">the Gen AI Paradox</a>” by McKinsey. In its analysis of agentic AI, McKinsey observes that despite the rapid proliferation of generative AI adoption among firms, many firms still have difficulty leveraging their adoption of this technology to make a tangible impact on business outcomes. The deployment of enterprise copilots and AI assistants has outpaced the need for changing operations for improved decision making, coordination, and execution.</p>



<p>In many cases, the primary problem did not come from the model used for AI. The challenge was to incorporate intelligence into the operations process.</p>



<p>This is where Enterprise Intelligence comes into play.</p>



<p>Enterprise Intelligence does not necessarily mean just implementing another form of artificial intelligence technology. It implies the organization’s ability to link AI, enterprise data, workflows, governance, and human decision-making into an effective operation model.</p>



<p>It has been found that successful organizations did not necessarily conduct the most pilots. They focused on optimizing workflows so that the intelligent capabilities reach the point of decision-making.</p>



<h2 class="wp-block-heading">AI agents are changing how enterprise decisions get executed</h2>



<p>The growing emergence of task-specific AI agents is speeding up this trend.</p>



<p>Unlike legacy automation platforms, AI agents are able to be contextually aware within and across business systems and workflows. AI agents are becoming more sophisticated at coordinating actions instead of completing specific, isolated tasks.</p>



<p>This trend becomes particularly apparent in operational systems where decision-making needs to cut across multiple teams and systems.</p>



<p>In ERP systems, for example, AI agents can:</p>



<ul class="wp-block-list">
<li>Detect procurement irregularities</li>



<li>Evaluate risks associated with suppliers</li>



<li>Suggest procurement options</li>



<li>Initiate approval processes</li>



<li>Coordinate activities between procurement, financial and operations teams</li>
</ul>



<p>Within CRM systems, companies are starting to use AI agents to:</p>



<ul class="wp-block-list">
<li>Prioritize customers based on purchase signals</li>



<li>Suggest next best actions in sales</li>



<li>Personalize customer interaction</li>



<li>Automate customer recovery workflows without escalation</li>
</ul>



<p>IT operations represent another domain where this trend is rapidly gaining momentum.</p>



<p>An IT operations team I worked with was able to significantly reduce alert fatigue by implementing an incident coordination process with support from AI assistance, where incidents were prioritized, correlated signals within the infrastructure were detected, and partial remediation tasks were automated. The engineers retained control over decision-making, yet response times got faster since teams did not waste time filtering operational noise.</p>



<p>These examples illustrate a broader point: AI agents are not simply automating tasks. They are reshaping how enterprise decisions are coordinated and executed.</p>



<h2 class="wp-block-heading">Why decision intelligence matters</h2>



<p>With increased AI agent deployment in workflow processes, yet another consideration comes up — ensuring the AI-generated recommendations result in enhanced organizational effectiveness.</p>



<p>This is where the concept of Decision Intelligence plays a crucial role.</p>



<p>For decades, enterprises have believed that more dashboards and analytics automatically equate to better decisions. The opposite has been true in my experience – decision-making gets slowed, fractured, and inconsistent amid an abundance of data.</p>



<p>Information is not enough to effect change.</p>



<p>Decision Intelligence is about optimizing the processes by which decisions get made, governed, monitored, and constantly iterated upon.</p>



<p>Among other considerations, these include:</p>



<ul class="wp-block-list">
<li>What decisions are most impactful for the business?</li>



<li>Where are the operational bottlenecks?</li>



<li>What processes require human decision-making?</li>



<li>Where does AI decision support play a role?</li>



<li>What actions are safe to automate?</li>



<li>What are new governance requirements?</li>
</ul>



<p>Such considerations become especially pertinent with increasing AI agent involvement.</p>



<p>If proper workflow re-design is not accompanied by governance, there is a risk of automating tasks without improving overall performance.</p>



<p>This is an issue that has been increasingly voiced by industry analysts. In this regard, <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure" rel="nofollow">Gartner</a> has indicated that many of the AI agent projects within the enterprises could fail to deliver the desired results without putting into place governance and controls. This is because AI agents will be increasingly responsible for the coordination of tasks in the system, and hence, it becomes necessary to put in place some guardrails as far as decisions are concerned.</p>



<p>I’ve worked with successful companies that managed to lower their service resolution times and increase operational agility only once they focused their AI-powered processes directly on key business metrics like cycle time reductions, escalations avoidance, margins improvement, or customer retention.</p>



<p>That shift — from experimentation to measurable operational impact — is where many enterprises are now focusing their attention.</p>



<h2 class="wp-block-heading">Fragmented AI creates fragmented outcomes</h2>



<p>One of the key operational challenges that I keep running into is fragmented intelligence within the enterprise.</p>



<p>Sales use one set of AI solutions. Customer Service uses another set of AI solutions. Supply Chain uses yet another set of forecasting models. Financial analysis works within an entirely different set of AI workflows.</p>



<p>While each solution might make some progress locally, integration at an enterprise level is often a challenge.</p>



<p>For example, while working with one organization focused primarily on retail, marketing optimization drove more promotional demand than inventory and staffing were able to meet. Each of those areas had its own intelligence, but there was no enterprise-level coordination of intelligence.</p>



<p>The consequence was friction within operations instead of acceleration.</p>



<p>In order for enterprise applications to be ready for the future, this fragmented approach to AI will not work. Enterprise apps have to become systems that integrate signals, workflows, decision-making and execution.</p>



<p>That is essentially the difference between AI being adopted and transformed by an enterprise.</p>



<h2 class="wp-block-heading">Leadership priorities for the AI-agent enterprise</h2>



<p>But as AI agents integrate into enterprise systems, the focus of corporate leaders also needs to shift.</p>



<p>No longer should leaders only think about what kind of AI technologies are going to be deployed.</p>



<p>Instead, they need to ask themselves:</p>



<ul class="wp-block-list">
<li>What outcomes need better performance?</li>



<li>What processes have too much friction?</li>



<li>What decisions are best left to humans?</li>



<li>Where does AI fit in for safe coordination?</li>



<li>Who will govern and oversee how things work?</li>



<li>How will success be tracked and measured?</li>
</ul>



<p>And generally speaking, organizations that are progressing well tend to have an operational approach to AI versus a testing one.</p>



<p>They do not focus on using cutting-edge AI but more on operational efficiency, coordination, governance, and value.</p>



<p>Such transformation is part of a bigger picture. Today’s companies realize that the way to gain any competitive edge does not lie in merely having AI systems, but rather in establishing an “<a href="https://newsroom.ibm.com/2026-05-05-think-2026-ibm-delivers-the-blueprint-for-the-ai-operating-model-as-the-ai-divide-widens" rel="nofollow">AI Operating Model</a>” as proposed by IBM, in which AI agents work together with company data, automation systems, governance, and human decision-making. As AI capabilities become more prevalent, the competitive factor will be found in the way companies design their operations around intelligent execution.</p>



<p>Practically, the best operating model I’ve observed combines human decision-making with AI coordination. In some processes, humans take the lead. In other processes, AI makes suggestions, but the manager makes the final decision. Finally, there could be certain repetitive operations that eventually run independently but with guardrails.</p>



<p>It’s all about intentionality.</p>



<h2 class="wp-block-heading">The future enterprise will operate differently</h2>



<p>Over time, all organizations will gain access to AI models, cloud computing, and enterprise software systems comparable to those used by others.</p>



<p>The difference lies in how well organizations embed intelligence within their workflows.</p>



<p>Organizations that thrive will be those that can develop systems that do all of the following:</p>



<ul class="wp-block-list">
<li>Sense changes early in their operations</li>



<li>Make decisions rapidly</li>



<li>Reduce workflow frictions</li>



<li>Learn continually based on results</li>



<li>Embed their investments in AI directly within their business processes</li>
</ul>



<p>AI agents are helping make this happen.</p>



<p>However, the bigger challenge goes beyond using even more AI.</p>



<p>The challenge involves changing the way enterprises sense, decide, execute, and learn operationally.</p>



<p>This is the evolution currently underway, which will transform enterprise application software and enterprise work in general.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['Plastic trash is now a low-cost aircraft fuel': This new reactor system converts plastic waste into sustainable jet fuel with promising economics]]></title>
<description><![CDATA[Researchers develop a reactor system converting plastic waste into jet fuel, using advanced catalysts with estimated costs of $1.0–$1.8 per kilogram.]]></description>
<link>https://tsecurity.de/de/3614083/it-nachrichten/plastic-trash-is-now-a-low-cost-aircraft-fuel-this-new-reactor-system-converts-plastic-waste-into-sustainable-jet-fuel-with-promising-economics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614083/it-nachrichten/plastic-trash-is-now-a-low-cost-aircraft-fuel-this-new-reactor-system-converts-plastic-waste-into-sustainable-jet-fuel-with-promising-economics/</guid>
<pubDate>Sun, 21 Jun 2026 22:17:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers develop a reactor system converting plastic waste into jet fuel, using advanced catalysts with estimated costs of $1.0–$1.8 per kilogram.]]></content:encoded>
</item>
<item>
<title><![CDATA[Angular Signals in practice: Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 17:21:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h4 class="wp-block-heading">Read the series:</h4>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a></li>



<li><a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a></li>



<li><a href="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html" data-type="link" data-id="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html">Angular Signals in practice: Building a signal-first form in Angular</a></li>
</ul>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 11:18:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Carvana launches its first test drive center at a dealership, with more to come]]></title>
<description><![CDATA[Carvana is converting old car dealerships into test drive centers.]]></description>
<link>https://tsecurity.de/de/3605627/it-nachrichten/carvana-launches-its-first-test-drive-center-at-a-dealership-with-more-to-come/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605627/it-nachrichten/carvana-launches-its-first-test-drive-center-at-a-dealership-with-more-to-come/</guid>
<pubDate>Wed, 17 Jun 2026 19:17:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Carvana is converting old car dealerships into test drive centers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tether is shipping TurboQuant KV-cache quantization with Vulkan support into its QVAC SDK]]></title>
<description><![CDATA[The latest release of qvac-fabric-llm.cpp, the inference engine of the QVAC Fabric LLM, features TurboQuant integration for resource management in long-running inference sessions. Tether adopts the technology as a path to better efficiency when running large



language models on devices with lim...]]></description>
<link>https://tsecurity.de/de/3604787/it-security-nachrichten/tether-is-shipping-turboquant-kv-cache-quantization-with-vulkan-support-into-its-qvac-sdk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604787/it-security-nachrichten/tether-is-shipping-turboquant-kv-cache-quantization-with-vulkan-support-into-its-qvac-sdk/</guid>
<pubDate>Wed, 17 Jun 2026 14:36:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The latest release of qvac-fabric-llm.cpp, the inference engine of the QVAC Fabric LLM, features TurboQuant integration for resource management in long-running inference sessions. Tether adopts the technology as a path to better efficiency when running large</p>



<p>language models on devices with limited compute resources.</p>



<p>TurboQuant is Google’s response to the Key-Value (KV) Cache’s capacity expansion during routine inference, which can reach up to 8GB for a 262,000-token context session using a 4B-parameter large language model.</p>



<p>Tether takes the stage as the first AI research team to ship the KV Cache compression algorithm to a publicly available local AI model. The Turboquant integration will be included in the latest version of the QVAC SDK (v0.12.0) and will be available through <a href="https://github.com/tetherto/qvac-fabric-llm.cpp" target="_blank" rel="noreferrer noopener">Fabric</a>, the inference and fine-tuning engine of the SDK.</p>



<p>This enables developers to serve intelligent models via the qvac-fabric-llm.cpp and compute inferences with negligible loss in precision, while consuming up to 5x less VRAM regardless of context size.</p>



<h2 class="wp-block-heading"><strong>Why does this matter?</strong></h2>



<p>When you use an AI assistant, the model records the results from your previous prompts in temporary memory on your device. This record is known as the Key-Value Cache. The KV Cache is akin to a notepad for jotting down key points in a discussion or while reading a book.</p>



<p>For an AI model, it serves as a reference point each time you ask a follow-up question. This makes it easy for the model to follow up on your conversation without having to re-run the whole thread, which would waste a lot of time.</p>



<p>Transformer-based AI models build their KV Cache by storing the “key points” and their identifier, token-by-token (equivalent to “word for word”) in square grids. When you ask a follow-up question, the model sorts the key point using their precise location in the grid and computes new inferences based on your new input (prompt/question).</p>



<p>The KV Cache is a memory optimization technique and ensures a smooth run throughout each usage session. However, as you continue your conversation with the AI assistant, the KV Cache grows larger and consumes more memory on your device.</p>



<p>For instance, a few hours of conversation that grows into a 262,000-token session could consume up to 8GB of VRAM, which is hardly available in user-grade devices. Despite being temporary, KV cache overload could limit how an AI application can be used, especially when running models locally on devices with limited compute capacity, which is the case for the majority of users. KV Cache bloat is a major bottleneck for local AI, pushing users to cloud-based AI.</p>



<p>As a solution, TurboQuant strategically reduces KV Cache memory bloat by converting high-precision data vectors into lower-bit integers. Similar to reducing the size of the handwriting on the notepad or using signs instead of plain words, it shrinks the space the KV cache occupies.</p>



<h2 class="wp-block-heading"><strong>How Turboquant compresses KV Cache memory</strong></h2>



<p>TurboQuant drastically reduces the memory consumed per cached token by using Polar quantization (PolarQuant) and Quantized Johnson-Lindenstrauss (QJL) techniques to bypass traditional quantization methods that require storing full-precision constants for small blocks of data.</p>



<p>It pairs PolarQuant’s structural efficiency with QJL’s zero-overhead error correction to compress caches up to 3 bits, delivering up to 5x improvement in memory management.</p>



<p>PolarQuant is what reduces the handwriting on the notepad or converts it into signs that consume less memory. It maps the KV Cache data onto a fixed circular grid and uses polar coordinates rather than the standard Cartesian (X, Y, Z) coordinates to locate key points.</p>



<p>This limits the details required to locate data to Angle (meaning of the data) and Radius (weight or importance of the data), rather than the full locational layout. It avoids the expensive data-normalization steps by replacing square grids with circular grids, simplifying vector representation and data location. This is similar to rewriting “Add 7 apples, then add 4 apples” as “Add 11 apples total.”</p>



<p>When compressing KV Cache data with PolarQuant, there is a risk of reducing the data’s weight score (importance rating). This is where the QJL comes in; it acts as a mathematical error-checker that corrects for a possible loss in attention score (the importance given to the data) during quantization. QJL uses signed bits (+1 or -1) to balance quantization errors. This way, it keeps the attention score perfectly (or nearly) accurate by balancing low-precision data with high-precision queries.</p>



<h2 class="wp-block-heading"><strong>TurboQuant on QVAC SDK: More possibilities for Local AI</strong></h2>



<p>TurboQuant is a major breakthrough for local and cloud AI, but especially for local AI, where computing overhead is a major bottleneck for routine use. Tether recognizes the technological brilliance of the algorithm and its potential for models built to operate on tight resources. By compressing what would normally consume 8GB of VRAM down to 1.6GB, TurboQuant frees up resources for your inference machine, expands your bandwidth, and imagination of what can be done with a local superintelligent setup.</p>



<p>The TurboQuant integration via qvac-fabric-llm.cpp is supported by the Vulkan backend. This offers important compatibility and performance advantages attributable to Vulkan’s agnosticism and TurboQuant’s direct GPU execution.</p>



<p>Vulkan support bridges the advantages that TurboQuant offers to a wider range of user-grade devices and vendors outside the NVIDIA ecosystem (AMD and NVIDIA are currently supported, with mobile GPUs planned). It enables users and developers to run highly optimized, compressed local inferences on a wide range of platforms, including personal computers and mobile device GPUs.</p>



<p>TurboQuant’s KV Cache compression happens directly on the device’s GPU and aligns with how a computer naturally handles operations. This means the maths is done on the GPU’s fastest, closest memory, ensuring that models served with <a href="https://github.com/tetherto/qvac-fabric-llm.cpp" target="_blank" rel="noreferrer noopener">Fabric</a> achieve the full 5x reduction in KV cache size while maintaining performance and precision. This lets users run much longer contexts (over 262,000 tokens) without running out of VRAM capacity.</p>



<p>TurboQuant lets you do more, with fewer resources, and in everyday environments. From simple follow-up queries to reviewing files that run in multiple gigabytes on your personal computers or mobile phones, it expands the scale of what can be done with an AI application. In QVAC SDK, it complements other optimization techniques inherent in Tether’s AI framework to power native intelligent systems that support an infinite number of users and autonomous agents. In a ten-billion-strong society, such systems will form a secure, viable, and unstoppable foundation for building the most complex superintelligent units for everyday use, biotechnology, and more.</p>



<p>From a macro perspective, compression techniques that reduce the operational resources required by AI models are the industry standard. The ability to develop and integrate such techniques will significantly impact the success of local AI models and infrastructure.</p>



<p><strong>Tether is committed to building AI solutions that run on any setup and let choose their own biases. Follow the QVAC revolution and contribute to Tether’s drive for open source AI.</strong></p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.3]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Exported renderDelimitedThinking from the @oh-my-pi/pi-ai/dialect barrel so consumers can reuse the dialect's  envelope unwrap-and-rewrap logic (the only ./dialect/rendering primitive re-exported; the rest stay dialect-internal).

Fixed

Fixed OpenAI Responses/Codex tool sc...]]></description>
<link>https://tsecurity.de/de/3603377/tools/v1603/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603377/tools/v1603/</guid>
<pubDate>Wed, 17 Jun 2026 02:23:16 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Exported <code>renderDelimitedThinking</code> from the <code>@oh-my-pi/pi-ai/dialect</code> barrel so consumers can reuse the dialect's <code>&lt;thinking&gt;</code> envelope unwrap-and-rewrap logic (the only <code>./dialect/rendering</code> primitive re-exported; the rest stay dialect-internal).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed OpenAI Responses/Codex tool schema normalization stripping provider-rejected regex lookaround patterns from MCP tool parameter schemas. (<a href="https://github.com/can1357/oh-my-pi/issues/2784" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2784/hovercard">#2784</a>)</li>
<li>Fixed OpenAI Responses parallel tool-call routing so late keyed argument deltas for a closed call are dropped instead of being appended to another open call.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for LaTeX color commands (<code>\textcolor</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>) in user-visible terminal prose and final chat to colorize output</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed STT dependency setup to validate recorder and model assets per <code>stt.modelName</code>, so switching speech models re-runs dependency checks and downloads for the new model</li>
<li>Changed STT startup with cached models to warm the speech model in the background and defer full model loading until transcription begins, reducing push-to-talk start latency</li>
<li>Allowed user-visible terminal and final-chat responses to include LaTeX math delimiters/commands and Mermaid <code>```mermaid</code> diagrams</li>
<li>Changed the hold-<code>Space</code> push-to-talk gesture to recognize a held bar from the <em>regularity</em> of the OS key auto-repeat rather than a raw space count or speed alone, so it no longer spams the editor, no longer eats deliberate space taps, and no longer triggers when the bar is smashed. Recording starts only after two consecutive inter-space deltas are "mechanical" — both fast (within ~120 ms) and near-identical, the metronomic signature of auto-repeat; the few pre-burst spaces typed are then tracked back out. Smashing (fast but jittery) and deliberate spacing (steady but slow) both keep typing real spaces and never start recording.</li>
<li>Updated markdown Mermaid rendering to color ASCII diagrams with the active theme and automatically choose a narrower layout that better fits the terminal width</li>
<li>Made the watched-session transcript sent to the advisor (and shown by <code>/advisor dump</code>) clearer: each turn now opens with a <code>### Session update</code> heading; watched-agent roles render as inline <code>**agent**:</code> / <code>**user**:</code> labels instead of level-2 headings that collided with the advisor's own turns; consecutive same-role messages collapse under one label (the watched agent emits one assistant message per tool call); and batched updates are joined by a blank line rather than a <code>---</code> rule.</li>
<li>Changed the compact transcript tool-intent prefix (<code>history://</code>, <code>/advisor dump</code>) from <code># </code> to <code>// </code> so intent lines read as comments instead of rendering as Markdown H1 headings.</li>
<li>Changed the advisor advice injected into the primary transcript from a <code>Advisor (...): - [severity] note</code> prose block to one <code>&lt;advisory severity="…" guidance="weigh, don't blindly obey"&gt;…&lt;/advisory&gt;</code> element per note, with XML-escaped bodies. (Relocated the shared <code>escapeXmlText</code> helper to <code>@oh-my-pi/pi-utils</code>.)</li>
<li>Reverted <code>/dump</code> and <code>/advisor dump raw</code> to the pre-16.x full verbose dump: system prompt, model/thinking config, tool inventory with parameters, and the message transcript rendered with markdown role headings (<code>## User</code>, <code>## Assistant</code>, <code>### Tool Call: &lt;name&gt;</code> with the call's <code>_i</code> intent as a <code>//</code> comment under the heading and the remaining arguments as a fenced YAML block, <code>### Tool Result: &lt;name&gt;</code>, plus <code>## Bash Execution</code>/<code>## File Mention</code>/summary sections) instead of the model's native-dialect turn envelopes and <code>&lt;invoke&gt;</code>/<code>&lt;parameter&gt;</code> XML tool calls. Dropped the compact default and the <code>[raw]</code> flag on <code>/dump</code>; the compact <code>→ tool(...) ⇒ ok</code> history format is no longer reachable from <code>/dump</code>. <code>/advisor dump</code> still defaults to compact, and <code>/advisor dump raw</code> now renders the same markdown dump (previously the model's native-dialect envelopes).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Whisper STT cache detection to require both encoder and decoder <code>.onnx</code> files, so partial model downloads now trigger a proper foreground download instead of being treated as fully cached</li>
<li>Fixed same-process <code>JsRuntime</code> cleanup so disposing an older inline/direct runtime no longer deletes a newer runtime's JS helper globals; inactive cmux/direct runtimes now re-activate their globals before sequential use while overlapping cross-runtime runs fail explicitly.</li>
<li>Fixed magic-keyword steering notices (<code>ultrathink-notice</code>, <code>orchestrate-notice</code>, <code>workflow-notice</code>) to be prepended before the related user message so they influence that same turn</li>
<li>Fixed dequeuing or popping queued user messages to remove their preceding hidden magic-keyword notice companions, preventing orphaned queued notices</li>
<li>Fixed queued user steers to auto-resume after interrupts even when the transcript tail is a preserved advisor card or other non-conversational custom message</li>
<li>Fixed queued user follow-up messages to remain queued after an interrupt and only run on explicit resume, even when an IRC wake leaves a provider-valid tail</li>
<li>Fixed stranded IRC asides to wake a response turn after interruption instead of remaining pending</li>
<li>Fixed accepted IRC asides to be flushed into the transcript during disposal instead of being discarded</li>
<li>Fixed interactive submissions made while the TUI had no active input waiter: they now start a real prompt directly, with steer fallback if a background turn races in, instead of queueing behind a non-resumable idle transcript and appearing to do nothing.</li>
<li>Fixed pressing Esc (or Alt+Up dequeue) while agent-authored messages were queued — advisor concern/blocker notes, hidden goal/plan/budget steers, IRC/extension asides — dumping their text into the user's editor. Editor restoration (<code>clearQueue()</code>), pending chips (<code>getQueuedMessages()</code>), and <code>popLastQueuedMessage()</code> now surface only genuinely user-authored queued messages (plain user turns and <code>attribution: "user"</code> custom messages like <code>/skill</code>). Plain Alt+Up dequeue leaves all other queued messages in place for the continuing stream; only the Esc interrupt path keeps just advisor cards (so abort's preservation still re-records them as visible advice) and drops other internal steers, so a user interrupt can't be silently undone by an auto-resume on leftover internal context. <code>queuedMessageCount</code> still reflects all actual queued work (advisor cards included) so <code>hasPendingMessages()</code>/RPC and the empty-submit abort gate stay accurate.</li>
<li>Fixed advisor <code>concern</code>/<code>blocker</code> advice being withheld from the running agent and then dumped as one burst at the next user prompt after a deliberate interrupt. A user interrupt latches advisor auto-resume suppression, but a non-user resume (synthetic/auto-continue, or a queued steer draining after the abort) leaves the run streaming with that latch still set, so every interrupting note was parked hidden in the next-turn queue instead of steered into the live turn — the agent never heard the advisor mid-run and the backlog flushed all at once on the next prompt. Suppression now only withholds interrupting advice while the agent is idle (or still tearing the interrupted turn down); once a turn is streaming again the note is steered in live, since steering an active run never auto-resumes a stopped one. A concern that strands in the steer queue past the resumed turn's final poll is reclaimed as visible advice when the agent settles (mirroring abort), so it neither auto-resumes the stopped run nor lingers to flush at the next prompt.</li>
<li>Fixed <code>omp --continue</code>/<code>-c</code> sometimes resuming into a subagent transcript instead of the interactive session. Subagent (and HTML-export) <code>SessionManager.open()</code> calls run in the parent's terminal and were clobbering the per-TTY <code>--continue</code> breadcrumb with their own artifact-dir session file; these headless opens now suppress the breadcrumb. <code>continueRecent()</code> also recovers already-poisoned breadcrumbs by resolving any session file inside a parent's artifacts dir (<code>&lt;parent&gt;/&lt;agentId&gt;.jsonl</code>) back up to the top-level session.</li>
<li>Fixed the Agent Hub stacking duplicate <code>Agent Hub · N running</code> frames and stranding garbage rows in scrollback while navigating with subagents still streaming. The hub was a non-fullscreen overlay composited over a live transcript, so each time a running subagent's progress grew the frame and scrolled the window the previously-painted hub copy was pushed permanently into the terminal's native scrollback (which the engine can't rewrite). It now renders inline in the editor slot — the same anchored region every other selector and the <code>ask</code> tool use — riding the normal append-only commit path, so the transcript commits above it exactly once and the hub repaints in place instead of leaking copies. (Avoids borrowing the alternate screen.)</li>
<li>Fixed every subagent registering itself as its own parent in the agent registry (<code>parentId === id</code>), so the Agent Hub rendered each agent as <code>sub · of &lt;itself&gt;</code> and the ←← parent-navigation gesture looped on the same agent. The SDK was reusing <code>parentTaskPrefix</code> — the agent's own artifact/output-id prefix — as the registry parent link; spawns now pass a separate <code>parentAgentId</code> (the spawning agent's id: <code>Main</code> for top-level <code>task</code> spawns, the parent subagent for nested spawns and eval <code>agent()</code>, the focused agent for <code>/tan</code>) and the registry records that as the parent.</li>
<li>Fixed messaging a <code>parked</code> subagent that was restored from disk (Agent Hub scan, or a resumed/restarted session) failing with <code>cannot be revived (no reviver registered)</code> even though its transcript was intact. Such refs carry a session file but no in-memory reviver — the executor's live reviver closure dies with the spawning turn/process — so IRC sends and Agent Hub focus refused them. <code>AgentLifecycleManager.ensureLive</code> now cold-revives them through a persisted-subagent reviver factory (installed by the top-level interactive/RPC session) that rebuilds the subagent from its JSONL the way <code>--resume</code> rebuilds a session: it reopens the file and replays it through <code>createAgentSession</code>, but sources the runtime contract from a now-readable <code>session_init</code> record (<code>SessionManager.peekSessionInit</code>) so tools, system prompt, output schema, and kind are restored rather than resurrected as a default top-level session. <code>session_init</code> now also persists the effective <code>spawns</code> allowlist and read-summarization flag so a cold revive keeps the original capability surface (old files without them deny re-spawning rather than defaulting to wildcard). Isolated runs and pre-<code>session_init</code> files whose recorded workspace no longer exists stay transcript-only (<code>history://</code>).</li>
<li>Fixed the terminal window-title OSC writes (<code>setTerminalTitle</code>/<code>pushTerminalTitle</code>/<code>popTerminalTitle</code>) leaking escape sequences to a developer's terminal during <code>bun test</code>; they now skip when the terminal is headless (the test-runtime default), matching the <code>ProcessTerminal</code> render/probe suppression so interactive-mode tests no longer paint to the real terminal</li>
<li>Fixed empty CLI sessions being retained after opening <code>omp</code> and exiting without a prompt (<a href="https://github.com/can1357/oh-my-pi/issues/2800" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2800/hovercard">#2800</a>).</li>
<li>Fixed <code>hooks/pre/*.ts</code> and <code>hooks/post/*.ts</code> files discovered through <code>hookCapability</code> being registered in discovery but never loaded into the extension runner, so their <code>tool_call</code> handlers now run without a manual <code>settings.json</code> <code>extensions</code> entry (<a href="https://github.com/can1357/oh-my-pi/issues/2796" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2796/hovercard">#2796</a>).</li>
<li>Fixed startup model fallback choosing the plain OpenAI <code>gpt-5.5</code> provider before the Codex OAuth provider when both shared the same default model id, which could surface a misleading OpenAI 401 despite valid Codex credentials (<a href="https://github.com/can1357/oh-my-pi/issues/2807" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2807/hovercard">#2807</a>).</li>
<li>Fixed local auto-thinking classification for reasoning-capable tiny models by giving them the same safe answer budget as online reasoning classifiers, with a larger local floor for non-reasoning tiny models (<a href="https://github.com/can1357/oh-my-pi/issues/2808" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2808/hovercard">#2808</a>).</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the built-in <code>render_mermaid</code> tool and its <code>renderMermaid.enabled</code> setting, so it can no longer be invoked directly</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Removed</h3>
<ul>
<li>Removed rendering support for the <code>render_mermaid</code> tool from the web tool registry</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added <code>\tfrac</code> support to stacked display-math rendering so it now displays as a vertical fraction in <code>latexToBlock</code> output</li>
<li>Added markdown parsing for own-line display-math blocks (<code>$$...$$</code> and <code>\[...\]</code>) and delimiter-free <code>\begin{...}...\end{...}</code> math environments so block equations render via LaTeX-to-Unicode</li>
<li>Added stacked rendering of display-math fractions (<code>\frac</code>, <code>\dfrac</code>, <code>\cfrac</code>): the numerator is drawn over a horizontal bar over the denominator, with surrounding terms and <code>align</code>/<code>equation</code>-style environment rows aligned to the bar. Triggered for own-line <code>$$</code>/<code>\[</code> blocks, bare <code>\begin{...}</code> environments, and a paragraph whose sole content is a single display-math span; inline <code>$...$</code> fractions stay single-line (<code>½</code>, <code>(a+b)/c</code>)</li>
<li>Added bare math auto-rendering in <code>renderMathInText</code> for math-shaped lines and math environment blocks that omit <code>$</code>/<code>\(</code> delimiters</li>
<li>Added LaTeX-to-Unicode rendering for markdown math spans, converting <code>$$...$$</code>, <code>$...$</code>, <code>\(...\)</code>, and <code>\[...\]</code> into readable Unicode in Markdown output</li>
<li>Exported LaTeX conversion helpers from the package entrypoint so consumers can call <code>latexToUnicode</code>, <code>latexToBlock</code>, <code>renderMathInText</code>, <code>inlineMathSpanEnd</code>, and <code>isBareMathEnvironment</code> directly</li>
<li>Expanded LaTeX-to-Unicode conversion coverage for additional math fonts, delimiters, extensible arrows, layout environments, cancel/brace annotations, references, and AMS symbols</li>
<li>Added ANSI color rendering for LaTeX <code>\textcolor</code>, scoped <code>\color</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>, including xcolor/CSS color parsing and truecolor/256-color terminal output</li>
<li>Added an optional <code>maxWidth</code> parameter to <code>MarkdownTheme.resolveMermaidAscii</code> to allow diagram resolvers to fit ASCII output to the available content width</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed markdown math rendering to preserve multiline layout for display equations, keeping <code>\\</code> row breaks as separate output lines (including inside list items)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>alignat</code>/<code>alignedat</code>/<code>gatheredat</code> rendering in <code>latexToBlock</code> so the required <code>{n}</code> preamble is not rendered as visible math content</li>
<li>Fixed math parsing to leave non-math LaTeX snippets (for example <code>\begin{itemize}</code>) and fenced code blocks as literal text instead of rendering them as math</li>
<li>Fixed <code>renderInlineMarkdown</code> to handle top-level display-math tokens so raw <code>$$...$$</code> delimiters are no longer leaked</li>
<li>Fixed inline math span detection so escaped dollars and currency-like patterns (such as <code>$5</code> and <code>$10</code>) are not converted as math</li>
<li>Fixed Mermaid diagram rendering in Markdown code blocks to clip each ASCII line to content width before wrapping, preventing preformatted diagram rows from fragmenting</li>
<li>Fixed fullscreen overlays losing keyboard focus to hidden prompt surfaces, which could make settings unresponsive while a background approval request was pending (<a href="https://github.com/can1357/oh-my-pi/issues/2789" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2789/hovercard">#2789</a>).</li>
<li>Fixed <code>bun test</code> runs inside a real terminal leaking TUI output: <code>ProcessTerminal</code> now honors a headless test-runtime default, so frame paints, <code>start()</code> capability probes (OSC 11 / DA1 / kitty), the progress keepalive, notifications, and teardown escapes no longer reach the developer's terminal, and stdin raw mode is never engaged. Previously <code>#safeWrite</code> only skipped on <code>!process.stdout.isTTY</code>, so a developer running the suite in an interactive terminal saw stray status/editor boxes and probe queries. Terminal-contract suites opt back into real I/O via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>escapeXmlText</code> utility to escape XML-significant characters <code>&amp;</code>, <code>&lt;</code>, and <code>&gt;</code> in element body text</li>
<li>Added <code>isTerminalHeadless()</code> / <code>setTerminalHeadless()</code> to centrally suppress real-terminal side effects (stdout escape/frame writes, stdin raw mode, CSI/OSC capability probes, SIGWINCH, window-title changes, emergency restore) under the test runtime. Defaults on when <code>bun test</code> sets <code>NODE_ENV=test</code>; terminal-contract tests opt out via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): keep overlay focus above hidden prompts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676940403" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2795" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2795/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2795">#2795</a></li>
<li>fix(coding-agent): load discovered hook factories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677385980" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2798" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2798/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2798">#2798</a></li>
<li>fix(cli): skip empty session persistence by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677808827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2804" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2804/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2804">#2804</a></li>
<li>fix(coding-agent): prefer Codex default auth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678553738" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2810">#2810</a></li>
<li>fix(coding-agent): expand local auto-thinking classifier budget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678723092" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2814" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2814/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2814">#2814</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.2...v16.0.3"><tt>v16.0.2...v16.0.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Intelligent Shield. OpenCTI]]></title>
<description><![CDATA[Beyond Ingestion Subtitle: Deploying AI-Driven Enrichment in OpenCTITransforming Threat Data into High-Confidence IntelligenceIn an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the c...]]></description>
<link>https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Beyond Ingestion <strong>Subtitle:</strong> Deploying AI-Driven Enrichment in OpenCTI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yZJrYF0KW4x5gzDg6xNN6A.png"></figure><h3>Transforming Threat Data into High-Confidence Intelligence</h3><p>In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the critical lack of context. “The Intelligent Shield” introduces a new paradigm: beyond simply ingesting data, it’s about deploying advanced, automated machine learning pipelines for <strong>AI-driven enrichment.</strong></p><p>This guide demonstrates how to integrate state-of-the-art Large Language Models (LLMs), such as <strong>Claude AI</strong>, into an <strong>OpenCTI</strong> ecosystem. By leveraging the <strong>OpenCTI STIX 2.1 Knowledge Graph</strong> and natural language processing, this architecture converts disparate, unstructured data feeds into high-fidelity, actionable intelligence. It automatically builds context, executes deep mapping to frameworks like the <strong>MITRE ATT&amp;CK Matrix</strong>, and generates calculated, real-time <strong>Confidence Scores</strong>, enabling organizations to proactively strengthen their defenses with an intuitive, automated <strong>Intelligent Shield.</strong></p><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#6e45"><strong>What is OpenCTI?</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#8ff6"><strong>Core Capabilities</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7dc1"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7865"><strong>Threat Intelligence Feeds</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fe8e"><strong>AI Integration Layer</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#c6df"><strong>Prerequisites</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7c94"><strong>Docker Compose Deployment</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#b276"><strong>Connector Configuration</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#a2bd"><strong>AI-Driven Enrichment Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#99be"><strong>Post-Deployment Hardening</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fd26"><strong>Operational Runbook</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#aabb"><strong>Troubleshooting</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7e3e"><strong>Usage Examples</strong></a></li></ol><h3>1. What is OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSYjMAN2q5yyUccU6F6daQ.png"></figure><p><strong>OpenCTI</strong> (Open Cyber Threat Intelligence) is an open-source platform developed by Filigran (formerly a project of ANSSI, the French national cybersecurity agency) for structuring, storing, organizing, visualizing, and sharing cyber threat intelligence (CTI).</p><p>It implements the <strong>STIX 2.1</strong> (Structured Threat Information eXpression) standard as its native data model and exposes a <strong>GraphQL API</strong> for all read/write operations. Every object — threat actors, campaigns, malware, vulnerabilities, indicators, attack patterns — is stored as a STIX Domain Object (SDO) or STIX Relationship Object (SRO) backed by two databases:</p><ul><li><strong>ElasticSearch / OpenSearch</strong> — full-text search and analytics</li><li><strong>Apache Cassandra (via JanusGraph)</strong> — graph relationship storage</li></ul><h3>Why OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1a3jOT66dfRuy3XvkQJ5NQ.png"></figure><h3>2. Core Capabilities</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uj2dA3oWyo03XyrbjkNrGg.png"></figure><h4>2.1 Knowledge Graph</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YvoudJ_c2ItEwEgTZ8TGaQ.png"></figure><ul><li>Entities: Threat Actors, Intrusion Sets, Campaigns, Malware, Tools, Vulnerabilities (CVE), Attack Patterns (MITRE ATT&amp;CK), Courses of Action, Sectors, Countries, Organizations</li><li>Relationships modelled as first-class STIX SROs with confidence scores, date ranges, and TLP markings</li><li>Diamond Model and Kill Chain views built in</li></ul><h4>2.2 Indicator Management</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pGfNRDKffBczwNJeMydW8w.png"></figure><ul><li>IOC lifecycle: valid_from / valid_until with automatic expiry</li><li>Detection rule generation (Sigma, YARA, Snort)</li><li>Bulk import via STIX, CSV, OpenIOC, MISP formats</li><li>Scoring and confidence weighting per source</li></ul><h4>2.3 MITRE ATT&amp;CK Navigator Integration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jOEvP3job4uFFPBnXLIkA.png"></figure><ul><li>Full ATT&amp;CK Enterprise / Mobile / ICS matrices</li><li>Heatmaps of technique usage per threat actor or campaign</li><li>Gap analysis against your current detection coverage</li></ul><h4>2.4 Threat Actor Profiling</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*N98FeMPaxF2ZYnhLF8kEGQ.png"></figure><ul><li>Attributed aliases, motivations (financial, espionage, hacktivism)</li><li>Geo and sector targeting mapped on world map</li><li>Timeline of campaigns and malware usage</li></ul><h4>2.5 Automation &amp; Playbooks</h4><ul><li>Built-in playbook engine (since v5.9): trigger enrichment, notifications, or SOAR actions on entity creation/modification(<strong>Enterprise Edition only)</strong></li><li>Python SDK for custom automation</li><li>Webhook support for external integrations</li></ul><h4>2.6 Collaboration &amp; Sharing</h4><ul><li>Role-based access control (RBAC) with groups and organizations</li><li>TLP (Traffic Light Protocol) enforcement at object level</li><li>TAXII 2.1 server — push feeds to SIEMs, firewalls, EDR platforms</li><li>Sharing with partner organizations via federated instances</li></ul><h4>2.7 Dashboard &amp; Reporting</h4><ul><li>Customizable dashboards with widget library</li><li>PDF report generation</li><li>Timeline, matrix, and entity views</li><li>Attack path visualization</li></ul><h3>3. Architecture Overview</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAFxmmcNnaHdD8ZDbXIbDw.png"></figure><h3>4. Threat Intelligence Feeds</h3><h4>4.1 Free / Open-Source Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zamxLo7VEhjGX0cOnZvRJQ.png"></figure><ul><li><a href="https://attack.mitre.org/?utm_source=chatgpt.com"><strong>MITRE ATT&amp;CK</strong></a> — Connector: opencti/connector-mitre — Data: Techniques, mitigations, groups, software — Setup: API key not needed.</li><li><a href="https://nvd.nist.gov/?utm_source=chatgpt.com"><strong>CVE / NVD</strong></a> — Connector: opencti/connector-cve — Data: Vulnerabilities — Setup: <a href="https://nvd.nist.gov/developers/request-an-api-key">NVD API key</a> recommended/required depending on configuration.</li><li><a href="https://otx.alienvault.com/?utm_source=chatgpt.com"><strong>AlienVault OTX</strong></a> — Connector: opencti/connector-alienvault — Data: IOCs, pulses, malware families — Setup: Free OTX account/API key.</li><li><a href="https://bazaar.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch MalwareBazaar</strong></a> — Connector: opencti/connector-malwarebazaar — Data: Malware hashes, malware metadata, file observables — Setup: Free MalwareBazaar API key.</li><li><a href="https://urlhaus.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch URLhaus</strong></a> — Connector: opencti/connector-urlhaus — Data: Malicious URLs — Setup: Public feed; no API key for CSV feed.</li><li><a href="https://feodotracker.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch Feodo Tracker</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> or ingest the Feodo CSV/blocklist feed manually — Data: Botnet C2 IPs — Setup: Free.</li><li><a href="https://internetdb.shodan.io/"><strong>Shodan InternetDB</strong></a> — Connector: opencti/connector-shodan-internetdb — Data: IP enrichment, domains, CPEs, CVEs, tags — Setup: No API key required.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>MISP Default / CIRCL OSINT Feeds</strong></a> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> — Data: STIX/MISP bundles, indicators, observables — Setup: Free.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>CyberCrime-Tracker feed via MISP default feeds</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> rather than a dedicated current connector — Data: C2 panels / freetext indicators — Setup: Free.</li><li><a href="https://openphish.com/?utm_source=chatgpt.com"><strong>OpenPhish</strong></a> — Connector: no verified current dedicated OpenCTI connector in the main repo; use generic feed ingestion where suitable — Data: Phishing URLs — Setup: Free/community feed options.</li><li><strong>DigitalSide IT-ISAC MISP Feed</strong> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> with custom MISP_FEED_URL — Data: IOCs / MISP-format feed — Setup: Free.</li></ul><h4>4.2 Commercial Feeds (require license/API key)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dMgCc4cuy0X9LxEAcR0PiQ.png"></figure><ul><li><a href="https://www.misp-project.org/"><strong>MISP — self-hosted</strong></a> — Connector: opencti/connector-misp — Strengths: community sharing, custom events, internal/private CTI exchange. The OpenCTI repo lists both misp and misp-feed; use misp for a live MISP instance with API access, and misp-feed for static MISP feed URLs.</li><li><a href="https://www.virustotal.com/"><strong>VirusTotal / Google Threat Intelligence</strong></a> — Connector: opencti/connector-virustotal — Strengths: file, URL, domain, and IP enrichment. The connector is under internal-enrichment, not external-import.</li><li><strong>Mandiant Threat Intelligence / Google Threat Intelligence</strong> — Connector: opencti/connector-mandiant — Strengths: APT intelligence, actor reporting, malware/campaign context.</li><li><a href="https://www.recordedfuture.com/"><strong>Recorded Future</strong></a> — Connectors: opencti/connector-recordedfuture and opencti/connector-recordedfuture-enrichment — Strengths: risk lists, enrichment, vulnerability/contextual intelligence, dark web and external threat data. Recorded Future documentation describes the OpenCTI integration as two components: an enrichment connector and a Recorded Future connector.</li><li><a href="https://www.crowdstrike.com/products/threat-intelligence/"><strong>CrowdStrike Falcon Intelligence</strong></a> — Connector: opencti/connector-crowdstrike — Strengths: actor tracking, indicators, adversary intelligence, Falcon ecosystem context.</li><li><a href="https://www.sekoia.io/"><strong>Sekoia.io Intelligence</strong></a> — Connector: opencti/connector-sekoia — Strengths: European threat landscape, CTI feed ingestion, actor/campaign context. Sekoia’s own documentation points to the OpenCTI GitHub connector path.</li><li><a href="https://threatconnect.com/"><strong>ThreatConnect</strong></a> — Connector: <strong>no verified current dedicated connector in the main OpenCTI connector tree</strong> — Strengths: enterprise TI management, source aggregation, workflow and case management. I found an OpenCTI GitHub label/feature reference for “threat connect,” but not a confirmed current connector folder equivalent to external-import/threatconnect.</li><li><a href="https://intel471.com/"><strong>Intel 471</strong></a> — Connectors: opencti/connector-intel471, opencti/connector-intel471-darknet, and opencti/connector-intel471_v2 — Strengths: underground forums, cybercrime actors, malware, infrastructure, dark web intelligence.</li></ul><h4>4.3 ISAC / Government Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dtrgjORW-h5AoEi0rOMBHw.png"></figure><ul><li><a href="https://www.cisa.gov/resources-tools/services/automated-indicator-sharing-ais-service?utm_source=chatgpt.com"><strong>CISA Automated Indicator Sharing / AIS</strong></a> — Method: TAXII/STIX client, AIS 2.0 uses TAXII 2.1 — Access: free service for eligible participants; contact CISA to onboard.</li><li><a href="https://www.fsisac.com/?utm_source=chatgpt.com"><strong>FS-ISAC</strong></a> — Method: STIX/TAXII and MISP automated feeds — Access: financial-sector membership; automated-feed credentials/licensing must be explicitly requested.</li><li><a href="https://health-isac.org/"><strong>Health-ISAC / H-ISAC</strong></a> — Method: HITS indicator-sharing feed; STIX/TAXII-compatible threat intelligence sharing — Access: healthcare-sector membership / Health-ISAC member access.</li><li><a href="https://www.misp-project.org/communities/?utm_source=chatgpt.com"><strong>NATO MISP Community</strong></a> — Method: MISP community / MISP sync — Access: official government cyber-defense entities from NATO nations, sponsored by their national representative in the NATO Multinational MISP Steering Board.</li><li><a href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape?utm_source=chatgpt.com"><strong>ENISA Threat Landscape</strong></a> — Method: public reports and CTI publications; not a confirmed public TAXII/STIX feed. ENISA’s CTL methodology references STIX 2.1 as a common CTI representation format, but this is different from offering a public feed endpoint.</li></ul><h4>4.4 Feed Priority and TLP Assignment</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XhNw0PBdOVuwb9zHT37S5Q.png"></figure><pre># Recommended TLP assignment by source<br>feeds:<br>  - source: mitre_attack<br>    tlp: WHITE          # public, shareable<br>    confidence: 90<br>  - source: alienvault_otx<br>    tlp: GREEN          # community sharing<br>    confidence: 60<br>  - source: mandiant<br>    tlp: AMBER          # restricted to org<br>    confidence: 85<br>  - source: internal_soc<br>    tlp: RED            # internal only<br>    confidence: 95</pre><h3>5. AI Integration Layer</h3><p>This is the “AI-driven” layer on top of standard OpenCTI — a custom connector and MCP server that adds:</p><h4>5.1 AI Enrichment Connector (Claude API)</h4><ul><li>On every new Report, Malware, or Threat-Actor ingested → call Claude API</li><li>Extract structured STIX entities from unstructured text (PDFs, blog posts)</li><li>Summarize long reports into 3-sentence executive briefs</li><li>Score indicator relevance against your organization’s sector profile</li><li>Suggest ATT&amp;CK technique mappings from narrative descriptions</li></ul><h4>5.2 AI Pipeline Architecture</h4><pre>New Report ingested<br>        │<br>        ▼<br>[AI Enrichment Connector]<br>        │<br>        ├─► Claude API: Extract entities → creates STIX SDOs<br>        ├─► Claude API: Map to ATT&amp;CK techniques<br>        ├─► Claude API: Generate executive summary<br>        └─► Claude API: Score severity for your sector<br>                │<br>                ▼<br>        Update Report in OpenCTI<br>        (summary, related entities, confidence scores)</pre><h3>6. Prerequisites</h3><h4>6.1 Hardware (minimum production)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ics48TK_7nXqH-diy8Uzng.png"></figure><h4>6.2 Software</h4><pre># Install Docker Engine (Ubuntu 22.04)<br>sudo apt-get update<br>sudo apt-get install -y ca-certificates curl gnupg lsb-release<br>sudo install -m 0755 -d /etc/apt/keyrings<br>curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \<br>  sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg<br>sudo chmod a+r /etc/apt/keyrings/docker.gpg<br>echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \<br>  https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \<br>  sudo tee /etc/apt/sources.list.d/docker.list &gt; /dev/null<br>sudo apt-get update<br>sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin<br># Add user to docker group<br>sudo usermod -aG docker $USER<br>newgrp docker<br># Verify<br>docker compose version</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*eM3O8rdQsyvwxf-0WEZX8w.png"></figure><h4>6.3 System Tuning (required for ElasticSearch)</h4><pre># ElasticSearch requires high vm.max_map_count<br>sudo sysctl -w vm.max_map_count=1048575<br>echo "vm.max_map_count=1048575" | sudo tee -a /etc/sysctl.conf<br><br># Increase file descriptor limits<br>echo "* soft nofile 65536" | sudo tee -a /etc/security/limits.conf<br>echo "* hard nofile 65536" | sudo tee -a /etc/security/limits.conf</pre><h3>7. Docker Compose Deployment</h3><h4><strong>7.0 Deploy from GitHub (recommended)</strong></h4><p>The fastest deployment path is to clone the maintained project repository and create a local `.env` from the sanitized template:</p><pre>cd /home/andrey<br>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd /home/andrey/openCTI<br># Create local secrets/config. This file is ignored by Git.<br>cp .env.example .env<br>nano .env<br># Start the full stack after filling in .env<br>./scripts/start-all.sh</pre><p>This gives you the Docker Compose files, OpenCTI patches, AI enrichment connector, helper scripts, and Docusaurus documentation in one checkout. Use the manual sections below if you want to recreate the files by hand or compare the generated content.</p><h4>7.1 Directory Structure</h4><pre>/home/andrey/openCTI/<br>├── .env                          # secrets and config<br>├── docker-compose.yml            # core stack<br>├── docker-compose.connectors.yml # feed connectors<br>├── docker-compose.ai.yml         # AI enrichment connector<br>├── patches/<br>│   └── back.js                   # ILM race condition fix (ES 8.13 + OpenCTI 6.2.0)<br>└── connectors/<br>    └── ai-enrichment/            # custom AI connector source</pre><h4>7.2 Environment File</h4><pre>cat &gt; /home/andrey/openCTI/.env &lt;&lt; 'EOF'<br># === Core ===<br>OPENCTI_ADMIN_EMAIL=admin@opencti.local<br>OPENCTI_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD<br>OPENCTI_ADMIN_TOKEN=CHANGE_ME_UUID4_TOKEN<br>OPENCTI_BASE_URL=http://localhost:8080<br><br># === Secrets ===<br>APP__ADMIN__TOKEN=CHANGE_ME_UUID4_TOKEN<br>APP__SECRET_KEY=CHANGE_ME_SECRET<br><br># === ElasticSearch ===<br># NOTE: key is ELASTIC_PASSWORD, not ELASTIC_AUTH<br>ELASTIC_PASSWORD=CHANGE_ME_ELASTIC_PASS<br><br># === Redis ===<br>REDIS_PASSWORD=opencti<br><br># === MinIO ===<br>MINIO_ROOT_USER=opencti<br>MINIO_ROOT_PASSWORD=CHANGE_ME_MINIO_PASS<br><br># === RabbitMQ ===<br>RABBITMQ_DEFAULT_USER=opencti<br>RABBITMQ_DEFAULT_PASS=CHANGE_ME_RABBITMQ_PASS<br><br># === Connector IDs (unique UUID4 per connector — NOT used for auth) ===<br>CONNECTOR_MITRE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_CVE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ALIENVAULT_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ABUSE_SSL_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_URLHAUS_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_AI_ENRICHMENT_TOKEN=CHANGE_ME_UUID4<br><br># === External API keys ===<br>ALIENVAULT_API_KEY=your_otx_key_here<br>NVD_API_KEY=your_nvd_api_key_here     # UUID format from nvd.nist.gov/developers/request-an-api-key<br>ANTHROPIC_API_KEY=your_claude_api_key_here<br>EOF<br><br># Generate unique UUIDs for connector IDs<br>python3 -c "import uuid; [print(uuid.uuid4()) for _ in range(8)]"# Generate proper tokens<br>python3 -c "import uuid; [print(f'Token: {uuid.uuid4()}') for _ in range(10)]"</pre><h4>7.3 Core Stack — docker-compose.yml</h4><pre>nano docker-compose.yml</pre><pre>version: "3"<br>services:<br>  redis:<br>    image: redis:7.2<br>    restart: always<br>    volumes:<br>      - redisdata:/data<br>    command: redis-server --requirepass ${REDIS_PASSWORD:-opencti}<br>  elasticsearch:<br>    image: docker.elastic.co/elasticsearch/elasticsearch:8.13.0<br>    volumes:<br>      - esdata:/usr/share/elasticsearch/data<br>    environment:<br>      - discovery.type=single-node<br>      - xpack.ml.enabled=false<br>      - xpack.security.enabled=true<br>      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD:-CHANGE_ME}<br>      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"<br>      - cluster.routing.allocation.disk.threshold_enabled=false<br>    ulimits:<br>      memlock:<br>        soft: -1<br>        hard: -1<br>    restart: always<br>  minio:<br>    image: minio/minio:RELEASE.2024-01-16T16-07-38Z<br>    volumes:<br>      - miniodata:/data<br>    ports:<br>      - "9001:9001"   # console<br>    environment:<br>      MINIO_ROOT_USER: ${MINIO_ROOT_USER:-opencti}<br>      MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>    command: server /data --console-address ":9001"<br>    restart: always<br>  rabbitmq:<br>    image: rabbitmq:3.13-management<br>    environment:<br>      RABBITMQ_DEFAULT_USER: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ_DEFAULT_PASS: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      RABBITMQ_NODENAME: rabbit01@localhost<br>    volumes:<br>      - rabbitmqdata:/var/lib/rabbitmq<br>    restart: always<br>  opencti:<br>    image: opencti/platform:6.2.0<br>    environment:<br>      NODE_OPTIONS: --max-old-space-size=8096<br>      APP__PORT: 8080<br>      APP__BASE_URL: ${OPENCTI_BASE_URL:-http://localhost:8080}<br>      APP__ADMIN__EMAIL: ${OPENCTI_ADMIN_EMAIL}<br>      APP__ADMIN__PASSWORD: ${OPENCTI_ADMIN_PASSWORD}<br>      APP__ADMIN__TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      APP__APP_LOGS__LOGS_LEVEL: error<br>      REDIS__HOSTNAME: redis<br>      REDIS__PORT: 6379<br>      REDIS__USE_SSL: "false"<br>      REDIS__PASSWORD: ${REDIS_PASSWORD:-opencti}<br>      ELASTICSEARCH__URL: http://elasticsearch:9200<br>      ELASTICSEARCH__USERNAME: elastic<br>      ELASTICSEARCH__PASSWORD: ${ELASTIC_PASSWORD:-CHANGE_ME}<br>      MINIO__ENDPOINT: minio<br>      MINIO__PORT: 9000<br>      MINIO__USE_SSL: "false"<br>      MINIO__ACCESS_KEY: ${MINIO_ROOT_USER:-opencti}<br>      MINIO__SECRET_KEY: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>      RABBITMQ__HOSTNAME: rabbitmq<br>      RABBITMQ__PORT: 5672<br>      RABBITMQ__USERNAME: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ__PASSWORD: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      SMTP__HOSTNAME: localhost<br>      PROVIDERS__LOCAL__STRATEGY: LocalStrategy<br>    volumes:<br>      - ./patches/back.js:/opt/opencti/build/back.js:ro<br>    ports:<br>      - "8080:8080"<br>    depends_on:<br>      - redis<br>      - elasticsearch<br>      - minio<br>      - rabbitmq<br>    restart: always<br>  worker:<br>    image: opencti/worker:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      WORKER_LOG_LEVEL: error<br>    depends_on:<br>      - opencti<br>    deploy:<br>      mode: replicated<br>      replicas: 3<br>    restart: always<br>volumes:<br>  esdata:<br>  redisdata:<br>  miniodata:<br>  rabbitmqdata:<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.4 Connectors — docker-compose.connectors.yml</h4><pre>nano docker-compose.connectors.yml</pre><pre>version: "3"<br>services:<br>  # MITRE ATT&amp;CK (no API key needed)<br>  connector-mitre:<br>    image: opencti/connector-mitre:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MITRE_TOKEN}<br>      CONNECTOR_NAME: "MITRE ATT&amp;CK"<br>      CONNECTOR_SCOPE: "marking-definition,identity,attack-pattern,course-of-action,intrusion-set,campaign,malware,tool,vulnerability,x-mitre-matrix,x-mitre-tactic,x-mitre-collection"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CONNECTOR_LOG_LEVEL: error<br>      MITRE_REMOVE_STATEMENT_MARKING: "true"<br>      MITRE_INTERVAL: 7  # days between full refresh<br>    restart: always<br>  # CVE / NVD Vulnerabilities<br>  connector-cve:<br>    image: opencti/connector-cve:6.2.0<br>    volumes:<br>      - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>      - ./patches/cve/vulnerability.py:/opt/opencti-connector-cve/services/client/vulnerability.py:ro<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_CVE_TOKEN}<br>      CONNECTOR_NAME: "Common Vulnerabilities and Exposures"<br>      CONNECTOR_SCOPE: "identity,vulnerability"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: info<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CVE_BASE_URL: "https://services.nvd.nist.gov/rest/json/cves"<br>      CVE_API_KEY: ${NVD_API_KEY}<br>      CVE_MAX_DATE_RANGE: 120<br>      CVE_MAINTAIN_DATA: "true"<br>      CVE_INTERVAL: 2<br>    restart: always<br>  # AlienVault OTX<br>  connector-alienvault:<br>    image: opencti/connector-alienvault:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_ALIENVAULT_TOKEN}<br>      CONNECTOR_NAME: "AlienVault OTX"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      ALIENVAULT_BASE_URL: "https://otx.alienvault.com"<br>      ALIENVAULT_API_KEY: ${ALIENVAULT_API_KEY}<br>      ALIENVAULT_TLP: "White"<br>      ALIENVAULT_CREATE_OBSERVABLES: "true"<br>      ALIENVAULT_CREATE_INDICATORS: "true"<br>      ALIENVAULT_PULSE_START_TIMESTAMP: "2020-01-01T00:00:00"<br>      ALIENVAULT_REPORT_STATUS: "New"<br>      ALIENVAULT_REPORT_TYPE: "threat-report"<br>      ALIENVAULT_GUESS_MALWARE: "false"<br>      ALIENVAULT_GUESS_CVE: "false"<br>      ALIENVAULT_INTERVAL: 30   # minutes<br>    restart: always<br>  # Abuse.ch SSL Blacklist<br>  connector-abuse-ssl:<br>    image: opencti/connector-abuse-ssl:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MALWAREBAZAAR_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch SSL Blacklist"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 50<br>      CONNECTOR_LOG_LEVEL: error<br>      ABUSE_SSL_URL: "https://sslbl.abuse.ch/blacklist/sslblacklist.csv"<br>      ABUSE_SSL_INTERVAL: 30  # minutes<br>    restart: always<br>  # Abuse.ch URLhaus<br>  connector-urlhaus:<br>    image: opencti/connector-urlhaus:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_URLHAUS_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch URLhaus"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      URLHAUS_CSV_URL: "https://urlhaus.abuse.ch/downloads/csv_recent/"<br>      URLHAUS_IMPORT_OFFLINE: "true"<br>      URLHAUS_INTERVAL: 2  # hours<br>    restart: always<br>  connector-threatfox:<br>    image: opencti/connector-threatfox:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_THREATFOX_TOKEN}<br>      CONNECTOR_NAME: "ThreatFox"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      THREATFOX_API_URL: "https://threatfox-api.abuse.ch/api/v1/"<br>      THREATFOX_CREATE_INDICATORS: "true"<br>      THREATFOX_CREATE_OBSERVABLES: "true"<br>      THREATFOX_INTERVAL: 3<br>    restart: always<br>  connector-import-document:<br>    image: opencti/connector-import-document:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_IMPORT_DOCUMENT_TOKEN}<br>      CONNECTOR_NAME: "ImportDocument"<br>      CONNECTOR_SCOPE: "application/pdf,text/plain,text/html"<br>      CONNECTOR_AUTO: "true"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: error<br>    restart: always<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.5 AI Enrichment Connector — docker-compose.ai.yml</h4><pre>nano docker-compose.ai.yml</pre><pre>version: "3"<br><br>services:<br>  connector-ai-enrichment:<br>    build:<br>      context: ./connectors/ai-enrichment<br>      dockerfile: Dockerfile<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_AI_ENRICHMENT_TOKEN}<br>      CONNECTOR_NAME: "AI Enrichment (Claude)"<br>      CONNECTOR_LOG_LEVEL: info<br>      ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}<br>      AI_MODEL: claude-opus-4-7<br>      AI_ENRICHMENT_REPORTS: "true"<br>      AI_ENRICHMENT_MALWARE: "true"<br>      AI_ENRICHMENT_THREAT_ACTORS: "true"<br>    restart: always<br><br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h3>8. Connector Configuration</h3><h4>Fast Start / Stop Scripts</h4><p>The repository includes two helper scripts for daily operations:</p><pre># Start core OpenCTI, wait for the UI/API, then start connectors and AI enrichment<br>./scripts/start-all.sh<br># Stop AI enrichment, connectors, and core OpenCTI while preserving Docker volumes<br>./scripts/stop-all.sh</pre><p>Use these scripts for normal start/stop operations after .env is configured. Use the manual commands below when debugging a specific service startup problem.</p><pre>nano start-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>WAIT_TIMEOUT="${WAIT_TIMEOUT:-300}"<br><br>wait_for_opencti() {<br>  local deadline=$((SECONDS + WAIT_TIMEOUT))<br><br>  echo "[start] Waiting for OpenCTI API on http://localhost:8080..."<br>  until curl -fsS http://localhost:8080 &gt;/dev/null 2&gt;&amp;1; do<br>    if (( SECONDS &gt;= deadline )); then<br>      echo "[start] OpenCTI did not become reachable within ${WAIT_TIMEOUT}s." &gt;&amp;2<br>      echo "[start] Check logs with: docker compose logs -f opencti" &gt;&amp;2<br>      return 1<br>    fi<br>    sleep 5<br>  done<br>}<br><br>echo "[start] Starting OpenCTI core stack..."<br>docker compose -f docker-compose.yml up -d<br><br>wait_for_opencti<br><br>echo "[start] Starting external connectors..."<br>docker compose -f docker-compose.connectors.yml up -d<br><br>echo "[start] Building and starting AI enrichment connector..."<br>docker compose -f docker-compose.ai.yml up -d --build<br><br>echo "[start] Done."<br>docker compose -f docker-compose.yml ps</pre><pre>nano stop-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>echo "[stop] Stopping OpenCTI core, connectors, and AI enrichment..."<br>docker compose \<br>  -f docker-compose.yml \<br>  -f docker-compose.connectors.yml \<br>  -f docker-compose.ai.yml \<br>  down --remove-orphans<br><br>echo "[stop] Done. Volumes are preserved."</pre><h4>8.1 Start the Core Stack</h4><pre>cd /home/andrey/openCTI<br><br># Pre-flight: ElasticSearch refuses allocation above 90% disk usage<br>df -h /var/lib/docker<br># If &gt; 90% full, run: docker system prune -a   (frees ~47 GB of unused images)<br><br># Create the shared Docker network (idempotent — safe to re-run)<br>docker network create opencti_network 2&gt;/dev/null || true<br><br># Start core services<br>docker compose -f docker-compose.yml up -d<br><br># Wait for ElasticSearch to be healthy before OpenCTI finishes initializing<br>until curl -s -u "elastic:${ELASTIC_PASSWORD}" \<br>  http://localhost:9200/_cluster/health | grep -q '"status":"green"\|"status":"yellow"'; do<br>  echo "Waiting for ES..."; sleep 5<br>done<br><br># Watch logs — first-run index creation takes 5-10 minutes<br># Look for "Listening on port 8080"<br>docker compose -f docker-compose.yml logs -f opencti | grep -E "Listening|ERROR|indices"</pre><h4>8.2 Start Connectors</h4><pre># Start feed connectors (after OpenCTI is healthy)<br>docker compose -f docker-compose.connectors.yml up -d<br># Verify connectors registered (wait ~60s for startup)<br>docker compose -f docker-compose.connectors.yml ps</pre><h4>8.3 Verify in UI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bgDghte5c5Hd2tKbutvP8A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fIQLlAGqYjzNesmSnRw2QQ.png"></figure><pre>http://localhost:8080<br>Login: admin@opencti.local / &lt;your password&gt;Navigation:<br>  Data → Connectors → check all show status "connected"<br>  Knowledge → Malwares → should start populating within minutes<br>  Activities → Logs → watch ingest events</pre><h3>9. AI-Driven Enrichment Pipeline</h3><h4>Overview</h4><p>The AI enrichment pipeline adds a Claude-powered layer on top of the standard OpenCTI ingestion flow. Every time a connector (AlienVault, MITRE, URLhaus, etc.) writes a new object into OpenCTI, an event is published to RabbitMQ. The AI connector subscribes to that event stream, calls the Claude API with the object’s content, and writes the extracted structured intelligence back into the graph as STIX relationships, notes, and entity updates — all automatically.</p><p><strong>Without AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                   (raw text, no relationships, no ATT&amp;CK mapping)</pre><p><strong>With AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                       ↓ AI connector picks it up from event stream<br>                   Claude API: extract entities, map techniques, score severity<br>                       ↓<br>                   Report now has:<br>                   ├── Note: executive summary (2-3 sentences)<br>                   ├── Relationship → ThreatActor (if found in graph)<br>                   ├── Relationship → Malware (if found in graph)<br>                   ├── Relationship → AttackPattern T1059.001 (created if missing)<br>                   └── x_opencti_score updated based on AI confidence</pre><h4>9.1 How the Event Stream Works</h4><p>OpenCTI uses RabbitMQ as its internal message bus. Every write operation (create, update, delete) on any STIX object publishes a message to a topic exchange. Connectors subscribe to this exchange via pycti's OpenCTIConnectorHelper.listen() method.</p><pre>OpenCTI platform<br>      │<br>      │ write event (STIX bundle)<br>      ▼<br>  RabbitMQ<br>  exchange: amq.topic<br>      │<br>      ├──► worker-1 (standard workers — write to ES/graph)<br>      ├──► worker-2<br>      ├──► worker-3<br>      └──► connector-ai-enrichment  ← our connector subscribes here<br>                  │<br>                  │ reads event payload:<br>                  │ {<br>                  │   "type": "create",<br>                  │   "data": { "id": "report--uuid", "type": "report", ... }<br>                  │ }<br>                  ▼<br>            calls Claude API<br>                  ▼<br>            writes enrichment back via GraphQL API</pre><p>Each message contains the full STIX object that was just created. The connector processes it and acknowledges the message — if it crashes mid-processing, RabbitMQ redelivers it.</p><p><strong>Connector type </strong><strong>INTERNAL_ENRICHMENT</strong> means:</p><ul><li>It does not import data on a schedule</li><li>It reacts to existing objects as they are created or updated</li><li>It appears in Settings → Connectors → Enrichment in the UI</li></ul><h4>9.2 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.10. Post-Deployment Hardening</p><h4>9.2 What Claude Extracts and How It Maps to STIX</h4><p>The connector sends the report’s description text to Claude with a structured prompt. Claude returns JSON. The connector then maps each field to STIX operations:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f1BfkVeUO3Qlt9Kj6-MkFg.png"></figure><p>Claude output fieldSTIX actionsummaryCreates a Note object attached to the report (object_refs)threat_actors[]Looks up ThreatActor by name in graph → creates related-to relationship to reportmalware_families[]Looks up Malware by name → creates related-to relationship to reportattack_techniques[]Looks up AttackPattern by external_id (T1059.001) → creates uses relationship to reporttargeted_sectors[]Looks up Identity (sector) → creates targets relationshiptargeted_countries[]Looks up Location by ISO code → creates targets relationshipconfidenceSets x_opencti_score on the report (0–100)</p><p><strong>Why look up instead of creating?</strong> MITRE ATT&amp;CK and identity data is already loaded by the MITRE connector. Looking up prevents duplicates. Only AttackPattern objects are created if missing (since Claude may identify techniques not yet in the graph).</p><h4>9.3 Connector Code</h4><pre>mkdir -p /home/andrey/openCTI/connectors/ai-enrichment</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/connector.py"><strong>connectors/ai-enrichment/connector.py</strong></a></p><pre>import os<br>import json<br>import time<br>import anthropic<br>from pycti import OpenCTIConnectorHelper<br><br>SYSTEM_PROMPT = """You are a senior cyber threat intelligence analyst.<br>Analyze threat intelligence content and return structured JSON only.<br>No prose, no markdown fences, no explanation — raw JSON."""<br><br>REPORT_PROMPT = """Analyze this threat intelligence report. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief, plain text)<br>- threat_actors: list of strings (actor names, aliases, groups mentioned)<br>- malware_families: list of strings (malware/tool names)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs only, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (e.g. ["Finance", "Healthcare", "Government"])<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2, e.g. ["US", "UA", "DE"])<br>- confidence: integer 0-100<br><br>Report:<br>{content}"""<br><br>INTRUSION_SET_PROMPT = """Analyze this threat actor / intrusion set profile. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief)<br>- aliases: list of strings (other known names)<br>- malware_families: list of strings (malware/tools this actor uses)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (sectors this actor targets)<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2 codes)<br>- motivation: string (one of: "espionage", "financial", "hacktivism", "destruction", "unknown")<br>- sophistication: string (one of: "minimal", "intermediate", "advanced", "expert", "unknown")<br>- confidence: integer 0-100<br><br>Profile:<br>{content}"""<br><br><br>class AIEnrichmentConnector:<br>    def __init__(self):<br>        config = {<br>            "opencti": {<br>                "url": os.environ.get("OPENCTI_URL", "http://opencti:8080"),<br>                "token": os.environ["OPENCTI_TOKEN"],<br>            },<br>            "connector": {<br>                "id": os.environ["CONNECTOR_ID"],<br>                "type": "INTERNAL_ENRICHMENT",<br>                "name": os.environ.get("CONNECTOR_NAME", "AI Enrichment (Claude)"),<br>                "scope": "Report,Intrusion-Set,Threat-Actor-Group,Malware",<br>                "log_level": os.environ.get("CONNECTOR_LOG_LEVEL", "info"),<br>                "auto": False,<br>            },<br>        }<br>        self.helper = OpenCTIConnectorHelper(config)<br>        self.client = anthropic.Anthropic(api_key=os.environ["ANTHROPIC_API_KEY"])<br>        self.model = os.environ.get("AI_MODEL", "claude-opus-4-7")<br><br>    # -------------------------------------------------------------------------<br>    # Claude call with retry on rate limit<br>    # -------------------------------------------------------------------------<br><br>    def _call_claude(self, prompt_template: str, content: str) -&gt; dict | None:<br>        for attempt in range(3):<br>            try:<br>                msg = self.client.messages.create(<br>                    model=self.model,<br>                    max_tokens=2048,<br>                    system=SYSTEM_PROMPT,<br>                    messages=[{"role": "user", "content": prompt_template.format(content=content[:8000])}],<br>                )<br>                return json.loads(msg.content[0].text)<br>            except anthropic.RateLimitError:<br>                wait = 60 * (attempt + 1)<br>                self.helper.log_warning(f"Rate limited — waiting {wait}s")<br>                time.sleep(wait)<br>            except (json.JSONDecodeError, anthropic.APIError) as e:<br>                self.helper.log_error(f"Claude call failed: {e}")<br>                return None<br>        return None<br><br>    # -------------------------------------------------------------------------<br>    # STIX write-back helpers<br>    # -------------------------------------------------------------------------<br><br>    def _add_note(self, entity_id: str, summary: str, confidence: int) -&gt; None:<br>        self.helper.api.note.create(<br>            abstract="AI Summary",<br>            content=summary,<br>            confidence=confidence,<br>            object_ids=[entity_id],<br>        )<br><br>    def _link_threat_actors(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            actor = self.helper.api.threat_actor_group.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if actor:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=actor["id"],<br>                    relationship_type="related-to",<br>                    confidence=confidence,<br>                )<br><br>    def _link_malware(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            malware = self.helper.api.malware.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if malware:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=malware["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _link_attack_patterns(self, entity_id: str, technique_ids: list, confidence: int) -&gt; None:<br>        for tid in technique_ids:<br>            pattern = self.helper.api.attack_pattern.read(<br>                filters={"mode": "and", "filters": [{"key": "x_mitre_id", "values": [tid]}], "filterGroups": []}<br>            )<br>            if not pattern:<br>                pattern = self.helper.api.attack_pattern.create(<br>                    name=tid,<br>                    x_mitre_id=tid,<br>                    confidence=50,<br>                )<br>            if pattern:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=pattern["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _update_score(self, entity_id: str, confidence: int) -&gt; None:<br>        self.helper.api.stix_domain_object.update_field(<br>            id=entity_id,<br>            input={"key": "x_opencti_score", "value": str(confidence)},<br>        )<br><br>    # -------------------------------------------------------------------------<br>    # Enrichment handlers per entity type<br>    # -------------------------------------------------------------------------<br><br>    def _enrich_report(self, report: dict) -&gt; str:<br>        content = report.get("description") or ""<br>        if len(content) &lt; 50:<br>            content = report.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching report: {report['name']}")<br>        result = self._call_claude(REPORT_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = report["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("threat_actors"):<br>            self._link_threat_actors(entity_id, result["threat_actors"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self._update_score(entity_id, confidence)<br>        self.helper.log_info(f"Enriched report '{report['name']}'")<br>        return "Enriched"<br><br>    def _enrich_intrusion_set(self, entity: dict) -&gt; str:<br>        content = entity.get("description") or entity.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching intrusion set: {entity['name']}")<br>        result = self._call_claude(INTRUSION_SET_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = entity["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self.helper.log_info(f"Enriched intrusion set '{entity['name']}'")<br>        return "Enriched"<br><br>    # -------------------------------------------------------------------------<br>    # Event handler<br>    # -------------------------------------------------------------------------<br><br>    def process_message(self, data: dict) -&gt; str:<br>        entity_type = data.get("entity_type", "").lower()<br>        entity_id = data.get("entity_id")<br>        enrichment_entity = data.get("enrichment_entity", {})<br><br>        self.helper.log_info(f"Received entity_type='{entity_type}' id='{entity_id}'")<br><br>        if not entity_id:<br>            return "Skipped"<br><br>        entity = enrichment_entity or {}<br><br>        if entity_type == "report":<br>            if not entity:<br>                entity = self.helper.api.report.read(id=entity_id) or {}<br>            if entity.get("confidence", 0) &lt; 40:<br>                return "Skipped: low confidence"<br>            return self._enrich_report(entity)<br><br>        if entity_type in ("intrusion-set", "threat-actor-group"):<br>            if not entity:<br>                entity = self.helper.api.intrusion_set.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            return self._enrich_intrusion_set(entity)<br><br>        if entity_type == "malware":<br>            if not entity:<br>                entity = self.helper.api.malware.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            content = entity.get("description") or entity.get("name", "")<br>            if not content or len(content) &lt; 10:<br>                return "Skipped: content too short"<br>            self.helper.log_info(f"Enriching malware: {entity['name']}")<br>            result = self._call_claude(REPORT_PROMPT, content)<br>            if not result:<br>                return "Skipped: Claude error"<br>            confidence = result.get("confidence", 50)<br>            if result.get("summary"):<br>                self._add_note(entity["id"], result["summary"], confidence)<br>            if result.get("attack_techniques"):<br>                self._link_attack_patterns(entity["id"], result["attack_techniques"], confidence)<br>            self._update_score(entity["id"], confidence)<br>            return "Enriched"<br><br>        return "Skipped"<br><br>    def start(self):<br>        self.helper.log_info("AI Enrichment connector starting...")<br>        self.helper.listen(self.process_message)<br><br><br>if __name__ == "__main__":<br>    AIEnrichmentConnector().start()</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/Dockerfile"><strong>connectors/ai-enrichment/Dockerfile</strong></a></p><pre>FROM python:3.11-slim<br>WORKDIR /app<br>COPY requirements.txt .<br>RUN pip install --no-cache-dir -r requirements.txt<br>COPY connector.py .<br>CMD ["python", "connector.py"]</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/requirements.txt"><strong>connectors/ai-enrichment/requirements.txt</strong></a></p><pre>pycti&gt;=6.2.0<br>anthropic&gt;=0.40.0</pre><h4>9.4 Deploy the AI Connector</h4><p><strong>Prerequisites:</strong> Set ANTHROPIC_API_KEY in .env first.</p><pre>cd /home/andrey/openCTI<br># Build the image<br>docker compose -f docker-compose.ai.yml build<br># Start it<br>docker compose -f docker-compose.ai.yml up -d<br># Verify it registered with OpenCTI (look for "AI Enrichment" in connector list)<br>docker logs opencti-connector-ai-enrichment-1 --tail=20</pre><p>In the OpenCTI UI: <strong>Settings → Connectors → Enrichment</strong> — the connector should appear with status connected after ~10 seconds.</p><h4>9.5 Testing the Pipeline</h4><p>Trigger a manual enrichment by importing a real threat report:</p><pre># Import a STIX report via the API to trigger the connector<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $(grep OPENCTI_ADMIN_TOKEN .env | cut -d= -f2)" \<br>  -H "Content-Type: application/json" \<br>  -d '{<br>    "query": "mutation { reportAdd(input: { name: \"Test: APT29 spearphishing campaign\", description: \"APT29, also known as Cozy Bear, conducted a spearphishing campaign targeting NATO members using a malicious PDF dropper that installed Cobalt Strike beacon via PowerShell (T1059.001). The campaign targeted defense contractors in Poland and Germany. The malware communicated with C2 over HTTPS using domain fronting (T1090.004).\", published: \"2024-01-15T00:00:00Z\", report_types: [\"threat-report\"] }) { id name } }"<br>  }'</pre><p>Then check what the AI connector wrote back:</p><pre># Watch connector logs for the enrichment<br>docker logs -f opencti-connector-ai-enrichment-1 2&gt;&amp;1 | grep -E "Enriching|Enriched|Error"<br># Expected output:<br># Enriching report: Test: APT29 spearphishing campaign<br># Enriched: 1 actors, 1 malware, 2 techniques</pre><p>In the UI, open the report — it should now have a Note with the summary, relationships to APT29 and Cobalt Strike, and links to T1059.001 and T1090.004.</p><h4>9.6 Cost and Rate Limiting</h4><p><strong>Estimated Claude API cost per report:</strong></p><ul><li>~500–2000 tokens input (report text, truncated at 8000 chars)</li><li>~300 tokens output (JSON response)</li><li>At claude-opus-4-7 pricing: ~$0.01–0.05 per report</li></ul><p><strong>Rate limiting:</strong> The Anthropic API has per-minute token limits. If AlienVault imports hundreds of reports in a burst, the connector will hit rate limits. Add a simple backoff:</p><pre>import time<br>def _call_claude(self, content: str) -&gt; dict | None:<br>    for attempt in range(3):<br>        try:<br>            msg = self.client.messages.create(...)<br>            return json.loads(msg.content[0].text)<br>        except anthropic.RateLimitError:<br>            time.sleep(60 * (attempt + 1))<br>        except (json.JSONDecodeError, anthropic.APIError) as e:<br>            self.helper.log_error(f"Claude call failed: {e}")<br>            return None<br>    return None</pre><p><strong>To limit scope</strong> (only enrich reports above a confidence threshold, skip low-quality feeds):</p><pre>def process_message(self, data: dict) -&gt; str:<br>    report = self.helper.api.report.read(id=entity_id)<br>    # Skip reports with low confidence (e.g. AlienVault auto-generated)<br>    if report.get("confidence", 0) &lt; 40:<br>        return "Skipped: low confidence"<br>    return self._enrich_report(report)</pre><h4>9.7 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epLGa3gwJILd0FyMKdsQQg.png"></figure><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.</p><h3>10. Post-Deployment Hardening</h3><h4>10.1 Reverse Proxy with TLS (nginx)</h4><pre># /etc/nginx/sites-available/opencti<br>server {<br>    listen 443 ssl http2;<br>    server_name opencti.yourdomain.com;<br>ssl_certificate     /etc/letsencrypt/live/opencti.yourdomain.com/fullchain.pem;<br>    ssl_certificate_key /etc/letsencrypt/live/opencti.yourdomain.com/privkey.pem;<br>    ssl_protocols       TLSv1.2 TLSv1.3;<br>    ssl_ciphers         ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;<br>    location / {<br>        proxy_pass         http://127.0.0.1:8080;<br>        proxy_set_header   Host $host;<br>        proxy_set_header   X-Real-IP $remote_addr;<br>        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header   X-Forwarded-Proto $scheme;<br>        proxy_read_timeout 300s;<br>        client_max_body_size 100m;<br>    }<br>}<br>server {<br>    listen 80;<br>    server_name opencti.yourdomain.com;<br>    return 301 https://$host$request_uri;<br>}</pre><h4>10.2 Backup Strategy</h4><pre>#!/bin/bash<br># /home/andrey/openCTI/scripts/backup.sh<br>set -euo pipefail<br>BACKUP_DIR="/mnt/backup/opencti/$(date +%Y%m%d_%H%M%S)"<br>mkdir -p "$BACKUP_DIR"<br># Snapshot ElasticSearch<br>curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  -X PUT "http://localhost:9200/_snapshot/backup/snapshot_$(date +%Y%m%d)" \<br>  -H 'Content-Type: application/json' \<br>  -d '{"indices": "*", "ignore_unavailable": true}'<br># Dump MinIO (reports, files)<br>docker run --rm \<br>  --network opencti_network \<br>  -v "$BACKUP_DIR:/backup" \<br>  minio/mc:latest \<br>  mirror myminio/opencti /backup/minio/<br>echo "Backup completed: $BACKUP_DIR"</pre><h4>10.3 Security Checklist</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hjQWso4p7MIiBfcRr15oZw.png"></figure><ul><li>Change all default passwords in .env</li><li>Generate unique UUID4 tokens for every connector</li><li>Enable TLS via nginx reverse proxy</li><li>Restrict port 8080 to localhost only (127.0.0.1:8080:8080)</li><li>Enable ElasticSearch authentication (already configured above)</li><li>Set up fail2ban on the nginx access log</li><li>Rotate OPENCTI_ADMIN_TOKEN every 90 days</li><li>Review TLP markings — ensure nothing RED leaks via TAXII</li><li>Enable audit logging: APP__APP_LOGS__LOGS_LEVEL: info</li></ul><h3>11. Operational Runbook</h3><h4>Day 1 — Initial Data Load</h4><pre># MITRE ATT&amp;CK loads first (foundational framework)<br># Wait ~10 minutes for it to complete, then verify:<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br><br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ attackPatterns { edges { node { name } } } }"}' | \<br>  python3 -c "import sys,json; d=json.load(sys.stdin); print('Techniques loaded:', len(d['data']['attackPatterns']['edges']))"<br># Should return 500+ techniques</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V2XGUwLrUpe1XNLUono5Ng.png"></figure><h4>Common Operations</h4><pre># Check all connector health<br>docker compose -f docker-compose.connectors.yml ps<br># View connector logs<br>docker compose -f docker-compose.connectors.yml logs --tail=50 connector-alienvault<br># Restart a stuck connector<br>docker compose -f docker-compose.connectors.yml restart connector-malwarebazaar<br># Scale workers for high ingest load<br>docker compose -f docker-compose.yml up -d --scale worker=5<br># Check ElasticSearch cluster health<br>curl -s -u elastic:${ELASTIC_PASSWORD} http://localhost:9200/_cluster/health?pretty<br># Check RabbitMQ queue depth (should stay near 0 at rest)<br>docker exec $(docker ps -qf name=rabbitmq) rabbitmqctl list_queues name messages</pre><h4>Monitoring Metrics to Watch</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dn9gJsZa98wedqD6PdcrQA.png"></figure><h4>Quick Reference</h4><pre># Start everything<br>cd /home/andrey/openCTI<br>docker network create opencti_network 2&gt;/dev/null || true<br>docker compose -f docker-compose.yml up -d<br>docker compose -f docker-compose.connectors.yml up -d<br>docker compose -f docker-compose.ai.yml up -d<br># Stop everything<br>docker compose -f docker-compose.ai.yml down<br>docker compose -f docker-compose.connectors.yml down<br>docker compose -f docker-compose.yml down<br># Access<br># UI:      http://localhost:8080<br># API:     http://localhost:8080/graphql<br># MinIO:   http://localhost:9001<br># RabbitMQ: http://localhost:15672</pre><h3>12. Troubleshooting</h3><h3>Known Issues — OpenCTI 6.2.0 + ElasticSearch 8.13</h3><h4>ILM Race Condition (resource_already_exists_exception)</h4><p>ES 8.13’s ILM daemon auto-bootstraps rollover indices the moment an index template with lifecycle.rollover_alias is created. OpenCTI's elCreateIndex does a check-then-create which loses the race. This kills initialization and loops with restart: always.</p><p><strong>Fix already applied:</strong> patches/back.js is mounted over the compiled bundle and makes elCreateIndex idempotent — it catches resource_already_exists_exception and returns null.</p><p><strong>Re-initialization procedure</strong> (if ES volume is dropped):</p><pre># 1. Delete any leftover index templates from a failed run<br>curl -s -u elastic:${ELASTIC_PASSWORD} -X DELETE \<br>  "http://localhost:9200/_index_template/opencti*"</pre><pre># 2. Flush Redis state<br>docker exec opencti-redis-1 redis-cli -a opencti FLUSHALL</pre><pre># 3. Start ES first, wait for green/yellow<br>docker compose up -d elasticsearch<br>until curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  <a href="http://localhost:9200/_cluster/health">http://localhost:9200/_cluster/health</a> | grep -q '"status":"green"\|"status":"yellow"'; do<br>  sleep 5; done</pre><pre># 4. Start the rest — OpenCTI will create 13 indices and load base STIX data (~5-10 min)<br>docker compose up -d</pre><h4>ElasticSearch Disk Watermark (cluster RED, no shard allocation)</h4><p>ES 8.x refuses all shard allocation when disk exceeds 90% high watermark. cluster.routing.allocation.disk.threshold_enabled=false is set in docker-compose.yml.</p><p>To reclaim disk space:</p><pre>docker system prune -a   # frees ~47 GB of unused images/containers</pre><h4>Connectors Can’t Reach opencti Hostname</h4><p>Both compose files must share the same Docker network. docker-compose.yml defines:</p><pre>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><p>If the main stack was started without this, run:</p><pre>docker network connect --alias opencti opencti_network opencti-opencti-1</pre><p>Then add the networks: block to docker-compose.yml and run docker compose up -d to make it permanent.</p><h4>OPENCTI_TOKEN vs CONNECTOR_ID</h4><p>Connectors authenticate to OpenCTI using OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}. The per-connector UUID variables (CONNECTOR_MITRE_TOKEN, etc.) are only used as CONNECTOR_ID — they identify the connector instance in the UI, not for authentication.</p><h4>CVE Connector — Zero Vulnerabilities Imported (NVD API Key Bug)</h4><p>connector-cve:6.2.0 has a bug: it sends the NVD API key as Bearer: &lt;key&gt; in the HTTP header, but NVD 2.0 API requires apiKey: &lt;key&gt;. The connector silently gets a non-200 response and imports nothing. Additionally, CVE_MAX_DATE_RANGE is required but missing from the image's default config — omitting it causes a TypeError: '&gt;' not supported between instances of 'NoneType' and 'int' crash every 60 seconds.</p><p><strong>Fix:</strong> Mount a patched api.py that uses the correct header, and add the missing vars:</p><pre>connector-cve:<br>  image: opencti/connector-cve:6.2.0<br>  volumes:<br>    - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>  environment:<br>    CVE_MAX_DATE_RANGE: 120<br>    CVE_MAINTAIN_DATA: "true"<br>    # ... other vars</pre><p>patches/cve/api.py — change header from "Bearer": api_key to "apiKey": api_key:</p><pre>headers = {"User-Agent": header}<br>if api_key:<br>    headers["apiKey"] = api_key</pre><h3>13. Usage Examples</h3><h4>13.1 Standard OpenCTI Workflows</h4><h4>Example 1 — Investigate an IP address</h4><p>You received an alert from your SIEM about suspicious outbound traffic to 103.113.70.102.</p><p><strong>In OpenCTI UI:</strong></p><pre>Search → type 103.113.70.102</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2k7QE2Urnr8tw_xJ2MyAPA.png"></figure><p>If AlienVault or URLhaus has seen it, you’ll find:</p><ul><li>Which threat actor uses this IP as C2</li><li>What malware family communicates with it</li><li>When it was first/last observed</li><li>TLP marking and confidence score</li><li>All reports that mention it</li></ul><p><strong>Via API:</strong></p><pre>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ stixCyberObservables(filters: {mode: and, filters: [{key: \"value\", values: [\"https://103.113.70.102/bin/support.client.exe\"]}], filterGroups: []}) { edges { node { id entity_type ... on Url { value } } } } }"}' | python3 -m json.tool</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fe53xHSxwntH5knkGjSO6g.png"></figure><h4>Example 2 — Build an APT profile</h4><p>You want to understand everything known about Lazarus Group before a threat briefing.</p><pre><br>Threats → Intrusion Sets → search "Lazarus"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S-QNk2tNF4lgs9q6-YaTUQ.png"></figure><p>The profile shows:</p><ul><li><strong>Attributed to:</strong> North Korea</li><li><strong>Motivations:</strong> Financial gain, Espionage</li><li><strong>Targets:</strong> Finance, Cryptocurrency, Defense</li><li><strong>Malware used:</strong> WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)</li><li><strong>Techniques:</strong> 80+ ATT&amp;CK techniques with usage relationships</li><li><strong>Campaigns:</strong> Operation AppleJeus, Dream Job, etc.</li><li><strong>Timeline:</strong> chronological view of all activity</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Gmvuu4OUs0uIgRZDt9p3fA.png"></figure><p>Click <strong>“ATT&amp;CK Patterns”</strong> tab → heatmap showing which techniques Lazarus uses most.</p><h4>Example 3 — Import a threat report (PDF / blog post)</h4><p>You found a Mandiant or CrowdStrike blog post about a new campaign.</p><pre>Data → Import → drag and drop the PDF or paste the URL<br>Select format: "Auto detect" or "Report"</pre><p>OpenCTI parses it and creates a Report object. The AI enrichment connector then picks it up automatically and extracts:</p><ul><li>Threat actors mentioned</li><li>Malware families</li><li>ATT&amp;CK technique IDs</li><li>Targeted sectors and countries</li></ul><p>All as STIX relationships, visible immediately in the UI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zPViHJ6GKjMeHMtM8240gg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YQBdTFlcQ_q9NcblRik5pw.png"></figure><h4>Example 4 — Track a CVE across your environment</h4><p>CVE-2024–21762 (Fortinet FortiOS RCE) was just published. Check what you know about it.</p><pre>Arsenal → Vulnerabilities → search "CVE-2024-21762"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G9LM5wxYywcTYVdLC331jw.png"></figure><p>After the CVE connector syncs, you’ll see:</p><ul><li>CVSS score and vector</li><li>Affected software versions</li><li>Which threat actors exploit it (once AlienVault/MITRE data arrives)</li><li>Which campaigns used it</li><li>Related indicators (IPs, domains used in exploitation)</li></ul><h4>Example 5 — Create an incident from a sighting</h4><p>Your EDR detected Cobalt Strike beacon on a workstation.</p><pre>Activities → Incidents → Create<br>  Name: "CS beacon on WS-042"<br>  Type: "Intrusion"<br>  Confidence: 90<br>  Add object: link to Cobalt Strike (malware)<br>  Add object: link to T1071.001 (C2 over HTTP)<br>  Add observable: add the C2 IP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zm8Mi5l-QnFsTb0jAia32A.png"></figure><p>With sighting_incident rule enabled, future detections of the same C2 IP automatically raise new incidents without manual work.</p><h4>Example 6 — Export IOCs to your firewall / SIEM</h4><p>You want a live blocklist of all HIGH confidence IPv4 indicators.</p><pre>Data → Indicators<br>Filter: Score &gt; 70, Type = IPv4-Addr, Valid until &gt; today<br>Export → CSV or STIX</pre><p>Or use the built-in <strong>TAXII 2.1 server</strong> to push directly to your SIEM:</p><pre>Settings → Taxii Server → Create collection "High confidence IOCs"<br>Configure your SIEM to poll: http://localhost:8080/taxii2/</pre><h4>Example 7 — Map your detection coverage against ATT&amp;CK</h4><p>You want to know which techniques you detect vs which you’re blind to.</p><pre>Technics → Attack Patterns<br>Filter by: used by (Lazarus Group)</pre><p>Cross-reference the list with your SIEM detection rules. Techniques with no detection rule = gap in coverage.</p><p>Export the filtered list as CSV and import into ATT&amp;CK Navigator for a visual heatmap of covered vs uncovered techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mPwgsMfkEtXK1y1rnlj0Hw.png"></figure><h4>Example 8 — Pivot from malware to infrastructure</h4><p>You found a Ryuk ransomware sample (SHA256 hash).</p><pre>Search → paste the SHA256</pre><p>From the malware object, pivot to:</p><ul><li><strong>Related indicators</strong> → domains and IPs used for C2</li><li><strong>Used by</strong> → Wizard Spider (threat actor)</li><li><strong>Campaigns</strong> → which ransomware campaigns used this variant</li><li><strong>Techniques</strong> → T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery)</li></ul><p>Each pivot is one click in the graph view.</p><h4>Example 9 — Share intelligence with a partner org</h4><p>You want to share a report with a partner but strip out RED-marked internal data.</p><pre>Open the report → Actions → Share<br>Select TLP level: TLP:AMBER (only partner can see it)</pre><p>Or use <strong>Workspaces → Sharing groups</strong> to create a federated share with another OpenCTI instance. All objects above RED are automatically excluded from the export.</p><h4>Example 10 — Build a custom dashboard for your sector</h4><p>Your org is in Finance. You want a live dashboard showing threats to your sector.</p><pre>Home → Dashboards → Create dashboard "Finance Threat Landscape"<br>Add widgets:<br>  - "Threat actors targeting Finance" (bar chart)<br>  - "Most used techniques against Finance" (ATT&amp;CK heatmap)<br>  - "New IOCs last 7 days" (timeline)<br>  - "Active campaigns" (list)<br>  - "CVEs affecting banking software" (table)</pre><p>Each widget auto-updates as new data arrives from connectors.</p><h4>If you like this research, <a href="https://www.paypal.com/donate/?business=W3XDKS7J9XTCG&amp;no_recurring=0&amp;item_name=Buy+me+a+coffee+%28PayPal%29+%E2%80%94+Keep+the+lab+running&amp;currency_code=USD">buy me a coffee (PayPal) — Keep the lab running</a></h4><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><h4>Stay connected:</h4><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><p>Follow My Work</p><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><p>Portfolio / Knowledge Base: <a href="https://1200km.com/">https://1200km.com/</a><br>Medium: <a href="https://medium.com/@1200km">https://medium.com/@1200km</a><br>GitHub: <a href="https://github.com/anpa1200">https://github.com/anpa1200</a><br>LinkedIn: <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></p><p>Andrey Pautov</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=057c9b4b9394" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux 7.2 is implementing the Rust zerocopy library to allow eliminating some additional "unsafe" Rust code elements within the kernel]]></title>
<description><![CDATA[From the article Miguel Ojeda already mailed in the many Rust code changes for the in-development Linux 7.2 kernel. This is quite a big Rust code with more than forty thousand new lines of Rust code in the kernel. The Rust changes are so big this cycle since they are pulling in the "zerocopy" lib...]]></description>
<link>https://tsecurity.de/de/3600037/linux-tipps/linux-72-is-implementing-the-rust-zerocopy-library-to-allow-eliminating-some-additional-unsafe-rust-code-elements-within-the-kernel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600037/linux-tipps/linux-72-is-implementing-the-rust-zerocopy-library-to-allow-eliminating-some-additional-unsafe-rust-code-elements-within-the-kernel/</guid>
<pubDate>Mon, 15 Jun 2026 21:06:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>From the article</h1> <p>Miguel Ojeda already mailed in the many Rust code changes for the in-development Linux 7.2 kernel. This is quite a big Rust code with more than forty thousand new lines of Rust code in the kernel.</p> <p>The Rust changes are so big this cycle since they are pulling in the "zerocopy" library to allow eliminating some additional "unsafe" Rust code elements within the kernel. The Rust pull request explains of integrating the Zerocopy code:</p> <p><strong><em>"Introduce support for the 'zerocopy' library:</em></strong> </p> <p><strong><em>Fast, safe, compile error. Pick two.</em></strong> </p> <p><strong><em>Zerocopy makes zero-cost memory manipulation effortless. We write `unsafe` so you don't have to.</em></strong> </p> <p><strong><em>It essentially provides derivable traits (e.g. 'FromBytes') and macros (e.g. 'transmute!') for safely converting between byte sequences and other types. Having such support allows us to remove some 'unsafe' code.</em></strong> </p> <p><strong><em>It is among the most downloaded Rust crates and it is also used by the Rust compiler itself.</em></strong> </p> <p><strong><em>It is licensed under "BSD-2-Clause OR Apache-2.0 OR MIT".</em></strong> </p> <p><strong><em>The crates are imported essentially as-is (only +2/-3 lines needed to be adapted), plus SPDX identifiers. Upstream has since added the SPDX identifiers as well as one of the tweaks at my request, thus reducing our future diffs on updates -- I keep the details in one of our usual live lists.</em></strong> </p> <p><strong><em>In total, it is about ~39k lines added, ~32k without counting 'benches/' which are just for documentation purposes.</em></strong> </p> <p><strong><em>The series includes a few Kbuild and rust-analyzer improvements and an example patch using it in Nova, removing one 'unsafe impl'.</em></strong> </p> <p><strong><em>I checked that the codegen of an isolated example function (similar to the Nova patch on top) is essentially identical. It also turns out that (for that particular case) the 'zerocopy' version, even with 'debug-assertions' enabled, has no remaining panics, unlike a few in the current code (since the compiler can prove the remaining 'ub_checks' statically).</em></strong> </p> <p><strong><em>So their "fast, safe" does indeed check out -- at least in that case."</em></strong></p> <p>Beyond pulling in Zerocopy to improve dealing with "unsafe" code around conversions, the Rust code for Linux 7.2 also adds support for AutoFDO. The Rust kernel code can now benefit from Automatic Feedback Directed Optimizations by the compiler to yield better performance. With the Rust Binder code was around a 13% performance difference. </p> <p>There is also Rust support for software tag-based Kernel Address Sanitizer (KASAN), support for the upcoming Rust 1.98 release, and other improvements. </p> <p>The full set of Rust feature changes submitted for the Linux 7.2 merge window can be found via <a href="https://lore.kernel.org/lkml/20260614202412.400461-1-ojeda@kernel.org/">this pull request</a>.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/somerandomxander"> /u/somerandomxander </a> <br> <span><a href="https://www.phoronix.com/news/Linux-7.2-Rust">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u6npqm/linux_72_is_implementing_the_rust_zerocopy/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/87ceb3fbef7fbc34d98350587fd2584a615c6dfc: [DTensor] Support _StridedShard to Shard through all-to-all (#170915)]]></title>
<description><![CDATA[(AI generated commit description)
[DTensor] Support _StridedShard to Shard through all-to-all
Summary
This PR adds support for redistributing tensors from _StridedShard placement to Shard placement using the all-to-all collective operation.
The key challenge is that _StridedShard produces non-con...]]></description>
<link>https://tsecurity.de/de/3597974/downloads/trunk87ceb3fbef7fbc34d98350587fd2584a615c6dfc-dtensor-support-stridedshard-to-shard-through-all-to-all-170915/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597974/downloads/trunk87ceb3fbef7fbc34d98350587fd2584a615c6dfc-dtensor-support-stridedshard-to-shard-through-all-to-all-170915/</guid>
<pubDate>Mon, 15 Jun 2026 06:16:03 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>(AI generated commit description)</p>
<h2>[DTensor] Support _StridedShard to Shard through all-to-all</h2>
<h3>Summary</h3>
<p>This PR adds support for redistributing tensors from <code>_StridedShard</code> placement to <code>Shard</code> placement using the all-to-all collective operation.</p>
<p>The key challenge is that <code>_StridedShard</code> produces non-contiguous (interleaved) shards, so converting to a regular <code>Shard</code> placement requires:</p>
<ol>
<li>Properly computing padding for both the source strided dimension and target dimension</li>
<li>Reordering elements after the all-to-all to restore contiguous layout</li>
</ol>
<h3>Example: Converting <code>_StridedShard(0, split_factor=2)</code> to <code>Shard(1)</code></h3>
<p>Consider the following setup:</p>
<ul>
<li><strong>Mesh shape</strong>: <code>(4,)</code> — 4 ranks on a single mesh dimension</li>
<li><strong>Original tensor shape</strong>: <code>(9, 4)</code></li>
<li><strong>Source placement</strong>: <code>(_StridedShard(0, split_factor=2),)</code></li>
<li><strong>Target placement</strong>: <code>(Shard(1),)</code></li>
</ul>
<h4>Step 1: Understand the _StridedShard distribution</h4>
<p>With <code>_StridedShard(0, split_factor=2)</code>, the tensor is conceptually split in two levels on dimension 0:</p>
<ol>
<li><strong>First level</strong>: Split into <code>split_factor=2</code> pieces → chunks of size ⌈9/2⌉ = 5, giving pieces <code>[0:5]</code> and <code>[5:9]</code></li>
<li><strong>Second level</strong>: Each piece is split into <code>num_chunks=4</code> pieces (mesh size)</li>
</ol>
<p>The shards are then interleaved so each rank gets one slice from each first-level piece:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Original tensor (9x4):            Strided sharding on dim 0:
┌─────────────────────┐
│ row 0               │  ─┐
│ row 1               │   ├─ First piece [0:5], split into 4 chunks
│ row 2               │   │  → chunks: [0:2], [2:4], [4:5], []
│ row 3               │   │
│ row 4               │  ─┘
│ row 5               │  ─┐
│ row 6               │   ├─ Second piece [5:9], split into 4 chunks
│ row 7               │   │  → chunks: [5:6], [6:7], [7:8], [8:9]
│ row 8               │  ─┘
└─────────────────────┘

Interleaved distribution to ranks:
  Rank 0: rows [0,1] + [5]     = rows [0,1,5]     (3 rows)
  Rank 1: rows [2,3] + [6]     = rows [2,3,6]     (3 rows)
  Rank 2: rows [4]   + [7]     = rows [4,7]       (2 rows)
  Rank 3: []         + [8]     = rows [8]         (1 row)"><pre class="notranslate"><code>Original tensor (9x4):            Strided sharding on dim 0:
┌─────────────────────┐
│ row 0               │  ─┐
│ row 1               │   ├─ First piece [0:5], split into 4 chunks
│ row 2               │   │  → chunks: [0:2], [2:4], [4:5], []
│ row 3               │   │
│ row 4               │  ─┘
│ row 5               │  ─┐
│ row 6               │   ├─ Second piece [5:9], split into 4 chunks
│ row 7               │   │  → chunks: [5:6], [6:7], [7:8], [8:9]
│ row 8               │  ─┘
└─────────────────────┘

Interleaved distribution to ranks:
  Rank 0: rows [0,1] + [5]     = rows [0,1,5]     (3 rows)
  Rank 1: rows [2,3] + [6]     = rows [2,3,6]     (3 rows)
  Rank 2: rows [4]   + [7]     = rows [4,7]       (2 rows)
  Rank 3: []         + [8]     = rows [8]         (1 row)
</code></pre></div>
<h4>Step 2: Pad for uniform all-to-all</h4>
<p>Before all-to-all, we pad so all ranks have uniform chunk sizes:</p>
<ul>
<li><strong>Old dimension (dim 0)</strong>: <code>max_chunk_size = 3</code>, pad ranks 2 and 3</li>
<li><strong>New dimension (dim 1)</strong>: size 4 with 4 chunks → already uniform (chunk size 1 each)</li>
</ul>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="After padding dim 0:
  Rank 0: [0,1,5] (no padding)    → shape (3, 4)
  Rank 1: [2,3,6] (no padding)    → shape (3, 4)
  Rank 2: [4,7,P] (+1 padding)    → shape (3, 4)
  Rank 3: [8,P,P] (+2 padding)    → shape (3, 4)"><pre class="notranslate"><code>After padding dim 0:
  Rank 0: [0,1,5] (no padding)    → shape (3, 4)
  Rank 1: [2,3,6] (no padding)    → shape (3, 4)
  Rank 2: [4,7,P] (+1 padding)    → shape (3, 4)
  Rank 3: [8,P,P] (+2 padding)    → shape (3, 4)
</code></pre></div>
<h4>Step 3: All-to-all on dim 0 → dim 1</h4>
<p>The all-to-all exchanges slices: each rank sends dim-1 slices to other ranks and receives dim-0 slices:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Before A2A (each rank has 3x4):     After A2A (each rank has 12x1):
  Rank 0: rows [0,1,5] cols [0,1,2,3]  →  col 0 from all ranks
  Rank 1: rows [2,3,6] cols [0,1,2,3]  →  col 1 from all ranks
  Rank 2: rows [4,7,P] cols [0,1,2,3]  →  col 2 from all ranks
  Rank 3: rows [8,P,P] cols [0,1,2,3]  →  col 3 from all ranks"><pre class="notranslate"><code>Before A2A (each rank has 3x4):     After A2A (each rank has 12x1):
  Rank 0: rows [0,1,5] cols [0,1,2,3]  →  col 0 from all ranks
  Rank 1: rows [2,3,6] cols [0,1,2,3]  →  col 1 from all ranks
  Rank 2: rows [4,7,P] cols [0,1,2,3]  →  col 2 from all ranks
  Rank 3: rows [8,P,P] cols [0,1,2,3]  →  col 3 from all ranks
</code></pre></div>
<h4>Step 4: Unpad and reorder</h4>
<p>After all-to-all, each rank has interleaved rows from the strided pattern with padding. We use <code>index_select</code> to:</p>
<ol>
<li>Extract only the valid (non-padded) elements</li>
<li>Reorder from strided order <code>[0,1,5,2,3,6,4,7,8]</code> back to natural order <code>[0,1,2,3,4,5,6,7,8]</code></li>
</ol>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="Final result - Shard(1) distribution:
  Rank 0: all 9 rows, col 0  → shape (9, 1)
  Rank 1: all 9 rows, col 1  → shape (9, 1)
  Rank 2: all 9 rows, col 2  → shape (9, 1)
  Rank 3: all 9 rows, col 3  → shape (9, 1)"><pre class="notranslate"><code>Final result - Shard(1) distribution:
  Rank 0: all 9 rows, col 0  → shape (9, 1)
  Rank 1: all 9 rows, col 1  → shape (9, 1)
  Rank 2: all 9 rows, col 2  → shape (9, 1)
  Rank 3: all 9 rows, col 3  → shape (9, 1)
</code></pre></div>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3749201916" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/170915" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/170915/hovercard" href="https://github.com/pytorch/pytorch/pull/170915">#170915</a><br>
Approved by: <a href="https://github.com/weifengpy">https://github.com/weifengpy</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GM Updates 250,000 EVs with Vehicle-to-Grid Firmware, Announces Grid-Scale Sodium-Ion Batteries]]></title>
<description><![CDATA["Battery breakthroughs will lessen AI's demand on the electricity grid," argues The Washington Post's editoral board, arguing that GM's latest moves "offer a fresh reminder that resource constraints can be solved by innovation." 

Or As Fortune put it, "America's electric grid is buckling under e...]]></description>
<link>https://tsecurity.de/de/3596172/it-security-nachrichten/gm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596172/it-security-nachrichten/gm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries/</guid>
<pubDate>Sat, 13 Jun 2026 22:50:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Battery breakthroughs will lessen AI's demand on the electricity grid," argues The Washington Post's editoral board, arguing that GM's latest moves "offer a fresh reminder that resource constraints can be solved by innovation." 

Or As Fortune put it, "America's electric grid is buckling under extreme weather, aging infrastructure, and an AI build-out that is quietly rewriting U.S. power demand — and General Motors wants to turn that crisis into a business." They describe GM's plan as offering itself "as a distributed utility in disguise... stitching together hundreds of thousands of battery-powered cars, new grid-scale storage, and a unified charging platform into what amounts to a virtual fleet of power plants."

 The bet puts GM on a collision course with Ford's newly branded Ford Energy unit as both Detroit rivals race to repurpose underused EV capacity for a more urgent problem: keeping the lights on in the AI era. GM's case rests on three planks. The first is its existing fleet. GM says more than 250,000 of its EVs on U.S. roads can already charge bidirectionally — pulling electricity from the grid and sending it back. "Every evening, a quiet transformation occurs across the American landscape," GM Energy vice president Wade Sheffer writes in an open letter to utilities and regulators, describing the EVs sitting in driveways as "a massive opportunity to aggregate energy storage capacity." 

 A firmware update is rolling out to customers with GM Energy's vehicle-to-home hardware, converting those systems into full vehicle-to-grid assets with no new hardware and turning home backup systems into grid resources when utilities need them. GM is piloting the idea in Michigan with DTE Energy at 30 employee homes, and has sketched a 2030 vision with Pacific Gas &amp; Electric in which more than 52,000 GM EVs help balance the grid out of a projected 130,000 vehicles in the area. 

GM is also "seeking partnerships with utility companies nationwide to assist in offering such vehicle-to-grid services for customers," reports CNBC, noting it's one of two moves "meant to address concerns about rising energy costs amid an artificial intelligence boom." 


 Forbes reports that GM's second goal "is to leapfrog the dominant battery cell tech used for energy storage packs right now" — right past the LFP (lithium-iron phosphate) stage, "which is dominated by China."

 Sodium batteries are cheaper to use than LFP because they don't need an additional cooling system. They also have a 20-year usable life and are made from materials that can be sourced from within the U.S., the company said at a briefing in San Francisco on Tuesday.
"Sodium-ion actually is the better chemistry for that application. And when I say sodium-ion is better, I mean GM's version of sodium-ion," Kurt Kelty, GM's battery chief and a long-time Tesla battery executive, told Forbes. He said GM is seeing great results from its prototypes, even at scorching temperatures of 55 Celsius (131 Fahrenheit). 

 "Sodium-ion-powered energy storage systems have the potential to operate without active cooling and with much less system complexity," Kurt Kelty, GM's vice president of battery and sustainability, said Tuesday in a blog post. "In large energy storage systems, that matters." Not having to cool the battery cells could lead to lower upfront costs as well as operating costs, the automaker said. 

TechCrunch reports on GM's big new partnership with energy-storage startup Peak Energy to develop GM's sodium-ion battery chemistry for grid-scale deployments:
GM wouldn't share with TechCrunch how much money it is investing in this energy-storage effort. But we do know the company has committed $900 million to commercialize new battery chemistries, an investment that includes a new battery-development center. .. The first GM cells are expected to enter trial production at the company's Battery Cell Development Center in 2028. 

"Our next-generation sodium-ion cell development will drive energy density higher," promises GM's blog post, arguing they're extending the company's battery expertise and technical infrastructure "into the electrical grid itself. If we get this right, we will not just build better batteries. We will help create a more resilient, more affordable and more flexible energy future... Every improvement we make strengthens the development stack that supports both EVs and energy storage." 

"The message: GM isn't just selling cars into a stressed grid; it's supplying the batteries to stabilize it," argues Fortune. 


And GM also announced they're augmenting their apps with an "Energy Pass" offering "seamless access to Tesla Supercharger, IONNA, Electrify America, and soon, ChargePoint and EVgo networks." Their goal is to simplify the charging experience with an app "that covers nearly 70% of all DC fast chargers in the United States, plus many Level 2 chargers, all through one app."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GM+Updates+250%2C000+EVs+with+Vehicle-to-Grid+Firmware%2C+Announces+Grid-Scale+Sodium-Ion+Batteries%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F13%2F0224235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F13%2F0224235%2Fgm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/06/13/0224235/gm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Factoring "short-sleeve" RSA keys with polynomials]]></title>
<description><![CDATA[What happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enough for us to detect these incorrectly generated keys in the wild. Together with Hanno Böck of the badkeys project, we found hundreds of uniqu...]]></description>
<link>https://tsecurity.de/de/3593284/it-security-nachrichten/factoring-short-sleeve-rsa-keys-with-polynomials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593284/it-security-nachrichten/factoring-short-sleeve-rsa-keys-with-polynomials/</guid>
<pubDate>Fri, 12 Jun 2026 13:28:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>What happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enough for us to detect these incorrectly generated keys in the wild. Together with Hanno Böck of the <a href="https://badkeys.info/">badkeys</a> project, we found hundreds of unique keys that not only have this property, but can be quickly factored. We also found the bug that led to many of these keys and analyzed historical data to track the issue over time. Surprisingly, the pattern of 0 bits is often highly structured, allowing us to develop a powerful polynomial-based cryptanalytic technique that exploits the pattern.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/shortsleevekeys_figure1_hu_49c6698c7e83848f.webp" alt="Figure 1: Two patterns of RSA moduli with repeated blocks of 0 bits seen in real-world examples." width="910" height="362" loading="lazy" decoding="async">
 <figcaption>Figure 1: Two patterns of RSA moduli with repeated blocks of 0 bits seen in real-world examples.</figcaption>
 </figure>
</p>
<p>These “short-sleeve” keys, named for how the 0 bits don’t fully cover the limbs of the big integers, largely fell into two patterns. Pattern 1 remains unexplained, but we traced pattern 2 to a type mismatch in big-integer code from old versions of the CompleteFTP file transfer software. The CompleteFTP bug also generated vulnerable short-sleeve DSA keys, and we recovered 603 unique RSA private keys and 74 DSA keys from internet scans. If you used CompleteFTP to generate host keys between December 2016 and December 2023, CompleteFTP has released a <a href="https://enterprisedt.com/downloads/KeyChecker.zip">tool</a> to check whether your keys need to be regenerated.</p>
<h2>How we found the weak keys</h2>
<p>The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number of real-world keys from public sources, including Certificate Transparency logs, internet-wide TLS and SSH scans, PGP keys, and many others. By searching this dataset for unexpectedly sparse RSA moduli, we uncovered a large number of keys in the wild with the patterns in Figure 1.</p>
<p>Both patterns include several regularly spaced blocks of all zeros interleaved with seemingly random data. Pattern 1 appears in CT logs for certificates issued to several large organizations, including <a href="https://crt.sh/?id=375717364">Yahoo</a> and <a href="https://crt.sh/?id=14320619439">Verizon</a>, and on some devices running NetApp software. Fortunately, these certificates have already expired, but we still shared our findings with these companies. We wanted to learn more about which product could be responsible for generating these keys, but we did not hear back. Pattern 2 appears on SSH hosts running the CompleteFTP software from EnterpriseDT. The underlying vulnerability affects RSA keys generated using versions 10.0.0–12.0.0 (Dec 2016–Mar 2019) and DSA keys generated with v10.0.0–23.0.4 (Dec 2016–Dec 2023).</p>
<p>These vulnerabilities affect a small minority of hosts on the internet, but the more interesting takeaway is that independent cryptographic implementations failed in similar ways. More implementations may include the same bugs, and so it’s worth tailoring cryptanalytic algorithms for this particular type of failure.</p>
<h2>Factoring with polynomials</h2>
<p>Cryptographic algorithms often need integers hundreds or thousands of bits long, and they represent these “big integers” using an array of smaller machine-sized values, called <em>limbs</em>. If we interpret pattern 1 as a sequence of 128-bit limbs, or 32-bit limbs in pattern 2, the repeated blocks of zeros correspond to a single block of zeros in each limb. Only a small contiguous subset of the limb is filled with random bits, and the rest of the limb is uncovered, hence the nickname “short-sleeve keys.”</p>
<p>By exploiting this mathematical structure in the limbs of these moduli, we replace the hard problem of factoring integers with the easy problem of factoring polynomials. That is, we take the modulus $n$ with unknown factors $p$ and $q$, express it as a polynomial $f_n(x)$ with small coefficients, factor $f_n(x)$ into $f_p(x)$ and $f_q(x)$, and convert these factors into $p$ and $q$. The technique of converting between integers and polynomials is common, including doing <a href="https://en.wikipedia.org/wiki/Kronecker_substitution">fast polynomial multiplication</a>, but sadly, few resources <a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/o2_vKIslDBc/m/iz7yNMy_AAAJ">describe</a> how to use it for fast integer factorization.</p>
<p>In particular, we use the digits in the base-$B$ representation of the integer to set the coefficients of the polynomial. In the normal base-10 representation, this involves replacing powers of 10 with powers of $x$, and then converting a polynomial back to an integer involves replacing powers of $x$ with powers of 10. Mathematically, the base-$B$ representation of an integer $a = \sum_i a_i B^i$ corresponds to the polynomial $f_a(x) = \sum_i a_i x^i$, and the polynomial evaluation $a = f_a(B)$ converts back to an integer. For short-sleeve keys, the base corresponds to the limb size, and the extra zero bits in each limb will lead to polynomials with exceptionally small coefficients.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/shortsleevekeys_figure2_hu_9d95cd1ea06ffa6c.webp" alt="Figure 2: Integers with blocks of 0 bits can be represented as polynomials with small coefficients." width="834" height="120" loading="lazy" decoding="async">
 <figcaption>Figure 2: Integers with blocks of 0 bits can be represented as polynomials with small coefficients.</figcaption>
 </figure>
</p>
<p>This method of representing integers with polynomials is useful because the product of evaluations $f_a(B) * f_c(B)$ equals the evaluation of the product $(f_a*f_c)(B)$. All evaluation does is replace $x$ with $B$, so it doesn’t matter if this happens before or after multiplication. The same is true of addition.<sup><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p>For a short-sleeve RSA modulus $n$ with $w$-bit limbs, we can use the base-$2^w$ representation to find a polynomial $f_n(x)$ with exceptionally small coefficients. If $f_p(x)$ and $f_q(x)$ also have exceptionally small coefficients, then $f_n(x) = f_p(x) * f_q(x)$. Note that for correctly generated prime factors, $f_p(x)$ and $f_q(x)$ will typically have $w$-bit coefficients; that’s why this attack doesn’t work in general.</p>
<p><a href="https://en.wikipedia.org/wiki/Factorization_of_polynomials#Factoring_univariate_polynomials_over_the_integers">Factoring polynomials</a> is easy, so we can factor $f_n(x)$ to get $f_p(x)$ and $f_q(x)$, then evaluate these factors at $2^w$ to get $p$ and $q$. This is the basic version of the attack, but I’m intentionally omitting a key insight needed to factor these real-world moduli. A full explanation is at the end of this blog.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/shortsleevekeys_figure3_hu_2438a334e3fbc87c.webp" alt="Figure 3: Special-form polynomials can be factored to reveal the RSA private key." width="944" height="239" loading="lazy" decoding="async">
 <figcaption>Figure 3: Special-form polynomials can be factored to reveal the RSA private key.</figcaption>
 </figure>
</p>
<p>The correspondence between integers and polynomials makes it easy to factor these special form moduli, but interestingly, it helps factor general RSA moduli as well. The General Number Field Sieve (GNFS) algorithm has the best known asymptotic performance, and the <a href="https://members.loria.fr/PZimmermann/talks/rsa250-prace.pdf">first step</a> is defining a number field by selecting a polynomial $f_n(x)$ and evaluation point $m$ such that $f_n(m) = n$.<sup><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<h2>Reverse engineering the CompleteFTP vulnerability</h2>
<p>After applying this technique to the keys that Hanno found, we found that the private factors are indeed short-sleeved: the prime factors have large, regularly spaced blocks of unset bits. The SSH banners for the hosts with the second pattern indicate they use the CompleteFTP software, so we reverse-engineered a trial version to determine what caused the vulnerable keys.</p>
<p>Dynamically generated RSA keys did not have the short-sleeve pattern<sup><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup>, so we used the <a href="https://github.com/icsharpcode/ilspy">ILSpy</a> tool to decompile the .NET code in the demo binary. After some reverse engineering, we found the bug that generated the short-sleeve keys. The following function fills the big integer represented by <code>bignumLimbs</code> with a randomly generated value of the desired bit length. See if you can spot the problem.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-csharp" data-lang="csharp"><span class="line"><span class="cl"><span class="kd">public</span> <span class="k">void</span> <span class="n">genRandomBits</span><span class="p">(</span><span class="kt">int</span> <span class="n">bits</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> 	<span class="c1">// Calculate the number of limbs</span>
</span></span><span class="line"><span class="cl"> 	<span class="kt">int</span> <span class="n">numLimbs</span> <span class="p">=</span> <span class="n">bits</span> <span class="p">/</span> <span class="m">32</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> 	<span class="c1">// Allocate space for the RNG output</span>
</span></span><span class="line"><span class="cl"> 	<span class="kt">byte</span><span class="p">[]</span> <span class="n">array</span> <span class="p">=</span> <span class="k">new</span> <span class="kt">byte</span><span class="p">[</span><span class="n">numLimbs</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> 	<span class="c1">// Call the system RNG</span>
</span></span><span class="line"><span class="cl"> 	<span class="n">rngProvider</span><span class="p">.</span><span class="n">GetNonZeroBytes</span><span class="p">(</span><span class="n">array</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> 	<span class="c1">// Copy to the limbs of the big number</span>
</span></span><span class="line"><span class="cl"> 	<span class="n">Array</span><span class="p">.</span><span class="n">Copy</span><span class="p">(</span><span class="n">array</span><span class="p">,</span> <span class="m">0</span><span class="p">,</span> <span class="n">bignumLimbs</span><span class="p">,</span> <span class="m">0</span><span class="p">,</span> <span class="n">numLimbs</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> 	<span class="c1">// Set the top bit to ensure proper bit length</span>
</span></span><span class="line"><span class="cl"> 	<span class="n">bignumLimbs</span><span class="p">[</span><span class="n">numLimbs</span> <span class="p">-</span> <span class="m">1</span><span class="p">]</span> <span class="p">|=</span> <span class="m">0x80000000</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> 	<span class="c1">// Store the length</span>
</span></span><span class="line"><span class="cl"> 	<span class="n">dataLength</span> <span class="p">=</span> <span class="n">numLimbs</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
 <figcaption><span>Figure 4: Decompiled code for the vulnerable genRandomBits in CompleteFTP. Several branches have been removed for clarity, and comments are added.</span></figcaption>
</figure>
<p>There’s a mismatch between the size of the limbs and the size of the RNG output! Each limb requires 32 bits of random material, but <code>Array.Copy</code> <a href="https://learn.microsoft.com/en-us/dotnet/api/system.array.copy?view=netframework-4.8.1">implicitly casts</a> each 8-bit element of the RNG output to its own element of the big-integer limbs. The repeating structure in the short-sleeve keys is because the issue affects each limb, and the 0 bits are because too small of a value is copied to each limb. This exactly matches the pattern of the cryptanalyzed keys.</p>
<p>We also figured out why our dynamic testing did not generate broken keys: the <code>genRandomBits</code> function was compiled in but unreachable in the latest version. Older versions used custom-written key-generation code that called this vulnerable function, which was later refactored to use standard .NET crypto APIs.</p>
<p>We reverse-engineered an older version of the CompleteFTP software to look for other calls to <code>genRandomBits</code> and found that DSA key generation was also affected. The 160-bit DSA private key $x$ was previously generated by this function, and the public key and parameters include a generator $g$ and target $y = g^x$. The private key is easily <a href="https://en.wikipedia.org/wiki/Baby-step_giant-step">recoverable</a>, and once we knew what to look for, we found vulnerable DSA keys in the wild as well.<sup><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<p>Since v12.1.0, CompleteFTP generates RSA keys using .NET’s <code>RSACryptoServiceProvider</code>, and since v23.1.0, it generates DSA keys using the <code>DSA.Create</code> API.</p>
<h2>How the vulnerability spread, and how it was contained</h2>
<p>The decision to refactor key-generation code to use standard libraries significantly mitigated the scope of the impact. This is actually reflected in the data. Prof. Nadia Heninger has a large collection of historical and contemporary SSH scans that we used to find <a href="https://eprint.iacr.org/2023/1711">broken SSH RSA signatures</a>, so I checked to see whether it included CompleteFTP hosts. There were typically hundreds of CompleteFTP hosts in each IPv4-wide scan, and after aligning the historical scans to the release history, the trend is clear.</p>
<p>




 

 




 


 <figure>
 <img src="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/shortsleevekeys_figure5_hu_5c586f6d854f2cbb.webp" alt="Figure 5: Over time, fewer CompleteFTP hosts run the vulnerable software, but a significant fraction still use vulnerable keys." width="1200" height="450" loading="lazy" decoding="async">
 <figcaption>Figure 5: Over time, fewer CompleteFTP hosts run the vulnerable software, but a significant fraction still use vulnerable keys.</figcaption>
 </figure>
</p>
<p>Starting with the introduction of the RSA vulnerability in December 2016, there was a consistent increase in the number of hosts with vulnerable keys, and once the rewritten RSA code was released in March 2019, this trend immediately stopped. However, even though the number of hosts running an affected version has steadily decreased since then, the proportion of affected keys has plateaued, consistent with customers who regularly update their software but generate their keys only once.</p>
<p>The EnterpriseDT team was very responsive throughout disclosure. To help these users, EnterpriseDT released v26.1.0 of <a href="https://enterprisedt.com/products/completeftp/">CompleteFTP</a> on May 8, 2026; this update automatically checks if the system is using a vulnerable RSA or DSA key and alerts the user if the key needs to be regenerated. They also released a <a href="https://enterprisedt.com/downloads/KeyChecker.zip">standalone tool</a> that does the same. In addition, the badkeys <a href="https://badkeys.info/">website</a> and standalone <a href="https://github.com/badkeys/badkeys">tool</a> now support the detection of vulnerable short-sleeve RSA keys.</p>
<p>In total, we recovered private keys for 603 unique RSA public keys and 74 DSA keys generated by vulnerable versions of CompleteFTP, and 26 RSA keys with the unidentified short-sleeve pattern. Our data sources are heavily biased toward RSA SSH keys, so these numbers do not reflect the actual prevalence.</p>
<h2>The search for more short-sleeve keys</h2>
<p>Unfortunately, we do not have more information about short-sleeve pattern 1, nor do we know whether that vulnerability extends to other key types. It’s common for cryptanalytic algorithms to exploit knowledge of <em>irregularly</em> spaced blocks of known bits (including ECDSA<sup><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup> and RSA<sup><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup>), but the regular spacing of short-sleeve leakage adds new structure, and there may be powerful variants of these algorithms that can exploit this property. If this type of leakage appears in two independent implementations of RSA, there are likely to be even more examples of short-sleeve keys out there.</p>
<p>In this instance, the impact of the vulnerabilities is fortunately limited, but it illustrates the power of practical research. The process of using known vulnerabilities to inspire more capable algorithms and using these algorithms to uncover new vulnerabilities generates a powerful feedback loop in cryptanalysis. It helps us understand how real cryptographic systems fail in practice, and it is only by observing how systems break that we learn how to make them more secure.</p>
<h2>Acknowledgments</h2>
<p>Thank you to Nadia Heninger for introducing me to Hanno and for letting me use the SSH scans for this project. Those scans consist of historical data from Censys and the University of Michigan provided by Zakir Durumeric and contemporary data and analysis scripts from Kevin He and George Sullivan.</p>
<h2>Appendix</h2>
<p>This final section is intended for those who want to implement the attack or write a proof that the attack works. I left out key details from the main post, but the following guided questions will help you close that gap. First, here are the full moduli for you to factorize. They are synthetically generated, but follow the same pattern as keys in the wild. The factors of $n_2$ were generated by calling <code>genRandomBits(1024)</code> in a loop until the result was prime.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">n_1=0xc889f7ef523b08e400000000000000014d2ee8284c7a03c000000000000000012c16eeaeab96ddc8000000000000000201036d671407a06600000000000000022f743377005a840d0000000000000001e8e3c0efdd8054ba000000000000000306ee98c677dfdf190000000000000002de525d2b1011ceae0000000000000424455c59eec3a0654500000000000003f8d762d68bcbe8cc3a00000000000000d31291f9aaa7e9a7d60000000000000337a82a59342aadff570000000000000295c495b3690a69b66c00000000000000d9c5e55654e9b14cba000000000000040f0f0f7d3bfdce03d6000000000000026b89ac77db000000000000000000036a77
</span></span><span class="line"><span class="cl">n_2=0x40000049000014ac8000900e00010ec58000b17b8001e0720001be890002169f80029cd5000349190003cd4480037c8c000397660003b28300041021000418cb00058a210004c2708004924980053b8780051cbd8005ebe80006bb27800765e6800651478007f62300073949800860950008614d800863988008d103800884c100099a260009a6d90009578f0007e84300080db800072e59000724f10007c0ec0006ec6600062231000605930005ca4c000566cc0005da92000574dd00040bf1000457dc0004cfbe0004c5640003fe6d0003ada60002de110002cbb30002d5a6000243840001cdf40001a8a9000151be000113f4000101070000acdf000029e5</span></span></code></pre>
</figure>
<ol>
<li>If you compute $f_{n_2}(x)$ using $B=2^{32}$, some of the coefficients are large. Why is that? Is it true that all of the coefficients of $f_p(x)$ and $f_q(x)$ are small?</li>
<li>Is there a bit shift $p \ll i$ such that $f_{2^i p}(x)$ has small coefficients? This is the key trick needed to turn arbitrary short-sleeve values into polynomials with small coefficients.</li>
<li>If $f_{2^i p}(x)$ and $f_{2^j q}(x)$ have small coefficients, can you still compute $f_{2^i p}(x)*f_{2^j q}(x)$ from public information? Can you still recover $p$ and $q$?</li>
<li>If this polynomial factorization technique worked for every $p$ and $q$, then RSA would be broken. Why is the short-sleeve property important, and why doesn’t this factorization method work in general? What are the limits?</li>
<li>The short-sleeve property allows us to construct the product $f_{2^i p}(x)*f_{2^j q}(x)$, but unless $f_{2^i p}(x)$ and $f_{2^j q}(x)$ are irreducible, factorization may split this into more than two terms. Prove that there is always an efficient way to recover $p$ and $q$ from the polynomial factorization.</li>
</ol>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li>
<p>In math terms, the evaluation map is a ring homomorphism. <a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fnref:1" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li>
<p>More accurately, modern factoring implementations use a generalization of this technique. They search for a pair of polynomials $f_0, f_1$ where $f_1$ is linear and $Resultant(f_0, f_1)$ is a small multiple of $n$. In the special case where $f_1$ is monic, then $Resultant(f_0, x - m) = n \Leftrightarrow f_0(m) = n$. <a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fnref:2" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li>
<p>CompleteFTP RSA key generation on Linux had a separate issue where the private exponent was set to 65537 and the public exponent was large. We disclosed, and this issue was fixed in v26.0.2. The Linux version of the tool offers <a href="https://enterprisedt.com/products/completeftp/editions/">different features</a> and is less popular than Windows. According to license data from EnterpriseDT, they believe no production users are affected by this issue. Our scans corroborate this claim, as we found no keys in the wild with this property. <a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fnref:3" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li>
<p>Diffie-Hellman key exchange also used the vulnerable function, but with a 2048-bit exponent. This is not vulnerable, and we believe that DH key exchanges that used this function are still cryptographically secure. <a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fnref:4" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li>
<p><a href="https://doi.org/10.1007/978-3-540-74462-7_9">Extended Hidden Number Problem and Its Cryptanalytic Applications</a> by Hlaváč and Rosa considers the problem of (EC)DSA nonces with multiple blocks of unknown bits at arbitrary locations. <a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fnref:5" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li>
<p><a href="https://doi.org/10.1007/978-3-540-89255-7">Solving Linear Equations Modulo Divisors: On Factoring Given Any Bits</a> by Herrmann and May considers factoring RSA when one of the factors has multiple contiguous blocks of unknown bits. <a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/#fnref:6" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
</ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content]]></title>
<description><![CDATA[Executive Summary




Cyble Research & Intelligence Labs (CRIL) has identified an active SEO poisoning campaign exploiting abandoned cloud DNS zone delegations to serve Thai-language gambling content under the domain authority of reputed enterprise organizations. The campaign has compromised 163 ...]]></description>
<link>https://tsecurity.de/de/3592514/it-security-nachrichten/borrowed-trust-systematic-exploitation-of-abandoned-cloud-dns-delegations-to-serve-thai-gambling-seo-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592514/it-security-nachrichten/borrowed-trust-systematic-exploitation-of-abandoned-cloud-dns-delegations-to-serve-thai-gambling-seo-content/</guid>
<pubDate>Fri, 12 Jun 2026 07:38:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Borrowed Trust, Cyble" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2.jpg 1200w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2-768x384.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) has identified an active SEO poisoning campaign exploiting abandoned cloud DNS zone delegations to serve Thai-language gambling content under the domain authority of reputed enterprise organizations. The campaign has compromised 163 organizations across 30+ countries, spanning federal government agencies, national healthcare systems, financial institutions, critical infrastructure operators, and major universities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The primary mechanism is the Azure DNS zone takeover. When enterprises decommission cloud infrastructure, NS delegations to Azure DNS zones are routinely left in place. The actor systematically identifies these abandoned delegations, claims the orphaned zones under a fresh Azure subscription, and deploys a Next.js gambling kit behind a valid Let's Encrypt wildcard TLS certificate, all resolving cleanly under the victim's own domain. A browser, a search engine, and a Thai user following a search result all see a page identical to a legitimate enterprise property.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This report documents the full campaign architecture: the pivot chain from initial discovery through infrastructure attribution, the DNS compromise mechanisms observed, the structured affiliate monetization layer with server-side geographic filtering and dual-tier commission tracking, and a dedicated 103-node application backend in Hong Kong tied to a single Chinese operator by twelve independent technical evidence points. At the time of publication, 161 organizations remain actively compromised.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Initial Discovery</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During an ongoing vulnerability assessment, CRIL identified an anomalous DNS resolution on the <strong>cardsforheroes.verizon.com</strong> subdomain environment. What initially appeared to be a single misconfigured endpoint turned out to be <strong>1000+</strong> <strong>individually named subdomains</strong>, each serving <strong>Thai-language online gambling</strong> content under <strong>Verizon's trusted domain authority</strong>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Every subdomain followed a gambling brand keyword pattern with URL-encoded Thai characters confirming the intended audience. All endpoints resolved to a single IP at <strong>OVH SAS (AS16276).</strong> Loading a representative endpoint revealed a fully rendered Next.js gambling application with outbound affiliate redirect links.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It matched the structural similarity of 97 other enterprise subdomains across completely unrelated organizations. The affiliate referral parameter on every redirect established the monetization intent immediately: this was not defacement or <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> delivery, but a structured operation funneling Thai search traffic to gambling registrations for commission.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Verizon endpoint was not the campaign's origin. Following it, 162 other compromised organizations were exposed.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120442,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-4-1024x771.png" alt="Figure 1: Screenshot of the compromised endpoint cod9[.]cardsforheroes[.]Verizon[.]com

Borrowed Trust" class="wp-image-120442"><figcaption class="wp-element-caption">Figure 1: Screenshot of the compromised endpoint cod9[.]cardsforheroes[.]Verizon[.]com</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Background: The Vulnerability Class</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Cloud infrastructure provisioning introduces a category of DNS misconfiguration that is structurally different from the record-level errors security teams routinely audit. When an enterprise provisions Azure resources for a project environment, a standard step is to delegate a subdomain to an Azure DNS zone by adding NS records in the parent DNS zone that point to Microsoft's nameservers for that environment. The zone lives inside the Azure subscription, the team manages its records there, and the project operates normally.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>"What consistently fails is the decommissioning step. When the project ends, and the Azure resources are deleted, the NS delegation in the parent DNS zone is not usually removed. It persists silently, pointing any DNS query for that subdomain to Azure nameservers that no longer serve authoritative records for it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In several cases identified during this investigation, these delegations had been left in place for over six years.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The exploitability of this configuration depends on another condition: whether the Azure DNS zone for that subdomain is claimable by a new subscriber. Microsoft's zone-creation model has historically allowed any subscriber to register a zone by name under their own subscription. A zone abandoned with a canceled subscription can be recreated by a third party, who then inherits the delegated DNS authority that the enterprise's parent zone never revoked.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Our analysis of this campaign demonstrates that awareness has not translated into hygiene at an enterprise scale.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">DNS Compromise Mechanisms</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Four distinct mechanisms account for the 163 confirmed victims. Each exploits the same underlying failure: a DNS delegation that outlived the infrastructure it was created to serve.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120443,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-5-1024x683.png" alt="" class="wp-image-120443"></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph {"style":{"typography":{"textAlign":"center"}}} --></p>
<p class="has-text-align-center"></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 1 — Azure DNS Zone Takeover (150+ Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The actor identifies subdomains whose NS records still point to Azure DNS nameservers, even though the underlying subscription has been canceled or abandoned. A new Azure subscription is created, the orphaned zone is claimed by name, a wildcard A record is added that points all subdomains to a delivery IP, and ACME HTTP-01 validation is performed through the now-controlled DNS to obtain a Let's Encrypt wildcard certificate. One DNS record exposes every possible subdomain of the environment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Direct authoritative DNS evidence confirms the mechanism. Querying Microsoft's own nameserver infrastructure returns the actor's wildcard A record. Zone SOA serials of 1 on confirmed victims establish that the zones were created from scratch by the actor, not modified from an existing state. Certificate Transparency logs confirm the dormancy periods:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A major pharmaceutical company's pilot subdomain: last legitimate certificate October 2019, actor certificate April 11, 2026 — a 6.5-year gap</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A global electronics company's IoT platform: last legitimate certificate February 2023, actor certificate April 10, 2026</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The bulk of actor-obtained certificates cluster in April 2026, indicating a concentrated automated exploitation window applied across targets abandoned over multiple years.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 2 — DigitalOcean DNS Zone Takeover (2 Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Two organizations, a US luxury furniture retailer and an Indian university, have their compromised subdomains delegated to DigitalOcean nameservers rather than Azure. Both carry wildcard records resolving to 38.127.8.49.</p>
<p>DigitalOcean's zone-claiming model carries the same structural vulnerability: abandoned DNS zones in canceled accounts become available for re-registration. The actor's tooling targets multiple cloud DNS providers.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 3 — Direct Wildcard Misconfiguration (2 Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A US energy company's development subdomain and a mobile payments platform's development subdomain both resolve via wildcard to 139.99.82.106, even though there is no cloud DNS zone delegation. Both use their own organizational nameservers, making cloud zone takeover mechanically impossible.</p>
<p>The wildcard records resolve from within the parent zone, indicating either an orphaned wildcard A record left in the organization's own DNS console when a project was decommissioned, or a direct DNS management access path the actor exploited. "A wildcard A record in the DNS console of a payments platform is a more direct access path than a cloud zone takeover.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 3 — Direct Wildcard Misconfiguration (2 Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A US energy company's development subdomain and a mobile payments platform's development subdomain both resolve via wildcard to 139.99.82.106, even though there is no cloud DNS zone delegation. Both use their own organizational nameservers, making cloud zone takeover mechanically impossible.</p>
<p>The wildcard records resolve from within the parent zone, indicating either an orphaned wildcard A record left in the organization's own DNS console when a project was decommissioned, or a direct DNS management access path the actor exploited. "A wildcard A record in the DNS console of a payments platform is a more direct access path than a cloud zone takeover.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 4 — Per-Subdomain A Records (1 Organization)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Verizon environment represents a distinct approach: 1000+ individually named A records rather than a single wildcard. Each gambling-keyword subdomain is a separately created DNS entry pointing to 51.79.199.51. This implies either an automated DNS API script with zone-write access or a compromised DNS management credential that enabled bulk record creation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"style":{"typography":{"textAlign":"left"}}} --></p>
<h2 class="wp-block-heading has-text-align-left"><strong>Technical Analysis</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph {"style":{"typography":{"textAlign":"center"}}} --></p>
<p class="has-text-align-center"><strong>Pivoting: From One Endpoint to 163 Organizations</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120450,"width":"1024px","height":"auto","sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large is-resized"><img src="https://cyble.com/wp-content/uploads/2026/06/image-6-1024x945.png" alt="" class="wp-image-120450"></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Pivot 1: 51.79.199.51 — Primary Delivery Node and First Scope Expansion</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The first pivot came from the primary delivery IP itself. Cross-referencing 51.79.199.51 against passive DNS resolution data and page fingerprint matching returned over 90 enterprise subdomains serving identical content, confirmed by:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Identical Next.js build ID</strong>: QQOrXCFjoI6C9oF-4YVhl</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Identical favicon path:</strong> /img/ib99-hq.ico</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Outbound affiliate redirects to the same <strong>three destination domains</strong> across every result</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Every result was a subdomain of a legitimately owned enterprise domain with a clean reputation. Standard <a href="https://cyble.com/knowledge-hub/what-is-a-threat-intelligence-feed/">threat intelligence feeds</a> returned no signal on any of them. The shared page fingerprint expanded the confirmed victim set from 1 organization to over 90 in a single query.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120457,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-18-1024x565.png" alt="" class="wp-image-120457"><figcaption class="wp-element-caption">Figure 2: Thai-language gambling page served from a compromised enterprise subdomain, advertising free credits with no deposit required.</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Pivot 2: 139.99.82.106 and 38.127.8.49 — Secondary and Tertiary Delivery Nodes</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Passive DNS resolution data against AS16276 (OVH) surfaced two additional delivery IPs operating in parallel. Both served the identical gambling kit with the same build fingerprint across a partially overlapping but distinct victim set. Government agencies, healthcare organizations, and several non-Azure takeover victims routed through these two nodes rather than the primary. Together, the three OVH nodes account for the full 163-organization victim estate. All three presented clean IP reputations, no prior association with threat actors, and standard deployment signatures at the surface level.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120458,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-19-1024x565.png" alt="Figure 2: Compromised endpoint pointing to “38[.]127[.]8[.]49”" class="wp-image-120458"><figcaption class="wp-element-caption">Figure 3: Compromised endpoint pointing to “38[.]127[.]8[.]49”</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Pivot 3: 38.173.56.218 — The JARM Anomaly That Exposed the Backend</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>JARM TLS fingerprinting against the primary delivery node returned thousands of global matches, nearly all of them generic shared hosting providers. One result stood apart by every observable metric: 38.173.56.218 in Hong Kong, AS398478 (PEG TECH INC), presenting:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A ThinkPHP application framework error on port 443</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A Chinese server management panel certificate identity on port 21</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>MySQL 5.7.44-log on port 3306</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Where every other JARM match represented commodity hosting, this node showed a purpose-built application stack managed from mainland China. This was the single point of entry from the OVH delivery layer into the backend infrastructure. Figures 2 and 3 showcase these using findings from <a href="https://odin.io/">ODIN by Cyble</a>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Affiliate Architecture: How the Campaign Monetizes</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Every destination redirect carries a ?rc= affiliate code — ibiza99vip1, bigwinv1, link99, or seven77vip1 — that attributes completed registrations to the actor and triggers a commission payout from the destination platform. This is standard affiliate marketing infrastructure; legal and illegal gambling operations use it. A server-side layer beneath the visible code separates this campaign from simple redirect farms. A POST request intercepted at a live endpoint returned this before any redirect was issued:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>"<strong>status</strong>": "ok",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>msg</strong>": "TH - Referrer verified",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>data</strong>": { "referrer": "link99" },</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>x-token":</strong> ""
</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The backend validates geographic origin server-side. Requests from outside Thailand are not redirected, keeping traffic focused and limiting scanner exposure. The link99 identifier is a sub-affiliate publisher ID that sits above the ?rc= codes in the platform's tracking hierarchy.</p>
<p>The actor earns at both tiers: publisher-level credit under link99 for delivering Thai traffic, and a per-registration payout under the ?rc= code for each conversion. The two layers are independent — campaign codes can rotate while link99 persists as the actor's permanent platform identity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120466,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-8-1024x650.png" alt="Figure 4: 5,547 results matching the JARM hash on ODIN (source: ODIN by Cyble)" class="wp-image-120466"><figcaption class="wp-element-caption">Figure 4: 5,547 results matching the JARM hash on ODIN (source: ODIN by Cyble)</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Pivoting on the Let's Encrypt certificate presented by this node, issued to broker-xm.com, returned 103 IPs across seven contiguous /24 subnets in 38.173.0.0/16, all within AS398478. A single certificate deployed across 103 servers in a wholesale-allocated IP block produced the complete backend fleet inventory from one certificate query.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120467,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-9-1024x573.png" alt="Figure 5: Results for Cert CN-&gt;broker-xm.com showcasing 200 hits from Hong Kong with the IP range 38.173.0.0/16 (source: ODIN by Cyble)" class="wp-image-120467"><figcaption class="wp-element-caption">Figure 5: Results for Cert CN-&gt;broker-xm.com showcasing 200 hits from Hong Kong with the IP range 38.173.0.0/16 (source: ODIN by Cyble)</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Affiliate Architecture: How the Campaign Monetizes</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Every destination redirect carries a ?rc= affiliate code — ibiza99vip1, bigwinv1, link99, or seven77vip1 — that attributes completed registrations to the actor and triggers a commission payout from the destination platform. This is standard affiliate marketing infrastructure; legal and illegal gambling operations use it. A server-side layer beneath the visible code separates this campaign from simple redirect farms. A POST request intercepted at a live endpoint returned this before any redirect was issued:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>"<strong>status</strong>": "ok",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>msg</strong>": "TH - Referrer verified",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>data</strong>": { "referrer": "link99" },</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>x-token":</strong> ""
</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The backend validates geographic origin server-side. Requests from outside Thailand are not redirected, keeping traffic focused and limiting scanner exposure. The link99 identifier is a sub-affiliate publisher ID that sits above the ?rc= codes in the platform's tracking hierarchy.</p>
<p>The actor earns at both tiers: publisher-level credit under link99 for delivering Thai traffic, and a per-registration payout under the ?rc= code for each conversion. The two layers are independent — campaign codes can rotate while link99 persists as the actor's permanent platform identity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120469,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/login-page-1024x562.png" alt="Figure 6 : Phishing page Redirected to hxxps://link99.nova555.rest/register/ with link99 as a referral code" class="wp-image-120469"><figcaption class="wp-element-caption">Figure 6 : Phishing page Redirected to hxxps://link99.nova555.rest/register/ with link99 as a referral code</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Four destination platforms have been confirmed — ibiza99.autos, big888.store, seven77.click, and stillsunday.pl. These domains are white-label deployments on a shared codebase, as confirmed by identical CSS hashes and JavaScript resilience logic across all three, except big888.store, which carries active Google Search Console verification, indicating the platform operator runs its own independent SEO operation beyond this campaign. Each platform maintains its own <strong>appbox.* CDN subdomains</strong>, a fourth infrastructure layer entirely separate from the delivery nodes, backend fleet, and victim domains.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120470,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/details-1024x565.png" alt="Figure 7: Asking for banking information post login via Thailand phone number
" class="wp-image-120470"><figcaption class="wp-element-caption">Figure 7: Asking for banking information post login via Thailand phone number<br></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">The Gambling Kit: What the Endpoint Delivers</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>An HTTP request to any compromised enterprise subdomain with Thai locale headers returns a fully rendered Next.js page that returns a legitimate enterprise web property. The page presents</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>lang="th" with Thai-language gambling platform branding</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A valid Let's Encrypt wildcard TLS certificate matching the victim subdomain, clean browser padlock, no warnings</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Schema.org FAQ structured data with Thai-language answers about minimum deposits, withdrawal timelines, and mobile compatibility, directly targeting the queries Thai users make when researching gambling platforms</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>AMP alternate links for Google mobile indexing coverage</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Static assets served from paths under the compromised domain itself, using the victim's domain authority as a CDN</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The minimum deposit advertised across all kit variants is 1 Thai Baht, approximately $0.03 USD. The 1-baht minimum ($0.03 USD) removes the deposit threshold that causes most users to abandon the registration flow before converting. The kit fingerprint is consistent across the entire victim estate, regardless of which victim domain or OVH node serves the content, confirming centralized build and deployment by a single operator.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120472,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/How-to-earn-874x1024.png" alt="Figure 8 - Three-tier referral commission structure (10%/3%/1%) plus 0.3% turnover rebate, embedded in the gambling kit served across all 163 compromised subdomains" class="wp-image-120472"><figcaption class="wp-element-caption">Figure 8 - Three-tier referral commission structure (10%/3%/1%) plus 0.3% turnover rebate, embedded in the gambling kit served across all 163 compromised subdomains</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120473,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Earn_attraction-1024x909.png" alt="Figure 9: Multi-level recruitment diagram promoting unlimited monthly commissions across three affiliate downline tiers." class="wp-image-120473"><figcaption class="wp-element-caption">Figure 9: Multi-level recruitment diagram promoting unlimited monthly commissions across three affiliate downline tiers.</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Backend Infrastructure: The Hong Kong Fleet</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The three OVH delivery nodes handle content distribution, but the application layer sits entirely within a separate dedicated infrastructure in Hong Kong. The 103-node backend fleet is distributed across seven /24 subnets within 38.173.0.0/16, all under AS398478 (PEG TECH INC). Seven independent evidence points converge on single-operator control; the MD5 match across all 103 nodes on port 80 alone eliminates coincidence.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Evidence Point</strong><strong></strong></td>
<td><strong>Detail</strong><strong></strong></td>
<td><strong>Weight</strong><strong></strong></td>
</tr>
<tr>
<td>HTTP body MD5 match</td>
<td>7df3d7cf3358af3f470ac7229387ef94 (615 bytes) identical across all 103 nodes on port 80</td>
<td>Critical</td>
</tr>
<tr>
<td>Single shared certificate</td>
<td>broker-xm.com Let's Encrypt cert deployed across all 103 servers</td>
<td>High</td>
</tr>
<tr>
<td>Envoy proxy fingerprint</td>
<td>Identical 503 error string on port 443 across all 103 nodes</td>
<td>High</td>
</tr>
<tr>
<td>MySQL version</td>
<td>5.7.44-log with binary replication logging enabled uniformly</td>
<td>High</td>
</tr>
<tr>
<td>BT-Panel provisioning</td>
<td>admin@bt.cn, Dongguan, Guangdong, on FTP certificates across all nodes</td>
<td>High</td>
</tr>
<tr>
<td>JARM fingerprint</td>
<td>07d14d16d21d21d07c42d43d000000270a013a3e21e28897e76e8fe13e2f7d uniform across fleet</td>
<td>High</td>
</tr>
<tr>
<td>Zero PTR records</td>
<td>No reverse DNS on any of the 103 IPs, deliberate suppression</td>
<td>Medium</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Detection and Hunting</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign produces no signal in standard security controls. Valid TLS certificates, clean IP reputation, trusted domain names, and no exploit delivery mean conventional tooling produces no signal. Detection requires operating at the DNS layer.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Certificate Transparency monitoring</strong> is the most reliable early indicator. An unexpected Let's Encrypt wildcard certificate on a corporate-owned subdomain, particularly following a period of no issuance, is an anomaly no legitimate provisioning scenario produces. Monitoring CT logs for wildcard certificates whose expected issuer is a corporate or premium CA would have detected every Azure takeover victim at the time of certificate issuance.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Azure DNS zone delegation</strong> <strong>auditing</strong> is a structural prevention control. Organizations should enumerate all NS delegation records in their parent DNS zones and verify that corresponding Azure DNS zones exist in subscriptions they own and actively manage. 163 organizations across 30 countries had gambling content served under their domain authority without any alert firing. One class of DNS misconfiguration enabled it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Wildcard DNS testing</strong> confirms active exploitation. A randomized nonsense hostname query against any Azure-delegated subdomain that returns a resolution should be treated as a compromised zone until proven otherwise.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Network and endpoint detection rules:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>DNS answers resolving to 51.79.199.51, 139.99.82.106, or 38.127.8.49</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>URL query parameters containing rc=ibiza99vip1, rc=bigwinv1, or rc=seven77vip1 or rc=link99</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>HTTP requests to /img/ib99-hq.ico</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Outbound connections to 38.173.30.0/24, 38.173.37.0/24, 38.173.56.0/24, 38.173.57.0/24, 38.173.235.0/24, 38.173.236.0/24, or 38.173.239.0/24</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Internet scanning queries:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>HTTP body MD5: 7df3d7cf3358af3f470ac7229387ef94</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>TLS certificate CN: broker-xm.com</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>ASN sweep: AS398478</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Remediation</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>For Azure DNS zone takeover victims:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true} --></p>
<ol class="wp-block-list"><!-- wp:list-item -->
<li>Remove the NS delegation from your parent DNS zone immediately. This severs the attack chain regardless of what the actor maintains inside the Azure zone, which is under their control and cannot be directly modified by the victim organization.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Report the abandoned zone to Microsoft MSRC at msrc@microsoft.com with the zone name and evidence. Microsoft can force-remove zones from subscriptions holding abandoned delegations.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Request revocation of any Let's Encrypt certificates issued against the compromised subdomain using the certificate serial numbers from crt.sh.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Audit all remaining subdomains for additional environment-style entries (dev, uat, staging, preprod, pilot, lab, test, sandbox) carrying NS delegations to cloud providers, and verify each delegation is intentional, current, and managed.
</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>For DigitalOcean zone takeover victims</strong>: Remove the NS delegation from the parent zone and verify whether the DigitalOcean zone exists in an account you own.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>For direct wildcard misconfiguration victims:</strong> Remove the wildcard A record from your DNS management console. If the origin of the record cannot be identified, treat the DNS management credential as compromised and rotate it immediately.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This campaign demonstrates that enterprise reputational trust can be systematically harvested through a single class of DNS misconfiguration that most organizations have no visibility into. The actor did not breach any perimeter or exploit any application vulnerability. They claimed what had been left unclaimed and built a commercial affiliate operation on top of it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The scale, 163 organizations across 30+ countries, is not the result of 163 separate attacks. It is an automated scanning process applied to a single vulnerability class. A single wildcard record beneath an abandoned Azure delegation exposes an unlimited subdomain namespace, each entry inheriting the full TLS-verified authority of the victim's brand. The campaign lives entirely within legitimate infrastructure, OVH delivery nodes, Let's Encrypt certificates, victim-owned domains, and organic search rankings, which is precisely why conventional controls produce no signal.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Audit your DNS estate. Every abandoned NS delegation pointing to a cloud provider is a candidate for the next version of this list. Every abandoned NS delegation pointing to a cloud provider is a potential entry in the next version of this list. The remediation is simple. The detection methodology is documented here. The gap between a decommissioned project and an actively exploited subdomain closed silently on 163 organizations. In several cases, it stayed closed for over six years.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>MITRE ATT&amp;CK® Techniques</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Technique</strong><strong></strong></td>
<td><strong>ID</strong><strong></strong></td>
<td><strong>Description</strong><strong></strong></td>
</tr>
<tr>
<td>Resource Development — Acquire Infrastructure</td>
<td>T1583.003</td>
<td>OVH VPS for delivery; PEG TECH INC ASN for backend fleet</td>
</tr>
<tr>
<td>Resource Development — Compromise Infrastructure</td>
<td>T1584</td>
<td>Azure DNS zone takeover of legitimate enterprise subdomains</td>
</tr>
<tr>
<td>Initial Access — Drive-by Compromise</td>
<td>T1189</td>
<td>Thai users directed to compromised enterprise subdomains via organic search</td>
</tr>
<tr>
<td>Persistence — Valid Accounts</td>
<td>T1078</td>
<td>DNS management credentials implied by per-subdomain record creation (Verizon)</td>
</tr>
<tr>
<td>Defense Evasion — Impersonation</td>
<td>T1656</td>
<td>Gambling kit served under legitimate enterprise TLS certificates</td>
</tr>
<tr>
<td>Defense Evasion — Valid Accounts: Cloud Accounts</td>
<td>T1078.004</td>
<td>Azure account used to claim abandoned DNS zones</td>
</tr>
<tr>
<td>Collection — Adversary-in-the-Middle</td>
<td>T1557</td>
<td>Server-side affiliate referrer verification intercepts the user session</td>
</tr>
<tr>
<td>Exfiltration — Web Service</td>
<td>T1567</td>
<td>User registration data and financial transactions were exfiltrated to gambling platforms</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Indicators of Compromise (IOCs)</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td colspan="3"><strong>Delivery Infrastructure</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>51.79.199.51</td>
<td>IP</td>
<td>Primary OVH delivery node, AS16276</td>
</tr>
<tr>
<td>139.99.82.106</td>
<td>IP</td>
<td>Secondary OVH delivery node, AS16276</td>
</tr>
<tr>
<td>38.127.8.49</td>
<td>IP</td>
<td>Tertiary OVH delivery node, AS16276</td>
</tr>
<tr>
<td>38.173.30.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.37.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.56.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.57.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.235.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.236.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.239.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td colspan="3"><strong>Certificates and Fingerprints</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>d9799ca2f08af6992dc80c49f9889fef40ed27c7</td>
<td>SHA1</td>
<td>bt.default.com custom CA on primary delivery node</td>
</tr>
<tr>
<td>broker-xm.com</td>
<td>Domain</td>
<td>Let's Encrypt cert across all 103 backend nodes</td>
</tr>
<tr>
<td>07d14d16d21d21d07c42d43d000000270a013a3e21e28897e76e8fe13e2f7d</td>
<td>JARM</td>
<td>TLS fingerprint across delivery and backend infrastructure</td>
</tr>
<tr>
<td>7df3d7cf3358af3f470ac7229387ef94</td>
<td>MD5</td>
<td>HTTP body hash, 615 bytes, port 80, all 103 backend nodes</td>
</tr>
<tr>
<td colspan="3"><strong>Campaign Kit Fingerprints</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>QQOrXCFjoI6C9oF-4YVhl</td>
<td>String</td>
<td>Next.js build ID across all delivery endpoints</td>
</tr>
<tr>
<td>/img/ib99-hq.ico</td>
<td>URI</td>
<td>Kit-specific favicon path</td>
</tr>
<tr>
<td>main.af42a497.css</td>
<td>Hash</td>
<td>Shared CSS fingerprint across all three destination platforms</td>
</tr>
<tr>
<td>pub-a4952b46ff9c4f6b8d5529cd21f9a1e3.r2.dev</td>
<td>Domain</td>
<td>Cloudflare R2 CDN bucket</td>
</tr>
<tr>
<td colspan="3"><strong>Affiliate Domains and Tracking</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>ibiza99.autos</td>
<td>Domain</td>
<td>Destination platform, affiliate code ibiza99vip1</td>
</tr>
<tr>
<td>big888.store</td>
<td>Domain</td>
<td>Destination platform, affiliate code bigwinv1</td>
</tr>
<tr>
<td>seven77.click</td>
<td>Domain</td>
<td>Destination platform, affiliate code seven77vip1</td>
</tr>
<tr>
<td>link99.nova555.rest</td>
<td>Domain</td>
<td>Destination platform, affiliate code link99</td>
</tr>
<tr>
<td>appbox.7y6texmeyy.com</td>
<td>Domain</td>
<td>ibiza99.autos image CDN</td>
</tr>
<tr>
<td>appbox.devh5api27.xyz</td>
<td>Domain</td>
<td>big888.store image CDN</td>
</tr>
<tr>
<td>appbox.55u4g5g4k2.com</td>
<td>Domain</td>
<td>seven77.click image CDN</td>
</tr>
<tr>
<td>322242757545449</td>
<td>Pixel ID</td>
<td>Facebook Pixel, ibiza99.autos</td>
</tr>
<tr>
<td>1607473696511298</td>
<td>Pixel ID</td>
<td>Facebook Pixel, ibiza99.autos</td>
</tr>
<tr>
<td>721331896825411</td>
<td>Pixel ID</td>
<td>Facebook Pixel, big888.store</td>
</tr>
<tr>
<td>GTM-NP59MP3T</td>
<td>GTM ID</td>
<td>Google Tag Manager, big888.store</td>
</tr>
<tr>
<td colspan="3"><strong>Parallel Operations (AS398478)</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>99997778.com</td>
<td>Domain</td>
<td>Active Chinese gambling platform, AS398478</td>
</tr>
<tr>
<td>bevictor.com</td>
<td>Domain</td>
<td>Chinese offshore sports betting (伟德国际), AS398478</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/borrowed-trust-cloud-dns-takeover-thai-gambling-seo-poisoning/">Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[It’s crunch time for Java modernization]]></title>
<description><![CDATA[Between 2029 and 2032, every currently supported long-term support (LTS) version of Java will reach end-of-support within a single three-year window: Java 17 in 2029, Java 8 in 2030, Java 21 in 2031, and Java 11 in 2032.



On paper, this looks like a manageable upgrade cycle. In practice, it cre...]]></description>
<link>https://tsecurity.de/de/3589980/ai-nachrichten/its-crunch-time-for-java-modernization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589980/ai-nachrichten/its-crunch-time-for-java-modernization/</guid>
<pubDate>Thu, 11 Jun 2026 11:19:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Between 2029 and 2032, every currently supported long-term support (LTS) version of <a href="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html" data-type="link" data-id="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html">Java</a> will reach end-of-support within a single three-year window: Java 17 in 2029, Java 8 in 2030, Java 21 in 2031, and Java 11 in 2032.</p>



<p>On paper, this looks like a manageable upgrade cycle. In practice, it creates a collision of timelines that most enterprises have failed to forecast. Organizations attempting to modernize incrementally—moving application by application, version by version—are operating on a model that the calendar has already rendered obsolete.</p>



<p>The primary danger here is the illusion of time. Traditional modernization plans rely on sequential upgrades and controlled pacing. However, when every major Java version expires in the same compressed window, sequential planning collapses. By the time this becomes obvious, organizations will be forced into reactive mode, making rushed decisions under extreme pressure.</p>



<h2 class="wp-block-heading">The modernization illusion</h2>



<p>For organizations planning traditional stepwise upgrades—Java 8 to Java 11 to Java 17 to <a href="https://www.infoworld.com/article/2338097/jdk-21-the-new-features-in-java-21.html" data-type="link" data-id="https://www.infoworld.com/article/2338097/jdk-21-the-new-features-in-java-21.html">Java 21</a>—this convergence elevates a routine maintenance task into a structural crisis. Enterprises with large Java estates will be forced to upgrade multiple applications across multiple versions simultaneously to maintain security compliance and business continuity. Waiting until the late 2020s to act guarantees a modernization process under emergency conditions.</p>



<p>While modern Java versions maintain strong backward compatibility, they cannot offset the drag of what enterprises are carrying forward: decades of accumulated technical debt.</p>



<p>In large Java environments, technical debt is pervasive. It exists as unused libraries, obsolete logic, forgotten dependencies, and dormant features—quietly inflating the size, risk, and complexity of every modernization effort. In many organizations, a significant portion of the codebase no longer executes in production, yet it still consumes developer attention, security oversight, and planning effort.</p>



<p>As codebases grow older and larger, this drag compounds. What looks like a simple version upgrade on a roadmap becomes a massive operational burden in practice.</p>



<h2 class="wp-block-heading">Why incremental planning fails</h2>



<p>Most modernization strategies assume that upgrades can be sequenced and absorbed gradually. That assumption is now dangerous. When multiple Java versions reach end-of-support in the same narrow window, enterprises don’t face a single modernization project—they face parallel modernization across their entire estate.</p>



<p>This shifts the challenge from engineering complexity to organizational capacity.</p>



<p>Consider a typical enterprise with 100 developers. If even a fraction of their time is spent maintaining, investigating, or working around unused and obsolete code, the organization burns meaningful engineering capacity on work that delivers no business value. Multiply that across dozens or hundreds of applications, and the bottleneck becomes clear: modernization is limited by people, not frameworks.</p>



<p>Parallel modernization requires parallel capacity—something most organizations haven’t budgeted for.</p>



<p>This explains why traditional approaches struggle to scale. Tools that analyze code in isolation cannot distinguish what actually matters in production. Without clear visibility into what code is relevant, organizations default to caution, effectively converting their timelines into risk.</p>



<h2 class="wp-block-heading">The real bottleneck: developer capacity</h2>



<p>The Java modernization crunch is a crisis of resource allocation, not a technology problem.</p>



<p>Every hour developers spend maintaining obsolete code or investigating unused dependencies is an hour lost to modernization. When organizations face simultaneous upgrades across multiple applications, human capacity becomes the limiting factor. Sequential planning and parallel modernization require the time and capacity most enterprises no longer have.</p>



<p>Organizations that delay action are consuming their flexibility rather than preserving it. Each year of inaction increases the volume of code that must be moved, reviewed, secured, and modernized within the same fixed window. By the time deadlines become unavoidable, the only remaining options are compression, shortcuts, and uncomfortable trade-offs.</p>



<h2 class="wp-block-heading">A different way to think about readiness</h2>



<p>The organizations that navigate this transition successfully will prioritize clarity over immediate upgrades.</p>



<p>Modernization at scale requires an accurate understanding of what actually matters in production before attempting to move it forward. Without that visibility, every upgrade effort inherits unnecessary complexity, consumes excess capacity, and introduces avoidable risk.</p>



<p>The goal is not simply adopting better tools, but reducing the structural load enterprises carry into modernization. Leaner systems modernize faster. Simpler estates scale better. Complexity compounds under time pressure.</p>



<h2 class="wp-block-heading">The timeline is already set</h2>



<p>The Java modernization crunch is a timing problem that is already locked in.</p>



<p>Enterprises that treat the next few years as business-as-usual will discover that sequential plans cannot survive compressed timelines. Those that confront technical debt now—before the pressure hits—will find the coming transition difficult but manageable. Those that don’t will face rushed decisions and permanent trade-offs.</p>



<p>By the time 2029 arrives, the window for gradual modernization will have closed. The calendar won’t wait for us to be ready.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Turn specs into evals for any agent with ASSERT]]></title>
<description><![CDATA[Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents.
The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft S...]]></description>
<link>https://tsecurity.de/de/3588463/it-security-nachrichten/turn-specs-into-evals-for-any-agent-with-assert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588463/it-security-nachrichten/turn-specs-into-evals-for-any-agent-with-assert/</guid>
<pubDate>Wed, 10 Jun 2026 19:10:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents.</p>
<p>The post <a href="https://commandline.microsoft.com/assert-written-intent-executable-evals/">Turn specs into evals for any agent with ASSERT</a> appeared first on <a href="https://www.microsoft.com/en-us/security/blog">Microsoft Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Turn specs into evals for any agent with ASSERT]]></title>
<description><![CDATA[Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first…
Read more →
T...]]></description>
<link>https://tsecurity.de/de/3588455/it-security-nachrichten/turn-specs-into-evals-for-any-agent-with-assert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588455/it-security-nachrichten/turn-specs-into-evals-for-any-agent-with-assert/</guid>
<pubDate>Wed, 10 Jun 2026 19:10:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/turn-specs-into-evals-for-any-agent-with-assert/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/turn-specs-into-evals-for-any-agent-with-assert/">Turn specs into evals for any agent with ASSERT</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The next frontier isn’t AI]]></title>
<description><![CDATA[Crude oil benchmarks spike 60% in 36 hours. By the time markets open Monday morning, a global manufacturer is sitting on exposure it cannot yet quantify: Fuel surcharges incoming from every logistics partner, supplies repriced across multiple product lines, long-haul shipping contracts suddenly u...]]></description>
<link>https://tsecurity.de/de/3584438/it-security-nachrichten/the-next-frontier-isnt-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584438/it-security-nachrichten/the-next-frontier-isnt-ai/</guid>
<pubDate>Tue, 09 Jun 2026 14:09:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Crude oil benchmarks spike 60% in 36 hours. By the time markets open Monday morning, a global manufacturer is sitting on exposure it cannot yet quantify: Fuel surcharges incoming from every logistics partner, supplies repriced across multiple product lines, long-haul shipping contracts suddenly underwater and a forward pricing model built on assumptions that no longer exist.</p>



<p>Emerging technologies can help. A live model of the enterprise can immediately surface where the damage flows and how it compounds. The system will evaluate tens of thousands of response combinations, such as which contracts to renegotiate, which freight to reroute and which lines to reprice, in order to return ranked suggestions in minutes that would take conventional systems days to produce. Meanwhile, at the company’s most energy-intensive facilities, plant managers might be communicating with robotic systems without a single line of code, reconfiguring production to respond to the changes.</p>



<p>I’m afraid this enterprise does not exist — yet. But your competition might be closer to it than you realize.</p>



<p>Sure, artificial intelligence has upended everything we know about business. But the next competitive frontier isn’t AI because all your competitors are making the same bet. The differentiator is orchestration. An unprecedented convergence of new technologies—digital twins, quantum computing and physical AI, to name just three — is making possible a fundamentally different kind of organization. How will you translate breakthrough innovations into a tangible business win?</p>



<h2 class="wp-block-heading">The enterprise as it actually is</h2>



<p>An enterprise digital twin is a live, continuously updated digital representation of the organization, built from digitized workflows and data. Paired with AI, the opportunity they unlock is fundamental. It can empower business leaders and AI agents alike to test decisions before committing to them by modeling outcomes and seeing consequences in a digital copy of the enterprise.</p>



<p>The technology allows you to reason against a live model of the enterprise as it actually is, rather than relying on intuition or historical patterns that may no longer be accurate. By using a digital twin, an agent can surface the projected impact of a decision before anything goes live, flagging risks and presenting options rather than simply executing.</p>



<p>On a more granular level, the technology can allow you to iterate on any product, work process or even entire manufacturing plant in a simulated setting. PepsiCo can now accurately recreate every piece of equipment, conveyor and operator routes, <a href="https://news.siemens.com/en-us/digital-twin-composer-ces-2026/" rel="nofollow">resulting</a> in expedited design cycles, 90% identification of potential issues and up to 15% decrease in capital expenditure.</p>



<p>Now imagine AI agents that do not just query the model but continuously refine it. Every task completed, every outcome recorded, feeds back into the digital twin, so the model grows more accurate with every cycle. Over time, the organization builds a self-sharpening picture of how it actually works and how it can work better, with real-time information available to every agent that carries out tactics and every leader making decisions.</p>



<h2 class="wp-block-heading">The decisions that can’t wait for answers</h2>



<p>Running meaningful simulations requires computation at a scale that varies dramatically by decision complexity. For the most consequential choices that require running algorithms across thousands of variables, classical computing runs out of road. <a href="https://www.servicenow.com/es/workflow/innovations/quantum-computing-real-world-impact.html" rel="nofollow">Quantum computing can address that ceiling</a> by processing multiple states simultaneously rather than sequentially, using qubits that each represent a potential exponential increase in capability. The result is an ability to tackle high-parameter optimization problems that classical hardware cannot handle in any practical timeframe.</p>



<p>Though we are still a few years away from seeing the technology come into fruition, companies are laying the foundation for quantum and seeing meaningful results. Working with quantum-enabled algorithm, <a href="https://www.hsbc.com/news-and-views/news/media-releases/2025/hsbc-demonstrates-worlds-first-known-quantum-enabled-algorithmic-trading-with-ibm" rel="nofollow">a proof of concept by HSBC recorded a 34% improvement</a> in trade fill prediction.</p>



<p>Now, envision pairing a detailed enterprise digital twin with quantum simulation, running hundreds of thousands of scenarios on a single acquisition decision, weighting product fit, cultural signals and competitive positioning, and returning a probability. Many decisions do not warrant that level of modeling, but some do. Organizations preparing now are building the decision architecture that will know the difference.</p>



<h2 class="wp-block-heading">Where intelligence meets the real world</h2>



<p>The enterprise doesn’t end at the screen. Neither should its intelligence. In the real world, most business processes ultimately result in a physical action, whether it’s a product being built or a customer consuming that product. Until now, digital intelligence has always had to hand that final action off to a human or, at best, a machine that carries out pre-programmed actions. That’s changing.</p>



<p><a href="https://www.servicenow.com/standard/resource-center/white-paper/wp-physical-ai-innovation-brief.html" rel="nofollow">Physical AI</a> encompasses the robots, sensors and autonomous machines that can perceive the physical world and act within it, converting digital decisions into real-world execution. We already have the technology to translate natural language instructions into physical commands, and projects like <a href="https://www.press.bmwgroup.com/global/article/detail/T0455864EN/bmw-group-to-deploy-humanoid-robots-in-production-in-germany-for-the-first-time" rel="nofollow">BMW’s humanoid robotics program</a> signal that we are taking a meaningful leap forward from explicitly programmed machines to the operational deployment of intelligent execution.</p>



<p>Physical AI still struggles in unfamiliar environments, and full autonomy requires more testing. But it won’t be long before we see physical AI systems step into places facing worker shortages, carrying out tasks like prepping operating rooms while freeing clinical staff for work that requires human judgment. The same extends to agriculture, logistics, field service and anywhere else where a process terminates in a physical action.</p>



<p>When that execution layer is connected to agentic AI, the result is transformative. A detected disruption triggers an immediate response: Inventory reallocated, robotic systems rerouted and machines dispatched to address the issue.</p>



<h2 class="wp-block-heading">Building tomorrow’s connective layer now</h2>



<p>Digital twins, quantum computing and physical AI are only three of many promising emerging technologies. The convergence is broader and moving faster than most enterprise strategies currently reflect. Together, they point toward something without precedent: An enterprise that can sense, simulate and act across digital and physical domains, learning from every cycle it completes.</p>



<p>AI belongs in this picture, but it is not the whole picture. Every competitor is already making a bet on AI. The differentiation lies in what surrounds it: The holistic nervous system that connects these technologies so they function as a system rather than a collection of deployments.</p>



<p>The organizations that will lead are not waiting. They are building the connective tissue now.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Minimus Unveils New Supply Chain Protection Proxy and Command-Line Interface for Container Management]]></title>
<description><![CDATA[Cloud software security firm Minimus today expanded its product portfolio with the general availability of Minimus Supply Chain Protection and minicli. The tools introduce a unified approach to managing third-party software risks and container image configurations.



The release of Supply Chain ...]]></description>
<link>https://tsecurity.de/de/3582186/it-nachrichten/minimus-unveils-new-supply-chain-protection-proxy-and-command-line-interface-for-container-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582186/it-nachrichten/minimus-unveils-new-supply-chain-protection-proxy-and-command-line-interface-for-container-management/</guid>
<pubDate>Mon, 08 Jun 2026 19:03:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cloud software security firm Minimus today expanded its product portfolio with the general availability of Minimus Supply Chain Protection and minicli. The tools introduce a unified approach to managing third-party software risks and container image configurations.</p>



<p>The release of Supply Chain Protection directly targets vulnerabilities found within the application package universe, where interwoven dependencies are frequently maintained by isolated third parties. Operating seamlessly as a pull-through proxy for NPM and PyPI, the solution evaluates public packages based on popularity, commit data, and cooling-off periods before they reach CI/CD pipelines. Platform teams can deploy multiple configurations tailored to the risk tolerances of different development environments.</p>



<p>In tandem, Minimus has launched minicli, a public command-line tool downloadable for macOS and Linux (AMD and ARM). The utility allows developers to inspect custom image structures—including internal file bundles and environment variables—and manage private images directly from the terminal. By converting image recipes into YAML files, teams can easily integrate change controls and automation into their existing technology stacks.</p>



<p>Together with Minimus Images, which eliminate up to 98% of standard container base image vulnerabilities, these updates offer an end-to-end strategy for securing both OS packages and application dependencies.</p>



<p><strong>About Minimus</strong></p>



<p>Minimus delivers a modern foundation for secure container software, open-source dependency management, and software supply chain security. The company was founded in October 2022 by container security pioneers Ben Bernstein, Dima Stopel, and John Morello (co-authors of NIST SP 800-190 and founders of Twistlock) to solve the ongoing operational burden of cloud vulnerability remediation. By engineering high-security container images directly from upstream project sources with only the absolute minimum software required to run, Minimus completely neutralizes 98% of typical cloud software vulnerabilities. Minimus offers a highly scalable, developer-friendly solution that deploys instantly via standard tools, and is backed by a $51M seed investment from YL Ventures and Mayfield. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smart TV Apps Found Converting Samsung and LG Devices Into AI Proxy Nodes]]></title>
<description><![CDATA[Free apps running on Samsung and LG smart TVs are raising privacy and security concerns after researchers found that some connected TV apps can turn home devices into residential proxy nodes. The activity is linked to Bright Data’s software development kit, or SDK. This SDK is added inside partne...]]></description>
<link>https://tsecurity.de/de/3580768/it-security-nachrichten/smart-tv-apps-found-converting-samsung-and-lg-devices-into-ai-proxy-nodes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580768/it-security-nachrichten/smart-tv-apps-found-converting-samsung-and-lg-devices-into-ai-proxy-nodes/</guid>
<pubDate>Mon, 08 Jun 2026 10:16:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Free apps running on Samsung and LG smart TVs are raising privacy and security concerns after researchers found that some connected TV apps can turn home devices into residential proxy nodes. The activity is linked to Bright Data’s software development kit, or SDK. This SDK is added inside partner apps and allows a user’s device, […]</p>
<p>The post <a href="https://cyberpress.org/smart-tvs-become-proxies/">Smart TV Apps Found Converting Samsung and LG Devices Into AI Proxy Nodes</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide]]></title>
<description><![CDATA[Estimative language, evidence discipline, and analytic integrity for cyber threat intelligenceExecutive SummaryThis is an analyst guide, not a formal CTI report. It does not answer a single priority intelligence requirement, assess one actor or campaign end to end, provide an IOC package, or prod...]]></description>
<link>https://tsecurity.de/de/3580440/hacking/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580440/hacking/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:18 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Estimative language, evidence discipline, and analytic integrity for cyber threat intelligence</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*le-GPHh7adFR9iex1Ff7qQ.png"></figure><h3>Executive Summary</h3><p>This is an analyst guide, not a formal CTI report. It does not answer a single priority intelligence requirement, assess one actor or campaign end to end, provide an IOC package, or produce a defensive detection plan. Its purpose is narrower: show how cyber threat intelligence analysts can apply Sherman Kent-style analytic discipline to public evidence without overstating what the evidence proves.</p><p>Sherman Kent was one of the central figures in professionalizing U.S. intelligence analysis. His writing emphasized clear estimative language, policy relevance, analytic independence, evidence discipline, explicit uncertainty, and the separation of fact from judgment (<a href="https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/">CIA, Words of Estimative Probability</a>; <a href="https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3">CIA, The Intelligence Process: A Digest from Strategic Intelligence</a>; <a href="https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf">CIA, Sherman Kent and the Profession of Intelligence Analysis</a>).</p><p>This article uses <strong>“Kent-style analytic discipline”</strong> as shorthand for that professional tradition. It is not claiming that there is one official, codified “Sherman Kent doctrine” that directly governs modern CTI. The safer claim is that Kent’s principles are consistent with later Intelligence Community analytic standards and structured analytic technique guidance, including ICD 203 and the CIA tradecraft primer (<a href="https://www.dni.gov/files/documents/ICD/ICD-203.pdf">ODNI, ICD 203</a>; <a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">CIA, A Tradecraft Primer</a>).</p><p>For CTI, this matters because analysts often work from incomplete telemetry, vendor reporting, malware analysis, infrastructure links, victimology, and government attribution statements. Those evidence types do not all prove the same thing. A file hash can support a malware-family claim. A command-and-control pattern can support a campaign link. Victimology can support a targeting assessment. None of those, by itself, proves adversary intent or state tasking.</p><p>This guide therefore focuses on one standard: make the reader see where evidence ends and assessment begins.</p><h3>Table of Contents</h3><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#4a1e"><strong>Evidence and Confidence Model Used Here</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#b693"><strong>Estimative Probability Reference</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#8b22"><strong>What Is Sherman Kent-Style Analytic Discipline?</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#43ac"><strong>What Maps From Traditional Intelligence to CTI — And What Does Not</strong></a></p><ul><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#285d"><strong>1. Policy Relevance Without Policy Capture</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#18ed"><strong>2. Facts, Assumptions, and Judgments</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#c7e3"><strong>3. Estimative Probability Language</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#bf34"><strong>4. Confidence Is Not Probability</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#bbfe"><strong>5. Alternative Hypotheses</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#da72"><strong>6. Warning, Indicators, and Collection Gaps</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#796b"><strong>7. Analytic Integrity in CTI</strong></a></li></ul><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#8e8e"><strong>Cognitive Biases CTI Analysts Should Name</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#b411"><strong>Where ATT&amp;CK and the Pyramid of Pain Fit</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#99f2"><strong>Kent-Style Checklist</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#2ba7"><strong>Practical Analyst Template</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#a5ae"><strong>Conclusion</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#a513"><strong>References</strong></a></p><h3>Evidence and Confidence Model Used Here</h3><p><strong>This article uses these evidence labels:</strong></p><ul><li><strong>Author-observed:</strong> directly inspected by the author. This article rarely uses this label because it is based on public reporting, not original telemetry or reverse engineering.</li><li><strong>Source-observed:</strong> the cited source claims direct access to evidence, such as imagery, telemetry, malware samples, incident response data, or official records.</li><li><strong>Reported:</strong> stated by a cited source, but not independently verified here.</li><li><strong>Assessed:</strong> analytic judgment made by a cited source.</li><li><strong>Inferred:</strong> reasonable interpretation made in this article from public evidence, but not directly observed.</li></ul><p><strong>Qualifiers are tracked separately from evidence labels:</strong></p><ul><li><strong>Qualifier / limitation:</strong> ambiguity, scope limit, alternate explanation, source-access constraint, or reason the evidence should not be overinterpreted.</li></ul><p><strong>Confidence attaches to a specific assessment, not to an example as a whole:</strong></p><ul><li><strong>High confidence:</strong> strong source access, strong credibility, meaningful corroboration, and a short inference chain.</li><li><strong>Moderate confidence:</strong> credible reporting, but incomplete visibility, limited corroboration, contested interpretation, or a longer inference chain.</li><li><strong>Low confidence:</strong> plausible inference from thin, indirect, or weakly corroborated evidence.</li></ul><p><strong>Every example uses the same four-field confidence basis:</strong></p><ul><li><strong>Source access:</strong> direct telemetry, reverse engineering, official record, government statement, vendor incident response, or secondary reporting.</li><li><strong>Source reliability:</strong> established, unknown, contested, or mixed.</li><li><strong>Information credibility:</strong> corroborated, single-source, inferred, or disputed.</li><li><strong>Author verification:</strong> verified, partially verified, or not independently verified here.</li></ul><p>This is still not a formal source-grading model. Operational CTI should use a more rigorous source reliability and information credibility system, especially when reporting will support security operations, legal action, executive decision-making, or public attribution.</p><h3>Estimative Probability Reference</h3><p>Kent argued that estimative words should not be left to normal conversational ambiguity. Different organizations use different probability bands, but a CTI team should publish and reuse one internal lexicon. A simple working version is:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O5dwFHm_ncEOU61MI32nLw.png"></figure><p>Probability is not confidence. “Likely” says how probable the judgment is. “Moderate confidence” says how strong the evidentiary basis is.</p><p>These bands are illustrative, not universal; the important control is consistency inside the publishing team.</p><h3>What Is Sherman Kent-Style Analytic Discipline?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oXWwShvs3qtrUWIDyfreXQ.png"></figure><p>Kent-style analytic discipline can be reduced to a practical standard: intelligence analysis should help decision-makers reason under uncertainty without hiding the uncertainty. The analyst’s job is not to sound certain. The analyst’s job is to make evidence, assumptions, probability, confidence, alternatives, and collection gaps visible enough that decision-makers understand the basis and limits of the judgment.</p><p>In practice, that means:</p><ol><li><strong>Serve the decision, not the preference:</strong> Intelligence should be relevant to policy or defensive decisions, but analytic judgment should not be shaped to support a preferred outcome.</li><li><strong>Separate facts from estimates:</strong> The analyst should distinguish observed evidence from assumptions, inference, and judgment.</li><li><strong>Use estimative language deliberately:</strong> Words such as “likely,” “probably,” “possible,” and “almost certainly” should communicate probability consistently rather than act as vague hedges.</li><li><strong>State confidence separately from probability:</strong> A judgment can be likely but low confidence if evidence is thin. A judgment can be high confidence but still not certain.</li><li><strong>Expose assumptions and alternatives:</strong> Analysts should test what else could explain the same evidence.</li><li><strong>Identify collection gaps:</strong> A good estimate says what is missing, not only what is believed.</li><li><strong>Preserve analytic integrity:</strong> Intelligence should be candid about uncertainty, source weakness, and dissent.</li></ol><p>This is not a mechanical checklist. It is a writing and reasoning discipline: structure the product so the reader can audit the analytic path.</p><h3>What Maps From Traditional Intelligence to CTI — And What Does Not</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*P_kpV2peYBfbICkYx0HRhg.png"></figure><p>Traditional national-security intelligence and CTI share the same analytic problem: decisions must be made before evidence is complete. Kent-style discipline maps well to CTI in several areas:</p><ul><li><strong>Estimative language:</strong> CTI needs disciplined wording for attribution, intent, targeting, capability, and likelihood of future activity.</li><li><strong>Source access:</strong> CTI must distinguish endpoint telemetry, network logs, malware samples, sinkhole data, victim reporting, vendor clustering, government statements, and media summaries.</li><li><strong>Confidence:</strong> CTI must explain whether confidence comes from direct artifacts, multiple independent sources, long-term tracking, or inference.</li><li><strong>Alternative hypotheses:</strong> CTI must test whether shared infrastructure means same actor, whether victimology means deliberate targeting, and whether malware behavior proves intent.</li><li><strong>Collection gaps:</strong> CTI should turn uncertainty into hunt tasks, telemetry requirements, malware-analysis questions, and intelligence requirements.</li></ul><h4>But not everything transfers cleanly:</h4><ul><li><strong>CTI evidence is often technical and perishable:</strong> Domains, infrastructure, certificates, hashes, and telemetry can age quickly.</li><li><strong>Vendor labels are not legal attribution:</strong> NOBELIUM, APT29, COZY BEAR, and other labels may overlap, but they are not automatically interchangeable.</li><li><strong>Visibility is uneven:</strong> One vendor may see endpoint telemetry, another may see cloud logs, and a government source may have classified access unavailable to public readers.</li><li><strong>Intent is harder than behavior:</strong> Malware execution, credential theft, and lateral movement can be documented technically. Strategic objective usually requires assessment.</li><li><strong>A CTI report needs a scoped question:</strong> This article is a tradecraft guide. A real CTI report would need a PIR, key judgments, actor or campaign scope, timeline, source base, indicators, affected victims or sectors, confidence per judgment, and defensive implications.</li></ul><h3>1. Policy Relevance Without Policy Capture</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mBQ_-Mvq3kbMpUNRP3Dc0g.png"></figure><p>Kent argued for intelligence that mattered to national decisions. Relevance does not mean advocacy. In CTI terms, the analyst should understand the decision context — patch prioritization, detection engineering, executive risk, incident response, threat hunting, vendor exposure, or public communication — without forcing the evidence to support a preferred action.</p><h4>Example 1: Cuban Missile Crisis imagery supported decision-making without replacing policy judgment</h4><ul><li><strong>Claim:</strong> October 1962 imagery narrowed uncertainty about Soviet offensive missile deployment in Cuba, but did not determine the U.S. policy response.</li><li><strong>Evidence:</strong> U.S. historical records describe a U-2 flight on October 14, 1962 and subsequent photo interpretation that identified Soviet MRBM sites under construction.</li><li><strong>Source access:</strong> Official historical records and archival imagery; reported in U.S. government records, not author-observed here.</li><li><strong>Assessment:</strong> This is a strong national-security example of policy-relevant intelligence: evidence clarified the threat, while the response remained a policy decision.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official records and archival imagery; Source reliability: established; Information credibility: corroborated; Author verification: public records checked, original imagery not independently analyzed here.</li><li><strong>Sources:</strong> <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">Office of the Historian, FRUS chronology</a>; <a href="https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba">National Archives, Aerial Photograph of Missiles in Cuba</a>.</li><li><strong>Qualifier / limitation:</strong> This is not a CTI case. It is used because the evidence-to-decision structure is directly relevant to CTI reporting.</li></ul><p>The CTI translation is straightforward: a malware sample, intrusion timeline, or cloud log can narrow uncertainty, but it does not automatically decide whether the organization should disclose publicly, isolate a business unit, attribute the incident, or notify regulators.</p><h4>Example 2: The 2007 Iran NIE decomposed a broad question into narrower judgments</h4><ul><li><strong>Claim:</strong> The 2007 Iran NIE separated several analytic questions — weaponization, enrichment, intent, and future capability — instead of treating “Iran’s nuclear program” as one indivisible judgment.</li><li><strong>Evidence:</strong> The declassified NIE uses differentiated judgments and confidence levels across related nuclear questions.</li><li><strong>Source access:</strong> Public declassified key judgments; reported by ODNI, not author-observed classified sourcing.</li><li><strong>Assessment:</strong> The product is a useful example of decomposing a broad question into narrower estimative judgments.</li><li><strong>Confidence in assessment:</strong> High for the decomposition claim; low for any claim about policy effect unless separately sourced.</li><li><strong>Confidence basis:</strong> Source access: declassified ODNI key judgments; Source reliability: established; Information credibility: primary public document; Author verification: public text checked, classified sourcing not available.</li><li><strong>Sources:</strong> <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">ODNI, Iran: Nuclear Intentions and Capabilities</a>; <a href="https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/">CIA CSI, 2007 NIE on Iran</a>.</li><li><strong>Qualifier / limitation:</strong> This article does not assess whether the NIE changed policy. It only uses the public product to show disciplined decomposition of judgments.</li></ul><h3>2. Facts, Assumptions, and Judgments</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f0Wu_l81Mk6vjtKsA73UQA.png"></figure><p>Kent-style analysis requires a visible boundary between what the analyst knows and what the analyst concludes. The most dangerous failures often occur when assumptions are written as if they are evidence.</p><h4>Example 1: Iraq WMD analysis shows the risk of assumption-driven certainty</h4><ul><li><strong>Claim:</strong> The Iraq WMD case is a negative example of insufficiently disciplined separation between evidence, assumptions, and judgment.</li><li><strong>Evidence:</strong> The WMD Commission identified weak collection, analytic errors, and failure to make clear how much analysis rested on assumptions rather than strong evidence.</li><li><strong>Source access:</strong> Official retrospective commission reporting; reported, not author-observed original intelligence.</li><li><strong>Assessment:</strong> The Kent-style lesson is that historical behavior and concealment indicators should not be converted into current capability judgments without showing the inference chain.</li><li><strong>Confidence in assessment:</strong> High for the official finding of intelligence failure; moderate for the article’s specific “assumption-driven certainty” framing.</li><li><strong>Confidence basis:</strong> Source access: official retrospective commission reporting; Source reliability: established; Information credibility: corroborated for broad failure, interpreted for this article’s lesson framing; Author verification: public report checked, original intelligence not available.</li><li><strong>Sources:</strong> <a href="https://govinfo.library.unt.edu/wmd/report/index.html">WMD Commission report index</a>; <a href="https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html">WMD Commission transmittal letter</a>; <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">GPO WMD Commission PDF</a>.</li><li><strong>Qualifier / limitation:</strong> The Iraq case is not a CTI case. It is included because it is a canonical warning about assumptions, source weakness, and overconfident estimates.</li></ul><p><strong>Correct Kent-style wording would separate:</strong></p><ul><li><strong>Reported:</strong> Iraq had historical WMD programs and had previously concealed activity.</li><li><strong>Reported:</strong> sources and technical indicators were interpreted as suggesting renewed activity.</li><li><strong>Assumed:</strong> past concealment behavior implied possible continuing programs.</li><li><strong>Assessed:</strong> Iraq retained or reconstituted WMD capabilities.</li><li><strong>Collection gap:</strong> direct, reliable access to current program status was limited.</li></ul><p>The failure mode is converting “the regime has concealed WMD before” into “the regime currently has active WMD programs” without making the inferential jump visible enough.</p><h4>Example 2: SolarWinds analysis required separating technical fact from attribution judgment</h4><ul><li><strong>Claim:</strong> SolarWinds reporting should distinguish technical supply-chain compromise from actor attribution and strategic intent.</li><li><strong>Evidence:</strong> CISA reported malicious code inserted into the SolarWinds software lifecycle; CrowdStrike analyzed SUNSPOT’s role in manipulating the build process.</li><li><strong>Source access:</strong> CISA-reported government advisory and CrowdStrike-reported technical analysis; not author-observed here.</li><li><strong>Assessment:</strong> The technical compromise, vendor cluster labels, government attribution, and intent assessment should be written as separate claims.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: government advisory and vendor technical analysis; Source reliability: established; Information credibility: corroborated for supply-chain compromise; Author verification: public reports checked, no independent reverse engineering here.</li><li><strong>Sources:</strong> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">CISA AA20–352A</a>; <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">CrowdStrike, SUNSPOT</a>.</li><li><strong>Qualifier / limitation:</strong> Public reporting can support strong technical conclusions while still leaving parts of attribution and intent dependent on non-public evidence.</li></ul><p><strong>Kent-style separation:</strong></p><ul><li><strong>Technical behavior:</strong> malicious Orion component inserted into build/update lifecycle.</li><li><strong>Tooling:</strong> SUNSPOT and SUNBURST.</li><li><strong>Vendor/government label:</strong> NOBELIUM, StellarParticle, APT29-style community labels depending on source.</li><li><strong>Attribution:</strong> assessed responsibility by governments or vendors.</li><li><strong>Intent:</strong> assessed intelligence collection or access objective.</li></ul><h3>3. Estimative Probability Language</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dOK04WErXA1j0WBJz5d0Xw.png"></figure><p>Kent’s “Words of Estimative Probability” addressed a persistent intelligence problem: analysts use words like “possible,” “probable,” and “likely,” but readers may assign different probabilities to the same words. This discipline does not require every estimate to become a math problem. It requires that probability language be intentional and consistent.</p><h4>Example 1: APT28 attribution should preserve source confidence</h4><ul><li><strong>Claim:</strong> Public APT28 attribution language should preserve the source’s estimative wording.</li><li><strong>Evidence:</strong> The linked Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government and targeted information useful to government interests. Older or fuller Mandiant/FireEye reporting may use different confidence phrasing, so analysts should preserve the exact wording of the specific source they cite.</li><li><strong>Source access:</strong> Vendor reporting based on proprietary analysis; exact source base not fully available to public readers.</li><li><strong>Assessment:</strong> “The cited Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government” is stronger tradecraft than writing “APT28 is proven to be Russia.”</li><li><strong>Confidence in assessment:</strong> High for the wording recommendation; moderate for public evaluation of the underlying sponsorship claim.</li><li><strong>Confidence basis:</strong> Source access: vendor reporting based on proprietary analysis; Source reliability: established vendor; Information credibility: credible but not fully public; Author verification: linked blog wording checked, underlying evidence not independently verified.</li><li><strong>Source:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations">Google Cloud / Mandiant, APT28</a>.</li><li><strong>Qualifier / limitation:</strong> Vendor attribution can be credible without being fully independently auditable from public evidence.</li></ul><p><strong>Kent-style wording:</strong></p><ul><li><strong>Better</strong>: “The cited Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government.”</li><li><strong>Weaker</strong>: “APT28 is Russian government-directed.”</li><li><strong>Worse</strong>: “APT28 is proven to be Russia.”</li></ul><p>The first version preserves the source, the estimative term, and the fact that the statement is an assessment.</p><h4>Example 2: 2007 Iran NIE showed probability and confidence in the same product</h4><ul><li><strong>Claim:</strong> The 2007 Iran NIE is a useful example of stating confidence levels across separate judgments.</li><li><strong>Evidence:</strong> The declassified NIE differentiates judgments about halted weaponization, enrichment, intent, and future decisions.</li><li><strong>Source access:</strong> Public declassified key judgments; original classified evidence not available here.</li><li><strong>Assessment:</strong> The product demonstrates why broad topics should be decomposed into narrower estimates with separate uncertainty.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: declassified ODNI key judgments; Source reliability: established; Information credibility: primary public document; Author verification: public text checked, classified sourcing not available.</li><li><strong>Source:</strong> <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">ODNI, Iran NIE</a>.</li><li><strong>Qualifier / limitation:</strong> Confidence language is not a guarantee of truth. It is a statement about evidentiary strength and analytic basis at the time of the estimate.</li></ul><h3>4. Confidence Is Not Probability</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PieOUrrsp4VbSGcRInnZpg.png"></figure><p>Probability answers: “How likely is the judgment?” Confidence answers: “How strong is the basis for the judgment?” Analysts often blur these together. Kent-style discipline keeps them separate.</p><h4>Example 1: Iraq WMD showed that high-confidence judgments can still be wrong</h4><ul><li><strong>Claim:</strong> High confidence does not guarantee analytic accuracy if the source base and assumptions are weak.</li><li><strong>Evidence:</strong> Official retrospective reporting found major problems in prewar Iraq WMD assessments, including unsupported or overstated judgments.</li><li><strong>Source access:</strong> Official retrospective investigations and public reporting.</li><li><strong>Assessment:</strong> The case shows why confidence statements must identify source quality, access, corroboration, and assumption sensitivity.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official retrospective investigations; Source reliability: established; Information credibility: corroborated for failure finding; Author verification: public reports checked, original intelligence not available.</li><li><strong>Sources:</strong> <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">WMD Commission report</a>; <a href="https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm">Senate Select Committee conclusions via GlobalSecurity mirror</a>.</li><li><strong>Qualifier / limitation:</strong> This does not mean confidence language is useless. It means confidence must be earned and explained.</li></ul><p><strong>Kent-style analysts should ask:</strong></p><ul><li>What are the strongest sources?</li><li>Which sources are single points of failure?</li><li>What assumptions connect the evidence to the judgment?</li><li>What reporting contradicts the judgment?</li><li>What evidence would reduce confidence?</li></ul><h4>Example 2: CTI malware behavior can be high confidence while intent remains moderate confidence</h4><ul><li><strong>Claim:</strong> A CTI product can have high confidence in technical behavior and lower confidence in actor intent.</li><li><strong>Evidence:</strong> Mandiant reporting ties WannaCry to SMBv1/TCP 445 propagation and EternalBlue/MS17–010 exploitation. The U.S. Department of Justice later alleged that a North Korean regime-backed programmer connected to Lazarus Group activity participated in creating the malware used in the WannaCry 2.0 attack.</li><li><strong>Source access:</strong> Mandiant malware analysis reported technical behavior; DOJ charged/alleged DPRK-linked involvement and provided public attribution material; not author-observed here.</li><li><strong>Assessment:</strong> Analysts should assign separate confidence to malware behavior, actor clustering, government attribution, and intent. Government attribution does not remove the need to distinguish technical behavior from strategic motivation.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: Mandiant malware analysis and DOJ charging/public attribution material; Source reliability: established; Information credibility: high for SMB/MS17–010 behavior, established public government attribution exists, inferred for intent and internal tasking; Author verification: public reporting checked, no independent malware analysis here.</li><li><strong>Sources:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile">Mandiant, WannaCry malware profile</a>; <a href="https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/">Mandiant, WannaCry use of EternalBlue</a>; <a href="https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and">DOJ, North Korean regime-backed programmer charged</a>.</li><li><strong>Qualifier / limitation:</strong> This article does not independently adjudicate the DPRK/Lazarus attribution. It uses the case to show how post-attribution CTI should still separate behavior, attribution, and intent.</li></ul><h3>5. Alternative Hypotheses</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OgBOQ_0sgEge7IwPdLOr7g.png"></figure><p>Kent-style analysis does not require analysts to treat all hypotheses as equally plausible. It does require analysts to ask what else could explain the evidence and what collection would discriminate between explanations.</p><h4>Example 1: 9/11 warning failure showed the cost of narrow imagination</h4><ul><li><strong>Claim:</strong> The 9/11 case illustrates why warning analysis needs alternative hypotheses before a threat becomes obvious in hindsight.</li><li><strong>Evidence:</strong> The 9/11 Commission identified failures of imagination, policy, capabilities, and management.</li><li><strong>Source access:</strong> Official retrospective commission reporting.</li><li><strong>Assessment:</strong> A warning product should test competing explanations for fragmentary indicators, including low-frequency but high-impact possibilities.</li><li><strong>Confidence in assessment:</strong> High for the broad warning lesson; moderate for any reconstructed pre-attack hypothesis set.</li><li><strong>Confidence basis:</strong> Source access: official retrospective commission reporting; Source reliability: established; Information credibility: corroborated for broad failure categories, illustrative for reconstructed hypotheses; Author verification: public report checked.</li><li><strong>Sources:</strong> <a href="https://www.9-11commission.gov/report/911Report.pdf">9/11 Commission Report PDF</a>; <a href="https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary">Office of Justice Programs summary</a>.</li><li><strong>Qualifier / limitation:</strong> Hindsight makes patterns look cleaner than they appeared at the time. The goal is humility and better warning structure, not retrospective certainty.</li></ul><p><strong>Possible analytic frame before the attack:</strong></p><ul><li><strong>H1:</strong> Al-Qaida intended overseas attacks against U.S. interests.</li><li><strong>H2:</strong> Al-Qaida intended a major attack inside the United States.</li><li><strong>H3:</strong> Al-Qaida intended aviation-related operations, but the exact target and method were unknown.</li><li><strong>Discrimination:</strong> travel patterns, flight training, visa anomalies, financial movement, communications, and detainee reporting could have been evaluated as indicators across hypotheses.</li></ul><h4>Example 2: NotPetya intent remains an assessed judgment</h4><ul><li><strong>Claim:</strong> NotPetya’s destructive effect is easier to establish publicly than the operators’ internal intent.</li><li><strong>Evidence:</strong> Microsoft reported destructive behavior and enterprise spread; Cisco Talos reported M.E.Doc infrastructure manipulation connected to the outbreak. The UK and U.S. governments publicly attributed NotPetya to the Russian government or Russian military in February 2018, and DOJ later charged GRU Unit 74455 officers in connection with NotPetya and other destructive operations.</li><li><strong>Source access:</strong> Vendor technical analysis, incident reporting, and public government attribution statements.</li><li><strong>Assessment:</strong> Destructive effect should be reported separately from strategic intent even after public government attribution exists.</li><li><strong>Confidence in assessment:</strong> High for destructive effect; moderate for specific intent claims.</li><li><strong>Confidence basis:</strong> Source access: vendor technical reporting and government attribution statements; Source reliability: established; Information credibility: corroborated for destructive effect, public attribution strengthens actor context, internal intent remains inferred; Author verification: public reports checked, no original telemetry review.</li><li><strong>Sources:</strong> <a href="https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/">Microsoft, NotPetya technical analysis</a>; <a href="https://blogs.cisco.com/security/talos/the-medoc-connection">Cisco Talos, The MeDoc Connection</a>; <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks">UK Government, Foreign Office Minister condemns Russia for NotPetya</a>; <a href="https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/">White House, Statement from the Press Secretary</a>; <a href="https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and">DOJ, Six Russian GRU officers charged</a>.</li><li><strong>Qualifier / limitation:</strong> Public attribution strengthens the actor context, but it still does not expose every internal objective, command decision, or intended propagation boundary.</li></ul><p><strong>Alternative hypotheses:</strong></p><ul><li><strong>H1:</strong> NotPetya was designed as a destructive state operation using ransomware aesthetics as cover.</li><li><strong>H2:</strong> NotPetya was designed primarily for Ukraine-focused disruption but propagated more broadly than intended.</li><li><strong>H3:</strong> The ransomware presentation reflected mixed objectives or operational cover rather than a pure financial motive.</li></ul><p>The evidence strongly supports destructive effect. It does not publicly prove the internal decision process behind the operation.</p><h3>6. Warning, Indicators, and Collection Gaps</h3><p>Kent-style analysis is not only retrospective. It should produce warning questions and collection requirements. A judgment with no collection gap is often a judgment that has not been examined carefully enough.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XkXGaxgF5xHc8p4jfSAsBg.png"></figure><h4>Example 1: Cuban Missile Crisis warning depended on collection timing and imagery interpretation</h4><ul><li><strong>Claim:</strong> The Cuban Missile Crisis shows how warning changes as collection improves.</li><li><strong>Evidence:</strong> Official records describe the October 14, 1962 U-2 mission, subsequent photo interpretation, and identification of MRBM sites under construction.</li><li><strong>Source access:</strong> Official records and imagery references.</li><li><strong>Assessment:</strong> Before imagery confirmation, the problem was warning under uncertainty; after imagery, the problem became site status, operational timeline, Soviet intent, and escalation risk.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official records and imagery references; Source reliability: established; Information credibility: corroborated; Author verification: public records checked.</li><li><strong>Sources:</strong> <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">Office of the Historian, FRUS chronology</a>; <a href="https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/">DIA photo record</a>.</li><li><strong>Qualifier / limitation:</strong> This is a national-security warning example, not a CTI intrusion case.</li></ul><p><strong>Kent-style warning questions:</strong></p><ul><li>What indicators would show offensive missile deployment rather than defensive military aid?</li><li>What collection confirms construction status?</li><li>What evidence distinguishes operational missiles from support equipment?</li><li>What is the time horizon before the threat becomes operational?</li><li>What assumptions could cause overreaction or underreaction?</li></ul><h4>Example 2: SolarWinds exposed a collection gap in trusted software supply chains</h4><ul><li><strong>Claim:</strong> SolarWinds showed that trusted software updates can create visibility gaps not solved by ordinary IOC matching.</li><li><strong>Evidence:</strong> CISA and CrowdStrike reporting describe malicious code inserted into a trusted software build and update process.</li><li><strong>Source access:</strong> Government advisory and vendor technical analysis.</li><li><strong>Assessment:</strong> The collection gap included build integrity, signed software provenance, vendor trust relationships, and anomalous post-update behavior.</li><li><strong>Confidence in assessment:</strong> High for the SolarWinds-specific gap; moderate for generalizing across all software supply-chain risk.</li><li><strong>Confidence basis:</strong> Source access: government advisory and vendor technical analysis; Source reliability: established; Information credibility: corroborated for SolarWinds compromise mechanism, inferred for broader supply-chain lessons; Author verification: public reports checked.</li><li><strong>Sources:</strong> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">CISA AA20–352A</a>; <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">CrowdStrike, SUNSPOT</a>.</li><li><strong>Qualifier / limitation:</strong> A supply-chain compromise does not imply every similar vendor relationship is equally exposed.</li></ul><h3>7. Analytic Integrity in CTI</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SjsMMnm-vjqrTKTrKl-QUA.png"></figure><p>CTI reporting often mixes telemetry, malware family names, vendor clusters, infrastructure, attribution, and intent. Analytic integrity means refusing to compress those into a single confident story unless the evidence supports it.</p><h4>Example 1: APT1 victimology supports targeting assessment, not observed reconnaissance</h4><ul><li><strong>Claim:</strong> APT1 victimology supports a target-selection assessment, but does not directly prove specific reconnaissance methods.</li><li><strong>Evidence:</strong> Mandiant reported that APT1 compromised at least 141 organizations across many industries and tied the victimology to Chinese strategic priorities.</li><li><strong>Source access:</strong> Vendor incident response and technical reporting; public readers do not see the full underlying evidence.</li><li><strong>Assessment:</strong> Victimology supports deliberate campaign-level targeting, while individual intrusion reconnaissance remains a collection gap unless separate evidence exists.</li><li><strong>Confidence in assessment:</strong> Moderate.</li><li><strong>Confidence basis:</strong> Source access: vendor incident response reporting; Source reliability: established vendor; Information credibility: credible but limited public raw data; Author verification: public report checked, underlying case data not available.</li><li><strong>Source:</strong> <a href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">Mandiant, APT1 report</a>.</li><li><strong>Qualifier / limitation:</strong> Victimology alignment is not proof of tasking or pre-compromise research for each victim.</li></ul><p><strong>Kent-style wording:</strong></p><ul><li><strong>Reported:</strong> APT1 compromised a large victim set across multiple sectors.</li><li><strong>Assessed by source:</strong> Victim sectors aligned with strategic economic and policy interests.</li><li><strong>Inferred by this article:</strong> The campaign likely involved deliberate target selection.</li><li><strong>Collection gap:</strong> The exact reconnaissance method before each intrusion is not directly shown by victimology alone.</li></ul><h4>Example 2: SUNBURST, GoldMax, Sibot, and StellarParticle should not be flattened into one label</h4><ul><li><strong>Claim:</strong> SolarWinds-related reporting requires careful separation of malware, tools, vendor clusters, campaign names, attribution, and intent.</li><li><strong>Evidence:</strong> Microsoft described GoldMax, GoldFinder, and Sibot as later-stage NOBELIUM tools; CrowdStrike used StellarParticle for related follow-on intrusion activity.</li><li><strong>Source access:</strong> Vendor technical analysis based on proprietary telemetry and incident response.</li><li><strong>Assessment:</strong> Treating SUNBURST, SUNSPOT, GoldMax, Sibot, NOBELIUM, StellarParticle, APT29, and COZY BEAR as interchangeable would collapse different analytic layers.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: vendor technical reporting; Source reliability: established vendors; Information credibility: credible and label-specific; Author verification: public reports checked, cross-vendor clustering not independently verified.</li><li><strong>Sources:</strong> <a href="https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/">Microsoft, GoldMax, GoldFinder, and Sibot</a>; <a href="https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/">CrowdStrike, StellarParticle observations</a>.</li><li><strong>Qualifier / limitation:</strong> Cross-vendor clustering may be valid, but it should be stated as an assessment with evidence, not assumed from name proximity.</li></ul><p><strong>Kent-style separation:</strong></p><ul><li><strong>Malware/tool:</strong> SUNBURST, SUNSPOT, GoldMax, GoldFinder, Sibot.</li><li><strong>Vendor cluster:</strong> NOBELIUM, StellarParticle, APT29-style community labels.</li><li><strong>Campaign:</strong> SolarWinds-related intrusion activity.</li><li><strong>Attribution:</strong> assessed state-linked responsibility.</li><li><strong>Intent:</strong> intelligence collection, access development, or other objectives.</li></ul><h3>Cognitive Biases CTI Analysts Should Name</h3><p>Kent-style discipline is partly about fighting predictable analytic failure modes. The CIA tradecraft primer emphasizes structured techniques because analysts working with incomplete and ambiguous information are vulnerable to cognitive bias (<a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">CIA, A Tradecraft Primer</a>).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_MKrRprTzQEF_CJcS2EefA.png"></figure><p><strong>Common CTI bias patterns:</strong></p><ul><li><strong>Confirmation bias:</strong> treating every new domain, malware string, or infrastructure overlap as support for the actor hypothesis already in the analyst’s head.</li><li><strong>Anchoring:</strong> giving too much weight to the first vendor label or first incident-response theory, even after better evidence appears.</li><li><strong>Mirror imaging:</strong> assuming the adversary values risk, cost, publicity, or operational tempo the same way the defender does.</li><li><strong>Availability bias:</strong> over-weighting the most recent high-profile campaign because it is memorable, not because it best explains the evidence.</li><li><strong>Groupthink:</strong> converging on a shared attribution label because peer teams or trusted vendors use it, without separately testing the underlying evidence.</li></ul><p>Structured analytic techniques are useful because they force friction into the analysis. Alternative hypotheses, key assumptions checks, evidence matrices, and premortems are not bureaucratic decoration; they are bias controls. In CTI, the most practical bias check is simple: before publishing an attribution, write down the strongest evidence against it.</p><h3>Where ATT&amp;CK and the Pyramid of Pain Fit</h3><p>MITRE ATT&amp;CK gives CTI teams a structured vocabulary for adversary tactics and techniques based on real-world observations (<a href="https://attack.mitre.org/">MITRE ATT&amp;CK</a>). The Pyramid of Pain, associated with David Bianco, explains why higher-level behavioral indicators and TTPs are usually harder for adversaries to change than hashes, IPs, and domains.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Avn2HMvyvckpmQTWnsCEiQ.png"></figure><p><strong>Kent-style discipline does not replace these frameworks. It tells analysts how to write about them:</strong></p><ul><li><strong>Hash, IP, domain:</strong> usually source-observed or reported technical indicators; useful but often perishable and weak for attribution.</li><li><strong>Host or network artifact:</strong> stronger than a raw IOC when tied to execution context, but still may not identify an actor.</li><li><strong>ATT&amp;CK technique:</strong> a behavioral claim. It should be mapped only when evidence supports the behavior, not because a malware family is commonly associated with the technique.</li><li><strong>Tool:</strong> stronger than a hash when supported by reverse engineering, but tool reuse and leaks can complicate attribution.</li><li><strong>TTP pattern:</strong> stronger for clustering when repeated across time, victims, infrastructure, and tooling.</li><li><strong>Actor attribution and intent:</strong> assessed judgments. ATT&amp;CK mapping can support them, but does not prove them by itself.</li></ul><p>Example: “The intrusion used credential dumping” is a technique-level claim. “This was APT28” is an attribution claim. “The objective was strategic intelligence collection” is an intent claim. They need different evidence and different confidence statements.</p><h3>Kent-Style Checklist</h3><p>Use this checklist before publishing an analytic judgment:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kZv6tiN5XkW8yiGJzvSiSA.png"></figure><ol><li><strong>Question:</strong> What decision or intelligence requirement does this answer?</li><li><strong>Claim:</strong> What exactly are you asserting?</li><li><strong>Evidence:</strong> What is source-observed, reported, assessed, or inferred?</li><li><strong>Source access:</strong> Did the source have telemetry, malware samples, logs, imagery, victim access, official records, or secondhand reporting?</li><li><strong>Source reliability:</strong> Is the source established, unknown, contested, or mixed?</li><li><strong>Information credibility:</strong> Is the information corroborated, single-source, inferred, or disputed?</li><li><strong>Author verification:</strong> What did you personally verify?</li><li><strong>Assumptions:</strong> What must be true for the judgment to hold?</li><li><strong>Probability:</strong> How likely is the judgment?</li><li><strong>Confidence:</strong> How strong is the evidence base?</li><li><strong>Alternatives:</strong> What else could explain the same evidence?</li><li><strong>Discrimination:</strong> What evidence would separate the hypotheses?</li><li><strong>Gaps:</strong> What do we still not know?</li><li><strong>Dissent:</strong> Are there credible disagreements or minority views?</li><li><strong>Change indicators:</strong> What would cause the assessment to change?</li></ol><h3>Practical Analyst Template</h3><pre>Product title:<br>Primary intelligence requirement:<br>Decision context:<br>Analyst:<br>Date:<br>Bottom line:<br>- Assessment:<br>- Probability language:<br>- Confidence:<br>- Scope and time horizon:<br>Claim:<br>- Exact claim:<br>- What this claim does not say:<br>Evidence base:<br>- Author-observed:<br>- Source-observed:<br>- Reported:<br>- Assessed by source:<br>- Inferred by analyst:<br>Source quality:<br>- Source access:<br>- Source reliability:<br>- Information credibility:<br>- Corroboration:<br>- Author verification:<br>Assumptions:<br>- Assumption 1:<br>- Assumption 2:<br>- Assumption sensitivity:<br>Alternative hypotheses:<br>- H1 (primary):<br>- H2 (alternative):<br>- H3 (alternative, if needed):<br>- Discriminating evidence:<br>- Current preferred hypothesis and why:<br>Confidence basis:<br>- Collection strength:<br>- Collection weakness:<br>- Analytic uncertainty:<br>- Dissent or caveats:<br>Collection requirements:<br>- Requirement 1:<br>- Requirement 2:<br>- Requirement 3:<br>Indicators to watch:<br>- Indicator that would increase confidence:<br>- Indicator that would decrease confidence:<br>- Indicator that would change the assessment:<br>Defensive or policy implications:<br>- Tactical:<br>- Operational:<br>- Strategic:</pre><h3>Conclusion</h3><p>Sherman Kent’s analytic legacy is not a historical curiosity. It is a practical discipline for writing intelligence under uncertainty. For CTI analysts, the lesson is especially important because cyber reporting routinely combines artifacts, telemetry, malware names, infrastructure links, vendor clusters, government statements, victimology, attribution, and intent.</p><p>The real-world examples show why the discipline matters:</p><ul><li>Cuban Missile Crisis imagery shows policy-relevant intelligence narrowing uncertainty without replacing policy judgment.</li><li>Iraq WMD analysis shows the danger of converting assumptions into confident conclusions.</li><li>The 2007 Iran NIE shows the value of decomposing a broad issue into separate judgments with separate confidence levels.</li><li>9/11 warning analysis shows why alternative hypotheses matter before a threat is obvious.</li><li>SolarWinds shows why CTI must separate technical fact, tooling, vendor labels, attribution, and intent.</li><li>APT1 victimology shows how to infer target selection without pretending to observe reconnaissance.</li><li>NotPetya shows why destructive effect and strategic intent must be assessed separately.</li></ul><p>Used this way, Kent-style analytic discipline helps CTI analysts produce clearer estimates, better collection requirements, more defensible confidence statements, and fewer overclaims.</p><h3>References</h3><ul><li>CIA, Sherman Kent, Words of Estimative Probability: <a href="https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/">https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/</a></li><li>CIA, Words of Estimative Probability PDF: <a href="https://www.cia.gov/resources/csi/static/Words-of-Estimative-Probability.pdf">https://www.cia.gov/resources/csi/static/Words-of-Estimative-Probability.pdf</a></li><li>CIA, The Intelligence Process: A Digest from Strategic Intelligence by Sherman Kent: <a href="https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3">https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3</a></li><li>CIA, Sherman Kent and the Profession of Intelligence Analysis: <a href="https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf">https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf</a></li><li>ODNI, Intelligence Community Directive 203: Analytic Standards: <a href="https://www.dni.gov/files/documents/ICD/ICD-203.pdf">https://www.dni.gov/files/documents/ICD/ICD-203.pdf</a></li><li>CIA, A Tradecraft Primer: Structured Analytic Techniques for Improving Intelligence Analysis: <a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf</a></li><li>Office of the Historian, Cuban Missile Crisis chronology and U-2 collection: <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">https://history.state.gov/historicaldocuments/frus1961-63v11/d16</a></li><li>National Archives, Aerial Photograph of Missiles in Cuba: <a href="https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba">https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba</a></li><li>DIA, Cuban Missile Crisis U-2 photo record: <a href="https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/">https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/</a></li><li>WMD Commission report index: <a href="https://govinfo.library.unt.edu/wmd/report/index.html">https://govinfo.library.unt.edu/wmd/report/index.html</a></li><li>WMD Commission report PDF: <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf</a></li><li>WMD Commission transmittal letter: <a href="https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html">https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html</a></li><li>Senate Select Committee conclusions on Iraq WMD intelligence via GlobalSecurity mirror: <a href="https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm">https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm</a></li><li>9/11 Commission Report PDF: <a href="https://www.9-11commission.gov/report/911Report.pdf">https://www.9-11commission.gov/report/911Report.pdf</a></li><li>Office of Justice Programs, 9/11 Commission Report summary: <a href="https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary">https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary</a></li><li>ODNI, Iran: Nuclear Intentions and Capabilities, 2007 NIE: <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf</a></li><li>CIA CSI, CIA Support to Policymakers: The 2007 NIE on Iran’s Nuclear Intentions and Capabilities: <a href="https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/">https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/</a></li><li>Mandiant, APT1: <a href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf</a></li><li>Google Cloud / Mandiant, APT28: <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations">https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations</a></li><li>CISA, SolarWinds AA20–352A: <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a</a></li><li>CrowdStrike, SUNSPOT: <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/</a></li><li>Microsoft, GoldMax, GoldFinder, and Sibot: <a href="https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/">https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/</a></li><li>CrowdStrike, StellarParticle observations: <a href="https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/">https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/</a></li><li>MITRE ATT&amp;CK: <a href="https://attack.mitre.org/">https://attack.mitre.org/</a></li><li>MITRE, MITRE ATT&amp;CK overview: <a href="https://www.mitre.org/focus-areas/cybersecurity/mitre-attack">https://www.mitre.org/focus-areas/cybersecurity/mitre-attack</a></li><li>Sqrrl / David Bianco, A Framework for Cyber Threat Hunting Part 1: The Pyramid of Pain: <a href="https://www.threathunting.net/files/A%20Framework%20for%20Cyber%20Threat%20Hunting%20Part%201_%20The%20Pyramid%20of%20Pain%20_%20Sqrrl.pdf">https://www.threathunting.net/files/A%20Framework%20for%20Cyber%20Threat%20Hunting%20Part%201_%20The%20Pyramid%20of%20Pain%20_%20Sqrrl.pdf</a></li><li>Mandiant, WannaCry malware profile: <a href="https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile">https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile</a></li><li>Mandiant, WannaCry use of EternalBlue: <a href="https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/">https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/</a></li><li>DOJ, North Korean regime-backed programmer charged in cyber attacks including WannaCry 2.0: <a href="https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and">https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and</a></li><li>Microsoft, NotPetya technical analysis: <a href="https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/">https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/</a></li><li>Cisco Talos, The MeDoc Connection: <a href="https://blogs.cisco.com/security/talos/the-medoc-connection">https://blogs.cisco.com/security/talos/the-medoc-connection</a></li><li>UK Government, Foreign Office Minister condemns Russia for NotPetya attacks: <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks">https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks</a></li><li>White House, Statement from the Press Secretary on NotPetya: <a href="https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/">https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/</a></li><li>DOJ, Six Russian GRU officers charged in connection with destructive malware including NotPetya: <a href="https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and">https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and</a></li></ul><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><p>Stay connected:</p><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=33142ad7553b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b">Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Winners Announced in 2026's 'International Obfuscated C Code Competition']]></title>
<description><![CDATA[Yesterday 2026's International Obfuscated C Code Contest concluded, with 22 new winners announced in a special three-hour livestreamed ceremony! Started 42 years ago, it's been described as the internet's longest-running contest, with entrants concocting convoluted programs glorying in the C prog...]]></description>
<link>https://tsecurity.de/de/3579779/it-security-nachrichten/winners-announced-in-2026s-international-obfuscated-c-code-competition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579779/it-security-nachrichten/winners-announced-in-2026s-international-obfuscated-c-code-competition/</guid>
<pubDate>Sun, 07 Jun 2026 19:50:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Yesterday 2026's International Obfuscated C Code Contest concluded, with 22 new winners announced in a special three-hour livestreamed ceremony! Started 42 years ago, it's been described as the internet's longest-running contest, with entrants concocting convoluted programs glorying in the C programming language's subtleties, all while having some fun. And "For IOCCC29, the volume and quality of submissions were at near-historic heights," explains its home page. 
There's a "Tetris-optimized" GameBoy emulator with source code that looks like a GameBoy, as well as a quasi-Rogue-like game voted "most likely to teleport." Awards were also given for the best imaginary emulator (a virtual machine in 366 bytes of C) and the best fractional emulator (a maze generator for the Commodore 64). But every one of the 22 winning programs seems wildly creative...

 Quine Pong. "Running the program produces the source code to generate the next frame, formatted to display the current frame. By repeatedly compiling and running each successive frame, you can play the game. To move, pass either "w" (up) or "e" (down) as an argument..." 

A winning Taiwanese programmer formatted their source code in the shape of a Tardis from Doctor Who — code that displays an intricate ASCII animation of Doctor Who's 1963 opening title sequence.

 One winning entry emulates an IBM 7040 mainframe, first converting a program (encoded in whitespace) into ASCII-character drawings of punchcards for a FORTRAN program — and then executing that program to calculate the light visible to an observer looking at black hole, ultimately creating an image. It's all recreating what astrophysicist Jean-Pierre Luminet had to do in 1978 to generate the first-ever simulated photograph of a black hole (on an IBM 7040 mainframe). "The entry can also run other FORTRAN programs — but "they must be provided as a deck of punch cards... Tools have been provided to convert to/from decks and to interpret..."

"We have added fun challenges to this year's winning entries competition..." the web site notes. "After you figure out what a given winning entry does, we encourage you to attempt the fun challenge!" 

Thanks to long-time Slashdot reader achowe for bringing the news (who has submitted winning entries in four different decades, starting in 1991 and continuing through 2025) — and who won again this year for a program simulating the Space Invaders-like game from Casio's 1980 MG-880 calculator.
 

Follow the IOCCC on Mastodon.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Winners+Announced+in+2026's+'International+Obfuscated+C+Code+Competition'%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F07%2F1730236%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F07%2F1730236%2Fwinners-announced-in-2026s-international-obfuscated-c-code-competition%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/06/07/1730236/winners-announced-in-2026s-international-obfuscated-c-code-competition?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Banks Want Blockchain Without Crypto]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 Large banks are exploring “tokenized deposits” as a way to modernize banking infrastructure without converting customer funds into cryptocurrency. Instead of placing money directly on-chain, the blockchain can act as a record laye...]]></description>
<link>https://tsecurity.de/de/3577847/it-security-video/banks-want-blockchain-without-crypto/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577847/it-security-video/banks-want-blockchain-without-crypto/</guid>
<pubDate>Sat, 06 Jun 2026 16:17:46 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/6IQvmeGSbDU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Large banks are exploring “tokenized deposits” as a way to modernize banking infrastructure without converting customer funds into cryptocurrency. Instead of placing money directly on-chain, the blockchain can act as a record layer that references deposits still held inside the conventional banking system.<br />
<br />
This approach could let banks benefit from blockchain-based settlement and transfer systems while avoiding the disintermediation associated with decentralized crypto networks. In practice, it preserves existing banking structures while adopting newer transaction rails underneath.<br />
<br />
If banks use blockchain technology but keep deposits fully inside the traditional financial system, is that genuine financial innovation — or simply legacy banking with upgraded infrastructure?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Blockchain #Banking #FinTech #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your outsourcing contract needs XLAs, not just SLAs]]></title>
<description><![CDATA[I’ve lost count of how many clients have called frustrated, not because their managed services provider (MSP) was missing SLAs, but because meeting every SLA still wasn’t helping employees do their jobs. Tickets close on time, uptime stays above target, and scorecards are green across the board y...]]></description>
<link>https://tsecurity.de/de/3572158/it-nachrichten/your-outsourcing-contract-needs-xlas-not-just-slas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572158/it-nachrichten/your-outsourcing-contract-needs-xlas-not-just-slas/</guid>
<pubDate>Thu, 04 Jun 2026 12:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve lost count of how many clients have called frustrated, not because their managed services provider (MSP) was missing SLAs, but because meeting every SLA still wasn’t helping employees do their jobs. Tickets close on time, uptime stays above target, and scorecards are green across the board yet employees remain frustrated by broken processes, recurring issues, and support that feels transactional instead of useful.</p>



<p>The help desk resolves tickets quickly without solving underlying problems, so employees create their own workarounds. This is the watermelon effect: green on the outside, red on the inside. It remains one of the most persistent problems in outsourced IT today.</p>



<h2 class="wp-block-heading">Patterns across major MSP relationships</h2>



<p>I see this pattern across relationships with every major provider. These are sophisticated organizations with mature delivery capabilities that can absolutely hit the metrics you put in front of them. That’s precisely the problem.</p>



<p><a href="https://www.cio.com/article/4160884/you-selected-the-right-vendors-now-govern-them-like-you-mean-it.html?utm=hybrid_search">Vendors</a> optimize for whatever the contract measures. If your contract only measures operational outputs, that’s what your provider will focus on. They’re not doing anything wrong. They’re doing exactly what the contract incentivizes.</p>



<p>What I’ve seen time and again is that the contracts organizations signed five or seven years ago were designed for a different model of IT support, one that enforces compliance and control costs. They weren’t designed to drive outcomes or improve the employee experience, and in many cases, those contracts are still running.</p>



<p>Realigning a major MSP relationship isn’t simply a matter of telling the provider to do better. It requires changing what the contract measures. That’s where experience level agreements come in.</p>



<h2 class="wp-block-heading">Why SLAs weren’t designed to measure what matters most</h2>



<p>SLAs were built for an earlier era of IT. The logic was straightforward: define the service, establish operational standards, measure compliance, and apply financial consequences when performance falls short. It’s precise, auditable, and legally defensible.</p>



<p>But SLAs measure the process, not the outcome. A service desk can resolve 95% of tickets within the agreed timeframe and still leave employees feeling completely unsupported. An application can technically meet uptime standards while being so slow and unreliable that employees avoid using it. That gap, between what the contract measures and what employees actually experience, is where productivity leaks, morale erodes, and the business case for outsourcing quietly unravels.</p>



<p>I’ve sat in enough quarterly business reviews with providers to know how this dynamic plays out. The provider presents a polished scorecard. Every metric is green or amber. The client’s internal stakeholders raise concerns about employee complaints, escalating shadow IT, and department heads who have stopped submitting tickets because they’ve given up. The provider points to the scorecard and there’s no mechanism in the contract to address the gap.</p>



<p>That’s a contract design problem, not a provider capability problem. And it’s one that experience-based measurements like XLAs are specifically designed to solve.</p>



<h2 class="wp-block-heading">The shift organizations need to make, and why it’s hard</h2>



<p>When I work with clients on <a href="https://www.cio.com/article/405257/6-top-managed-cloud-services-providers-and-how-to-choose.html?utm=hybrid_search">realigning MSP relationships</a>, the conversation often starts with frustration, and the solution isn’t straightforward either. Organizations face real structural barriers to making this shift, like with baseline data, for instance. You can’t set meaningful experience targets without knowing where you’re starting from. Many of my clients have been operating on SLA-only contracts for years, sometimes with the same provider, and they have no employee experience data at all. They know ticket volumes and resolution times, but they have no idea how employees actually feel about the service.</p>



<p>Contract language is another issue. Major MSPs have mature commercial teams that are very skilled at navigating ambiguous commitments. Improving the employee experience isn’t a contractual commitment. A defined happiness score is, one that’s measured by a specific tool, and reported monthly with agreed escalation protocols when thresholds are missed.</p>



<p>Another is incentive alignment. The most common mistake I see organizations make is converting an XLA into a penalty mechanism. If the only consequence for missing an experience target is a financial deduction, providers will manage the number rather than the experience. The most effective XLA structures I’ve worked on combine penalties for persistent underperformance with shared gain mechanisms that reward genuine improvement.</p>



<h2 class="wp-block-heading">Four ways to structure XLAs in an outsourcing contract</h2>



<p>Based on what I’ve seen work across client relationships, there are four practical models for building XLAs into a contract. The right starting point depends on where the organization and the provider relationship currently are.</p>



<p><strong>1. Commit to a defined experience score</strong>. The vendor commits contractually to achieving a defined satisfaction threshold. This is the most rigorous model and requires established baseline data on both sides. It works best when the relationship has been running for at least six to 12 months and both parties have experience measurement in place.</p>



<p><strong>2. Commit to a digital experience score</strong>. Here, the XLA is tied to a broader digital employee experience (DEX) score that combines employee sentiment with technical telemetry. Providers like HCL and Cognizant increasingly support this model through partnerships with platforms like Nexthink.</p>



<p><strong>3. Commit to continuous improvement</strong>. Rather than setting fixed thresholds immediately, both parties agree to a shared obligation to improve experience metrics over time, with targets reviewed and reset every six months. This is usually the best entry point for organizations that are new to experience measurement. It builds a data baseline, establishes a culture of shared accountability, and avoids the trap of locking in arbitrary targets before either party understands the benchmarks.</p>



<p><strong>4. Commit to delivering the XLA capability</strong>. In this model, the provider takes responsibility for building and operating the measurement infrastructure itself. This works well when the client lacks internal XLA capability but still wants accountability built into the relationship from the outset. I’ve seen this work particularly well in new contract structures with Accenture and Capgemini, both of which have invested in building proprietary experience measurement frameworks.</p>



<h2 class="wp-block-heading">What XLAs actually measure</h2>



<p>Unlike SLAs, which focus on technical outputs, XLAs focus on human outcomes. The metrics I most commonly see built into client contracts include:</p>



<ul class="wp-block-list">
<li>Employee satisfaction scores</li>



<li>Perceived lost productivity time</li>



<li>Repeat incident rates for the same underlying issue</li>



<li>Ease of getting support across different channels</li>



<li>Task completion success rates</li>



<li>Confidence in IT services overall</li>
</ul>



<p>The goal isn’t to eliminate SLAs as systems still need uptime targets and response standards, and providers operate at a scale where those operational commitments genuinely matter. So the goal is to add the missing layer of whether or not employees feel supported and productive, not just if tickets are being processed.</p>



<h2 class="wp-block-heading">The data infrastructure behind a working XLA program</h2>



<p>Strong XLA programs depend on three categories of data working together. Getting this right is often where the real negotiation with providers happens, because <a href="https://www.cio.com/article/4168669/7-signs-your-data-isnt-ready-for-ai.html?utm=hybrid_search">data ownership</a> and transparency are genuinely contested terrain in major MSP relationships.</p>



<p><strong>Experience data (X-data)</strong>: This is the human layer, how employees feel about their IT experience. It comes from pulse surveys, post-interaction feedback, and always-on feedback channels. Platforms like HappySignals, Nexthink, and Qualtrics are commonly used. One of the most important negotiating points I work through with clients is ensuring that this data is owned by the client, not the provider. Some MSPs propose operating the measurement platform themselves, which creates a structural conflict of interest.</p>



<p><strong>Operational data (O-data)</strong>: This is the traditional metrics layer already stored in ITSM platforms most common among our clients like ServiceNow or Jira Service Management. Most providers already produce this data and the value comes from correlating it with experience data, not treating it in isolation.</p>



<p><strong>Technical data (T-data)</strong>: This is the infrastructure layer comprised of device health, application performance, network latency, and endpoint health. Platforms like Nexthink and 1E collect this telemetry passively. When experience scores drop, correlating against technical data tells you whether the problem is the technology environment, the support process, or the service interaction itself. Without that triangulation, you know something is wrong but can’t pinpoint why.</p>



<h2 class="wp-block-heading">The transparency problem</h2>



<p>In my experience, the biggest failure point in XLA programs isn’t the metrics but transparency. When clients hide poor experience scores or providers obscure unfavorable data, the foundation of the XLA model breaks down.</p>



<p>I’ve seen MSPs manage the measurement platform and report improving scores, only for independent measurement to reveal a very different reality. The strongest XLA programs treat experience data as jointly owned, openly shared, and central to collaborative problem-solving.</p>



<p>Contracts create accountability, but governance drives improvement. Weekly working sessions, monthly reviews, and leadership steering meetings matter far more than scorecards alone. Building that level of transparency is often the hardest part.</p>



<h2 class="wp-block-heading">The shift from service delivery to outcome delivery</h2>



<p>The shift from SLA-only contracts to XLA-enabled outsourcing reflects more than a new measurement framework. It signals a fundamental change in how organizations define IT value. Cost and efficiency still matter, but leading organizations are now asking whether technology investments improve employee productivity, reduce frustration, and create better support experiences. That requires a different level of provider accountability.</p>



<p>MSPs can deliver experience-based outcomes, but they rarely prioritize them unless contracts demand it. XLAs formalize those expectations, and increasingly, organizations see them as the standard for measuring meaningful IT performance.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The next AI breakthrough won’t come from bigger models, but from better data]]></title>
<description><![CDATA[Artificial intelligence does not advance at the same pace across industries. It presses forward in some directions while lagging behind in others.



Spend time with today’s most advanced AI applications, and this contrast becomes obvious. In software development, AI is quickly becoming ubiquitou...]]></description>
<link>https://tsecurity.de/de/3571975/ai-nachrichten/the-next-ai-breakthrough-wont-come-from-bigger-models-but-from-better-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571975/ai-nachrichten/the-next-ai-breakthrough-wont-come-from-bigger-models-but-from-better-data/</guid>
<pubDate>Thu, 04 Jun 2026 11:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence does not advance at the same pace across industries. It presses forward in some directions while lagging behind in others.</p>



<p>Spend time with today’s most advanced AI applications, and this contrast becomes obvious. In software development, AI is quickly becoming ubiquitous. It writes production-ready code, explains obscure libraries, and iterates at a pace human teams have difficulty matching.</p>



<p>But place that same AI model inside a complex customer support workflow or ask it to reason through a nuanced clinical scenario, and the cracks begin to show. Multi-step reasoning falters. Context gets lost. Performance drops in ways that can seem inconsistent with the model’s strengths elsewhere.</p>



<p>These AI models are often similar. They run on similar hardware and are often trained in similar ways. So why the mismatch in performance across tasks? The simplest explanation is also the most overlooked: data.</p>



<p>Software engineering benefits from an immense, structured, and highly visible digital record. Code is written in standardized languages, benefits from robust documentation, is reviewed in public forums, and is discussed at scale. That ecosystem has generated a robust and massively useful pool of training material.</p>



<p>Other fields often do not. For example, healthcare data is scattered across institutions, wrapped in privacy constraints, expressed in multiple modalities, and rarely ready out-of-the-box for AI training. Enterprise workflows are captured in internal systems that were never designed for training AI. Multilingual speech data varies widely in quality and representation.</p>



<p>This imbalance creates what I describe as “the data gap.” This is the distance between what models are capable of in theory and what they can achieve in practice, because the right data does not yet exist in usable form. Closing this data gap may be the most important—and least glamorous—challenge in AI today.</p>



<h2 class="wp-block-heading">The missing pillar of AI progress</h2>



<p>Three forces are driving the recent advances in AI: the models, the chips, and the data.</p>



<p>On the AI models, the field has invested heavily. Major research organizations employ thousands of researchers and scientists who are actively refining architectures, training techniques, and evaluation methods. Breakthroughs are measured in benchmark scores, conference papers, and model performance on human tasks. On the computing chips, the investment has been equally intense. Hardware manufacturers and infrastructure providers are pouring billions of dollars into building and supporting data centers that deliver faster results via large-scale training.</p>



<p>Yet data has not received the same institutional focus for AI development. Conversations with researchers at frontier AI labs share a similar frustration that today’s model capabilities in key use cases, such as healthcare, are limited less by architectural imagination and more by the availability of high-quality, domain-specific data. The bottleneck is not always a lack of ideas, but a lack of reliable inputs.</p>



<p>We are long past scraping the internet for useful data, and this path does not scale. Progress depends on building and curating datasets that reflect the complexity of true lived experience and organizational processes. That work requires both scientific rigor and research specialization in the field of data for AI.</p>



<h2 class="wp-block-heading">The dataset behind every leap</h2>



<p>The <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html" data-type="link" data-id="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">history of AI</a> reinforces a consistent lesson: major leaps in model capability follow major leaps in the availability of quality data. From early vision systems that relied on clearly labeled images to today’s language models trained on massive text collections, each major leap has depended on access to more high-quality data.</p>



<p>Architectural innovation alone is rarely enough. The value of these new approaches only emerges when paired with large, structured, and representative datasets that reveal what the models can actually do in practice. Whether in vision or language, progress has depended on the painstaking work of collecting, organizing, and validating the underlying data.</p>



<p><a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Large language models</a> illustrate this clearly. Their emergence was not just the result of better training techniques, but of access to an unprecedented volume of data. The models did not generate that data. They relied on it. That pattern raises a pressing question for the present: who is building the next generation of foundational datasets?</p>



<p>Across domains ranging from healthcare to audio to agentic task performance, there is no widely accepted blueprint. What constitutes a gold-standard dataset for training an AI agent to handle complex enterprise tasks? What does a clinically meaningful evaluation look like for a model that will assist in medical decision-making? How should multilingual speech data be curated to ensure broad representation and reliable performance?</p>



<p>These are not simple sourcing problems. They are fundamental research challenges that need to be solved.</p>



<h2 class="wp-block-heading">When data is treated as a commodity</h2>



<p>Too often, consequential data decisions are handled like procurement exercises. An organization requests “medical conversations” or “wildlife scenes,” and the request is routed to internal procurement or data sourcing teams, or to external data vendors, who assemble data that appears to match the description. The implicit assumption is that data is interchangeable, that one dataset is as good as another so long as it meets a basic specification.</p>



<p>Actual application suggests otherwise. Seemingly small choices about factors such as inclusion criteria, annotation standards, filtering rules, and validation protocols can dramatically alter downstream performance. Data design shapes model behavior as much as architecture does.</p>



<p>Three structural issues compound the problem:</p>



<ul class="wp-block-list">
<li><strong>Capacity: </strong>There are relatively few specialized teams dedicated to building domain-specific datasets at the highest level of rigor. Talent and funding have gravitated toward model development and hardware innovation. Data work often operates in the background, even though it underpins both.</li>



<li><strong>Design: </strong>Constructing a dataset is a distinct discipline from designing a neural network. It requires expertise in experimental design, domain knowledge, and statistical validation. Expecting model researchers to simultaneously shoulder the full burden of data research, while also training and evaluating the models, overlooks the complexity of the upstream task.</li>



<li><strong>Translation: </strong>The researchers who are requesting specific data sources to improve the models are often not the same people responsible for sourcing that data. As a result, nuances and research-backed expertise can often be missing or diluted as requests pass through layers of procurement and vendor relationships. The result can be data that meets the specification sheet, but in fact fails to advance model performance.</li>
</ul>



<p>The rise of annotation providers and reinforcement learning services has addressed part of the need. Rating model outputs, labeling text, and evaluating structured information are essential for many optimization tasks. But these activities generate data that is carefully constructed for specific, bounded purposes.</p>



<p>The frontier challenges in AI require more. They demand datasets derived from real human activity and organic organizational processes. Such data is complex, multimodal, and sensitive. It is rarely AI-ready by default. And converting it into reliable training and evaluation material is a scientific undertaking.</p>



<h2 class="wp-block-heading">The need for scientific rigor for the AI data layer</h2>



<p>If high-quality data is a central bottleneck, then scientific rigor is part of the solution. Just as leading model-builders have dedicated research labs and hardware has dedicated development ecosystems, the data layer for AI requires focused, scientifically-grounded institutions.</p>



<p>This means engaging directly with core questions like dataset design, evaluation methodology, and quality control. The conversation cannot end at volume; it must address data structure, representativeness, and expert validation.</p>



<p>Dataset construction must be approached as experimental design. Protocols must be documented and validated. Evaluation frameworks must test whether the dataset truly reflects the intended applications.</p>



<p>The field also requires standards and benchmarks that reflect real-world complexity, not simplified proxies. In healthcare, for instance, evaluating a system intended for clinical assistance with generic question-and-answer tests is insufficient. Real-world clinical environments involve multimodal inputs and contextual judgment. Benchmarks must reflect that reality if they are to function as meaningful gates before deployment.</p>



<p>Quality measurement is another crucial frontier. Finance relies on standardized metrics such as credit scores to assess risk. AI lacks an equivalent for datasets and benchmarks. Developing clear methodology to quantify dataset quality and evaluation reliability brings clarity to model assessment.</p>



<p>The criteria for evaluating a multilingual audio library will differ from those of a multimodal oncology dataset. Yet the underlying principle remains constant. Better models require better-defined, better-measured data.</p>



<h2 class="wp-block-heading">The risks of getting it wrong</h2>



<p>As AI systems move closer to high-stakes deployment, weak data practices carry tangible risks.</p>



<p>Benchmarks cannot be created with the same data that is used for training—that’s giving the test answers to the model ahead of time. Scaling data volume without prioritizing data quality and selection diminishes model performance gains, and can even bias against or omit underrepresented populations. These are methodological challenges, and ones that must be solved.</p>



<p>The rigor required at the data layer may not attract headlines. It does not typically lend itself to dramatic product launches. Yet the data layer for AI is foundational to trust, safety, and sustained progress for all AI progress.</p>



<h2 class="wp-block-heading">An ecosystem for the data era</h2>



<p>No single organization can resolve the data gap alone. What is needed is an ecosystem of AI data labs and research groups, each focused on different domains and challenges but united by a commitment to scientific discipline. These institutions would collaborate with model researchers and domain experts who would tackle challenges such as dataset contamination, factuality, groundedness, de-identification, international representation, and bias. They would design benchmarks that mirror real-world complexity rather than simplified abstractions.</p>



<p>AI’s trajectory will not be determined solely by larger models or faster chips. It will be shaped by the datasets we construct, the standards we adopt, and the rigor we apply at the foundation. The uneven frontier we see today reflects an uneven data landscape. Bridging the gap requires deliberate, research-driven dataset design.</p>



<p>If we want AI systems capable of operating reliably in clinical contexts, navigating enterprise workflows, and functioning responsibly across languages and cultures, we must treat data for AI as a first-class scientific endeavor.</p>



<p>AI models have their research labs. AI chip-builders have their fabrication plants. AI data needs institutions of equal seriousness and ambition.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angular Signals explained: How pull-based reactivity changes how we model state]]></title>
<description><![CDATA[Angular’s introduction of Signals has generated both excitement and confusion. For many developers, Signals appear to be “simpler observables” or a more convenient way to trigger updates without subscriptions. Others attempt to map them directly onto familiar RxJS patterns, expecting emissions, o...]]></description>
<link>https://tsecurity.de/de/3571974/ai-nachrichten/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571974/ai-nachrichten/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state/</guid>
<pubDate>Thu, 04 Jun 2026 11:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Angular’s introduction of Signals has generated both excitement and confusion. For many developers, Signals appear to be “simpler observables” or a more convenient way to trigger updates without subscriptions. Others attempt to map them directly onto familiar RxJS patterns, expecting emissions, operators, and event-style coordination.</p>



<p>Both interpretations miss the point.</p>



<p>Signals are not primarily an event system, and they are not designed to replace RxJS. They represent a different way of modeling application behavior, one that centers on current state and explicit dependencies rather than sequences of events. This distinction is subtle at first, but it has significant consequences for how applications are structured and reasoned about over time.</p>



<p>In a previous article, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>,” we reframed form behavior as a state-driven problem rather than an event-driven one. That shift raises an important follow-up question: what kind of reactive primitive is best suited for expressing state and derived behavior? To answer that, we need to understand Signals on their own terms, independent of any specific feature such as forms.</p>



<p>This article examines Angular Signals as a reactivity model rather than a convenience API. By clarifying what Signals are and, just as importantly, what they are not, we can better understand where they fit alongside RxJS and why they align so naturally with state-heavy problems such as form modeling.</p>



<h2 class="wp-block-heading"><a></a>Signals as a state primitive (not an event system)</h2>



<p>To understand why Signals are a good fit for form modeling, it helps to be precise about what Signals are, and just as importantly, what they are not.</p>



<p>Signals are not an event system. They do not represent a sequence of things that happened over time. Instead, a signal represents a <em>current value</em>, along with a dependency graph that describes how other values derive from it. When a signal changes, Angular does not broadcast an event. It simply marks dependent computations as stale and reevaluates them the next time they are read. This is what we mean by fine-grained change detection control.</p>



<p>This distinction may seem subtle, but it has profound implications for how we reason about application logic.</p>



<p>Reactive streams encourage developers to think in terms of emissions. When something changes, subscribers are notified, operators transform the stream, and side effects occur in response. This model is extremely powerful for asynchronous workflows, but it introduces temporal reasoning even when time is not an essential concern. Developers must ask not only <em>what</em> the current state is, but <em>how</em> it arrived there and <em>which emission</em> triggered a particular piece of logic.</p>



<p>Signals, by contrast, encourage a declarative, pull-based model. A computed signal does not react to changes as they occur. Instead, it declares that its value depends on other signals. When those dependencies change, the computed value is simply recomputed the next time it is accessed. There is no notion of subscription order, missed emissions, or stale listeners.</p>



<p>This pull-based model aligns naturally with form state. At any moment, a form has a well-defined set of values. From those values, validity, error messages, and UI flags can be derived. These relationships do not depend on the sequence of changes that led to the current state. They depend only on the current state itself.</p>



<p>This is why Signals feel simpler when applied to state-heavy problems. They shift the developer’s focus away from orchestration and toward declaration. Instead of asking “What should happen when this changes?”, the question becomes “What does this value depend on?”</p>



<p>It is important to note that this does not make Signals a replacement for RxJS. Angular still relies on observables for asynchronous streams, external events, and integration with APIs that produce values over time. Signals and RxJS serve different purposes. In the context of forms, Signals are best used to represent <em>state and derived state</em>, while RxJS remains useful for asynchronous side effects and integration points.</p>



<p>By keeping this distinction clear, we avoid the trap of using Signals as a less expressive event system. Instead, we use them for what they do best: modeling state in a way that is explicit, deterministic, and easy to reason about.</p>



<h2 class="wp-block-heading"><a></a>Designing a signal-first form model with Angular Signal Forms</h2>



<p>Before looking at any concrete implementation, it is worth clarifying what a “signal-first” form model actually implies. The goal is not to introduce a new abstraction that replaces Angular Forms, nor is it to hide form behavior behind another layer of indirection. Instead, the intent is to reorient how form state is represented and reasoned about.</p>



<p>In a signal-first approach, the form’s data model is treated as the single source of truth. Signals are used to represent that state directly, rather than mirroring it through control hierarchies or intermediary objects. The form itself becomes a projection over the state, attaching semantics such as validation, interaction metadata, and submission behavior without duplicating or owning the data.</p>



<p>This distinction is subtle but important. Traditional form models often encourage developers to think of the form as the container of state, with values flowing in and out through events. A signal-first model reverses that relationship. State exists independently of the form, and the form derives its behavior from that state. This makes it easier to inspect, reason about, and test form behavior, because the underlying data remains explicit and accessible.</p>



<p>The examples in this section are therefore intentionally minimal. They are not meant to demonstrate every feature of Angular Signal Forms, but to illustrate how a state-driven representation reshapes form architecture. The emphasis is on structure and intent rather than mechanics. More detailed implementation concerns, such as asynchronous validation, persistence, and UI composition, are explored in the following article.</p>



<p>Once we accept that form behavior is largely derived from state, the next question becomes how that idea is expressed in Angular itself. Angular’s Signal Forms API is a direct response to this shift in thinking. Rather than modeling forms as trees of controls emitting events, Signal Forms begin with a signal-backed model and layer form behavior validation, interaction state, and submission on top of it.</p>



<p>The starting point is still the same: a plain data model representing the values the form collects. In a signal-first approach, this model is wrapped in a writable signal and treated as the single source of truth. There is no duplication of state between the UI and the form model, and no need to synchronize multiple representations of the same data.</p>



<p>From this model signal, a form instance is created using Angular’s <code>form()</code> function. The role of this function is not to introduce a second state container, but to attach form semantics to an existing state object. The form instance provides structured access to fields, validation results, and interaction metadata, all of which are exposed as signals.</p>



<p>Validation is declared through a schema function passed to <code>form()</code>. This schema associates validation rules directly with specific fields in the model. Built-in validators such as <code>required()</code> and <code>email()</code> express constraints declaratively, and Angular automatically reevaluates them whenever the underlying values change. Validation results are not stored imperatively; they are derived and exposed through field-level signals such as i<code>nvalid()</code>, <code>errors()</code>, and <code>pending()</code>.</p>



<p>This design is significant because it keeps validation aligned with the mental model established earlier. Validation rules do not “run” in response to events. They describe constraints on state. When state changes, derived validation state updates automatically, without subscriptions, listeners, or life-cycle hooks.</p>



<h3 class="wp-block-heading">Angular Signals Form example</h3>



<p>A minimal example illustrates the shape of this approach. The model remains a simple interface, and the signal holds the current form values.</p>



<pre class="wp-block-code"><code>interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>The form is then created by passing this model signal into <code>form()</code>, along with a schema that declares validation rules.</p>



<pre class="wp-block-code"><code>const registrationModel = signal<registrationdata>({
  email: '',
  password: '',
  confirmPassword: '',
  acceptedTerms: false,
});

const registrationForm = form(registrationModel, (schema) =&gt; {
  required(schema.email, { message: 'Email is required' });
  email(schema.email, { message: 'Enter a valid email address' });

  required(schema.password, { message: 'Password is required' });
  required(schema.confirmPassword, { message: 'Please confirm your password' });

  required(schema.acceptedTerms, {
    message: 'You must accept the terms to continue',
  });
});
</registrationdata></code></pre>



<p>What matters here is not the syntax, but the structure. The model signal defines <em>what the form is</em>. The schema defines <em>what constraints apply</em>. Angular takes responsibility for deriving field state and exposing it through signals that the UI can consume directly.</p>



<p>Each field now has a clear, inspectable state. Whether a field is valid, invalid, touched, or pending is no longer inferred by tracing event streams or subscription chains. It is available as a signal, derived from the current model and the declared rules. This makes form behavior easier to reason about, test, and debug.</p>



<p>Just as importantly, this model scales naturally. Cross-field validation, such as checking that two password fields match, can be expressed declaratively using schema-level logic that reads from multiple fields. Form-level state, such as whether submission should be allowed, is derived rather than toggled imperatively. The form remains a projection of the state, not a controller of behavior.</p>



<p>I have avoided discussing templates or DOM integration here. The purpose of this section is to show that Angular’s Signal Forms align closely with the first-principles model introduced above. They do not replace that model; they formalize it.</p>



<p>In the next article in this series, we will connect this signal-first form to an actual Angular component. We will bind fields to inputs, render validation feedback using field state signals, and implement submission logic. This implementation will form the foundation of the GitHub example that accompanies this series and will be extended in later articles to cover asynchronous validation, persistence, and hybrid approaches.</p>



<h2 class="wp-block-heading">The power of Signals</h2>



<p>Angular Signals represent a deliberate shift in how reactivity is expressed within the framework. Rather than focusing on events, emissions, and coordination, Signals encourage developers to describe relationships between values. Computation becomes declarative, dependencies become explicit, and behavior becomes easier to reason about by inspection rather than reconstruction.</p>



<p>This does not diminish the role of RxJS. Event streams, asynchronous workflows, and integration with external systems remain essential parts of modern applications. Signals and RxJS solve different problems, and treating them as interchangeable inevitably leads to confusion. When each is used for what it does best — Signals for state and derivation, RxJS for coordination and side effects — the resulting architecture becomes clearer and more maintainable.</p>



<p>Viewed through this lens, the appeal of Signals is not novelty, but alignment. Signals map closely to how developers already think about state: as something that exists now, from which other values can be derived deterministically. This alignment reduces cognitive overhead, particularly in parts of an application where behavior is dominated by state rather than time.</p>



<p>With this understanding in place, we can now turn to practice. The next article applies these ideas to a concrete Angular example, showing how a signal-first approach reshapes form modeling, validation, and UI logic without reintroducing event-driven complexity.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI saves workers a day a week, but they don’t know what to do with it]]></title>
<description><![CDATA[A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.



The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontlin...]]></description>
<link>https://tsecurity.de/de/3571382/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571382/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</guid>
<pubDate>Thu, 04 Jun 2026 06:01:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.</p>



<p>The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontline employees who use AI on a regular basis save upwards of a full day each week; however, 66% are not given guidance on what to do with time they save, and “more than half don’t redirect it to strategic work.”</p>



<p>The <a href="https://www.bcg.com/publications/2026/ai-at-work-why-strategy-matters-more-than-tools" target="_blank" rel="nofollow">report</a>, <em>AI at Work: Strategy Matters More Than Tools</em>, is based on a global survey of 11,749 employees in 14 markets, from industries ranging from financial services to the healthcare sector.</p>



<p><a href="https://www.bcg.com/about/people/experts/david-martin" target="_blank" rel="nofollow">David Martin</a>, global leader of people and organization work at BCG, and the report’s lead author, said via email that the number of employees lacking the required guidance is surprising, “but it also tracks with what we see in many AI transformations. Companies have moved quickly to give people tools, but many have not yet redesigned the work around those tools.”</p>



<p>Saved time, he added, does not automatically become value. If a frontline employee saves a few hours a week, but has no direction on whether to use that time for customer service, quality improvement, innovation, or faster execution, “that value can simply leak out of the organization”</p>



<p>The fix is for leaders to change the scoreboard, Martin said: “Don’t just measure AI adoption or hours saved. Decide where that time should go, measure whether it is being reinvested, and give managers clear guidance on how to help teams use it. This is where AI transformation becomes a management challenge, not just a technology rollout.”</p>



<p>In fact, said <a href="https://www.bcg.com/about/people/experts/vinciane-beauchene" target="_blank" rel="nofollow">Vinciane Beauchene,</a> a managing director and partner at BCG and one of the report’s five co-authors, “the first wave of AI focused on individual productivity. The coming wave will need to transform collective work.”</p>



<p>“Everyone is talking about AI replacing work,” she said, “but it is in fact really about rethinking the human value-add inside.”</p>



<h2 class="wp-block-heading">A managerial revolution underway</h2>



<p>According to Beauchene, “this is the role of leaders. Our survey reveals a true managerial revolution in the age of AI; 65% of managers and leaders now believe agents will take over at least half of their job in the next three years, and frontline workers see their jobs evolving towards more managing and directing AI.”</p>



<p>A BCG <a href="https://www.bcg.com/press/3june2026-ai-reshaping-jobs-faster-than-companies-reshaping-work" target="_blank" rel="nofollow">release</a> stated that the survey also highlights the continued emergence and maturity of AI agents, with 30% of respondents saying that agents are already integrated into workflows, more than double the number from last year’s report (13%).</p>



<p>Other key findings revealed that AI adoption among frontline workers has surged, with 74% saying they now use it daily or a few times a week, which is up 23 percentage points from a year ago. In addition, six out of 10 people believe that, within the next three years, AI agents could do at least half of their jobs.</p>



<p>And a survey <a href="https://web-assets.bcg.com/eb/92/4b39b729403fb6fcae4ff974b234/ai-at-work-slideshow-jun-2026-1.pdf" target="_blank" rel="nofollow">slideshow</a> released by the company pointed out, “the AI ‘honeymoon’ won’t last unless leaders bring strategic clarity driving sustained impact AI’s novelty and cognitive stretch fuel enjoyment early on. But sustained joy comes from strategic clarity. Employees thrive when the direction is real and the message reaches them with strong CEO involvement.”</p>



<h2 class="wp-block-heading">Strategic clarity is a key differentiator</h2>



<p>The report suggests that CEOs take a holistic approach to AI transformations by focusing on business outcomes as opposed to AI usage, investing in “redesigning work end-to-end, not in more tools,” placing people at the heart of that redesign, and governing AI not as a one-off program, but as a moving target.</p>



<p>Overall, BCG says that strategic clarity, “more broadly emerges from the survey as the most crucial differentiator in sustaining AI’s impact over time as organizations are moving past simply implementing AI tools in use case deployment initiatives.”</p>



<p>Increasingly, it adds, “the focus is shifting to redesigning end-to-end workﬂows and processes to reimagine functions, as well as to building and innovating new business models and products to drive growth, which have nearly doubled year-over-year.”</p>



<p>Global leader of BCG’s tech build and design unit BCG X <a href="https://www.bcg.com/about/people/experts/sylvain-duranton" target="_blank" rel="nofollow">Sylvain Duranton</a>, also a report co-author, added, “employees don’t push back on AI intensity; they thrive when the strategy is clear, the direction is real, and the message reaches them.”</p>



<p>He added, “Business value and employee enjoyment aren’t trade-offs. The organizations capturing the greatest business value are the same ones where employees enjoy work the most.”</p>



<p>Despite the opportunity, the report notes that only one-third of frontline employees say that leadership’s communications about AI are clear, and only 28% “see a strong connection between what leaders say and what the organization actually does.”</p>



<p>However, Martin said, management can’t deal with this situation on its own. “CIOs have a critical role, but this is not a problem they can solve alone, and I would not frame it as something IT created by itself,” he noted.</p>



<p>Many organizations, he said, “started with the natural first step of getting tools into people’s hands safely and at scale. That was necessary, but it is not sufficient.”</p>



<p>The next phase “has to be much more cross-functional,” he said. “CIOs should help set the technology foundation, governance, data model, and measurement systems, but they also have an important role in creating strategic clarity. Employees need to understand why the organization is using AI, where it is meant to create value, and how it should change the work.”</p>



<p>Martin pointed out that CIOs should also pay close attention to cognitive load, especially on technology teams, as those teams are often the heaviest AI users.</p>



<p>“This means they may be among the most exposed to the mental strain that can come with reviewing outputs, managing AI tools, and keeping up with constant change,” he observed. The biggest gains come when technology strategy, workforce strategy, and employee experience move together. If AI remains only an IT program, companies will “undercapture” the value.</p>



<h2 class="wp-block-heading">New expectations</h2>



<p>The abundance of AI activity is also having another effect, in that 60% of respondents say the bar for work that counts as ‘good enough’ is now higher.</p>



<p>That, said Martin, is because AI is changing expectations. “If a tool can produce a first draft, summarize research, generate options, or automate a routine task, then ‘good enough’ moves up the value chain,” he said. “People are being asked to spend less time producing basic output and more time exercising judgment like checking quality, improving the answer, making decisions, and applying context.” </p>



<p>While that can be a good thing, he said, because it can make work more interesting and more valuable, “it also explains why employees are feeling more mental strain. The work that remains is often more complex. Leaders need to recognize that AI does not just make people faster, it changes what excellence looks like. That means companies need to update training, performance expectations, and management support accordingly.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI saves workers a day a week, but they don’t know what to do with it]]></title>
<description><![CDATA[A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.



The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontlin...]]></description>
<link>https://tsecurity.de/de/3571380/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571380/it-nachrichten/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it/</guid>
<pubDate>Thu, 04 Jun 2026 06:01:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A report released Wednesday by Boston Consulting Group (BCG) indicates that many organizations are having difficulty converting efficiency gains that are AI-driven into any sort of measurable value.</p>



<p>The fourth edition of the consultancy’s annual Global AI at Work Survey reveals 42% of frontline employees who use AI on a regular basis save upwards of a full day each week; however, 66% are not given guidance on what to do with time they save, and “more than half don’t redirect it to strategic work.”</p>



<p>The <a href="https://www.bcg.com/publications/2026/ai-at-work-why-strategy-matters-more-than-tools" target="_blank" rel="noreferrer noopener">report</a>, <em>AI at Work: Strategy Matters More Than Tools</em>, is based on a global survey of 11,749 employees in 14 markets, from industries ranging from financial services to the healthcare sector.</p>



<p><a href="https://www.bcg.com/about/people/experts/david-martin" target="_blank" rel="noreferrer noopener">David Martin</a>, global leader of people and organization work at BCG, and the report’s lead author, said via email that the number of employees lacking the required guidance is surprising, “but it also tracks with what we see in many AI transformations. Companies have moved quickly to give people tools, but many have not yet redesigned the work around those tools.”</p>



<p>Saved time, he added, does not automatically become value. If a frontline employee saves a few hours a week, but has no direction on whether to use that time for customer service, quality improvement, innovation, or faster execution, “that value can simply leak out of the organization”</p>



<p>The fix is for leaders to change the scoreboard, Martin said: “Don’t just measure AI adoption or hours saved. Decide where that time should go, measure whether it is being reinvested, and give managers clear guidance on how to help teams use it. This is where AI transformation becomes a management challenge, not just a technology rollout.”</p>



<p>In fact, said <a href="https://www.bcg.com/about/people/experts/vinciane-beauchene" target="_blank" rel="noreferrer noopener">Vinciane Beauchene,</a> a managing director and partner at BCG and one of the report’s five co-authors, “the first wave of AI focused on individual productivity. The coming wave will need to transform collective work.”</p>



<p>“Everyone is talking about AI replacing work,” she said, “but it is in fact really about rethinking the human value-add inside.”</p>



<h2 class="wp-block-heading">A managerial revolution underway</h2>



<p>According to Beauchene, “this is the role of leaders. Our survey reveals a true managerial revolution in the age of AI; 65% of managers and leaders now believe agents will take over at least half of their job in the next three years, and frontline workers see their jobs evolving towards more managing and directing AI.”</p>



<p>A BCG <a href="https://www.bcg.com/press/3june2026-ai-reshaping-jobs-faster-than-companies-reshaping-work" target="_blank" rel="noreferrer noopener">release</a> stated that the survey also highlights the continued emergence and maturity of AI agents, with 30% of respondents saying that agents are already integrated into workflows, more than double the number from last year’s report (13%).</p>



<p>Other key findings revealed that AI adoption among frontline workers has surged, with 74% saying they now use it daily or a few times a week, which is up 23 percentage points from a year ago. In addition, six out of 10 people believe that, within the next three years, AI agents could do at least half of their jobs.</p>



<p>And a survey <a href="https://web-assets.bcg.com/eb/92/4b39b729403fb6fcae4ff974b234/ai-at-work-slideshow-jun-2026-1.pdf" target="_blank" rel="noreferrer noopener">slideshow</a> released by the company pointed out, “the AI ‘honeymoon’ won’t last unless leaders bring strategic clarity driving sustained impact AI’s novelty and cognitive stretch fuel enjoyment early on. But sustained joy comes from strategic clarity. Employees thrive when the direction is real and the message reaches them with strong CEO involvement.”</p>



<h2 class="wp-block-heading">Strategic clarity is a key differentiator</h2>



<p>The report suggests that CEOs take a holistic approach to AI transformations by focusing on business outcomes as opposed to AI usage, investing in “redesigning work end-to-end, not in more tools,” placing people at the heart of that redesign, and governing AI not as a one-off program, but as a moving target.</p>



<p>Overall, BCG says that strategic clarity, “more broadly emerges from the survey as the most crucial differentiator in sustaining AI’s impact over time as organizations are moving past simply implementing AI tools in use case deployment initiatives.”</p>



<p>Increasingly, it adds, “the focus is shifting to redesigning end-to-end workﬂows and processes to reimagine functions, as well as to building and innovating new business models and products to drive growth, which have nearly doubled year-over-year.”</p>



<p>Global leader of BCG’s tech build and design unit BCG X <a href="https://www.bcg.com/about/people/experts/sylvain-duranton" target="_blank" rel="noreferrer noopener">Sylvain Duranton</a>, also a report co-author, added, “employees don’t push back on AI intensity; they thrive when the strategy is clear, the direction is real, and the message reaches them.”</p>



<p>He added, “Business value and employee enjoyment aren’t trade-offs. The organizations capturing the greatest business value are the same ones where employees enjoy work the most.”</p>



<p>Despite the opportunity, the report notes that only one-third of frontline employees say that leadership’s communications about AI are clear, and only 28% “see a strong connection between what leaders say and what the organization actually does.”</p>



<p>However, Martin said, management can’t deal with this situation on its own. “CIOs have a critical role, but this is not a problem they can solve alone, and I would not frame it as something IT created by itself,” he noted.</p>



<p>Many organizations, he said, “started with the natural first step of getting tools into people’s hands safely and at scale. That was necessary, but it is not sufficient.”</p>



<p>The next phase “has to be much more cross-functional,” he said. “CIOs should help set the technology foundation, governance, data model, and measurement systems, but they also have an important role in creating strategic clarity. Employees need to understand why the organization is using AI, where it is meant to create value, and how it should change the work.”</p>



<p>Martin pointed out that CIOs should also pay close attention to cognitive load, especially on technology teams, as those teams are often the heaviest AI users.</p>



<p>“This means they may be among the most exposed to the mental strain that can come with reviewing outputs, managing AI tools, and keeping up with constant change,” he observed. The biggest gains come when technology strategy, workforce strategy, and employee experience move together. If AI remains only an IT program, companies will “undercapture” the value.</p>



<h2 class="wp-block-heading">New expectations</h2>



<p>The abundance of AI activity is also having another effect, in that 60% of respondents say the bar for work that counts as ‘good enough’ is now higher.</p>



<p>That, said Martin, is because AI is changing expectations. “If a tool can produce a first draft, summarize research, generate options, or automate a routine task, then ‘good enough’ moves up the value chain,” he said. “People are being asked to spend less time producing basic output and more time exercising judgment like checking quality, improving the answer, making decisions, and applying context.” </p>



<p>While that can be a good thing, he said, because it can make work more interesting and more valuable, “it also explains why employees are feeling more mental strain. The work that remains is often more complex. Leaders need to recognize that AI does not just make people faster, it changes what excellence looks like. That means companies need to update training, performance expectations, and management support accordingly.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4181057/ai-saves-workers-a-day-a-week-but-they-dont-know-what-to-do-with-it.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco sees quantum networking as the future of networking]]></title>
<description><![CDATA[Particle entanglement, superposition and teleportation are key concepts in quantum physics. Einstein famously dismissed such phenomena as “spooky action at a distance.”



Quantum computing is the nascent field of technology bringing that spookiness to life, but it is quantum networking that will...]]></description>
<link>https://tsecurity.de/de/3570753/it-security-nachrichten/cisco-sees-quantum-networking-as-the-future-of-networking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570753/it-security-nachrichten/cisco-sees-quantum-networking-as-the-future-of-networking/</guid>
<pubDate>Wed, 03 Jun 2026 22:34:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Particle entanglement, superposition and teleportation are key concepts in quantum physics. Einstein famously dismissed such phenomena as “spooky action at a distance.”</p>



<p>Quantum computing is the nascent field of technology bringing that spookiness to life, but it is quantum networking that will actually enable quantum computing to be useful by connecting multiple systems together. According to Cisco, quantum networking’s practical utility isn’t limited to quantum computing, and it can have a material impact on the regular networks we use today.</p>



<p>In a deep-dive session at Cisco Live, <a href="https://www.linkedin.com/in/rkompella/">Ramana Kompella</a>, head of Cisco Research and Cisco Fellow, detailed precisely what quantum networking is, how it works at a theoretical level, and what Cisco is building to enable real world applications.</p>



<p>During his session, Kompella made the case that the bottleneck to practical quantum computing is not the processor. It is the network connecting processors together. His argument drew directly from the history of classical infrastructure: The same scale-out methodology that built the modern internet could, he said, accelerate the arrival of useful quantum computing by decades.</p>



<p>“Quantum networking can accelerate the arrival of practical quantum computing by decades by using the scale-out methodology that we’ve used successfully in our classical infrastructure,” Kompella said.</p>



<h2 class="wp-block-heading">How quantum networking actually works</h2>



<p>The starting point is understanding why quantum networks cannot be built like classical ones. </p>



<p>“Quantum networking is completely different from classical networking,” Kompella said.</p>



<p>In a classical network, data moves as packets through switches and routers. In a quantum network, information is not transported directly. Instead, the network distributes entangled photon pairs between nodes. Entanglement links two photons so that measuring the state of one instantly determines the state of the other, regardless of the distance between them.</p>



<p><strong>The qubit</strong>: Where classical computing processes data as bits, ones and zeros, quantum computing uses qubits, units of quantum information that exploit a property called superposition. Superposition means a qubit can represent a one, a zero, or any combination of both at the same time, until it is measured. That ability to hold multiple states simultaneously is what gives quantum computers their computational potential. Each entangled photon pair can transfer exactly one qubit of information.</p>



<p><strong>Quantum teleportation</strong>: Rather than sending a qubit directly across a wire, quantum networking uses entangled photon pairs to transfer quantum information from a sender to a receiver. The process is called teleportation because the qubit effectively disappears at one end and reappears at the other without physically traveling the intervening distance.</p>



<p><strong>The speed-of-light caveat</strong>: Teleportation sounds instantaneous, and in one sense it is, but the receiver still cannot use the arriving qubit until a classical signal arrives confirming how to interpret it. That classical signal travels at the speed of light. Information does not move faster than light.</p>



<h2 class="wp-block-heading">The hardware: What Cisco has built</h2>



<p>With those fundamentals in place, the question becomes how to build infrastructure that delivers entanglement at scale. Cisco has developed two pieces of hardware designed to answer that question.</p>



<p><strong>The entanglement source</strong>: Announced<a href="https://www.networkworld.com/article/3978702/cisco-unveils-prototype-quantum-networking-chip.html"> last May</a>, Cisco’s entanglement source generates 200 million entangled photon pairs per second. It operates at standard telecom frequencies, which means it runs over existing fiber infrastructure rather than requiring a dedicated quantum fiber plant. It also runs at room temperature, with no cryogenic hardware required.</p>



<p><strong>The Universal Quantum Switch</strong>: The centerpiece of Kompella’s session was a chip he pulled from his shirt pocket: a prototype of the<a href="https://www.networkworld.com/article/4162201/cisco-switch-aimed-at-building-practical-quantum-networks.html"> Cisco Universal Quantum Switch</a>, built from thin film lithium niobate.</p>



<p>“I’ve seen people pulling out pluggables from their pockets all the time,” Kompella said. “I get a chance to pull it out of my pocket to showcase the quantum switch chip.”</p>



<p>Standard optical switching hardware cannot be used in a quantum network. It disturbs the fragile quantum states being transmitted. The Cisco switch is built specifically to preserve quantum information through the switching operation.</p>



<p>The universality in its name comes from modality conversion. Quantum computers are not all built the same way. Superconducting, neutral atom, ion trap and photonic systems each encode quantum information differently, using polarization, time bin, frequency bin and other modalities. A switch that handles only one encoding type locks an operator into a single hardware vendor. The Cisco Universal Quantum Switch converts between modalities, so a single fabric can interconnect heterogeneous quantum processors.</p>



<p>“We are building the switch and fabric in order to actually interconnect all of them, not just any one type,” Kompella said.</p>



<h2 class="wp-block-heading">Architecture: the quantum data center model</h2>



<p>Cisco’s architecture puts the switch at the center of a pod-based topology that mirrors classical data center design: processors and shared resources grouped into pods, interconnected through layers of switching.</p>



<p>Entanglement protocols are required. Three protocols handle end-to-end entanglement between quantum processors:</p>



<ul class="wp-block-list">
<li><strong>Emitter-Scatterer:</strong> One side emits a photon that interacts with a matter qubit on the receiving end.</li>



<li><strong>Emitter-Emitter:</strong> Both sides emit photons that meet at a Bell State Measurement Device.</li>



<li><strong>Scatter-Scatter:</strong> Two entanglement sources achieve transitive entanglement across two measurement points.</li>
</ul>



<p>Each protocol suits different hardware configurations.</p>



<p>A distributed compiler is also required. A large quantum circuit cannot run on a single processor today. Cisco’s distributed quantum compiler partitions circuits across multiple processors and manages execution across the network. It also handles distributed error correction through syndrome measurement, a non-destructive operation that detects and corrects erroneous qubits without collapsing quantum states, extended to the network layer to ensure the interconnect does not introduce new errors into the computation.</p>



<h2 class="wp-block-heading">Classical applications that benefit now</h2>



<p>Kompella also addressed a question that goes beyond quantum computing: Can classical networking applications benefit from a quantum network today? Two properties make that possible. The first is entanglement. The second is the no-cloning theorem, which states that quantum information can be moved but not copied.</p>



<p><strong>Quantum Sync</strong>: Two trading desks separated by tens of kilometers want to execute coordinated buy or sell decisions simultaneously. In a classical network, one side sends a message and waits for a response, and at the microsecond timescales of high-frequency trading, that propagation delay matters. With an entangled state between the two nodes, both sides make a joint decision without waiting for a message to cross the link. Kompella said the approach carries a 10% to 15% advantage over any classical coordination scheme.</p>



<p><strong>Quantum Alert</strong>: The threat is harvest now, decrypt later: An attacker taps the fiber, collects encrypted packets, and waits for a quantum computer capable of breaking the encryption. Quantum Alert multiplexes entangled photons onto existing classical fiber. Both endpoints perform joint measurements, producing correlated detections called coincidences. A dip in coincidences signals that photons are being absorbed. An attacker cannot inject replacement entangled photons, so the pattern breaks regardless.</p>



<p>“That’s what makes this foolproof against an eavesdropper,” Kompella said.</p>



<h2 class="wp-block-heading">From lab to live fiber, and what comes next</h2>



<p>Cisco has moved beyond controlled environments. Working with a partner called Connect, Cisco ran entanglement-swapping experiments over live operational fiber in New York.</p>



<p>“We got much better rates than what lab results actually look like,” Kompella said.</p>



<p>On the computing side, Cisco has announced partnerships with IBM and, more recently, Atom Computing, a neutral-atom quantum computing vendor. The collaboration spans the software stack, distributed error correction and transduction, which is the process of converting quantum information between different physical carrier types, with the goal of stitching heterogeneous quantum nodes into a single end-to-end network.</p>



<p>The partnerships reflect the same architectural logic as the Universal Quantum Switch. Cisco is not betting on one quantum computing modality winning. It is building the interconnect layer that works regardless of which one does.</p>



<p>“Quantum networking has many practical and commercial use cases in the classical world today,” Kompella said.</p>



<h4 class="wp-block-heading">Read more stories from Cisco Live 2026</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Will Broadcom’s VMware strategy keep paying big dividends?]]></title>
<description><![CDATA[Four years ago, when Broadcom announced plans to buy VMware, analysts recommended that enterprises start looking for an exit strategy based on Broadcom’s less-than-stellar track record with prior acquisitions. The fear was that Broadcom would raise prices, reduce support, and stop investing in th...]]></description>
<link>https://tsecurity.de/de/3570142/it-security-nachrichten/will-broadcoms-vmware-strategy-keep-paying-big-dividends/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570142/it-security-nachrichten/will-broadcoms-vmware-strategy-keep-paying-big-dividends/</guid>
<pubDate>Wed, 03 Jun 2026 17:35:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Four years ago, when Broadcom announced plans to buy VMware, analysts recommended that enterprises start <a href="https://www.networkworld.com/article/1293388/broadcom-moves-roil-vmware-customer-base.html">looking for an exit strategy</a> based on Broadcom’s less-than-stellar track record with prior acquisitions. The fear was that Broadcom would raise prices, reduce support, and stop investing in the technology.</p>



<p>Some of those concerns have come to pass. Broadcom eliminated perpetual licenses, forced customers onto a more costly <a href="https://www.networkworld.com/article/2092056/broadcom-changes-vmware-pricing-amid-customer-backlash-and-eu-questioning.html">subscription model</a>, pushed customers toward longer term contracts, raised the minimum licensed cores per order from 16 to 72, required that customers buy a full bundle of VMware products under the Virtual Cloud Foundation (VCF) banner, significantly reduced the number of resellers, and focused attention on the top 10,000 customers (out of a total customer base in excess of 300,000).</p>



<p>On the other hand, Broadcom has poured significant resources into VCF, as evidenced by the recent release of <a href="https://www.networkworld.com/article/4166905/broadcom-bets-big-on-vmware-cloud-foundation-9-1.html">VCF 9.1</a>, which the company describes as an AI- and Kubernetes-native private cloud platform with integrated security.</p>



<p>And CEO Hock Tan has articulated a clear vision for VMware as the indispensable platform for enterprises running both traditional and AI workloads in a private cloud setting.</p>



<p>“VMware Cloud Foundation, VCF, is the essential software layer in data centers integrating CPUs, GPUs, storage, and networking into a common, high-performance, private cloud environment,” Tan said during Broadcom’s earnings call in March. “As the permanent abstraction layer between AI software and physical chips, VCF cannot be disintermediated or replaced.” </p>



<p>Whether Broadcom’s strategy is brilliant (from the Wall Street perspective) or diabolical (from the enterprise perspective), it seems to be working. Broadcom’s first quarter 2026 revenue was up 29%, and the company said it expects an astounding 47% year-over-year increase in the current quarter. While much of that is driven by chip sales, VMware revenue was up 13% year-over-year, and recurring VMware-based revenue growth is on pace for a 19% increase.</p>



<p>“Of our 10,000 largest customers, over 87% have now adopted VCF,” Tan boasted during the company’s March earnings call. “This growth reflects our success in converting our enterprise customers from perpetual vSphere to the full VCF software stack subscription.”</p>



<p>So, what happened to the mass migration away from VMware and onto alternative virtualization platforms or the public cloud? And is the Broadcom strategy sustainable over the long term?</p>



<h2 class="wp-block-heading">Migration plans muddied by complexity</h2>



<p>There’s no question that the disruption caused by Broadcom’s acquisition of VMware has resulted in virtually all customers investigating alternatives. And that’s where it gets murky, because the two-phase analysis of figuring out <a href="https://www.networkworld.com/article/3813523/thinking-of-moving-off-vmware-gartner-tallies-cost-of-large-scale-vmware-migration.html">what it would take to extricate from the VMware platform</a>, and then deciding on an alternative, is exceedingly complex.</p>



<p>Gartner analyst <a href="https://www.linkedin.com/in/paul-delory/">Paul Delory</a> has pointed out that it could take a midsized organization two years and a large enterprise up to four years to untangle its dependency on VMware. The <a href="https://www.networkworld.com/article/3846853/enterprises-reevaluate-virtualization-strategies-amid-broadcom-uncertainty.html">cost and complexity of that migration</a> might cancel out any savings associated with a lower-cost alternative and might introduce additional risk, says Delory.</p>



<p>Companies that are actively seeking to move off VMware but have not done so already are facing a very difficult task, <a href="https://www.linkedin.com/in/kltownsend/">Keith Townsend</a>, technology management consultant and founder of <a href="https://thectoadvisor.com/">The CTO Advisor</a>, tells <em>Network World.</em></p>



<p>“More than technical difficulties are operational difficulties,” Townsend says. “VMware is not just a technology. It’s the established operating model for these customers’ software defined data center. This includes everything from capacity management, procurement and audit. Furthermore, any potential savings to move to a new platform may not be worth the operational risk or distraction from other projects, such as AI infrastructure.”</p>



<p>A recent <a href="https://www.cloudbolt.io/company/news/new-cloudbolt-research-86-of-companies-actively-reducing-their-vmware-footprint/">survey</a> commissioned by CloudBolt paints a similar picture, with 87% of respondents indicating that they are actively reducing their VMware footprint, but only 4% have completed a full migration. The complexity of migrating and associated costs were cited as the top roadblocks.</p>



<p>Forrester analyst <a href="https://www.linkedin.com/in/naveenchhabra/">Naveen Chhabra</a> says he has spoken with hundreds of VMware shops over the past few years. “I see most companies reducing their VMware estate as much as possible,” he says. However, Chhabra adds that what’s possible is highly dependent on factors like how soon the current VMware license expires and how many VMware tools are in use.</p>



<p>Companies with a short time to renew and that use a ton of VMware have few options other than to stick with it for the time being. Customers that have a longer runway before contract renewal time and only use a small number of VMware tools are in a better position to migrate. They have time to analyze dependencies, come up with a migration/modernization plan, and explore alternatives.</p>



<p>But, for large enterprises, it’s even more complex than that. Faced with the choice of maintaining on VMware, migrating, or modernizing, enterprises are “doing all three simultaneously,” says Chhabra.</p>



<h2 class="wp-block-heading">Law firm modernizes on Nutanix</h2>



<p><a href="https://www.linkedin.com/in/tconners/">Tim Conners</a>, chief technology officer at the global law firm Simpson Thacher &amp; Bartlett LLP (STB), tells <em>Network World</em> that concerns about the difficulty of migrating off VMware are somewhat overblown.</p>



<p>“There’s tons of fear out there, but it’s not as hard are they’re making it out to be. We built four new data centers in the past 12 months in all four corners of the planet, all powered by Nutanix, with pretty much zero down time,” Conners says.</p>



<p>STB was in a relatively unique position. The company’s data center hardware infrastructure, which includes HPE, Everpure (formerly Pure Storage), and Dell products, was approaching end of life. The firm needed to move its primary data center, plus it was experiencing rapid expansion across Europe, Asia, and Latin America. “We started looking at [questions such as] what does our future look like? Where do we want to go? How do we innovate? How do we scale? We needed to modernize our network for the AI revolution that we saw coming. We were a little lucky in the sense of the timing of all that,” says Conners.</p>



<p>While STB was primarily a VMware shop, there was some Nutanix gear in the mix, Conners said, and he had experience with Nutanix at prior jobs. The migration was driven not by cost concerns or dissatisfaction with VMware, but by a desire to modernize the infrastructure, to standardize across data centers, and to simplify from a three-tier architecture to an “all-in-one” box that integrates compute, storage and networking.</p>



<p>Since he was building out new infrastructure capacity in new locations, Conners didn’t have to move existing gear around, and could install the new hyperconverged infrastructure in a parallel operation. “We didn’t have to put servers on dollies,” he says.</p>



<p>The migration to an entirely new platform also gave Conners the opportunity to take a hard look at capacity needs, to “clean up” the existing infrastructure, and to right-size for the future, building in extra capacity to accommodate growth.</p>



<p>Conners says with Nutanix live migration tools, the cutover has been smooth, and the Nutanix HCI has delivered increased yield for his general compute and VDI environments. He adds that Nutanix service and support, which was a concern under Broadcom, has been top notch.</p>



<h2 class="wp-block-heading">Is the Broadcom strategy sustainable?</h2>



<p>According to Broadcom, 87% of the top 10,000 customers are re-upping on VCF. According to CloudBolt, 87% of survey respondents are actively reducing their VMware footprint. How can both things be true?</p>



<p>When Chhabra drills down into the numbers, he points out that if all of those VMware customers were absorbing massive price hikes, then Broadcom’s VMware revenue growth would reflect those skyrocketing numbers. The fact that VMware revenue is only growing at a modest 13% indicates that customers are renewing, but at the same time reducing their overall VMware footprint. By his calculations, the average customer is only renewing 25% of its VMware estate.</p>



<p><a href="https://www.linkedin.com/in/srmcdowell/">Steve McDowell</a>, chief analyst and founder at NAND Research, notes that Broadcom’s VMware strategy isn’t focused on growing its customer base.</p>



<p>“Broadcom’s VMware strategy prioritizes monetizing the existing customer base over expanding it,” McDowell says. “It’s an approach that has already generated strong short-term financial results and promises to continue to deliver over the near-term. The challenge is that it’s a strategy that’s driving many customers to competitors.”</p>



<p>McDowell adds: “The critical question for 2026 and beyond is whether higher average revenue per customer can continue to outpace the inevitable churn from aggressive pricing shifts. Broadcom has delivered on its promise to investors in the near term, but sustaining momentum without further alienating its customer base will determine whether this high-stakes bet pays off in the long run.”</p>



<p>Broadcom is also banking on companies continuing to invest in private clouds rather than simply moving workloads to the public cloud. And Tan wants to cash in on AI-powered private cloud data centers.</p>



<p>Chhabra is not convinced about the latter. “How many companies will be able to get the infrastructure to run private AI models? Do companies have a business plan to do that? How much power is required to run hundreds of kilowatts of racks? Private cloud AI certainly has a story, but how much translates into revenue for VMware? That’s the question.”</p>



<p>Still, if Broadcom finds success outside its largest tier of VMware customers, there’s room for more growth. In Broadcom’s March earnings call, Tan noted that the largest 10,000 companies are finding success and value with VCF. “We are now looking at whether the next 20,000, 30,000 midsized companies see it the same way. Stay tuned.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Wallet in iOS 27 Could Make Bill Splitting Much Easier]]></title>
<description><![CDATA[Apple is expected to unveil iOS 27 at WWDC next week, and a new report suggests the update will introduce a useful Apple Wallet feature that helps users split bills directly from a photo of a receipt. The new tool appears designed for group dinners, shared expenses, and other situations where div...]]></description>
<link>https://tsecurity.de/de/3564025/ios-mac-os/apple-wallet-in-ios-27-could-make-bill-splitting-much-easier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564025/ios-mac-os/apple-wallet-in-ios-27-could-make-bill-splitting-much-easier/</guid>
<pubDate>Mon, 01 Jun 2026 20:23:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is expected to unveil iOS 27 at WWDC next week, and a new report suggests the update will introduce a useful Apple Wallet feature that helps users split bills directly from a photo of a receipt. The new tool appears designed for group dinners, shared expenses, and other situations where dividing a bill often becomes time-consuming and confusing.



According to Bloomberg, iOS 27 will allow iPhone users to take a picture of a receipt and assign individual items to different people. Once everyone’s purchases are identified, the feature can automatically calculate how much each person owes and generate payment requests.



The system is also expected to include taxes and tips in the final calculation, making it easier to settle restaurant bills without manually using a calculator or a separate app. Apple reportedly plans to connect the feature with Apple Cash, its peer-to-peer payment service that lets users send and receive money.



Available Across Multiple Apple Devices



The report says users will be able to access the feature through both the Wallet app and the Messages app. Apple is also working on integration with Apple Watch, allowing users to manage shared expenses from their wrist.



This addition continues Apple's effort to expand Wallet beyond payments and digital cards by turning it into a broader financial management tool for everyday use.



The bill-splitting tool is not the only Wallet feature rumored for iOS 27. Earlier reports suggested Apple is also working on support for converting physical passes into digital versions stored in Apple Wallet. For example, users could photograph a gym membership barcode and save it as a digital pass on their iPhone.



With WWDC just days away, Apple Wallet is shaping up to be one of the apps receiving meaningful upgrades in iOS 27, especially for users who regularly share expenses with friends and family.]]></content:encoded>
</item>
<item>
<title><![CDATA[viable/strict/1780178955: Use SVE `exp_u20`/`fexp_u20` for SVE128 (#184341)]]></title>
<description><![CDATA[This PR makes the SVE128 CPU capability use the SVE exp_u20 and fexp_u20 implementations from #161049 and #177645 for the float vectorizer path used by CPU FlashAttention/SDPA.
The SVE128 vectorizer still uses the 128-bit ASIMD float32x4_t type for Vectorized, but it is compiled with SVE enabled ...]]></description>
<link>https://tsecurity.de/de/3559749/downloads/viablestrict1780178955-use-sve-expu20fexpu20-for-sve128-184341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559749/downloads/viablestrict1780178955-use-sve-expu20fexpu20-for-sve128-184341/</guid>
<pubDate>Sun, 31 May 2026 00:16:30 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This PR makes the SVE128 CPU capability use the SVE <code>exp_u20</code> and <code>fexp_u20</code> implementations from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3337763098" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/161049" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/161049/hovercard" href="https://github.com/pytorch/pytorch/pull/161049">#161049</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088757804" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/177645" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/177645/hovercard" href="https://github.com/pytorch/pytorch/pull/177645">#177645</a> for the float vectorizer path used by CPU FlashAttention/SDPA.</p>
<p>The SVE128 vectorizer still uses the 128-bit ASIMD <code>float32x4_t</code> type for <code>Vectorized&lt;float&gt;</code>, but it is compiled with SVE enabled and <code>-msve-vector-bits=128</code>. This lets the SVE128 implementation reuse the existing SVE <code>exp_u20(svfloat32_t)</code> and <code>fexp_u20(svfloat32_t)</code> functions by converting between <code>float32x4_t</code> and <code>svfloat32_t</code> using the helpers introduced in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4014630689" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/176256" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/176256/hovercard" href="https://github.com/pytorch/pytorch/pull/176256">#176256</a>.</p>
<h2>Implementation</h2>
<p>The patch:</p>
<ul>
<li>hoists the existing SVE <code>exp_u20_fast_path</code>/<code>fexp_u20</code> implementations so they can be reused by both SVE256 and SVE128 code paths</li>
<li>keeps SVE256 behavior unchanged by calling the hoisted helper from <code>Vectorized&lt;float&gt;::exp_u20()</code>/<code>Vectorized&lt;float&gt;::fexp_u20()</code></li>
<li>adds SVE128 <code>Vectorized&lt;float&gt;::exp_u20()</code>/<code>Vectorized&lt;float&gt;::fexp_u20()</code> overrides that call the SVE helpers through no-op <code>float32x4_t</code>/<code>svfloat32_t</code> conversions</li>
</ul>
<h2>Performance</h2>
<p>Using the SDPA benchmark from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088757804" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/177645" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/177645/hovercard" href="https://github.com/pytorch/pytorch/pull/177645">#177645</a>, here are the scaled-dot-production-attention speedups (vs current) achieved on a 96-core Neoverse V2 instance (<code>c8g.metal-24xl</code>):</p>
<h3>FP32 (exp_u20)</h3>
<table>
<thead>
<tr>
<th>Case</th>
<th align="right">1 thread</th>
<th align="right">8 threads</th>
<th align="right">16 threads</th>
<th align="right">32 threads</th>
<th align="right">64 threads</th>
<th align="right">96 threads</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>llama_prefill_s2048_bs1</code></td>
<td align="right">+3.6%</td>
<td align="right">+3.2%</td>
<td align="right">+3.0%</td>
<td align="right">+2.6%</td>
<td align="right">+2.9%</td>
<td align="right">+5.2%</td>
</tr>
<tr>
<td><code>llama_decode_t4096_bs1</code></td>
<td align="right">+1.7%</td>
<td align="right">+1.1%</td>
<td align="right">-0.6%</td>
<td align="right">+1.5%</td>
<td align="right">-0.2%</td>
<td align="right">+1.1%</td>
</tr>
<tr>
<td><code>mllama_vision_lv6400_bs1</code></td>
<td align="right">+7.6%</td>
<td align="right">+6.3%</td>
<td align="right">+6.4%</td>
<td align="right">+6.1%</td>
<td align="right">+6.0%</td>
<td align="right">+5.6%</td>
</tr>
<tr>
<td><code>whisper_enc_1500_bs1</code></td>
<td align="right">+9.2%</td>
<td align="right">+8.3%</td>
<td align="right">+7.7%</td>
<td align="right">+7.4%</td>
<td align="right">+6.8%</td>
<td align="right">+5.3%</td>
</tr>
<tr>
<td><code>whisper_enc_1500_bs8</code></td>
<td align="right">+9.2%</td>
<td align="right">+7.6%</td>
<td align="right">+7.6%</td>
<td align="right">+7.3%</td>
<td align="right">+6.8%</td>
<td align="right">+6.1%</td>
</tr>
</tbody>
</table>
<h3>BF16 (fexp_u20)</h3>
<table>
<thead>
<tr>
<th>Case</th>
<th align="right">1 thread</th>
<th align="right">8 threads</th>
<th align="right">16 threads</th>
<th align="right">32 threads</th>
<th align="right">64 threads</th>
<th align="right">96 threads</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>llama_prefill_s2048_bs1</code></td>
<td align="right">+6.9%</td>
<td align="right">+6.7%</td>
<td align="right">+6.5%</td>
<td align="right">+5.7%</td>
<td align="right">+4.9%</td>
<td align="right">+4.9%</td>
</tr>
<tr>
<td><code>llama_decode_t4096_bs1</code></td>
<td align="right">+1.2%</td>
<td align="right">+2.1%</td>
<td align="right">+3.0%</td>
<td align="right">-1.1%</td>
<td align="right">+0.7%</td>
<td align="right">+1.9%</td>
</tr>
<tr>
<td><code>mllama_vision_lv6400_bs1</code></td>
<td align="right">+10.1%</td>
<td align="right">+9.8%</td>
<td align="right">+9.7%</td>
<td align="right">+8.5%</td>
<td align="right">+7.4%</td>
<td align="right">+7.2%</td>
</tr>
<tr>
<td><code>whisper_enc_1500_bs1</code></td>
<td align="right">+11.5%</td>
<td align="right">+11.5%</td>
<td align="right">+11.6%</td>
<td align="right">+8.5%</td>
<td align="right">+8.6%</td>
<td align="right">+8.6%</td>
</tr>
<tr>
<td><code>whisper_enc_1500_bs8</code></td>
<td align="right">+11.5%</td>
<td align="right">+11.5%</td>
<td align="right">+11.5%</td>
<td align="right">+9.6%</td>
<td align="right">+7.9%</td>
<td align="right">+8.6%</td>
</tr>
</tbody>
</table>
<p>Shape legend:</p>
<table>
<thead>
<tr>
<th>Case</th>
<th align="right">B</th>
<th align="right">Hq</th>
<th align="right">Hkv</th>
<th align="right">Lq</th>
<th align="right">Lk</th>
<th align="right">D</th>
<th>causal</th>
<th>gqa</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>llama_prefill_s2048_bs1</code></td>
<td align="right">1</td>
<td align="right">32</td>
<td align="right">8</td>
<td align="right">2048</td>
<td align="right">2048</td>
<td align="right">128</td>
<td>True</td>
<td>True</td>
</tr>
<tr>
<td><code>llama_decode_t4096_bs1</code></td>
<td align="right">1</td>
<td align="right">32</td>
<td align="right">8</td>
<td align="right">1</td>
<td align="right">2048</td>
<td align="right">128</td>
<td>False</td>
<td>True</td>
</tr>
<tr>
<td><code>mllama_vision_lv6400_bs1</code></td>
<td align="right">1</td>
<td align="right">16</td>
<td align="right">16</td>
<td align="right">6400</td>
<td align="right">6400</td>
<td align="right">80</td>
<td>False</td>
<td>False</td>
</tr>
<tr>
<td><code>whisper_enc_1500_bs1</code></td>
<td align="right">1</td>
<td align="right">20</td>
<td align="right">20</td>
<td align="right">1500</td>
<td align="right">1500</td>
<td align="right">64</td>
<td>False</td>
<td>False</td>
</tr>
<tr>
<td><code>whisper_enc_1500_bs8</code></td>
<td align="right">8</td>
<td align="right">20</td>
<td align="right">20</td>
<td align="right">1500</td>
<td align="right">1500</td>
<td align="right">64</td>
<td>False</td>
<td>False</td>
</tr>
</tbody>
</table>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475981750" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184341" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/184341/hovercard" href="https://github.com/pytorch/pytorch/pull/184341">#184341</a><br>
Approved by: <a href="https://github.com/fadara01">https://github.com/fadara01</a>, <a href="https://github.com/aditew01">https://github.com/aditew01</a>, <a href="https://github.com/jgong5">https://github.com/jgong5</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intercepting Docker Application Requests Using Burp Suite on Windows]]></title>
<description><![CDATA[Intercepting Docker Application Requests Using Burp Suite on WindowsBlogs use a more complex Docker + Burp Suite setup because not all application traffic is generated by a browser. In many Dockerized applications, requests can be made internally by services, background workers, APIs, or even oth...]]></description>
<link>https://tsecurity.de/de/3554034/hacking/intercepting-docker-application-requests-using-burp-suite-on-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554034/hacking/intercepting-docker-application-requests-using-burp-suite-on-windows/</guid>
<pubDate>Thu, 28 May 2026 14:09:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*sz7NthXQSf7oAWGuujZROA.png"><figcaption>Intercepting Docker Application Requests Using Burp Suite on Windows</figcaption></figure><p>Blogs use a more complex Docker + Burp Suite setup because not all application traffic is generated by a browser. In many Dockerized applications, requests can be made internally by services, background workers, APIs, or even other containers, which bypass the browser proxy entirely. A simple “browser → Burp Suite” setup only captures client-side traffic, but it misses these internal or server-to-server requests. By routing Docker container traffic through Burp Suite and controlling networking at the container level (or via Docker’s network/proxy configuration), security testers can intercept and analyze <em>all</em> HTTP/S traffic flowing in and out of the container environment. This is why advanced blogs often demonstrate full Docker + Burp integration instead of a basic browser proxy setup.</p><h3>Table of Contents</h3><ol><li>Introduction &amp; Windows Architecture Overview</li><li>Prerequisites &amp; Tooling</li><li>Understanding the Windows Docker Networking Stack</li><li>METHOD 1: Per-Container Proxy via Environment Variables (Simplest)</li><li>METHOD 2: Docker Desktop Built-in Proxy Configuration</li><li>METHOD 3: Docker Daemon-Level Proxy (System-wide Interception)</li><li>METHOD 4: WSL2 Deep-Dive — Intercepting Docker-on-WSL Traffic Through Windows Burp</li><li>Installing Burp’s CA Certificate in Windows Containers (Nano Server / Windows Server Core)</li><li>Intercepting Docker Registry Pull/Push Traffic on Windows</li><li>Windows Firewall Configuration</li><li>Troubleshooting Matrix — Windows-Specific Issues</li><li>Complete PoC Walkthrough — Step-by-Step Lab</li><li>Appendix: PowerShell Automation Scripts</li></ol><h3>1. Introduction &amp; Windows Architecture Overview</h3><p>Unlike Linux where Docker runs natively on the host kernel, Docker Desktop on Windows operates inside a lightweight Hyper-V VM (or WSL2 backend). This creates a network boundary between Burp Suite (running as a native Windows application) and Docker containers (running inside that VM). Understanding this topology is critical before attempting traffic interception.</p><p><strong>Architecture diagram (conceptual):</strong></p><pre>┌─────────────────────────────────────────────────────────────┐<br>│                   WINDOWS HOST                               │<br>│                                                              │<br>│  ┌──────────────────┐          ┌──────────────────────┐     │<br>│  │  Burp Suite       │          │  Browser / curl /    │     │<br>│  │  (127.0.0.1:8080) │          │  native apps         │     │<br>│  └────────┬─────────┘          └──────────────────────┘     │<br>│           │                                                 │<br>│  ┌────────▼─────────────────────────────────────────┐       │<br>│  │         host.docker.internal / vEthernet           │       │<br>│  │         (WSL / Hyper-V Virtual Switch)             │       │<br>│  └───────────────────────┬──────────────────────────┘       │<br>│                          │                                   │<br>├──────────────────────────┼───────────────────────────────────┤<br>│            ┌─────────────▼──────────────┐                    │<br>│            │   DOCKER VM / WSL2 VM      │                    │<br>│            │                            │                    │<br>│            │  ┌──────────────────────┐  │                    │<br>│            │  │   Containers         │  │                    │<br>│            │  │   (Linux/Windows)    │  │                    │<br>│            │  └──────────────────────┘  │                    │<br>│            └────────────────────────────┘                    │<br>└─────────────────────────────────────────────────────────────┘</pre><p><strong>Key Windows-specific facts:</strong></p><ul><li>host.docker.internal resolves from inside any container to the Windows host IP — this is the magic gateway for Burp.</li><li>There is no docker0 bridge on Windows — don't look for 172.17.0.1.</li><li>Docker Desktop for Windows uses either WSL2 backend (default, recommended) or Hyper-V backend.</li><li>Windows Firewall blocks inbound connections by default — you must add a rule for Burp.</li></ul><h3>2. Prerequisites &amp; Tooling</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/931/1*DdbBbYE1acLo-tuPOnNmqg.png"></figure><p><strong>Verify your Docker backend:</strong></p><pre># Open PowerShell as Administrator<br>docker version<br># Look for "OS/Arch: windows/amd64" for the client<br># For the server, check if it says "linux/amd64" (WSL2) or "windows/amd64" (Hyper-V)<br></pre><p><strong>Check WSL2 mode:</strong></p><pre>wsl -l -v<br># Make sure your Docker-desktop distribution shows "Running" and version "2"</pre><h3>3. Understanding the Windows Docker Networking Stack</h3><p>This is the most misunderstood aspect. Here’s what you need to know:</p><h3>The host.docker.internal DNS Record</h3><p>Docker Desktop automatically adds a DNS entry in every container that resolves to the Windows host’s IP address:</p><pre># From inside any Linux container on Docker Desktop Windows<br>ping host.docker.internal<br># PINGS 192.168.x.x (the Windows host's vEthernet IP)</pre><p>On Windows containers (not Linux containers — these are rare), host.docker.internal resolves to 10.0.75.1 by default.</p><h3>The vEthernet (WSL) Adapter</h3><p>When using WSL2 backend, Docker Desktop creates a virtual switch. Find its IP:</p><pre>ipconfig<br># Look for:<br>#   Ethernet adapter vEthernet (WSL (Hyper-V firewall)):<br>#      IPv4 Address. . . . . . . . . . . : 192.168.XX.XX</pre><p>This IP is what containers see as the gateway to the host. Burp must bind to ALL interfaces (0.0.0.0) so it’s reachable from this virtual adapter.</p><h3>No docker0 Bridge</h3><p>On Windows, there is no docker0 bridge device. The Linux bridge networking model doesn't apply. Containers on Docker Desktop Windows are routed through the Hyper-V virtual switch / WSL2 network NAT.</p><h3>4. METHOD 1: Per-Container Proxy via Environment Variables (Simplest)</h3><p>This is the quickest way to intercept traffic from a single container. No Docker config changes needed.</p><h3>Step 1: Configure Burp to Listen on All Interfaces</h3><ol><li>Open Burp Suite → Proxy tab → Options sub-tab</li><li>Under Proxy Listeners, if the default listener is bound to 127.0.0.1:8080, click Edit</li><li>Change Bind to address from Loopback only to All interfaces</li><li>Click OK</li></ol><p>Why: Containers cannot reach 127.0.0.1 on the Windows host. They connect through the virtual network adapter, so Burp must listen on 0.0.0.0.</p><h3>Step 2: Run a Container with Proxy Environment Variables</h3><pre># Using host.docker.internal (magic DNS name — works on Docker Desktop Windows)<br>docker run --rm -it `<br>  -e http_proxy="http://host.docker.internal:8080" `<br>  -e https_proxy="http://host.docker.internal:8080" `<br>  -e HTTP_PROXY="http://host.docker.internal:8080" `<br>  -e HTTPS_PROXY="http://host.docker.internal:8080" `<br>  -e no_proxy="localhost,127.0.0.1,.local" `<br>  ubuntu:22.04 bash</pre><h3>Step 3: Install Burp’s CA Certificate Inside the Container</h3><p>First, export Burp’s CA certificate:</p><ol><li>In Burp, go to Proxy → Options → Import / Export CA Certificate</li><li>Click Export → Certificate in DER format → Save as burp.der</li></ol><p>Now, from inside the container:</p><pre># Inside the container<br>apt-get update &amp;&amp; apt-get install -y ca-certificates curl<br><br># Download the cert from the Windows host<br># Option A: Host it on a local web server temporarily<br># Option B: Copy via docker cp (from another terminal)</pre><p>Better approach — mount the cert at runtime:</p><pre># On Windows host, convert DER to PEM first<br>openssl x509 -inform DER -in burp.der -out burp.pem -outform PEM<br><br># Run with cert mounted<br>docker run --rm -it `<br>  -v C:\Users\%USERNAME%\Desktop\burp.pem:/usr/local/share/ca-certificates/burp.crt `<br>  -e http_proxy="http://host.docker.internal:8080" `<br>  -e https_proxy="http://host.docker.internal:8080" `<br>  ubuntu:22.04 bash -c "apt-get update &amp;&amp; apt-get install -y ca-certificates &amp;&amp; update-ca-certificates &amp;&amp; curl -v https://github.com"</pre><h3>Step 4: Verify Interception</h3><p>Set Burp’s Proxy → Intercept to Intercept is on, then from the container:</p><pre>curl -v https://api.github.com/zen</pre><p>The request pauses in Burp. Click Forward to release it)Skip</p><h3>PoC: Docker Compose on Windows</h3><pre># docker-compose.yml<br>version: '3.8'<br>services:<br>  intercepted-app:<br>    image: node:18-alpine<br>    environment:<br>      - http_proxy=http://host.docker.internal:8080<br>      - https_proxy=http://host.docker.internal:8080<br>      - HTTP_PROXY=http://host.docker.internal:8080<br>      - HTTPS_PROXY=http://host.docker.internal:8080<br>      - no_proxy=localhost,127.0.0.1<br>    volumes:<br>      - ./app:/app:ro<br>    working_dir: /app<br>    command: node app.js</pre><pre># Run<br>docker-compose up<br><br># The Node.js app's outbound HTTP/HTTPS calls appear in Burp</pre><h3>5. METHOD 2: Docker Desktop Built-in Proxy Configuration</h3><p>Docker Desktop for Windows has a native proxy settings UI. This automatically propagates proxy env vars to all containers started through Docker Desktop.</p><h3>Step 1: Configure Docker Desktop Proxy</h3><ol><li>Open Docker Desktop → click the gear icon (Settings)</li><li>Navigate to Resources → Proxies</li><li>Toggle Manual proxy configuration to ON</li><li>Enter:</li></ol><ul><li>HTTP proxy: <a href="http://host.docker.internal:8080/">http://host.docker.internal:8080</a></li><li>HTTPS proxy: <a href="http://host.docker.internal:8080/">http://host.docker.internal:8080</a></li><li>No proxy: localhost,127.0.0.1,.local,.internal</li></ul><p>5. Click Apply &amp; Restart</p><h3>Step 2: Every Container Now Uses the Proxy</h3><p>No -e flags needed anymore:</p><pre>docker run --rm alpine:latest wget -qO- https://google.com<br># ^^^ This goes through Burp automatically</pre><h3>Step 3: Install CA Certificate</h3><p>You still need to install Burp’s CA in each image you test. The easiest way on Windows:</p><p>Create a base image with Burp’s CA pre-installed:</p><pre># Dockerfile.burp-base<br>FROM alpine:latest<br>COPY burp.pem /usr/local/share/ca-certificates/burp.crt<br>RUN apk add --no-cache ca-certificates &amp;&amp; update-ca-certificates</pre><pre>docker build -t burp-base -f Dockerfile.burp-base .</pre><p>Then use burp-base as your base for any container you want to intercept.</p><h3>Step 4: Verify the Proxy is Active</h3><pre># Check Docker Desktop proxy settings from CLI<br>docker info | Select-String -Pattern "Proxy"</pre><h3>6. METHOD 3: Docker Daemon-Level Proxy (System-wide Interception)</h3><p>This targets the Docker daemon itself — intercepting docker pull, docker push, and all container traffic at the engine level.</p><h3>Step 1: Configure Docker Daemon Proxy on Windows</h3><p>On Windows, Docker daemon config lives at %ProgramData%\Docker\config\daemon.json:</p><pre>{<br>  "proxy": {<br>    "http-proxy": "http://host.docker.internal:8080",<br>    "https-proxy": "http://host.docker.internal:8080",<br>    "no-proxy": "localhost,127.0.0.1,.local,.internal"<br>  }<br>}</pre><p>If the file doesn’t exist, create it.</p><h3>Step 2: Restart Docker Desktop</h3><pre># Restart via tray icon or:<br>Restart-Service docker</pre><h3>Step 3: Verify Daemon Proxy</h3><pre>docker info<br># Look for:<br># HTTP Proxy: http://host.docker.internal:8080<br># HTTPS Proxy: http://host.docker.internal:8080<br># No Proxy: localhost,127.0.0.1,.local,.internal</pre><h3>Step 4: Intercept Docker Pull Traffic</h3><p>Now when you run docker pull:</p><pre>docker pull alpine:latest</pre><p>In Burp’s HTTP history, you’ll see requests to:</p><ul><li>https://auth.docker.io/token?... (authentication token)</li><li>https://registry-1.docker.io/v2/library/alpine/manifests/latest (manifest)</li><li>https://registry-1.docker.io/v2/library/alpine/blobs/sha256:... (layer blobs)</li></ul><h3>7. METHOD 4: WSL2 Deep-Dive — Intercepting Docker-on-WSL Traffic Through Windows Burp</h3><p>If you run Docker inside a WSL2 distribution (e.g., Kali Linux in WSL2 with Docker installed natively), the networking is more complex. Here’s the complete setup.</p><h3>Architecture</h3><pre>┌──────────────────────────────────────────────────────┐<br>│                  WINDOWS HOST                         │<br>│  ┌──────────────────────────────────────────────┐    │<br>│  │  Burp Suite (0.0.0.0:8081)                    │    │<br>│  └──────────▲───────────────────────────────────┘    │<br>│             │                                        │<br>│  ┌──────────┴───────────────────────────────────┐    │<br>│  │  vEthernet (WSL) 192.168.X.X                  │    │<br>│  └──────────────────┬───────────────────────────┘    │<br>├─────────────────────┼────────────────────────────────┤<br>│  ┌──────────────────▼───────────────────────────┐    │<br>│  │  WSL2 VM                                     │    │<br>│  │  ┌───────────────────────────────────────┐    │    │<br>│  │  │  Kali/WSL eth0 172.X.X.X               │    │    │<br>│  │  │  ┌─────────────────────────────────┐   │    │    │<br>│  │  │  │  mitmproxy port 8080            │   │    │    │<br>│  │  │  │  (port-forwarded from WSL→Win)  │   │    │    │<br>│  │  │  └──────────▲──────────────────────┘   │    │    │<br>│  │  │             │                          │    │    │<br>│  │  │  ┌──────────┴──────────────────────┐   │    │    │<br>│  │  │  │  Docker containers in WSL       │   │    │    │<br>│  │  │  └─────────────────────────────────┘   │    │    │<br>│  │  └───────────────────────────────────────┘    │    │<br>│  └──────────────────────────────────────────────┘    │<br>└──────────────────────────────────────────────────────┘</pre><h3>Step 1: Install mitmproxy in WSL</h3><pre># Inside your WSL distribution (Kali/Ubuntu)<br>sudo apt update &amp;&amp; sudo apt install -y mitmproxy python3-pip</pre><h3>Step 2: Set Up Port Forwarding from WSL2 to Windows</h3><p>Save this as C:\Scripts\wsl2-portforward.ps1:</p><pre># wsl2-portforward.ps1<br># Run as Administrator<br><br>$wslIp = bash.exe -c "ip addr show eth0 | grep -oP 'inet \K[\d.]+'"<br>$ports = @(8080)  # mitmproxy port inside WSL<br><br># Remove old firewall rules<br>Remove-NetFireWallRule -DisplayName 'WSL2 Burp Proxy' -ErrorAction SilentlyContinue<br><br># Add new firewall rule<br>New-NetFireWallRule -DisplayName 'WSL2 Burp Proxy' `<br>  -Direction Inbound -LocalPort $ports -Action Allow -Protocol TCP<br><br># Remove old portproxy rules<br>foreach ($port in $ports) {<br>    netsh interface portproxy delete v4tov4 listenport=$port listenaddress=0.0.0.0 | Out-Null<br>    netsh interface portproxy add v4tov4 `<br>      listenport=$port `<br>      listenaddress=0.0.0.0 `<br>      connectport=$port `<br>      connectaddress=$wslIp<br>}<br><br>Write-Host "[+] WSL2 IP: $wslIp"<br>Write-Host "[+] Ports forwarded: $($ports -join ',')"<br>Write-Host "[+] Firewall rule added"</pre><p>Run it:</p><pre># PowerShell as Administrator<br>Set-ExecutionPolicy Bypass -Scope Process<br>.\wsl2-portforward.ps1</pre><h3>Step 3: Start mitmproxy in WSL</h3><pre># In WSL terminal<br>mitmproxy --listen-port 8080 --set block_global=false</pre><h3>Step 4: Configure Burp with an Upstream Proxy</h3><ol><li>In Burp Suite, go to User Options → Connections</li><li>Under Upstream Proxy Servers, click Add</li><li>Set:</li></ol><ul><li>Destination host: * (wildcard — all traffic)</li><li>Proxy host: 127.0.0.1</li><li>Proxy port: 8080 (this is the forwarded mitmproxy port)</li></ul><p>4. Click OK</p><h3>Step 5: Configure Burp’s Proxy Listener</h3><ol><li>Proxy → Options → Proxy Listeners</li><li>Add a listener on 0.0.0.0:8081</li><li>This is the port you’ll point your Windows browser to</li></ol><h3>Step 6: Install CA Certificates</h3><ul><li>In WSL: mitmproxy’s CA is at ~/.mitmproxy/mitmproxy-ca-cert.pem</li><li>Install mitmproxy CA on Windows as a trusted root</li><li>Install Burp’s CA on Windows as a trusted root (see below`</li></ul><p><strong>Chain summary:</strong></p><pre>Browser → Burp (127.0.0.1:8081) → mitmproxy (127.0.0.1:8080 forwarded from WSL) → Docker containers inside WSL</pre><h3>8. Installing Burp’s CA Certificate in Windows Containers (Nano Server / Windows Server Core)</h3><p>Windows containers (not Linux containers) run a full Windows kernel. Installing a CA in them is different.</p><h3>For Windows Server Core Containers</h3><pre># Dockerfile.windows-intercept<br>FROM mcr.microsoft.com/windows/servercore:ltsc2022<br><br># Copy Burp certificate (PEM format)<br>COPY burp.pem C:\burp-ca.crt<br><br># Install into Windows certificate store<br>RUN certutil -addstore -f Root C:\burp-ca.crt<br><br># Set proxy environment variables<br>ENV http_proxy=http://host.docker.internal:8080<br>ENV https_proxy=http://host.docker.internal:8080</pre><pre>docker build -t intercepted-windows -f Dockerfile.windows-intercept .<br>docker run --rm intercepted-windows powershell Invoke-WebRequest -Uri https://example.com</pre><h3>For Nano Server Containers</h3><pre>FROM mcr.microsoft.com/windows/nanoserver:ltsc2022<br>COPY burp.pem C:\burp-ca.crt<br>RUN certoc.exe -addstore Root C:\burp-ca.crt</pre><p><em>Note: Windows containers are limited to the same OS build as the host. Use </em><em>mcr.microsoft.com/windows images matching your Windows build number.</em></p><h3>9. Intercepting Docker Registry Pull/Push Traffic on Windows</h3><p>When you configure the Docker daemon proxy (Method 3), docker pull and docker push traffic flows through Burp.</p><h3>What You’ll See in Burp’s HTTP History</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/912/1*1IkQ-Gxj984R-srfiEouiw.png"></figure><h3>PoC: Intercept and Modify a Docker Pull</h3><pre># In Burp: Intercept is ON<br># In PowerShell:<br>docker pull alpine:latest<br><br># Burp catches the manifest request - you can see:<br># GET /v2/library/alpine/manifests/latest HTTP/1.1<br># Host: registry-1.docker.io<br># Accept: application/vnd.docker.distribution.manifest.v2+json<br># Authorization: Bearer &lt;token&gt;<br># Forward it - the blob requests will also appear</pre><h3>10. Windows Firewall Configuration</h3><p>Windows Defender Firewall blocks inbound connections to Burp by default. You must create an allow rule.</p><h3>Automated (PowerShell)</h3><pre># PowerShell as Administrator<br>New-NetFirewallRule -DisplayName "Burp Suite Proxy" `<br>  -Direction Inbound `<br>  -LocalPort 8080,8081 `<br>  -Action Allow `<br>  -Protocol TCP `<br>  -Profile Any</pre><h3>Manual (GUI)</h3><ol><li>Open Windows Defender Firewall with Advanced Security</li><li>Click Inbound Rules → New Rule</li><li>Rule Type: Port</li><li>Protocol: TCP, Specific local ports: 8080,8081</li><li>Action: Allow the connection</li><li>Profile: Tick all three (Domain, Private, Public)</li><li>Name: Burp Suite Proxy</li><li>Click Finish</li></ol><h3>11. Troubleshooting Matrix — Windows-Specific Issues</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/1*NoJPjmXqC5cgEDMeylaNDw.png"></figure><h3>Diagnostic Commands</h3><pre># Test Burp is reachable from the host<br>curl -x http://127.0.0.1:8080 http://httpbin.org/get<br><br># Test Burp is reachable from a container<br>docker run --rm alpine:latest wget -qO- http://host.docker.internal:8080<br><br># Check Docker proxy settings<br>docker info | Select-String -Pattern "Proxy|proxy"<br><br># Verify portproxy rules (WSL2 method)<br>netsh interface portproxy show all<br><br># Check Docker Desktop proxy UI is active<br># Settings → Resources → Proxies should show your values<br><br># Reset Docker proxy to default<br># Remove or empty the "proxy" key in %ProgramData%\Docker\config\daemon.json<br># Reset Docker Desktop proxy UI to "No proxy"</pre><h3>12. Complete PoC Walkthrough — Step-by-Step Lab</h3><p>Here’s a full end-to-end lab you can run on a clean Windows machine with Docker Desktop.</p><h3>Lab Goal</h3><p>Intercept all outbound HTTPS traffic from an ubuntu:22.04 container making API calls.</p><h3>Step 1: Export Burp CA</h3><ol><li>Open Burp Suite → Proxy → Options → Import/Export CA Certificate</li><li>Click Export → Certificate in DER format</li><li>Save to C:\burp-lab\burp.der</li></ol><h3>Step 2: Convert to PEM</h3><pre># Using OpenSSL for Windows<br>openssl x509 -inform DER -in C:\burp-lab\burp.der -out C:\burp-lab\burp.pem -outform PEM</pre><h3>Step 3: Configure Burp Listener</h3><p>Burp → Proxy → Options → Proxy Listeners:</p><ul><li>Default listener: Edit → change to All interfaces</li><li>Add secondary listener: 0.0.0.0:8081 (for WSL scenarios)</li></ul><h3>Step 4: Configure Windows Firewall</h3><pre>New-NetFireWallRule -DisplayName "Burp Lab" -Direction Inbound -LocalPort 8080 -Action Allow -Protocol TCP</pre><h3>Step 5: Create a PoC Container with a Custom Dockerfile</h3><pre># C:\burp-lab\Dockerfile<br>FROM ubuntu:22.04<br><br># Install Burp CA<br>COPY burp.pem /usr/local/share/ca-certificates/burp.crt<br>RUN apt-get update &amp;&amp; \<br>    apt-get install -y ca-certificates curl dnsutils &amp;&amp; \<br>    update-ca-certificates &amp;&amp; \<br>    rm -rf /var/lib/apt/lists/*<br><br># Proxy env vars<br>ENV http_proxy=http://host.docker.internal:8080<br>ENV https_proxy=http://host.docker.internal:8080<br>ENV HTTP_PROXY=http://host.docker.internal:8080<br>ENV HTTPS_PROXY=http://host.docker.internal:8080<br>ENV no_proxy=localhost,127.0.0.1<br><br># Test script<br>COPY test.sh /test.sh<br>RUN chmod +x /test.sh<br>CMD ["/test.sh"]</pre><pre># C:\burp-lab\test.sh<br>#!/bin/bash<br>echo "=== Testing HTTP ==="<br>curl -v http://httpbin.org/get 2&gt;&amp;1 | head -20<br><br>echo "=== Testing HTTPS ==="<br>curl -v https://api.github.com/zen 2&gt;&amp;1<br><br>echo "=== Testing API call ==="<br>curl -s https://jsonplaceholder.typicode.com/posts/1 | head -100</pre><h3>Step 6: Build and Run</h3><pre>cd C:\burp-lab<br>docker build -t burp-lab .<br>docker run --rm burp-lab</pre><h3>Step 7: Observe in Burp</h3><ol><li>Set Burp’s Intercept to ON</li><li>Watch each request pause in the Proxy → Intercept tab</li><li>Click Forward to release each one</li><li>After completion, review all traffic in Proxy → HTTP history</li></ol><h3>Step 8: Modify a Request in Flight (The “Killer Feature”)</h3><ol><li>With Intercept ON, run the container again</li><li>When the jsonplaceholder.typicode.com request appears:</li></ol><ul><li>Modify the URL from /posts/1 to /posts/2</li><li>Or modify the Accept header</li><li>Or change GET to POST and inject a body</li></ul><p>3. Click Forward to send the modified request</p><p>4. The container receives the modified response</p><h3>13. Appendix: PowerShell Automation Scripts</h3><h3>Script 1: One-Click Burp + Docker Intercept Setup</h3><p>Save as C:\Scripts\setup-burp-docker.ps1:</p><pre># setup-burp-docker.ps1<br># Run as Administrator<br><br>param(<br>    [int]$BurpPort = 8080,<br>    [string]$BurpCertPath = "$env:USERPROFILE\Desktop\burp.der"<br>)<br><br>Write-Host "[*] Setting up Burp + Docker interception on Windows" -ForegroundColor Cyan<br><br># 1. Firewall rule<br>Write-Host "[*] Adding Windows Firewall rule for port $BurpPort..."<br>Remove-NetFireWallRule -DisplayName "Burp Suite Docker Proxy" -ErrorAction SilentlyContinue<br>New-NetFireWallRule -DisplayName "Burp Suite Docker Proxy" `<br>  -Direction Inbound -LocalPort $BurpPort -Action Allow -Protocol TCP<br><br># 2. Convert DER to PEM if needed<br>$pemPath = $BurpCertPath -replace '\.der$', '.pem'<br>if (Test-Path $BurpCertPath) {<br>    Write-Host "[*] Converting DER to PEM..."<br>    openssl x509 -inform DER -in $BurpCertPath -out $pemPath -outform PEM<br>    Write-Host "[+] PEM saved to: $pemPath"<br>}<br><br># 3. Docker Desktop proxy config (via daemon.json)<br>$daemonPath = "$env:ProgramData\Docker\config\daemon.json"<br>$config = @{<br>    proxy = @{<br>        "http-proxy" = "http://host.docker.internal:$BurpPort"<br>        "https-proxy" = "http://host.docker.internal:$BurpPort"<br>        "no-proxy" = "localhost,127.0.0.1,.local,.internal"<br>    }<br>}<br><br>if (Test-Path $daemonPath) {<br>    $existing = Get-Content $daemonPath -Raw | ConvertFrom-Json<br>    $existing | Add-Member -Force -NotePropertyMembers @{proxy = $config.proxy}<br>    $existing | ConvertTo-Json -Depth 10 | Set-Content $daemonPath<br>} else {<br>    $config | ConvertTo-Json | Set-Content $daemonPath<br>}<br><br>Write-Host "[+] daemon.json updated at: $daemonPath"<br><br># 4. Create test Dockerfile<br>$testDir = "$env:TEMP\burp-docker-test"<br>New-Item -ItemType Directory -Force -Path $testDir | Out-Null<br><br>@"<br>FROM ubuntu:22.04<br>COPY burp.pem /usr/local/share/ca-certificates/burp.crt<br>RUN apt-get update &amp;&amp; apt-get install -y ca-certificates curl &amp;&amp; update-ca-certificates<br>ENV http_proxy=http://host.docker.internal:$BurpPort<br>ENV https_proxy=http://host.docker.internal:$BurpPort<br>ENV HTTP_PROXY=http://host.docker.internal:$BurpPort<br>ENV HTTPS_PROXY=http://host.docker.internal:$BurpPort<br>ENV no_proxy=localhost,127.0.0.1<br>CMD curl -v https://api.github.com/zen<br>"@ | Out-File -FilePath "$testDir\Dockerfile" -Encoding ascii<br><br>if (Test-Path $pemPath) {<br>    Copy-Item $pemPath "$testDir\burp.pem"<br>}<br><br>Write-Host @"<br><br>[+] Setup complete!<br><br>Next steps:<br>1. Ensure Burp is listening on ALL interfaces (0.0.0.0:$BurpPort)<br>2. Restart Docker Desktop to pick up proxy changes<br>3. Build the test container:<br>   cd $testDir<br>   docker build -t burp-test .<br>   docker run --rm burp-test<br>4. Watch traffic appear in Burp's HTTP history<br><br>Verification:<br>- Firewall rule: netsh advfirewall firewall show rule name='Burp Suite Docker Proxy'<br>- Docker proxy: docker info | Select-String Proxy<br>"@ -ForegroundColor Green</pre><h3>Script 2: WSL2 Port Forward on Boot (Scheduled Task)</h3><pre># Create a Scheduled Task that runs on logon<br>$action = New-ScheduledTaskAction -Execute "PowerShell.exe" `<br>  -Argument "-WindowStyle Hidden -ExecutionPolicy Bypass -File C:\Scripts\wsl2-portforward.ps1"<br><br>$trigger = New-ScheduledTaskTrigger -AtLogOn -User $env:USERNAME<br>$settings = New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries<br>$principal = New-ScheduledTaskPrincipal -UserId $env:USERNAME -RunLevel Highest<br><br>Register-ScheduledTask -TaskName "WSL2-Burp-PortForward" `<br>  -Action $action `<br>  -Trigger $trigger `<br>  -Settings $settings `<br>  -Principal $principal `<br>  -Description "Forwards WSL2 port 8080 to Windows host for Burp Suite interception"</pre><h3>Quick Reference Card</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*rnZ6ESAKF6bGe90e3VawxQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5UzsBY9bYZKqhkPaJDr7DQ.png"><figcaption>Docker + Burp Simple FAQ</figcaption></figure><h4>❓ If I open a Docker web app in browser, is browser proxy enough to capture traffic?</h4><blockquote>Yes ✅<br> Browser → Burp Suite → Docker app<br> This is enough for basic testing.</blockquote><h4>❓ Then why do blogs use complex Docker + Burp setup?</h4><blockquote>Because not all traffic comes from the browser. Some requests are made directly by the container.</blockquote><h4>❓ When is browser proxy enough?</h4><blockquote>When you manually use the website in a browser (manual testing like login, forms, XSS, etc.).</blockquote><h4>❓ When do you need Docker proxy setup?</h4><blockquote>When the container itself sends requests, such as:</blockquote><blockquote>backend API calls</blockquote><blockquote>microservices communication</blockquote><blockquote>CLI tools inside container</blockquote><blockquote>external HTTP requests (curl, requests, etc.)</blockquote><h4>❓ Simple difference?</h4><blockquote>Browser proxy = captures what <em>you click in browser</em></blockquote><blockquote>Docker proxy = captures what <em>container sends automatically</em></blockquote><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="http://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a></p><p><em>#BugBounty #WebSecurity #EthicalHacking #Hinglish #InfoSec #securityTalent </em>#CyberSecurity #BurpSuite #Docker #WindowsSecurity #PenetrationTesting #MITM #ProxyInterception #DockerDesktop #WSL2 #Infosec #WebApplicationSecurity #AppSec #RedTeam #EthicalHacking #APIsecurity #PowerShell</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=4060a8ff1a4d" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/intercepting-docker-application-requests-using-burp-suite-on-windows-4060a8ff1a4d">Intercepting Docker Application Requests Using Burp Suite on Windows</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI talent problem CIOs cannot delegate to HR]]></title>
<description><![CDATA[As enterprises accelerate AI adoption, many CIOs remain focused on platforms, governance and scale. But the real competitive risk may be elsewhere. Top AI talent is increasingly choosing employers not only for pay but also for access to compute, freedom to experiment and the ability to operate at...]]></description>
<link>https://tsecurity.de/de/3550970/it-security-nachrichten/the-ai-talent-problem-cios-cannot-delegate-to-hr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550970/it-security-nachrichten/the-ai-talent-problem-cios-cannot-delegate-to-hr/</guid>
<pubDate>Wed, 27 May 2026 14:08:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises accelerate AI adoption, many CIOs remain focused on platforms, governance and scale. But the real competitive risk may be elsewhere. Top AI talent is increasingly choosing employers not only for pay but also for access to compute, freedom to experiment and the ability to operate at full leverage. If HR and leadership teams fail to understand that shift, organizations may lose their best builders before the problem is even visible.</p>



<h2 class="wp-block-heading">The silent talent drain in AI: Why CIOs must rethink recruitment before HR falls behind</h2>



<p>Most CIOs still frame the AI race as a contest over platforms, models, governance, security and deployment speed. That is understandable. Those are the visible levers. They show up in board packs, transformation plans, vendor briefings and budget requests. But a more consequential battle is now emerging underneath that surface. The next decisive advantage in AI will not come only from who buys the best tools. It will come from who attracts, enables and retains the small pool of talent capable of converting those tools into outsized business value.</p>



<p>That is where many enterprises are exposed, often without realising it.</p>



<p>The market for top AI talent is changing faster than most corporate talent systems. ManpowerGroup’s 2025 global research confirms that <a href="https://www.manpowergroup.com/en/news-releases/news/global-talent-shortage-reaches-turning-point-as-ai-skills-claim-top-spot" target="_blank" rel="nofollow">AI skills now top the talent</a>, while enterprise AI adoption is shifting from experimentation to scaled activation. That combination is increasing demand for people who can build, integrate, govern and operationalize AI at speed. The shortage is no longer abstract. It is already shaping compensation, hiring strategies and employer positioning.</p>



<p>The problem, and this is something I see repeatedly in my own advisory work, is that many CIOs are investing in AI infrastructure while still operating with a pre-AI model of talent. They are modernising data estates, deploying copilots, building policy guardrails and signing enterprise contracts, yet they are not redesigning the conditions under which high-leverage AI talent chooses to work. That is the blind spot. In the AI era, capability is no longer defined only by human skill. It is increasingly defined by the degree of access an organization gives to that skill. Access to frontier models. Access to compute. Access to experimentation. Access to tools without institutional drag.</p>



<h2 class="wp-block-heading">The new talent currency is not just pay. It’s leverage</h2>



<p>That shift matters because the economics of productivity are changing. In a traditional enterprise environment, output scaled relatively predictably with team size, process discipline and management quality. AI changes that. Recent empirical research, including a <a href="https://www.stlouisfed.org/on-the-economy/2025/feb/impact-generative-ai-work-productivity" target="_blank" rel="nofollow">St. Louis Federal Reserve analysis</a>, shows that one exceptional engineer, data scientist or product builder with the right tooling can now produce value that would previously have required a team. This makes leverage, not effort alone, the core variable. And leverage is determined largely by the environment the organization creates.</p>



<p>This is where the emerging conversation around AI tokens becomes strategically important. The point is not simply whether companies literally compensate employees with tokens. The more important issue is what tokens represent. They represent capacity. They represent the right to use computing, models, and AI systems at a level that meaningfully amplifies human output. In effect, AI capacity is becoming part of the employee value proposition.</p>



<p>Top AI talent is not only asking about the salary. They are increasingly asking: What will I be able to do here? How fast can I test ideas? Will advanced models be available or tightly rationed? Is computing treated as productive capital or as a cost to be restricted? Will I spend my time building or seeking approvals? That is a fundamental shift in how elite technical talent evaluates employers. The old logic of compensation, title and brand prestige is weakening as a sole mechanism for attraction. For the best AI practitioners, leverage is becoming the real differentiator. As TechTarget’s coverage of the <a href="https://www.techtarget.com/searchcio/feature/The-AI-talent-wars-explained-What-CIOs-need-to-know" target="_blank" rel="nofollow">AI talent wars facing CIOs</a> makes clear, this is not a future problem it is a current one.</p>



<h2 class="wp-block-heading">Your AI strategy may be strong. Your talent model may be broken</h2>



<p>Many enterprises are not prepared for this change. Their HR systems still revolve around fixed salary bands, annual bonus structures, standardized job architecture and conventional notions of fairness. Those mechanisms made sense in a world where productivity differences were meaningful but still bounded. AI changes that distribution. Output is becoming more uneven, more non-linear and more sensitive to tooling and access. Two people with similar titles may generate radically different business value depending on the AI environment around them. If the talent model does not reflect that reality, the organization risks flattening its own advantage. This is why CIOs need to treat AI recruitment and retention as an operating model issue, not just an HR issue. If HR does not understand the strategic meaning of compute access, token budgets, frontier tooling and experimentation freedom, then top talent will slip away before formal metrics ever reveal the problem. Candidates may decline offers because they sense low leverage. Existing employees may remain on the payroll but reduce discretionary effort because the environment does not allow them to work at full capacity. Innovation slows, not because the company lacks ambition, but because it has built friction into the very layer where disproportionate value should emerge.</p>



<p>The danger is that this attrition is often silent. It does not always begin with resignations. It begins with smaller signals. Less experimentation. Fewer prototypes. More time spent navigating the process. A slow shift from creative momentum to compliance behaviour. Eventually, strong people leave for environments where their capabilities compound faster. We have seen this play out already as <a href="https://www.techtarget.com/searchcio/feature/How-big-tech-AI-talent-poaching-affects-the-AI-talent-wars" target="_blank" rel="nofollow">big tech firms aggressively poaching AI talent,</a>, leaving mid-market and large enterprises with shrinking candidate pools. Leadership then explains the loss in familiar terms, perhaps compensation, culture or career progression, without recognising that the deeper issue was constrained leverage.</p>



<h2 class="wp-block-heading">If HR doesn’t learn this fast, the market will teach it harshly</h2>



<p>This is already becoming a strategic management question for CIOs. Many companies are talking about AI transformation at the top without fully translating what it means for the people expected to drive it day-to-day. That gap matters. A company can claim to be ambitious in AI while still making it unnecessarily difficult for its best people to perform at the level they know is possible.</p>



<p>So, what should CIOs do?</p>



<ul class="wp-block-list">
<li><strong>Reframe computing as strategic capital.</strong> In the hands of high-leverage talent, compute is not just an operating expense. It is a multiplier of productivity, innovation velocity and learning speed. Treating it purely as a cost line risk starving the very people most capable of generating returns from it.</li>



<li><strong>Drive closer alignment among HR, finance and technology leadership.</strong> HR must recognize that access to AI tools is no longer merely a provisioning matter. It is part of the talent proposition. Finance must recognize that disciplined enablement can create far more value than indiscriminate restriction. Technology leaders must design governance models that support responsible speed, not just control. As CIO.com reports, CIOs will begin co-leading, and those who move first will have a structural advantage.</li>



<li><strong>Evolve recruitment narratives.</strong> The old employer story of salary, benefits and career path is no longer sufficient for top AI candidates. The new story is about capability. What models will they have access to? What sandbox can they use? How much experimentation budget exists? How quickly can they move from concept to deployment? In the AI era, the strongest candidates are choosing environments rather than just employers.</li>



<li><strong>Revisit how performance is evaluated.</strong> It is no longer enough to measure output using conventional management proxies alone. In AI-heavy roles, leaders will increasingly need to understand the relationship between talent, tooling, compute and business outcomes. The question is not simply who worked harder. It is the one who created more value through augmented capability.</li>
</ul>



<p>None of this means abandoning governance, fairness or cost discipline. It means modernising them. The CIO challenge is not to create an unrestricted AI playground. It is to build a system that enables the right people to move quickly within sensible boundaries. That distinction matters. The winners in this market will not be the firms that ignore risk. They will be the firms that design for responsible leverage. As a recent <a href="https://globalcio.com/articles/main/key-challenges-for-cios-in-2026-strategy-governance-and-ai-at-scale/" target="_blank" rel="nofollow">GlobalCIO roundtable concluded</a>, AI at scale is an organizational and operational challenge, not just a technical one.</p>



<p>The deeper provocation for CIOs is this: Are you building an AI-enabled enterprise, or a permission-constrained one? Those are not the same thing. One attracts builders. The other gradually exhausts them. The next stage of the AI race will not be won only through technology choices. It will be won through organizational design. CIOs who recognize this early will help build environments where exceptional people can produce exceptional results. Those who do not may keep investing heavily in AI while quietly losing the people best positioned to make that investment matter.</p>



<p>That is the talent risk many enterprises still do not see. The next AI winner will not be the firm that buys the most tools. It will be the one that lets exceptional people use them at full power.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight]]></title>
<description><![CDATA[Executive Summary




Cyble Research and Intelligence Labs (CRIL) has identified a novel Android banking trojan, dubbed OverlayPhantom, actively distributed in the wild via malicious URLs.


The malware employs a two-stage infection chain, using a dropper application that impersonates trusted pla...]]></description>
<link>https://tsecurity.de/de/3549734/it-security-nachrichten/overlayphantom-the-android-banking-trojan-hiding-in-plain-sight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549734/it-security-nachrichten/overlayphantom-the-android-banking-trojan-hiding-in-plain-sight/</guid>
<pubDate>Wed, 27 May 2026 06:21:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/05/OverlayPhantom-blog-fetaured.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="OverlayPhantom" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/05/OverlayPhantom-blog-fetaured.webp 1200w, https://cyble.com/wp-content/uploads/2026/05/OverlayPhantom-blog-fetaured-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/05/OverlayPhantom-blog-fetaured-1024x512.webp 1024w, https://cyble.com/wp-content/uploads/2026/05/OverlayPhantom-blog-fetaured-768x384.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs (CRIL) has identified a novel Android banking trojan, dubbed OverlayPhantom, actively distributed in the wild via malicious URLs.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> employs a two-stage infection chain, using a dropper application that impersonates trusted platforms, including the official Austrian government identity application, ID Austria, and the widely used consumer platform TikTok, to deceive victims into installing it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once deployed, OverlayPhantom masquerades as "Google Play Services" and abuses Android's Accessibility Service to gain persistent, elevated control of the infected device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware is capable of executing over 30 remote commands, conducting real-time screen streaming, performing overlay attacks using embedded HTML phishing pages, and exfiltrating harvested credentials to a multi-port Command and Control (C&amp;C) infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Victimology</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>OverlayPhantom, active since May 2025, targets over 180 applications across banking, financial services, and cryptocurrency platforms, spanning 10 countries, including the United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":119136,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/Figure-1-%E2%80%93-OverlayPhantoms-targets.png" alt="Figure 1 – OverlayPhantom’s targets" class="wp-image-119136"><figcaption class="wp-element-caption"><em>Figure 1 – OverlayPhantom’s targets</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The breadth of its targeting, combined with its operational sophistication, indicates a financially motivated <a href="https://cyble.com/threat-actor-profiles/">threat actor</a> with the capability and intent to conduct large-scale fraud across Western markets.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>OverlayPhantom is a sophisticated Android banking trojan distributed via phishing URLs that impersonate high-trust applications.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware deploys via a dropper application that simulates a fake Google Play service update and guides victims to enable the Accessibility Service.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>It abuses Android's Accessibility Service to silently monitor foreground app activity, intercept user input, simulate gestures, and maintain persistent control over the infected device.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware currently targets over 180 banking, finance, and cryptocurrency applications across 10 countries using embedded WebView-based HTML phishing overlays that are visually indistinguishable from the legitimate apps they impersonate.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>C&amp;C communication is handled over three dedicated non-standard ports — 9091 for command dispatch, 9092 for device status reporting, and 9090 for screen streaming.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>OverlayPhantom supports over 30 remote commands, enabling the threat actor to perform automated gestures, manipulate clipboard content, lock the device screen, display fake notifications, and capture PIN or password input via custom overlay windows.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A built-in JPEG-based screen streaming capability, powered by Android's MediaProjection API, grants the threat actor near real-time visual access to the victim's device screen with minimal bandwidth overhead.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During an investigation into government-themed URL impersonation, Cyble Research and Intelligence Labs (CRIL) uncovered a previously undocumented Android banking trojan, dubbed <strong>OverlayPhantom</strong>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware is being actively distributed in the wild through malicious URLs and masquerades as legitimate, high-trust applications to deceive users into installing it. CRIL’s analysis indicates that OverlayPhantom has been active since early May 2025.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The initial sample discovered was hosted at hxxps://bitlrewards-app[.]com/api/download/IDAustria, distributing a malicious APK masquerading as ID Austria — the official Austrian government digital identity application.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The choice of this lure is significant, as impersonating a government identity service creates a strong <a href="https://cyble.com/knowledge-hub/what-is-social-engineering/">social engineering</a> pretext, particularly for victims who may be prompted to grant sensitive permissions under the guise of identity verification.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A second sample attributed to the same malware was identified impersonating TikTok and appeared to target users in Spain. The use of a high-popularity consumer application as a secondary lure indicates the threat actor is deliberately diversifying their distribution strategy across both institutional and consumer-facing decoys.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Although the distribution URL and observed sample appeared to target Austria, source code analysis revealed that OverlayPhantom is configured to target more than 180 applications across banking, financial services, and cryptocurrency platforms in multiple geographies, including the United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom. This wide targeting scope suggests a financially motivated threat actor operating a scalable and well-resourced campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware abuses Android's Accessibility Service, a recurring technique among sophisticated Android banking trojans, to gain elevated control over the infected device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Observed capabilities include overlay attacks to harvest credentials by displaying fraudulent screens over legitimate banking applications, real-time screen streaming to exfiltrate sensitive on-screen data, and automated action execution to perform unauthorized transactions and interactions without user awareness.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The combination of government and consumer app impersonation, wide geographic and sector targeting, and abuse of core Android accessibility features positions OverlayPhantom as a significant threat to both retail banking customers and cryptocurrency users across Western markets.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>OverlayPhantom employs a two-stage delivery mechanism, utilizing a dropper application as the initial infection vector before deploying the core malware payload.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Upon execution, the dropper presents the victim with a convincing fake Google Play update screen, social-engineering the user into voluntarily installing what appears to be a legitimate system update. This technique effectively bypasses user suspicion by leveraging the inherent trust associated with the Google Play ecosystem.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, the dropper includes an interactive step-by-step tutorial that guides the victim through enabling the Accessibility Service.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":119137,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/Figure-2-%E2%80%93-Google-Play-Update-lure-to-install-OverlayPhantom.png" alt="Figure 2 – Google Play Update lure to install OverlayPhantom" class="wp-image-119137"><figcaption class="wp-element-caption"><em>Figure 2 – Google Play Update lure to install OverlayPhantom</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the victim completes the installation, the OverlayPhantom payload is installed onto the device. The malware immediately prompts the user to grant Accessibility Service permissions. Subsequently, it masquerades as "Google Play Services", making it significantly harder for the victim to identify or remove the malicious application.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":119138,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/Figure-3-%E2%80%93-Hiding-itself-as-Google-Play-Services-and-prompting-to-enable-Accessibility-Service.png" alt="Figure 3 – Hiding itself as Google Play Services and prompting to enable Accessibility Service" class="wp-image-119138"><figcaption class="wp-element-caption"><em>Figure 3 – Hiding itself as Google Play Services and prompting to enable Accessibility Service</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Command &amp; Control Communication</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the victim grants the Accessibility Service permission, OverlayPhantom immediately establishes communication with its Command and Control (C&amp;C) server at hxxps://199.217[.]99[.]122, utilizing a socket-based connection for real-time bidirectional communication between the infected device and the threat actor's infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Notably, the malware does not rely on a single communication channel. Instead, it distributes its C&amp;C traffic across three dedicated ports, as listed below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Port</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>9092</td>
<td>Used for device status and reporting</td>
</tr>
<tr>
<td>9091</td>
<td>Used as a Command and Control channel</td>
</tr>
<tr>
<td>9090</td>
<td>Used for screen streaming</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p>Over OverlayPhantom, port 9091 receives operator-issued commands, executes them on the victim's device, and subsequently relays stolen data or execution status reports back to the server.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of the malware's source code reveals that OverlayPhantom can execute over 30 distinct commands, reflecting the breadth of control the threat actor can exert over a compromised device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":119139,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/Figure-4-%E2%80%93-Commands-received-from-the-server.png" alt="Figure 4 – Commands received from the server" class="wp-image-119139"><figcaption class="wp-element-caption"><em>Figure 4 – Commands received from the server</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The full command set is detailed in the table below.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Command</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>tap</td>
<td>Performs a Tap Gesture</td>
</tr>
<tr>
<td>doubleTap</td>
<td>Performs a double-tap gesture</td>
</tr>
<tr>
<td>longPress</td>
<td>Performs a long-press gesture</td>
</tr>
<tr>
<td>swipe</td>
<td>Performs a swipe gesture</td>
</tr>
<tr>
<td>draw</td>
<td>Performs a custom gesture path</td>
</tr>
<tr>
<td>openRecents</td>
<td>Opens the Recent Apps screen</td>
</tr>
<tr>
<td>switchScreen</td>
<td>Keep the screen on from the locked state</td>
</tr>
<tr>
<td>volumeUp</td>
<td>Increases Audio Volume</td>
</tr>
<tr>
<td>volumeDown</td>
<td>Reduces the volume</td>
</tr>
<tr>
<td>power</td>
<td>Open the power menu</td>
</tr>
<tr>
<td>brightSettings</td>
<td>Open display settings</td>
</tr>
<tr>
<td>back</td>
<td>Performs back action</td>
</tr>
<tr>
<td>home</td>
<td>Performs home action</td>
</tr>
<tr>
<td>buf</td>
<td>Set the attacker-provided text to the clipboard content</td>
</tr>
<tr>
<td>target</td>
<td>Malware receives the list of target applications</td>
</tr>
<tr>
<td>startStreamJpeg</td>
<td>Initiates screen streaming</td>
</tr>
<tr>
<td>stopStreamJpeg</td>
<td>Stops screen streaming</td>
</tr>
<tr>
<td>startStreamACNode</td>
<td>Start sending Accessibility node information</td>
</tr>
<tr>
<td>stopStreamACNode</td>
<td>Stop sending Accessibility node information</td>
</tr>
<tr>
<td>ping</td>
<td>Maintaining the keepalive mechanism</td>
</tr>
<tr>
<td>Pong</td>
<td>Maintaining the keepalive mechanism</td>
</tr>
<tr>
<td>stub</td>
<td>Not implemented</td>
</tr>
<tr>
<td>register</td>
<td>Registers the device with BotID</td>
</tr>
<tr>
<td>resendInj</td>
<td>Reset target package injection list</td>
</tr>
<tr>
<td>rmResend</td>
<td>Deletes the file received from the server</td>
</tr>
<tr>
<td>switchOffScreen</td>
<td>Lock the device screen</td>
</tr>
<tr>
<td>blankScreen</td>
<td>Display a blank overlay screen</td>
</tr>
<tr>
<td>blankScreenRm</td>
<td>Removes the blank overlay screen</td>
</tr>
<tr>
<td>pinj</td>
<td>Display an overlay window to collect a PIN, a password or a draw pattern</td>
</tr>
<tr>
<td>notif</td>
<td>Displays a fake notification banner using the target app icon and name</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Overlay Attack: Targeting Banking, Finance, and Cryptocurrency Applications</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>OverlayPhantom leverages the Accessibility Service to continuously monitor foreground application activity on the infected device. The malware maintains a hardcoded target application list embedded in its source code and includes a collection of counterfeit HTML <a href="https://cyble.com/knowledge-hub/what-is-phishing/">phishing</a> pages bundled directly into the APK's resources.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These pages are meticulously crafted to impersonate legitimate banking and financial applications, deceiving victims into submitting their credentials or payment card details.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":119140,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/Figure-5-%E2%80%93-Counterfeit-HTML-phishing-pages-in-the-APK-file.png" alt="Figure 5 – Counterfeit HTML phishing pages in the APK file" class="wp-image-119140"><figcaption class="wp-element-caption"><em>Figure 5 – Counterfeit HTML phishing pages in the APK file</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the victim launches a banking or financial application, OverlayPhantom silently checks whether the application's package name is present in its target list.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Upon a positive match, the malware retrieves the corresponding phishing page from its internal resources, renders it in an embedded WebView, and displays it as a seamless overlay window directly above the legitimate application. From the victim's perspective, the experience is indistinguishable from interacting with the genuine application.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":119144,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/Figure-6-%E2%80%93-Fake-banking-pages-designed-to-steal-banking-credentials.png" alt="Figure 6 – Fake banking pages designed to steal banking credentials" class="wp-image-119144"><figcaption class="wp-element-caption"><em>Figure 6 – Fake banking pages designed to steal banking credentials</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the victim enters their credentials into the fraudulent overlay, OverlayPhantom harvests the submitted username, password, or card details and silently exfiltrates the stolen data to the C&amp;C server, completing the credential theft cycle without raising any visible indication of compromise on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Screen Streaming</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>OverlayPhantom provides real-time screen streaming via JPEG, which can be controlled remotely via the <em><u>startStreamJpeg </u></em>and <em>stopStreamJpeg</em> commands.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Upon receiving the startStreamJpeg command, the malware initiates a screen capture using Android's MediaProjection API, creating a VirtualDisplay instance named jpeg-stream and attaching it to an ImageReader to continuously capture the device's screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The output is resized to a fixed width of 540 pixels, with the height dynamically calculated to preserve the victim device's native screen aspect ratio.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":119142,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/Figure-7-%E2%80%93-Initiating-Screen-Capturing-1.png" alt="Figure 7 – Initiating Screen Capturing" class="wp-image-119142"><figcaption class="wp-element-caption"><em>Figure 7 – Initiating Screen Capturing</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While screen capture is active, the malware establishes a TCP connection to the C&amp;C server on port 9090. Before transmitting any frames, it sends a bot and session identifier, derived from the malware's configured Bot ID and the device ID, to register the streaming session with the operator.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware then enters a continuous capture loop, calling <em>acquireLatestImage()</em> to fetch the latest screen frame, converting it into a Bitmap, compressing it as a JPEG, and writing the resulting bytes directly to the socket.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This provides the threat actor with near-real-time visibility into the victim's screen activity while keeping bandwidth consumption lower than that of raw frame transmission.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The streaming loop incorporates resilience logic to handle interruptions gracefully. If no frame is available, the malware briefly sleeps and resumes polling. In the event of a socket failure, it increments a retry counter, pauses for approximately two seconds, closes the active stream and socket, and attempts to re-establish the connection.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the retry threshold is exceeded, the streaming flag is disabled to prevent an indefinite number of reconnection attempts. The operator can terminate the stream at any time by issuing the <em>stopStreamJpeg </em>command, which flips the streaming state and invokes the corresponding service logic to cleanly shut down the capture session.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>OverlayPhantom represents a mature and methodically engineered Android banking threat. From its deceptive dropper stage — which exploits user trust in the Google Play ecosystem — to its abuse of the Accessibility Service, multi-port C&amp;C architecture, overlay-based credential harvesting, and real-time screen streaming, the malware demonstrates a high degree of operational sophistication.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Its broad targeting scope, encompassing over 180 banking, financial, and cryptocurrency applications across 10 countries at the time of this analysis, further underscores the scale of the threat actor's ambitions. Based on the observed functionality, we anticipate the threat actor’s targeting scope and potential blast radius will continue to expand.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The techniques employed by OverlayPhantom are not novel in isolation, but their combination, particularly the use of government and consumer application lures, hardcoded phishing overlays, and granular remote-control capabilities, reflects a threat actor with both the technical capability and the strategic intent to conduct large-scale financial fraud across multiple regions.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Organizations and individuals operating in the targeted geographies should treat this threat with a high degree of urgency.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Install Apps Only from Trusted Sources:</strong><br>Download apps exclusively from official platforms, such as the <a href="https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/">Google Play Store</a>. Avoid third-party app stores or links received via SMS, social media, or email.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Be Cautious with Permissions and Installs:</strong><br>Never grant permissions and install an application unless you're certain of an app's legitimacy.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Watch for Phishing Pages:</strong><br>Always verify the URL and avoid suspicious links and websites that ask for sensitive information.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Enable Multi-Factor Authentication (MFA):</strong><br>Use MFA for banking and financial apps to add an extra layer of protection, even if credentials are compromised.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Report Suspicious Activity:</strong><br>If you suspect you've been targeted or infected, report the incident to your bank and local authorities immediately. If necessary, reset your credentials and perform a factory reset.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Use Mobile Security Solutions:</strong><br>Install a mobile security application that includes real-time scanning.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Keep Your Device Updated:</strong><br> Ensure your Android OS and apps are updated regularly. Security patches often address vulnerabilities exploited by malware.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td>Initial Access (<a href="https://attack.mitre.org/tactics/TA0027">TA0027</a>)</td>
<td>Phishing (<a href="https://attack.mitre.org/techniques/T1660/">T1660</a>)</td>
<td>OverlayPhantom is distributed via phishing sites</td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Event Triggered Execution: Broadcast Receivers (T1624.001)</td>
<td>OverlayPhantom implemented a broadcast receiver for screen capturing</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Hide Artifacts: Suppress Application Icon (<a href="https://attack.mitre.org/techniques/T1628/001/">T1628.001</a>)</td>
<td>OverlayPhantom hides its icon</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Obfuscated Files or Information (<a href="https://attack.mitre.org/techniques/T1406/">T1406</a>)</td>
<td>Malware uses obfuscated strings</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Masquerading: Match Legitimate Name or Location (<a href="https://attack.mitre.org/techniques/T1655/001/">T1655.001</a>)</td>
<td>OverlayPhantom masquerades as Google Play Service</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Abuse Accessibility Features (<a href="https://attack.mitre.org/techniques/T1453/">T1453</a>)</td>
<td>OverlayPhantom abuses Accessibility service</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Software Discovery  (<a href="https://attack.mitre.org/techniques/T1418/">T1418</a>)</td>
<td>OverlayPhantom checks the installed application list against the target list</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Screen Capture (<a href="https://attack.mitre.org/techniques/T1513/">T1513</a>)</td>
<td>OverlayPhantom captures screen content</td>
</tr>
<tr>
<td>Command &amp; Control (<a href="https://attack.mitre.org/tactics/TA0037">TA0037</a>)</td>
<td>Application Layer Protocol (<a href="https://attack.mitre.org/techniques/T1437/">T1437</a>)</td>
<td>OverlayPhantom communicates with C2 over TCP</td>
</tr>
<tr>
<td>Command &amp; Control (<a href="https://attack.mitre.org/tactics/TA0037">TA0037</a>)</td>
<td>Non-Standard Port (<a href="https://attack.mitre.org/techniques/T1509/">T1509</a>)</td>
<td>OverlayPhantom uses a non-standard port</td>
</tr>
<tr>
<td>Exfiltration (<a href="https://attack.mitre.org/tactics/TA0036">TA0036</a>)</td>
<td>Exfiltration Over C2 Channel (<a href="https://attack.mitre.org/techniques/T1646/">T1646</a>)</td>
<td>OverlayPhantom exfiltrates data to the C&amp;C server</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table {"align":"center"} --></p>
<figure class="wp-block-table aligncenter">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Indicators</strong></td>
<td class="has-text-align-center" data-align="center"><strong>Indicator type</strong></td>
<td class="has-text-align-center" data-align="center"><strong>Description</strong></td>
</tr>
<tr>
<td>hxxps://bitlrewards-app[.]com/api/download/IDAustria</td>
<td class="has-text-align-center" data-align="center">URL</td>
<td class="has-text-align-center" data-align="center">Distribution URL</td>
</tr>
<tr>
<td>199.217[.]99[.]122</td>
<td class="has-text-align-center" data-align="center">IP</td>
<td class="has-text-align-center" data-align="center">C&amp;C server</td>
</tr>
<tr>
<td>9ef37376bfaa18e193cc72218924ad8ebf56d2667d348f0eae5ae6ec45ab8775 f8b614a2918378063d6e6655b676ceb52ae65b1510e2cc08087fcac31acb7aeb 8ddc1f2a75f3d5b5bd054a5367bd5015ebc90f3453d63c7cce438c12dc2ae86a</td>
<td class="has-text-align-center" data-align="center">FileHash-SHA256</td>
<td class="has-text-align-center" data-align="center">OverlayPhantom Hash</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/overlayphantom-android-banking-trojan/">OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection]]></title>
<description><![CDATA[A North Korea-linked threat group, Void Dokkaebi, also known as Famous Chollima, has significantly upgraded its malware delivery techniques by converting its Python-based InvisibleFerret malware into compiled binary modules. InvisibleFerret was previously deployed as readable Python scripts, maki...]]></description>
<link>https://tsecurity.de/de/3545634/it-security-nachrichten/invisibleferret-malware-uses-pyd-and-so-files-to-evade-script-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545634/it-security-nachrichten/invisibleferret-malware-uses-pyd-and-so-files-to-evade-script-detection/</guid>
<pubDate>Mon, 25 May 2026 15:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A North Korea-linked threat group, Void Dokkaebi, also known as Famous Chollima, has significantly upgraded its malware delivery techniques by converting its Python-based InvisibleFerret malware into compiled binary modules. InvisibleFerret was previously deployed as readable Python scripts, making it easier…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/invisibleferret-malware-uses-pyd-and-so-files-to-evade-script-detection/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/invisibleferret-malware-uses-pyd-and-so-files-to-evade-script-detection/">InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection]]></title>
<description><![CDATA[A North Korea-linked threat group, Void Dokkaebi, also known as Famous Chollima, has significantly upgraded its malware delivery techniques by converting its Python-based InvisibleFerret malware into compiled binary modules. InvisibleFerret was previously deployed as readable Python scripts, maki...]]></description>
<link>https://tsecurity.de/de/3545595/it-security-nachrichten/invisibleferret-malware-uses-pyd-and-so-files-to-evade-script-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545595/it-security-nachrichten/invisibleferret-malware-uses-pyd-and-so-files-to-evade-script-detection/</guid>
<pubDate>Mon, 25 May 2026 14:38:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A North Korea-linked threat group, Void Dokkaebi, also known as Famous Chollima, has significantly upgraded its malware delivery techniques by converting its Python-based InvisibleFerret malware into compiled binary modules. InvisibleFerret was previously deployed as readable Python scripts, making it easier for defenders to detect through static analysis and signature-based tools. The latest campaign leverages Cython, […]</p>
<p>The post <a href="https://gbhackers.com/invisibleferret-malware-uses-pyd/">InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Regulator Ofcom Cracks Down on Viral Deepfake Nude Content]]></title>
<description><![CDATA[Ofcom has announced tougher measures aimed at stopping the spread of non-consensual intimate images and AI-generated deepfake abuse online, as the UK regulator pushes tech companies to strengthen user safety protections.

The updated guidance, released Monday, will require platforms to do more ...]]></description>
<link>https://tsecurity.de/de/3531915/it-security-nachrichten/uk-regulator-ofcom-cracks-down-on-viral-deepfake-nude-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531915/it-security-nachrichten/uk-regulator-ofcom-cracks-down-on-viral-deepfake-nude-content/</guid>
<pubDate>Wed, 20 May 2026 08:53:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="non-consensual intimate image" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image.webp 1376w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-1140x636.webp 1140w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image.webp 1376w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-1024x572.webp 1024w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-768x429.webp 768w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-750x419.webp 750w, https://thecyberexpress.com/wp-content/uploads/non-consensual-intimate-image-1140x636.webp 1140w" sizes="(max-width: 1376px) 100vw, 1376px" title="UK Regulator Ofcom Cracks Down on Viral Deepfake Nude Content 1"></p>Ofcom has announced tougher measures aimed at stopping the spread of non-consensual intimate images and <a href="https://thecyberexpress.com/ai-content-generation-systems/" target="_blank" rel="noopener">AI-generated deepfake</a> abuse online, as the UK regulator pushes tech companies to strengthen user safety protections.

The updated guidance, released Monday, will require platforms to do more to identify, detect, and remove illegal intimate content shared without consent. The changes are part of Ofcom’s strengthened Illegal Content Codes under the <a href="https://thecyberexpress.com/ofcom-online-child-safety-rules/" target="_blank" rel="noopener">UK’s Online Safety Act </a>and are expected to come into force in autumn 2026, subject to parliamentary approval.

At the centre of the updated rules is the growing concern over <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-are-deepfakes/" target="_blank" rel="noopener" title="deepfake" data-wpil-keyword-link="linked" data-wpil-monitor-id="28336">deepfake</a> intimate images, including AI-generated nude content and manipulated explicit media targeting women and girls online.
<h2>Tech Platforms Asked to Deploy Hash Matching Technology</h2>
Under the proposed measures, <a href="https://thecyberexpress.com/?s=Ofcom" target="_blank" rel="noopener">Ofcom</a> is recommending that certain platforms and apps expand their use of automated detection systems known as “hash matching” technology to identify and block illegal intimate images before they spread further online.

Hash matching works by converting harmful images into unique digital fingerprints, or hashes, which are then stored in a database. When users attempt to upload the same or similar content again, platforms can automatically detect and block the material.

Ofcom specifically referenced the use of databases such as StopNCII, one of the leading systems designed to combat the spread of non-consensual intimate imagery online.

The regulator <a href="https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/platforms-should-use-detection-technology-to-stop-spread-of-illegal-intimate-images-online-under-strengthened-ofcom-codes" target="_blank" rel="nofollow noopener">said</a> the move is aimed at providing stronger protections for women and girls who are increasingly being targeted through AI-enabled abuse and image manipulation.

According to Ofcom, the updated recommendations, combined with new UK legislation banning “nudification tools,” could significantly reduce the circulation of harmful intimate content online.
<h2>UK Government Pushes Faster Removal of Non-Consensual Intimate image</h2>
The tougher stance follows recent action by the UK government to pressure technology companies into removing abusive content more quickly.

Earlier this year, UK Prime Minister Keir Starmer <a href="https://www.gov.uk/government/news/tech-firms-will-have-to-take-down-abusive-images-within-48-hours-under-new-law-to-protect-women-and-girls" target="_blank" rel="nofollow noopener">backed</a> legislation introducing heavy penalties for platforms that fail to promptly remove illegal intimate images.

Under the law, companies may face substantial fines if they do not take down reported content within 48 hours. Authorities have also warned that services repeatedly failing to comply could face restrictions or blocking in the UK.

The government said the rules are intended to prevent victims from repeatedly reporting the same harmful images while waiting for action from online platforms.

The push for stricter enforcement comes amid rising global concern over the misuse of generative AI tools to create realistic explicit deepfake content without consent.
<h2>Deepfake Concerns Grew After Viral AI Image Abuse Cases</h2>
The UK government’s increased focus on <strong>deepfake intimate images</strong> follows widespread concern over reports that millions of manipulated nude images involving women and children circulated online through AI-powered tools and chatbots earlier this year.

Regulators and child safety advocates have warned that the rapid growth of generative AI platforms has made it easier to create convincing fake explicit images, raising concerns around online abuse, harassment, and exploitation.

Ofcom said technology companies must take greater responsibility for detecting harmful content and preventing its distribution across their platforms.
<h2>Ofcom Investigation Into Online Platforms Continues</h2>
<p data-start="4023" data-end="4144">The latest action also comes as Ofcom continues broader investigations into online platforms under the Online Safety Act.</p>
<p data-start="4146" data-end="4346">In April, the regulator <a href="https://thecyberexpress.com/ofcom-investigation-targets-telegram/" target="_blank" rel="nofollow noopener">expanded</a> an ongoing probe into <span class="hover:entity-accent entity-underline inline cursor-pointer align-baseline"><span class="whitespace-normal">Telegram</span></span>, Teen Chat, and Chat Avenue over concerns linked to child sexual abuse material (CSAM) and online grooming.</p>
<p data-start="4348" data-end="4522">According to Ofcom, the investigation began after receiving evidence suggesting that harmful content and predatory behaviour may have been taking place across these services.</p>
<p data-start="4524" data-end="4772">A major focus of the investigation involves Telegram’s potential exposure to <a href="https://thecyberexpress.com/20-years-of-csam/" target="_blank" rel="noopener">CSAM</a>. Authorities said intelligence shared by the Canadian Centre for Child Protection indicated the alleged presence and distribution of abusive material on the platform.</p>
<p data-start="4774" data-end="4943">Following its own assessment, Ofcom launched a formal investigation into whether Telegram may have failed to meet its legal responsibilities under the Online Safety Act.</p>
<p data-start="4945" data-end="5137">The regulator stated that platforms offering user-to-user communication services are legally required to assess <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28335">risks</a> related to illegal content and implement safeguards to prevent its spread.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Is CZUR ET Max One of the Best Book Scanners for Mac Users?]]></title>
<description><![CDATA[The number of Mac users is growing rapidly, especially in education, design, and research fields. However, when it comes to scanner options, the ecosystem is still lagging. Many devices claim to “support macOS,” but the actual user experience is often far from ideal: the software feels more like ...]]></description>
<link>https://tsecurity.de/de/3527801/ios-mac-os/why-is-czur-et-max-one-of-the-best-book-scanners-for-mac-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527801/ios-mac-os/why-is-czur-et-max-one-of-the-best-book-scanners-for-mac-users/</guid>
<pubDate>Tue, 19 May 2026 06:37:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The number of Mac users is growing rapidly, especially in education, design, and research fields. However, when it comes to scanner options, the ecosystem is still lagging. Many devices claim to “support macOS,” but the actual user experience is often far from ideal: the software feels more like an add-on rather than something designed specifically for Mac users; features are sometimes limited compared to the Windows version; and compatibility with newer Apple Silicon chips is not always fully optimized. For those who rely on a Mac for daily work, these issues can create unnecessary frustration.



This is where CZUR ET Max stands out. It is one of the few book scanning solutions that delivers a smooth and stable experience on macOS, meeting the needs of Mac users without requiring any compromises.



1. Native macOS Compatibility: More Important Than You Think



Many people underestimate the value of true native macOS support until problems appear. Compatibility is not just about whether a device can run on a Mac. For users who are used to the smooth Mac experience, a scanner that is only “barely usable” can create unnecessary delays and frustration.



Common “Mac Compatible” Problems







Many scanners claim to support Mac, but the real experience is often less than ideal. In many cases, users only get basic scanning functions, while advanced features such as auto-cropping, OCR text recognition, and batch processing are limited to the Windows version.



Some devices also require outdated or complicated drivers, making installation inconvenient and sometimes causing system conflicts or permission issues.



For users with Apple Silicon chips such as M1, M2, and M3, these problems can be even more noticeable, including slow performance, software crashes, or recognition errors. In addition, some brands rarely update their Mac software, leaving compatibility issues unresolved for long periods.



These are common frustrations for Mac users, especially educators, designers, researchers, and content creators who depend on efficient workflows.



The Advantage of CZUR ET Max



CZUR ET Max stands out in this area. It offers official support for macOS 10.13 and later, while fully supporting Apple’s native ecosystem for a more natural and stable experience within macOS. Its software is optimized specifically for Mac rather than simply ported from Windows, making the interface, workflow, and system integration feel much more natural for Mac users.



Easy Setup, Smooth Workflow



The setup process is simple: download, install, and start using it right away. There is no need to install Windows, run a virtual machine, or spend time troubleshooting drivers.



This creates a smoother, more stable workflow that fits naturally into the Mac ecosystem.



2. Designed for Books: Better Than Traditional Flatbed Scanners







Traditional flatbed scanners were never designed specifically for books and are mostly used as a compromise solution. While they work well for single pages, the experience is often far from ideal when scanning bound materials.



Common Issues with Flatbed Scanners



Scanning books usually requires pressing them flat against the glass, which is not only inconvenient but can also damage the book spine over time. The process is repetitive and slow, requiring constant positioning, scanning, and page turning.



In addition, content near the spine often appears distorted or shadowed, affecting readability and requiring extra post-processing.



Features of CZUR ET Max




Non-Contact Scanning (No Book Pressing Required)




CZUR ET Max uses a non-contact scanning design, allowing books to be scanned without being pressed flat. This helps protect the book spine and ensures a smoother workflow. With laser curve-flattening technology, it automatically corrects page curvature, while auto-page detection and finger removal further improve scan quality and efficiency.




Fast Enough for Real Workflows




The device scans at around 1.5 seconds per page and supports automatic page detection and batch processing, making it suitable for high-frequency use cases such as academic research, teaching preparation, and document archiving. For example, scanning multiple textbooks with a flatbed scanner may take several hours, while CZUR ET Max can complete the task in about an hour and make the content immediately ready for review.




Built-in OCR: Multi-Language Recognition




It includes ABBYY OCR technology with support for 180+ languages, converting scanned content into searchable PDF, Word, or Excel files for easy editing and retrieval.



Importance for Mac Users







OCR: Making scanned files truly “searchable and usable.”



macOS relies heavily on Spotlight for file search, but without OCR, scanned documents remain as images that cannot be recognized or searched by the system. As a result, digitized paper documents are still difficult to use in practice.



The CZUR ET Max includes built-in OCR, converting scanned content into searchable and editable text, allowing it to fully integrate into the Mac information management system. Users can directly use Spotlight to find keywords, or copy, cite, and edit the extracted text, significantly improving content reuse efficiency. For users handling large volumes of documents, textbooks, or contracts, this is a key step from simple archiving to truly usable knowledge.



Seamless integration into Mac workflows







The CZUR ET Max fits naturally into macOS file management workflows. Scanned files are saved directly to the connected Mac’s local storage and can be exported as PDF, Word, or TXT files for organization in Finder.



A typical workflow looks like this:Scan → generate editable files → organize in Finder → sync via iCloud or other cloud services → access on MacBook, iPad, or iPhone.



This workflow aligns well with the Mac ecosystem. Although it does not support native cross-device synchronization, combining it with iCloud or similar tools still enables a smooth multi-device experience.



Final Thoughts



Overall, the CZUR ET Max is not a device designed for users with only occasional scanning needs. Instead, it is better suited for individuals who regularly handle large volumes of paper-based materials. For students, teachers, researchers, and professionals building structured digital archives, its OCR capabilities and stable local scanning workflow can significantly improve document organization and reuse efficiency.



While it may not be ideal for those who only scan single pages occasionally or have very limited budgets, its value becomes increasingly clear for users who rely heavily on books, academic papers, or contracts over time.]]></content:encoded>
</item>
<item>
<title><![CDATA[The real AI bottleneck isn’t what you think]]></title>
<description><![CDATA[At HumanX in San Francisco earlier this year, Andrew Ng made a point that reframed how many in the room were thinking about enterprise AI. Ng built the AI infrastructure at Google Brain and Baidu before founding DeepLearning.AI and Coursera, which now serves roughly 148 million learners globally....]]></description>
<link>https://tsecurity.de/de/3525532/it-security-nachrichten/the-real-ai-bottleneck-isnt-what-you-think/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525532/it-security-nachrichten/the-real-ai-bottleneck-isnt-what-you-think/</guid>
<pubDate>Mon, 18 May 2026 12:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>At HumanX in San Francisco earlier this year, Andrew Ng made a point that reframed how many in the room were thinking about enterprise AI. Ng built the AI infrastructure at Google Brain and Baidu before founding DeepLearning.AI and<a href="https://www.coursera.org/" rel="nofollow"> </a><a href="https://www.coursera.org/" rel="nofollow">Coursera</a>, which now serves roughly 148 million learners globally. He is someone whose read on where AI creates organizational stress has earned its credibility.</p>



<p>His teams, he said, now expect two engineers to deliver in a month what previously required fifteen engineers over three. They are responding by hiring more engineers, not fewer, because the idea backlog has outrun the capacity to execute.</p>



<p>The implication is easy to miss. The bottleneck has moved. It is no longer in engineering capacity. It is decision-making speed. Engineers finish work and ask, “now what?” Product managers, not developers, have become the scarcest resource in the AI era. And the organizations pulling ahead are not the ones with the most AI tools. They are the ones that figured out how to make faster, better decisions about what to do with what AI produces.</p>



<p>This is more significant than it first appears. For three years, the dominant enterprise AI conversation has been about execution: Which tools to deploy, how to drive adoption, how to manage risk. Those are real questions. But they are not the binding constraint anymore. The binding constraint is judgment. How fast can the organization decide what to scale, what to fix and what to stop?</p>



<h2 class="wp-block-heading">The visibility problem is a decision problem</h2>



<p>What Lanai sees in customer data makes this concrete. One revenue operations team had 140 reps using AI across three regions. One rep had built a renewal outreach workflow that outperformed the team average by 110 times. Leadership had no idea it existed. There was no system to surface it, no way to connect it to the pipeline and no path to replicate it.</p>



<p>Once the workflow was visible, the team extracted it, deployed it as a governed agent and rolled it to all 140 reps across three regions in 72 hours. The result was 11.4 FTE of reclaimed capacity and $2.8 million in the affected pipeline. The technology was not the challenge. The decision was and that was only possible once someone could see what was actually happening.</p>



<p>The same pattern appears on the cost side. A customer in IT and security discovered 23 AI tools running across six departments. Nine were completely ungoverned, with customer PII flowing through personal accounts. Three enterprise licenses sat at under 8% utilization. The tools existed. The spend existed. What did not exist was a single place to see what was critical versus redundant and make a call. Once that visibility existed, they consolidated to 14 governed tools and cut $340,000 in shelfware. Not by deploying new technology. By making a decision they previously could not make because they lacked the information to make it confidently.</p>



<p><a href="https://www.coursera.org/business/resource/ai-skills-report" rel="nofollow">Coursera’s own retention data</a> points in the same direction from a different angle. Employees who completed AI training were retained at 50% higher rates than those who did not. The most valuable output was not task efficiency. It was that people who understood what AI could do started generating better ideas about what to do with it. The upside was clearer thinking about direction, not faster execution of the same tasks.</p>



<h2 class="wp-block-heading">The work itself is changing faster than the org chart</h2>



<p>There is a deeper structural issue underneath the visibility problem. The org chart and the income statement, the two systems enterprises use to understand who does the work and what it costs, were both designed in an era when the answer to “who does the work?” was so obvious nobody bothered to say it out loud: a human being.</p>



<p><a href="https://hbr.org/2014/09/the-chart-that-organized-the-20th-century?autocomplete=true" rel="nofollow">McCallum’s 1855 railroad org chart</a> mapped thousands of people across miles of track. Pacioli’s double-entry system evolved into the profit-and-loss account so merchants could see what was left after paying people, not processors. The industrial revolution added depreciation to admit that machines do work over time, but even that assumed workers were either people or large pieces of hardware. It never imagined a world where software itself is on the shop floor, doing the work as operating labor.</p>



<p>AI is operating labor in a software costume. And neither the org chart nor the P&amp;L was built to see it.</p>



<p>When an agent handles ten thousand support tickets, it appears on the P&amp;L as software expense. When a human did that work, it was labor. The substitution is real but registers nowhere official. Based on observed activity across Lanai B2B SaaS customers, here is where knowledge work actually sits today, and where customers predict it is going by 2028:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Level</strong></td><td><strong>Definition</strong></td><td><strong>Today</strong></td><td><strong>2028</strong></td></tr><tr><td>L1</td><td>Work only a human should own: accountability, trust, novel judgment</td><td>45%</td><td>20%</td></tr><tr><td>L2</td><td>Human does the work; AI assists and accelerates</td><td>35%</td><td>30%</td></tr><tr><td>L3</td><td>Agent executes; human reviews the output</td><td>15%</td><td>35%</td></tr><tr><td>L4</td><td>Agent runs end-to-end; no human required</td><td>5%</td><td>15%</td></tr></tbody></table> </div></figure>



<p><em>Source: </em><a href="https://www.withlanai.com/" rel="nofollow"><em>Lanai customer data</em></a><em>, 2026. Prediction: Lexi Reese, CEO Lanai.</em></p>



<p>The L2 peak-and-decline finding is the most counterintuitive and the most important. L2 does not decline because AI assistance gets worse. It declines because the best-adopted L2 workflows get promoted out of it. The question for any organization is not how to stay in L2. It is which L2 workflows are ready to move, and whether the organization has the data to make that call deliberately rather than accidentally.</p>



<p>By 2028, L3 will become the modal form of knowledge work. The most common configuration will be an agent executing a task while a human decides whether it was done right. That is a fundamentally different job description than what most knowledge worker roles were designed around. And it is arriving faster than most org designs are prepared for.</p>



<h2 class="wp-block-heading">The management problem nobody budgeted for</h2>



<p>Most enterprise AI dashboards are not built to surface any of this. They track adoption rates, active users and tasks completed. Those metrics measure activity. They do not measure whether the organization is converting AI activity into decisions, and decisions into results.</p>



<p>The gap shows up most visibly when the CFO asks what the company got for its AI spend. Token spend that was $5,000 a month eighteen months ago is $40,000 today in many organizations, with no clean story attached. The executives who survive that conversation are not the ones who spent less. They are the ones who built the translation layer between spend and outcome before anyone demanded it. Tokens to threads. Threads to tasks. Tasks to time saved. Time saved to business result. That chain exists in the data. Most organizations have not assembled it.</p>



<p>The CIOs who will have the clearest story for their boards in 2026 are the ones who treated AI deployment as a management problem from the start, built the systems to connect AI activity to the business outcomes they are already accountable for, and developed the organizational habit of acting on what they see.</p>



<p>Execution stops being the constraint. Judgment becomes the scarce resource. The organization that was slow because humans could not execute fast enough is now slow for a different reason: Not enough people who can make the right call under genuine uncertainty. Most org charts are designed to consume judgment, not develop it.</p>



<p>Leaders approved the tools. The ones pulling ahead are the ones who decided to own the outcomes.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[FlipaClip for PC – Create 2D Animation on Windows (2026)]]></title>
<description><![CDATA[Want to create 2D animation on a Windows computer? If yes, then download this Flipaclip app on your PC and showcase your drawing skills to the world with the help of powerful tools. Are you ready? Let’s animate for free!



Facts – Has 30+ million users and is one of the most popular apps in the ...]]></description>
<link>https://tsecurity.de/de/3519906/windows-tipps/flipaclip-for-pc-create-2d-animation-on-windows-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519906/windows-tipps/flipaclip-for-pc-create-2d-animation-on-windows-2026/</guid>
<pubDate>Fri, 15 May 2026 15:42:27 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img fetchpriority="high" decoding="async" width="300" height="300" src="https://www.buildsometech.com/wp-content/uploads/2026/05/FlipaClip-PC-Icon.jpg" alt="FlipaClip PC Icon" class="wp-image-31809" title="FlipaClip PC Icon"></figure>
</div>


<p>Want to create 2D animation on a Windows computer? If yes, then download this Flipaclip app on your PC and showcase your drawing skills to the world with the help of powerful tools. Are you ready? Let’s animate for free!</p>



<p><strong>Facts</strong> – Has 30+ million users and is one of the most popular apps in the Art &amp; Design category.</p>



<h2 class="wp-block-heading">What is Flipaclip?</h2>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img decoding="async" width="265" height="266" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Cartoon-Character-of-a-girl-with-Pencil.png" alt="Cartoon Character of a girl with Pencil" class="wp-image-31810" title="Cartoon Character of a girl with Pencil"></figure>
</div>


<p><strong>FlipaClip</strong> is an animation app that allows you to create animated videos, movies, and GIF files. It was developed by Visual Blasters LLC and has been awarded “App of the Year” by the Google Play Store. </p>



<p>Being one of the most advanced software applications, creators love using it to make different animated styles like Memes, Stop Motion, Stickman Figures, Anime, Cartoons, Sketches, Scribbles, Gacha Life, Loopable NFT, Furry Art, etc.</p>



<p>If you love exploring your creativity by sketching, drawing, storyboarding, or animating videos, Flipaclip has everything to bring your imagination into reality. </p>



<p>Doesn’t matter if you are a professional or beginner, with features like Dark &amp; light mode, Onion skin, Frames viewer, Stack projects, and Grid, you will never feel left out at any moment.</p>



<h2 class="wp-block-heading">How to Download and Install FlipaClip on Windows PC?</h2>



<p>If you are someone who loves to draw but is not very good at it, then installing and using apps like Flipaclip can help you. With this, you will not be only drawing or sketching your ideas on canvas but will also be converting them into animated movies or videos on PC.</p>



<p>However, this app is absolutely free to download from official App Stores, but if you want to use all the premium features then you have to upgrade it. </p>



<p>Also, note that if you are looking for a way where “<strong>No emulator</strong>” is required then I am sorry because there is no official version of Flipaclip for Windows. Here we will be using “<em>Bluestacks</em>” because it’s the best one and also compatible with almost all laptops, computers, or desktops.</p>



<p>Minimum System Requirements:-</p>



<ul class="wp-block-list">
<li>Operating System: Windows 7, 8, 10, 11 &amp; MacOS.</li>



<li>Processor: Intel i3 or AMD Ryzen 3.</li>



<li>RAM: At least 2GB. ( 4GB is more preferred )</li>



<li>HDD: 5GB of free storage space.</li>



<li>Check if graphics drivers are up to date.</li>



<li>Permission: Must be an administrator on the system.</li>
</ul>



<p><strong>Note:-</strong> Please make sure all the software is updated to the latest version.</p>



<p>And here is the step-by-step guide which you need to follow:-</p>



<p><strong>Step 1:</strong> Download the online or offline installer of Bluestacks <strong><a href="https://www.bluestacks.com/" target="_blank" rel="noopener">from here</a></strong>.</p>



<p><strong>Step 2:</strong> Now double-click on the installer file and start installing Bluestacks.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img decoding="async" width="443" height="216" src="https://www.buildsometech.com/wp-content/uploads/2026/05/double-clicking-on-installer-file.png" alt="double clicking on installer file" class="wp-image-31812" title="double clicking on installer file"></figure>
</div>


<p><strong>Step 3:</strong> Launch or run the <strong>Bluestacks AppPlayer</strong> once installation is done.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="768" height="130" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Launch-appPlayer.png" alt="Launch appPlayer" class="wp-image-31813" title="Launch appPlayer"></figure>



<p><strong>Step 4:</strong> Open the <strong>Play Store</strong> app and sign in to your Google account.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="768" height="413" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Sign-in-Play-Store-app-768x413-1.png" alt="Sign in Play Store app 768x413 1" class="wp-image-31814" title="Sign in Play Store app 768x413 1"></figure>
</div>


<p><strong>Note:-</strong> If you don’t want to log in, then you can download the flipaclip.apk file.</p>



<p><strong>Step 5:</strong> If you are using Play Store then search for “<strong>Flipaclip</strong>” and then click on the <strong>Install</strong> button.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="884" height="179" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Installing-Flipaclip-on-PC.png" alt="Installing Flipaclip on PC" class="wp-image-31815" title="Installing Flipaclip on PC" srcset="https://www.buildsometech.com/wp-content/uploads/2026/05/Installing-Flipaclip-on-PC.png 884w, https://www.buildsometech.com/wp-content/uploads/2026/05/Installing-Flipaclip-on-PC-768x156.png 768w" sizes="auto, (max-width: 884px) 100vw, 884px"></figure>



<p><strong>Note:-</strong> If you have directly downloaded the APK file on your PC, then double-click on it to install.</p>



<p><strong>Step 6:</strong> Once the application is installed successfully, open it and follow the given instructions to get started.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="1191" height="739" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Running-App-on-a-Windows-System.png" alt="Running App on a Windows System" class="wp-image-31816" title="Running App on a Windows System" srcset="https://www.buildsometech.com/wp-content/uploads/2026/05/Running-App-on-a-Windows-System.png 1191w, https://www.buildsometech.com/wp-content/uploads/2026/05/Running-App-on-a-Windows-System-768x477.png 768w" sizes="auto, (max-width: 1191px) 100vw, 1191px"></figure>
</div>


<p>Now you can start animating your awesome ideas using this wonderful software.</p>



<h2 class="wp-block-heading">Exclusive Features</h2>



<h3 class="wp-block-heading">Animate In Seconds</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Animate-In-Seconds.png" alt="Animate In Seconds" class="wp-image-31817" title="Animate In Seconds"></figure>
</div>


<p>With an amazing timeline layout, you can easily create 2D frame by frame animations within seconds. Besides that, you also get different animating tools such as frames viewer, overlay grids, and back &amp; forward controls for faster navigation.</p>



<h3 class="wp-block-heading">Art Drawing Tools</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Art-Drawing-Tools.png" alt="Art Drawing Tools" class="wp-image-31818" title="Art Drawing Tools"></figure>
</div>


<p>Drawing features of flipaclip like Custom canvas sizes, Multiple fonts &amp; Apple pencil support for free have always been a plus point for users. And that’s why, they love to design their characters for Minecraft, Battle Royale, Roblox &amp; other games.</p>



<h3 class="wp-block-heading">Add Sounds &amp; Music</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Add-Sounds-and-Music.png" alt="Add Sounds and Music" class="wp-image-31819" title="Add Sounds and Music"></figure>
</div>


<p>Ever thought of having an animation video without music, I know it sounds pretty boring. But don’t worry, this app lets you add audio clips, voice recordings, &amp; dialogues without any cost. You also get access to the popular curated audios to use.</p>



<h3 class="wp-block-heading">Draw On Video</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Draw-On-Video.png" alt="Draw On Video" class="wp-image-31820" title="Draw On Video"></figure>
</div>


<p>With this application, inserting images and clips on canvas or the top of your videos has become very easy. One new feature that really excites me is Rotoscopes, using which you can easily make your own animated stories using different filters/effects.</p>



<h3 class="wp-block-heading">Animation Layers</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Animation-Layers.png" alt="Animation Layers" class="wp-image-31821" title="Animation Layers"></figure>
</div>


<p>Flipaclip has always been very beneficial to basic users because it allows them to use up to 3 layers in their free plans. Whereas in premium plans they can add up to 10 layers but recently in their new update they have added some more layers.</p>



<h3 class="wp-block-heading">Alpha Lock &amp; Clipping Mask</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Alpha-Lock-and-Clipping-Mask.png" alt="Alpha Lock and Clipping Mask" class="wp-image-31822" title="Alpha Lock and Clipping Mask"></figure>
</div>


<p>It’s a special feature that is known to very less users. Alpha Lock is used to edit a specific layer without tFun Challengesouching the transparent region, whereas Clipping Mask uses one layer to control the transparency of the other layer or layers.</p>



<h3 class="wp-block-heading">Make Movies</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Make-Movies.png" alt="Make Movies" class="wp-image-31823" title="Make Movies"></figure>
</div>


<p>If you think that this app only helps in making video animations then you are slightly wrong because it can also help you in creating movies from still images. Moreover, you can also export and save your files in different formats like MP4, GIF, etc.</p>



<h3 class="wp-block-heading">Share Videos Online</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Share-Videos-Online.png" alt="Share Videos Online" class="wp-image-31824" title="Share Videos Online"></figure>
</div>


<p>Love sharing your work, then Flipaclip is here for you. Now you can directly share your videos with millions of creators and friends using social media platforms such as Youtube, TikTok, Tumblr Facebook, Instagram, Facebook, and more.</p>



<h3 class="wp-block-heading">Fun Challenges</h3>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="330" height="440" src="https://www.buildsometech.com/wp-content/uploads/2026/05/Fun-Challenges.png" alt="Fun Challenges" class="wp-image-31825" title="Fun Challenges"></figure>
</div>


<p>We know it’s a pretty good animation app but what makes it even better is its community and connectivity with users. You can participate in different challenges like Spooky Challenge, Lofi Challenge, and Prompt Challenge &amp; can win free exciting prizes.</p>



<h2 class="wp-block-heading">Frequently Asked Questions (FAQs)</h2>


<div class="rank-math-block">
<div class="rank-math-list ">
<div class="rank-math-list-item">
<h3 class="rank-math-question ">Is FlipaClip easy?</h3>
<div class="rank-math-answer ">

<p>Yes, flipaclip is very easy to use. And the best part is that it’s pretty good for beginners because it has a very simple layout using which users can easily learn to animate their videos without getting into technical details.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">How much is flipaclip?</h3>
<div class="rank-math-answer ">

<p>Currently, Flipaclip has two premium plans. The first one is Plus (Monthly), which costs you around <strong>$5.99</strong>, and the second is Plus (Annual), which is <strong>$29.99</strong>. But if you are just starting then the free version is more than enough.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">Is FlipaClip available for PC?</h3>
<div class="rank-math-answer ">

<p>No, flipaclip is not officially available for PC to download but you can still run it on your Windows and Mac devices using emulators. It also works on Microsoft Surface laptops via the Amazon App Store.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">Is flipaclip safe to use?</h3>
<div class="rank-math-answer ">

<p>Talking about Flipaclip safety, then this app is absolutely safe for kids and school students. However, the app follows all the proper guidelines but in the community, you may meet young adults talking about animations &amp; video creation.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">How to get FlipaClip on Windows 10 without Bluestacks?</h3>
<div class="rank-math-answer ">

<p>If you want to get flipaclip on your Windows 10 without using Bluestacks, check this guide. Here we have shared different installation methods using other Android emulators like Nox Player, LDPlayer, Gameloop, Memu Play, etc.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">Is FlipaClip on google play?</h3>
<div class="rank-math-answer ">

<p>Yes, Flipaclip is available on the Google Play Store and has been the editor’s choice for years. It is one of the best animation applications that you can use on your Android Mobile, Smartphones, Tablets, and Chromebooks.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">How do I install FlipaClip on Windows 11?</h3>
<div class="rank-math-answer ">

<p>To install Flipaclip on Windows 11 follow these steps:-<br>1. Open Microsoft Store &amp; search for “Amazon Appstore”.<br>2. Download and install it on your computer.<br>3. Open the Amazon Appstore &amp; search for “Flipaclip”.<br>4. Click on the Get button, it will start installing.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">Is there an app like FlipaClip for PC?</h3>
<div class="rank-math-answer ">

<p>Yes, there are plenty of flipaclip alternatives that can be used on PC. One software we highly recommend is <strong>Synfig Studio</strong> because it is open-source and has all the capabilities to be a great 2D animation tool.</p>

</div>
</div>
<div class="rank-math-list-item">
<h3 class="rank-math-question ">Is FlipaClip completely free?</h3>
<div class="rank-math-answer ">

<p>No, flipaclip is not completely free to use but there are so many important features &amp; tools like Lasso, Eraser, Brushes, Paint Buckets, Fill, Ruler shapes, Layers, Formats, and Fonts which doesn’t cost you any money &amp; are totally worth it.</p>

</div>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Capacity markets could reshape cloud computing]]></title>
<description><![CDATA[An article from AI CERTs reporting on the Anthropic-SpaceX capacity arrangement caught my attention because it highlights a possibility the cloud market has been moving toward for years but has never fully embraced. The traditional assumption has always been simple: If you need elastic infrastruc...]]></description>
<link>https://tsecurity.de/de/3519073/ai-nachrichten/capacity-markets-could-reshape-cloud-computing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519073/ai-nachrichten/capacity-markets-could-reshape-cloud-computing/</guid>
<pubDate>Fri, 15 May 2026 11:18:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>An article from <a href="https://www.aicerts.ai/news/spacex-deal-redefines-cloud-computing-supply/">AI CERTs reporting on the Anthropic-SpaceX capacity arrangement</a> caught my attention because it highlights a possibility the cloud market has been moving toward for years but has never fully embraced. The traditional assumption has always been simple: If you need elastic infrastructure at scale, you go to a hyperscaler such as AWS, Microsoft, or Google. They own the data centers, they understand multitenancy, and they know how to deliver <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">computing as a repeatable service</a>. The article suggests something different may now be emerging. Organizations with excess capacity may be able to act, at least temporarily, like cloud providers.</p>



<p>This is a meaningful shift. If access to compute, power, and networking can be packaged and sold by enterprises, AI infrastructure operators, telecoms, colocation players, and perhaps even large private data center owners, then cloud computing becomes less about who invented the model and more about who has available capacity right now. In other words, the market starts to behave less like a neatly segmented cloud industry and more like a dynamic exchange for compute resources.</p>



<h2 class="wp-block-heading">The economics make sense</h2>



<p>The positive side of this trend is easy to understand. The first and most obvious benefit is price. Non-hyperscale providers with excess capacity are often not carrying the same cost structures, margin expectations, or service packaging as the major cloud vendors. If they have unused GPUs, underutilized clusters, or stranded power and cooling resources, they may be willing to sell access at rates that are materially lower than the traditional cloud market. For enterprises under pressure to control AI and infrastructure costs, that matters.</p>



<p>The second benefit is efficiency. If capacity already exists somewhere and can be used by another party, we may be able to satisfy demand without immediately building new data centers, deploying more hardware, or consuming more incremental power than is already committed. In a market where new capacity takes time, capital, permits, and energy planning, repurposing existing excess supply is not just financially attractive, it is operationally smart. We have spent years talking about sustainability in cloud. One practical path to sustainability is making better use of what is already running.</p>



<p>The third benefit is optionality. Enterprises increasingly want alternatives to hyperscaler lock-in, especially for specialized workloads such as AI model training, inference, analytics, and bursty high-performance computing. If a broader market of capacity suppliers emerges, buyers gain leverage. They may not move every workload away from the major providers, but they will have more negotiating power and more architectural flexibility.</p>



<h2 class="wp-block-heading">The operational challenges</h2>



<p>The problem, of course, is that most organizations with excess capacity are not cloud providers. They may own infrastructure, but owning infrastructure is not the same thing as delivering cloud services. True cloud providers offer automation, provisioning, identity controls, billing, observability, policy management, resilience, service-level agreements, and mature multitenant architectures. Rank-and-file capacity suppliers typically do not.</p>



<p>That means a great deal of coordination has to occur in the background to make this work. Networking has to be integrated. Security controls have to be mapped. Data governance has to be enforced. Capacity has to be monitored and scheduled. Performance isolation has to be managed. Contracts, compliance responsibilities, and operational support boundaries have to be spelled out in painful detail. None of that is impossible, but none of it is free.</p>



<p>This becomes even more difficult when you consider multitenancy. Hyperscalers are built to let many customers safely and efficiently share infrastructure. A one-off capacity supplier may be set up for internal use, single-purpose use, or a narrow class of workloads. Converting that into something that behaves like a cloud service for outside tenants requires tools, expertise, and process maturity. In many cases, the buyer will end up doing part of that heavy lifting. That reduces the pricing advantage and introduces risk.</p>



<h2 class="wp-block-heading">Excess capacity can be temporary</h2>



<p>Another negative is duration. Excess capacity is excess only until the owner needs it back. That is the part many enthusiastic buyers will underestimate. You may enter into an arrangement because another organization has idle GPUs, spare compute, or available power headroom, but those assets are often strategic. At some point, the owner may decide it needs that capacity for its own workloads, new customers, or internal growth.</p>



<p>Then you have a migration problem. You move in, integrate systems, adapt security models, tune performance, and settle into operations, only to discover that the clock was always ticking. Now you have to move out. That means data movement, workload refactoring, revalidation of controls, downtime planning, cost overruns, and renewed security review. Temporary capacity can solve an immediate supply problem, but it can also create a deferred complexity problem that lands squarely on the enterprise customer.</p>



<p><a href="https://www.csoonline.com/article/568841/what-is-information-security-definition-principles-and-jobs.html">Security </a>concerns are especially important here. Every temporary hosting relationship expands the trust boundary. Data may reside in unfamiliar environments. Administrative access patterns may differ from internal standards. Logging, encryption, and incident response processes may not align cleanly. Enterprises can manage those risks, but only if they treat these deals as serious platform decisions, not opportunistic side arrangements.</p>



<h2 class="wp-block-heading">A proven concept, despite risk</h2>



<p>Still, I think the core concept has now been validated. The idea that enterprises can exchange or lease capacity outside the hyperscaler model is no longer theoretical. In certain cases, it may be a very viable option, especially for organizations that need lower-cost compute, specialized hardware access, or interim capacity while waiting for longer-term infrastructure plans to catch up.</p>



<p>The next interesting question will be market structure. Today, these arrangements are likely to be negotiated business to business, one deal at a time. That does not scale well. Over time, I suspect we will see intermediary systems emerge that function more like brokers or exchanges. Such platforms could discover available capacity, classify it, verify security and compliance characteristics, normalize service definitions, and automatically match buyers with suppliers. That would make the market far more efficient than manually brokering deals one by one.</p>



<p>If that happens, cloud computing changes again. It stops being defined solely by branded public cloud platforms and starts to include federated, brokered, and dynamically sourced capacity markets. Some of that capacity will come from hyperscalers. Some of it will come from specialized providers. Some of it may come from organizations that never intended to become cloud sellers but find themselves participating anyway because the economics are too compelling to ignore.</p>



<p>I would not overstate the maturity of this model yet. The operational, contractual, and security issues are real, and the lack of true <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> multitenant design among many suppliers is a serious limitation. However, the potential upside is also real. If enterprises can access lower-cost computing outside the hyperscaler ecosystem, and if excess capacity can be productized safely and efficiently, this could become an important new sourcing option.</p>



<p>I will keep an eye on this space. There may be real benefit here, especially for enterprises looking for a practical path to lower-cost computing and more flexible sourcing. At the very least, it is an interesting development. At best, it may be the beginning of a broader market where compute capacity itself becomes a tradable service, available from far more players than the cloud industry has traditionally allowed.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SIMATIC]]></title>
<description><![CDATA[View CSAF
Summary
SIMATIC CN 4100 contains multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SIMATIC CN 4100 and recommends to update to the latest version.
The following versions of Siemens...]]></description>
<link>https://tsecurity.de/de/3517151/it-security-nachrichten/siemens-simatic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517151/it-security-nachrichten/siemens-simatic/</guid>
<pubDate>Thu, 14 May 2026 17:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-134-10.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>SIMATIC CN 4100 contains multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SIMATIC CN 4100 and recommends to update to the latest version.</strong></p>
<p>The following versions of Siemens SIMATIC are affected:</p>
<ul>
<li>SIMATIC CN 4100 vers:intdot/&lt;5.0 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.6</td>
<td>Siemens</td>
<td>Siemens SIMATIC</td>
<td>NULL Pointer Dereference, Reachable Assertion, Use After Free, Out-of-bounds Write, Integer Overflow or Wraparound, Allocation of Resources Without Limits or Throttling, Out-of-bounds Read, Covert Timing Channel, Stack-based Buffer Overflow, Inefficient Algorithmic Complexity, Missing Release of Memory after Effective Lifetime, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Improper Locking, Uncontrolled Recursion, Buffer Access with Incorrect Length Value, Race Condition within a Thread, Missing Synchronization, Use of Uninitialized Resource, Double Free, Missing Release of Resource after Effective Lifetime, Loop with Unreachable Exit Condition ('Infinite Loop'), Improper Update of Reference Count, Improper Control of a Resource Through its Lifetime, Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), Unexpected Status Code or Return Value, Divide By Zero, Improper Validation of Specified Index, Position, or Offset in Input, Comparison Using Wrong Factors, Observable Timing Discrepancy, Improper Validation of Syntactic Correctness of Input, Deadlock, Signal Handler Race Condition, Improper Following of Specification by Caller, Improper Check for Dropped Privileges, Transmission of Private Resources into a New Sphere ('Resource Leak'), Improper Resource Shutdown or Release, Improper Access Control, Exposure of Sensitive Information to an Unauthorized Actor, Relative Path Traversal, Improper Neutralization of Escape, Meta, or Control Sequences, Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade'), Uncontrolled Resource Consumption, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authentication for Critical Function, Improper Check for Unusual or Exceptional Conditions</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-47704</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check link_res-&gt;hpo_dp_link_enc before using it [WHAT &amp; HOW] Functions dp_enable_link_phy and dp_disable_link_phy can pass link_res without initializing hpo_dp_link_enc and it is necessary to check for null before dereferencing. This fixes 2 FORWARD_NULL issues reported by Coverity.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47704">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-57924</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is usually performed by a filesystem &gt;encode_fh() method that may fail for various reasons. The legacy users of exportfs_encode_fh(), namely, nfsd and name_to_handle_at(2) syscall are ready to cope with the possibility of failure to encode a file handle. There are a few other users of exportfs_encode_{fh,fid}() that currently have a WARN_ON() assertion when -&gt;encode_fh() fails. Relax those assertions because they are wrong. The second linked bug report states commit 16aac5ad1fa9 ("ovl: support encoding non-decodable file handles") in v6.6 as the regressing commit, but this is not accurate. The aforementioned commit only increases the chances of the assertion and allows triggering the assertion with the reproducer using overlayfs, inotify and drop_caches. Triggering this assertion was always possible with other filesystems and other reasons of -&gt;encode_fh() failures and more particularly, it was also possible with the exact same reproducer using overlayfs that is mounted with options index=on,nfs_export=on also on kernels &lt; v6.6. Therefore, I am not listing the aforementioned commit as a Fixes commit. Backport hint: this patch will have a trivial conflict applying to v6.6.y, and other trivial conflicts applying to stable kernels &lt; v6.6.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-57924">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58240</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling from async If we're not doing async, the handling is much simpler. There's no reference counting, we just need to wait for the completion to wake us up and return its result. We should preferably also use a separate crypto_wait. I'm not seeing a UAF as I did in the past, I think aec7961916f3 ("tls: fix race between async notify and socket close") took care of it. This will make the next fix easier.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58240">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6021</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6021">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6052</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-6052">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-7425</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-7425">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-8916</a></h3>
<div class="csaf-accordion-content">
<p>Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://github.Com/bcgit/bc-java/blob/main/pkix/src/main/java/org/bouncycastle/pkix/jcajce/PKIXCertPathReviewer.Java, https://github.Com/bcgit/bc-java/blob/main/prov/src/main/java/org/bouncycastle/x509/PKIXCertPathReviewer.Java. This issue affects BC Java: from 1.44 through 1.78; BC Java: from 1.44 through 1.78; BCPKIX FIPS: from 1.0.0 through 1.0.7, from 2.0.0 through 2.0.7.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-8916">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/770.html">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9230</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9231</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a timing signal which may allow such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS, and so this CVE is not relevant in most TLS contexts. However, given that it is possible to add support for such certificates via a custom provider, coupled with the fact that in such a custom provider context the private key may be recoverable via remote timing measurements, we consider this to be a Moderate severity issue. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as SM2 is not an approved algorithm.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/385.html">CWE-385 Covert Timing Channel</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9232</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9232">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9820</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-9820">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-14831</a></h3>
<div class="csaf-accordion-content">
<p>A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-14831">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/407.html">CWE-407 Inefficient Algorithmic Complexity</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-23143</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. When I ran the repro [0] and waited a few seconds, I observed two LOCKDEP splats: a warning immediately followed by a null-ptr-deref. [1] Reproduction Steps: 1) Mount CIFS 2) Add an iptables rule to drop incoming FIN packets for CIFS 3) Unmount CIFS 4) Unload the CIFS module 5) Remove the iptables rule At step 3), the CIFS module calls sock_release() for the underlying TCP socket, and it returns quickly. However, the socket remains in FIN_WAIT_1 because incoming FIN packets are dropped. At this point, the module's refcnt is 0 while the socket is still alive, so the following rmmod command succeeds. # ss -tan State Recv-Q Send-Q Local Address:Port Peer Address:Port FIN-WAIT-1 0 477 10.0.2.15:51062 10.0.0.137:445 # lsmod | grep cifs cifs 1159168 0 This highlights a discrepancy between the lifetime of the CIFS module and the underlying TCP socket. Even after CIFS calls sock_release() and it returns, the TCP socket does not die immediately in order to close the connection gracefully. While this is generally fine, it causes an issue with LOCKDEP because CIFS assigns a different lock class to the TCP socket's sk-&gt;sk_lock using sock_lock_init_class_and_name(). Once an incoming packet is processed for the socket or a timer fires, sk-&gt;sk_lock is acquired. Then, LOCKDEP checks the lock context in check_wait_context(), where hlock_class() is called to retrieve the lock class. However, since the module has already been unloaded, hlock_class() logs a warning and returns NULL, triggering the null-ptr-deref. If LOCKDEP is enabled, we must ensure that a module calling sock_lock_init_class_and_name() (CIFS, NFS, etc) cannot be unloaded while such a socket is still alive to prevent this issue. Let's hold the module reference in sock_lock_init_class_and_name() and release it when the socket is freed in sk_prot_free(). Note that sock_lock_init() clears sk-&gt;sk_owner for svc_create_socket() that calls sock_lock_init_class_and_name() for a listening socket, which clones a socket by sk_clone_lock() without GFP_ZERO. [0]: CIFS_SERVER="10.0.0.137" CIFS_PATH="//${CIFS_SERVER}/Users/Administrator/Desktop/CIFS_TEST" DEV="enp0s3" CRED="/root/WindowsCredential.txt" MNT=$(mktemp -d /tmp/XXXXXX) mount -t cifs ${CIFS_PATH} ${MNT} -o vers=3.0,credentials=${CRED},cache=none,echo_interval=1 iptables -A INPUT -s ${CIFS_SERVER} -j DROP for i in $(seq 10); do umount ${MNT} rmmod cifs sleep 1 done rm -r ${MNT} iptables -D INPUT -s ${CIFS_SERVER} -j DROP [1]: DEBUG_LOCKS_WARN_ON(1) WARNING: CPU: 10 PID: 0 at kernel/locking/lockdep.c:234 hlock_class (kernel/locking/lockdep.c:234 kernel/locking/lockdep.c:223) Modules linked in: cifs_arc4 nls_ucs2_utils cifs_md4 [last unloaded: cifs] CPU: 10 UID: 0 PID: 0 Comm: swapper/10 Not tainted 6.14.0 #36 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:hlock_class (kernel/locking/lockdep.c:234 kernel/locking/lockdep.c:223) ... Call Trace: __lock_acquire (kernel/locking/lockdep.c:4853 kernel/locking/lockdep.c:5178) lock_acquire (kernel/locking/lockdep.c:469 kernel/locking/lockdep.c:5853 kernel/locking/lockdep.c:5816) _raw_spin_lock_nested (kernel/locking/spinlock.c:379) tcp_v4_rcv (./include/linux/skbuff.h:1678 ./include/net/tcp.h:2547 net/ipv4/tcp_ipv4.c:2350) ... BUG: kernel NULL pointer dereference, address: 00000000000000c4 PF: supervisor read access in kernel mode PF: error_code(0x0000) - not-present page PGD 0 Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 10 UID: 0 PID: 0 Comm: swapper/10 Tainted: G W 6.14.0 #36 Tainted: [W]=WARN Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:__lock_acquire (kernel/ ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-23143">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-23160</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be removed explicitly to avoid a resource leak. Free the structure in case the allocation of the firmware structure fails during the firmware initialization.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-23160">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-31257</a></h3>
<div class="csaf-accordion-content">
<p>This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-31257">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37931</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: btrfs: adjust subpage bit start based on sectorsize When running machines with 64k page size and a 16k nodesize we started seeing tree log corruption in production. This turned out to be because we were not writing out dirty blocks sometimes, so this in fact affects all metadata writes. When writing out a subpage EB we scan the subpage bitmap for a dirty range. If the range isn't dirty we do bit_start++; to move onto the next bit. The problem is the bitmap is based on the number of sectors that an EB has. So in this case, we have a 64k pagesize, 16k nodesize, but a 4k sectorsize. This means our bitmap is 4 bits for every node. With a 64k page size we end up with 4 nodes per page. To make this easier this is how everything looks [0 16k 32k 48k ] logical address [0 4 8 12 ] radix tree offset [ 64k page ] folio [ 16k eb ][ 16k eb ][ 16k eb ][ 16k eb ] extent buffers [ | | | | | | | | | | | | | | | | ] bitmap Now we use all of our addressing based on fs_info-&gt;sectorsize_bits, so as you can see the above our 16k eb-&gt;start turns into radix entry 4. When we find a dirty range for our eb, we correctly do bit_start += sectors_per_node, because if we start at bit 0, the next bit for the next eb is 4, to correspond to eb-&gt;start 16k. However if our range is clean, we will do bit_start++, which will now put us offset from our radix tree entries. In our case, assume that the first time we check the bitmap the block is not dirty, we increment bit_start so now it == 1, and then we loop around and check again. This time it is dirty, and we go to find that start using the following equation start = folio_start + bit_start * fs_info-&gt;sectorsize; so in the case above, eb-&gt;start 0 is now dirty, and we calculate start as 0 + 1 * fs_info-&gt;sectorsize = 4096 4096 &gt;&gt; 12 = 1 Now we're looking up the radix tree for 1, and we won't find an eb. What's worse is now we're using bit_start == 1, so we do bit_start += sectors_per_node, which is now 5. If that eb is dirty we will run into the same thing, we will look at an offset that is not populated in the radix tree, and now we're skipping the writeout of dirty extent buffers. The best fix for this is to not use sectorsize_bits to address nodes, but that's a larger change. Since this is a fs corruption problem fix it simply by always using sectors_per_node to increment the start bit.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37931">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37968</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IRQ function in this driver is reading the flag twice: once to lock a mutex and once to unlock it. Even though the code setting the flag is designed to prevent it, there are subtle cases where the flag could be true at the mutex_lock stage and false at the mutex_unlock stage. This results in the mutex not being unlocked, resulting in a deadlock. Fix it by making the opt3001_irq() code generally more robust, reading the flag into a variable and using the variable value at both stages.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37968">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/667.html">CWE-667 Improper Locking</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38322</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix crash in icl_update_topdown_event() The perf_fuzzer found a hard-lockup crash on a RaptorLake machine: Oops: general protection fault, maybe for address 0xffff89aeceab400: 0000 CPU: 23 UID: 0 PID: 0 Comm: swapper/23 Tainted: [W]=WARN Hardware name: Dell Inc. Precision 9660/0VJ762 RIP: 0010:native_read_pmc+0x7/0x40 Code: cc e8 8d a9 01 00 48 89 03 5b cd cc cc cc cc 0f 1f ... RSP: 000:fffb03100273de8 EFLAGS: 00010046 .... Call Trace: icl_update_topdown_event+0x165/0x190 ? ktime_get+0x38/0xd0 intel_pmu_read_event+0xf9/0x210 __perf_event_read+0xf9/0x210 CPUs 16-23 are E-core CPUs that don't support the perf metrics feature. The icl_update_topdown_event() should not be invoked on these CPUs. It's a regression of commit: f9bdf1f95339 ("perf/x86/intel: Avoid disable PMU if !cpuc-&gt;enabled in sample read") The bug introduced by that commit is that the is_topdown_event() function is mistakenly used to replace the is_topdown_count() call to check if the topdown functions for the perf metrics feature should be invoked. Fix it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38322">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38347</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on ino and xnid syzbot reported a f2fs bug as below: INFO: task syz-executor140:5308 blocked for more than 143 seconds. Not tainted 6.14.0-rc7-syzkaller-00069-g81e4f8d68c66 #0 "echo 0 &gt; /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:syz-executor140 state:D stack:24016 pid:5308 tgid:5308 ppid:5306 task_flags:0x400140 flags:0x00000006 Call Trace: context_switch kernel/sched/core.c:5378 [inline] __schedule+0x190e/0x4c90 kernel/sched/core.c:6765 __schedule_loop kernel/sched/core.c:6842 [inline] schedule+0x14b/0x320 kernel/sched/core.c:6857 io_schedule+0x8d/0x110 kernel/sched/core.c:7690 folio_wait_bit_common+0x839/0xee0 mm/filemap.c:1317 __folio_lock mm/filemap.c:1664 [inline] folio_lock include/linux/pagemap.h:1163 [inline] __filemap_get_folio+0x147/0xb40 mm/filemap.c:1917 pagecache_get_page+0x2c/0x130 mm/folio-compat.c:87 find_get_page_flags include/linux/pagemap.h:842 [inline] f2fs_grab_cache_page+0x2b/0x320 fs/f2fs/f2fs.h:2776 __get_node_page+0x131/0x11b0 fs/f2fs/node.c:1463 read_xattr_block+0xfb/0x190 fs/f2fs/xattr.c:306 lookup_all_xattrs fs/f2fs/xattr.c:355 [inline] f2fs_getxattr+0x676/0xf70 fs/f2fs/xattr.c:533 __f2fs_get_acl+0x52/0x870 fs/f2fs/acl.c:179 f2fs_acl_create fs/f2fs/acl.c:375 [inline] f2fs_init_acl+0xd7/0x9b0 fs/f2fs/acl.c:418 f2fs_init_inode_metadata+0xa0f/0x1050 fs/f2fs/dir.c:539 f2fs_add_inline_entry+0x448/0x860 fs/f2fs/inline.c:666 f2fs_add_dentry+0xba/0x1e0 fs/f2fs/dir.c:765 f2fs_do_add_link+0x28c/0x3a0 fs/f2fs/dir.c:808 f2fs_add_link fs/f2fs/f2fs.h:3616 [inline] f2fs_mknod+0x2e8/0x5b0 fs/f2fs/namei.c:766 vfs_mknod+0x36d/0x3b0 fs/namei.c:4191 unix_bind_bsd net/unix/af_unix.c:1286 [inline] unix_bind+0x563/0xe30 net/unix/af_unix.c:1379 __sys_bind_socket net/socket.c:1817 [inline] __sys_bind+0x1e4/0x290 net/socket.c:1848 __do_sys_bind net/socket.c:1853 [inline] __se_sys_bind net/socket.c:1851 [inline] __x64_sys_bind+0x7a/0x90 net/socket.c:1851 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Let's dump and check metadata of corrupted inode, it shows its xattr_nid is the same to its i_ino. dump.f2fs -i 3 chaseyu.img.raw i_xattr_nid [0x 3 : 3] So that, during mknod in the corrupted directory, it tries to get and lock inode page twice, result in deadlock. - f2fs_mknod - f2fs_add_inline_entry - f2fs_get_inode_page --- lock dir's inode page - f2fs_init_acl - f2fs_acl_create(dir,..) - __f2fs_get_acl - f2fs_getxattr - lookup_all_xattrs - __get_node_page --- try to lock dir's inode page In order to fix this, let's add sanity check on ino and xnid.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38347">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38491</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 __mptcp_do_fallback net/mptcp/protocol.h:1223 [inline] WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 mptcp_do_fallback net/mptcp/protocol.h:1244 [inline] WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 check_fully_established net/mptcp/options.c:982 [inline] WARNING: CPU: 1 PID: 7704 at net/mptcp/protocol.h:1223 mptcp_incoming_options+0x21a8/0x2510 net/mptcp/options.c:1153 Modules linked in: CPU: 1 UID: 0 PID: 7704 Comm: syz.3.1419 Not tainted 6.16.0-rc3-gbd5ce2324dba #20 PREEMPT(voluntary) Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:__mptcp_do_fallback net/mptcp/protocol.h:1223 [inline] RIP: 0010:mptcp_do_fallback net/mptcp/protocol.h:1244 [inline] RIP: 0010:check_fully_established net/mptcp/options.c:982 [inline] RIP: 0010:mptcp_incoming_options+0x21a8/0x2510 net/mptcp/options.c:1153 Code: 24 18 e8 bb 2a 00 fd e9 1b df ff ff e8 b1 21 0f 00 e8 ec 5f c4 fc 44 0f b7 ac 24 b0 00 00 00 e9 54 f1 ff ff e8 d9 5f c4 fc 90 &lt;0f&gt; 0b 90 e9 b8 f4 ff ff e8 8b 2a 00 fd e9 8d e6 ff ff e8 81 2a 00 RSP: 0018:ffff8880a3f08448 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff8880180a8000 RCX: ffffffff84afcf45 RDX: ffff888090223700 RSI: ffffffff84afdaa7 RDI: 0000000000000001 RBP: ffff888017955780 R08: 0000000000000001 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000 R13: ffff8880180a8910 R14: ffff8880a3e9d058 R15: 0000000000000000 FS: 00005555791b8500(0000) GS:ffff88811c495000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000110c2800b7 CR3: 0000000058e44000 CR4: 0000000000350ef0 Call Trace: tcp_reset+0x26f/0x2b0 net/ipv4/tcp_input.c:4432 tcp_validate_incoming+0x1057/0x1b60 net/ipv4/tcp_input.c:5975 tcp_rcv_established+0x5b5/0x21f0 net/ipv4/tcp_input.c:6166 tcp_v4_do_rcv+0x5dc/0xa70 net/ipv4/tcp_ipv4.c:1925 tcp_v4_rcv+0x3473/0x44a0 net/ipv4/tcp_ipv4.c:2363 ip_protocol_deliver_rcu+0xba/0x480 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x2f1/0x500 net/ipv4/ip_input.c:233 NF_HOOK include/linux/netfilter.h:317 [inline] NF_HOOK include/linux/netfilter.h:311 [inline] ip_local_deliver+0x1be/0x560 net/ipv4/ip_input.c:254 dst_input include/net/dst.h:469 [inline] ip_rcv_finish net/ipv4/ip_input.c:447 [inline] NF_HOOK include/linux/netfilter.h:317 [inline] NF_HOOK include/linux/netfilter.h:311 [inline] ip_rcv+0x514/0x810 net/ipv4/ip_input.c:567 __netif_receive_skb_one_core+0x197/0x1e0 net/core/dev.c:5975 __netif_receive_skb+0x1f/0x120 net/core/dev.c:6088 process_backlog+0x301/0x1360 net/core/dev.c:6440 __napi_poll.constprop.0+0xba/0x550 net/core/dev.c:7453 napi_poll net/core/dev.c:7517 [inline] net_rx_action+0xb44/0x1010 net/core/dev.c:7644 handle_softirqs+0x1d0/0x770 kernel/softirq.c:579 do_softirq+0x3f/0x90 kernel/softirq.c:480 __local_bh_enable_ip+0xed/0x110 kernel/softirq.c:407 local_bh_enable include/linux/bottom_half.h:33 [inline] inet_csk_listen_stop+0x2c5/0x1070 net/ipv4/inet_connection_sock.c:1524 mptcp_check_listen_stop.part.0+0x1cc/0x220 net/mptcp/protocol.c:2985 mptcp_check_listen_stop net/mptcp/mib.h:118 [inline] __mptcp_close+0x9b9/0xbd0 net/mptcp/protocol.c:3000 mptcp_close+0x2f/0x140 net/mptcp/protocol.c:3066 inet_release+0xed/0x200 net/ipv4/af_inet.c:435 inet6_release+0x4f/0x70 net/ipv6/af_inet6.c:487 __sock_release+0xb3/0x270 net/socket.c:649 sock_close+0x1c/0x30 net/socket.c:1439 __fput+0x402/0xb70 fs/file_table.c:465 task_work_run+0x150/0x240 kernel/task_work.c:227 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop+0xd4 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38491">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/667.html">CWE-667 Improper Locking</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38502</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given two programs each utilizing a cgroup local storage with a different value size, and one program doing a tail call into the other. The verifier will validate each of the indivial programs just fine. However, in the runtime context the bpf_cg_run_ctx holds an bpf_prog_array_item which contains the BPF program as well as any cgroup local storage flavor the program uses. Helpers such as bpf_get_local_storage() pick this up from the runtime context: ctx = container_of(current-&gt;bpf_ctx, struct bpf_cg_run_ctx, run_ctx); storage = ctx-&gt;prog_item-&gt;cgroup_storage[stype]; if (stype == BPF_CGROUP_STORAGE_SHARED) ptr = &amp;READ_ONCE(storage-&gt;buf)-&gt;data[0]; else ptr = this_cpu_ptr(storage-&gt;percpu_buf); For the second program which was called from the originally attached one, this means bpf_get_local_storage() will pick up the former program's map, not its own. With mismatching sizes, this can result in an unintended out-of-bounds access. To fix this issue, we need to extend bpf_map_owner with an array of storage_cookie[] to match on i) the exact maps from the original program if the second program was using bpf_get_local_storage(), or ii) allow the tail call combination if the second program was not using any of the cgroup local storage maps.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38502">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38552</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: plug races between subflow fail and subflow creation We have races similar to the one addressed by the previous patch between subflow failing and additional subflow creation. They are just harder to trigger. The solution is similar. Use a separate flag to track the condition 'socket state prevent any additional subflow creation' protected by the fallback lock. The socket fallback makes such flag true, and also receiving or sending an MP_FAIL option. The field 'allow_infinite_fallback' is now always touched under the relevant lock, we can drop the ONCE annotation on write.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38552">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38614</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures that the graph is loop-free and does some recursion depth checks, but those recursion depth checks don't limit the depth of the resulting tree for two reasons: - They don't look upwards in the tree. - If there are multiple downwards paths of different lengths, only one of the paths is actually considered for the depth check since commit 28d82dc1c4ed ("epoll: limit paths"). Essentially, the current recursion depth check in ep_loop_check_proc() just serves to prevent it from recursing too deeply while checking for loops. A more thorough check is done in reverse_path_check() after the new graph edge has already been created; this checks, among other things, that no paths going upwards from any non-epoll file with a length of more than 5 edges exist. However, this check does not apply to non-epoll files. As a result, it is possible to recurse to a depth of at least roughly 500, tested on v6.15. (I am unsure if deeper recursion is possible; and this may have changed with commit 8c44dac8add7 ("eventpoll: Fix priority inversion problem").) To fix it: 1. In ep_loop_check_proc(), note the subtree depth of each visited node, and use subtree depths for the total depth calculation even when a subtree has already been visited. 2. Add ep_get_upwards_depth_proc() for similarly determining the maximum depth of an upwards walk. 3. In ep_loop_check(), use these values to limit the total path length between epoll nodes to EP_MAX_NESTS edges.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38614">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38670</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() `cpu_switch_to()` and `call_on_irq_stack()` manipulate SP to change to different stacks along with the Shadow Call Stack if it is enabled. Those two stack changes cannot be done atomically and both functions can be interrupted by SErrors or Debug Exceptions which, though unlikely, is very much broken : if interrupted, we can end up with mismatched stacks and Shadow Call Stack leading to clobbered stacks. In `cpu_switch_to()`, it can happen when SP_EL0 points to the new task, but x18 stills points to the old task's SCS. When the interrupt handler tries to save the task's SCS pointer, it will save the old task SCS pointer (x18) into the new task struct (pointed to by SP_EL0), clobbering it. In `call_on_irq_stack()`, it can happen when switching from the task stack to the IRQ stack and when switching back. In both cases, we can be interrupted when the SCS pointer points to the IRQ SCS, but SP points to the task stack. The nested interrupt handler pushes its return addresses on the IRQ SCS. It then detects that SP points to the task stack, calls `call_on_irq_stack()` and clobbers the task SCS pointer with the IRQ SCS pointer, which it will also use ! This leads to tasks returning to addresses on the wrong SCS, or even on the IRQ SCS, triggering kernel panics via CONFIG_VMAP_STACK or FPAC if enabled. This is possible on a default config, but unlikely. However, when enabling CONFIG_ARM64_PSEUDO_NMI, DAIF is unmasked and instead the GIC is responsible for filtering what interrupts the CPU should receive based on priority. Given the goal of emulating NMIs, pseudo-NMIs can be received by the CPU even in `cpu_switch_to()` and `call_on_irq_stack()`, possibly *very* frequently depending on the system configuration and workload, leading to unpredictable kernel panics. Completely mask DAIF in `cpu_switch_to()` and restore it when returning. Do the same in `call_on_irq_stack()`, but restore and mask around the branch. Mask DAIF even if CONFIG_SHADOW_CALL_STACK is not enabled for consistency of behaviour between all configurations. Introduce and use an assembly macro for saving and masking DAIF, as the existing one saves but only masks IF.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38670">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38676</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel cmdline While the kernel command line is considered trusted in most environments, avoid writing 1 byte past the end of "acpiid" if the "str" argument is maximum length.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38676">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/805.html">CWE-805 Buffer Access with Incorrect Length Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38677</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in dnode page As Jiaming Zhang reported: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x1c1/0x2a0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0x17e/0x800 mm/kasan/report.c:480 kasan_report+0x147/0x180 mm/kasan/report.c:593 data_blkaddr fs/f2fs/f2fs.h:3053 [inline] f2fs_data_blkaddr fs/f2fs/f2fs.h:3058 [inline] f2fs_get_dnode_of_data+0x1a09/0x1c40 fs/f2fs/node.c:855 f2fs_reserve_block+0x53/0x310 fs/f2fs/data.c:1195 prepare_write_begin fs/f2fs/data.c:3395 [inline] f2fs_write_begin+0xf39/0x2190 fs/f2fs/data.c:3594 generic_perform_write+0x2c7/0x910 mm/filemap.c:4112 f2fs_buffered_write_iter fs/f2fs/file.c:4988 [inline] f2fs_file_write_iter+0x1ec8/0x2410 fs/f2fs/file.c:5216 new_sync_write fs/read_write.c:593 [inline] vfs_write+0x546/0xa90 fs/read_write.c:686 ksys_write+0x149/0x250 fs/read_write.c:738 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf3/0x3d0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f The root cause is in the corrupted image, there is a dnode has the same node id w/ its inode, so during f2fs_get_dnode_of_data(), it tries to access block address in dnode at offset 934, however it parses the dnode as inode node, so that get_dnode_addr() returns 360, then it tries to access page address from 360 + 934 * 4 = 4096 w/ 4 bytes. To fix this issue, let's add sanity check for node id of all direct nodes during f2fs_get_dnode_of_data().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38677">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38679</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload bound check Currently, The event_seq_changed() handler processes a variable number of properties sent by the firmware. The number of properties is indicated by the firmware and used to iterate over the payload. However, the payload size is not being validated against the actual message length. This can lead to out-of-bounds memory access if the firmware provides a property count that exceeds the data available in the payload. Such a condition can result in kernel crashes or potential information leaks if memory beyond the buffer is accessed. Fix this by properly validating the remaining size of the payload before each property access and updating bounds accordingly as properties are parsed. This ensures that property parsing is safely bounded within the received message buffer and protects against malformed or malicious firmware behavior.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38679">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38680</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen &gt; 2), buf the function accesses buffer[3], requiring at least 4 bytes. This can lead to an out-of-bounds read if the buffer has exactly 3 bytes. Fix it by checking that the buffer has at least 4 bytes in uvc_parse_format().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38680">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38681</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() Memory hot remove unmaps and tears down various kernel page table regions as required. The ptdump code can race with concurrent modifications of the kernel page tables. When leaf entries are modified concurrently, the dump code may log stale or inconsistent information for a VA range, but this is otherwise not harmful. But when intermediate levels of kernel page table are freed, the dump code will continue to use memory that has been freed and potentially reallocated for another purpose. In such cases, the ptdump code may dereference bogus addresses, leading to a number of potential problems. To avoid the above mentioned race condition, platforms such as arm64, riscv and s390 take memory hotplug lock, while dumping kernel page table via the sysfs interface /sys/kernel/debug/kernel_page_tables. Similar race condition exists while checking for pages that might have been marked W+X via /sys/kernel/debug/kernel_page_tables/check_wx_pages which in turn calls ptdump_check_wx(). Instead of solving this race condition again, let's just move the memory hotplug lock inside generic ptdump_check_wx() which will benefit both the scenarios. Drop get_online_mems() and put_online_mems() combination from all existing platform ptdump code paths.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38681">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/366.html">CWE-366 Race Condition within a Thread</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38683</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix panic during namespace deletion with VF The existing code move the VF NIC to new namespace when NETDEV_REGISTER is received on netvsc NIC. During deletion of the namespace, default_device_exit_batch() &gt;&gt; default_device_exit_net() is called. When netvsc NIC is moved back and registered to the default namespace, it automatically brings VF NIC back to the default namespace. This will cause the default_device_exit_net() &gt;&gt; for_each_netdev_safe loop unable to detect the list end, and hit NULL ptr: [ 231.449420] mana 7870:00:00.0 enP30832s1: Moved VF to namespace with: eth0 [ 231.449656] BUG: kernel NULL pointer dereference, address: 0000000000000010 [ 231.450246] #PF: supervisor read access in kernel mode [ 231.450579] #PF: error_code(0x0000) - not-present page [ 231.450916] PGD 17b8a8067 P4D 0 [ 231.451163] Oops: Oops: 0000 [#1] SMP NOPTI [ 231.451450] CPU: 82 UID: 0 PID: 1394 Comm: kworker/u768:1 Not tainted 6.16.0-rc4+ #3 VOLUNTARY [ 231.452042] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 11/21/2024 [ 231.452692] Workqueue: netns cleanup_net [ 231.452947] RIP: 0010:default_device_exit_batch+0x16c/0x3f0 [ 231.453326] Code: c0 0c f5 b3 e8 d5 db fe ff 48 85 c0 74 15 48 c7 c2 f8 fd ca b2 be 10 00 00 00 48 8d 7d c0 e8 7b 77 25 00 49 8b 86 28 01 00 00 &lt;48&gt; 8b 50 10 4c 8b 2a 4c 8d 62 f0 49 83 ed 10 4c 39 e0 0f 84 d6 00 [ 231.454294] RSP: 0018:ff75fc7c9bf9fd00 EFLAGS: 00010246 [ 231.454610] RAX: 0000000000000000 RBX: 0000000000000002 RCX: 61c8864680b583eb [ 231.455094] RDX: ff1fa9f71462d800 RSI: ff75fc7c9bf9fd38 RDI: 0000000030766564 [ 231.455686] RBP: ff75fc7c9bf9fd78 R08: 0000000000000000 R09: 0000000000000000 [ 231.456126] R10: 0000000000000001 R11: 0000000000000004 R12: ff1fa9f70088e340 [ 231.456621] R13: ff1fa9f70088e340 R14: ffffffffb3f50c20 R15: ff1fa9f7103e6340 [ 231.457161] FS: 0000000000000000(0000) GS:ff1faa6783a08000(0000) knlGS:0000000000000000 [ 231.457707] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 231.458031] CR2: 0000000000000010 CR3: 0000000179ab2006 CR4: 0000000000b73ef0 [ 231.458434] Call Trace: [ 231.458600] [ 231.458777] ops_undo_list+0x100/0x220 [ 231.459015] cleanup_net+0x1b8/0x300 [ 231.459285] process_one_work+0x184/0x340 To fix it, move the ns change to a workqueue, and take rtnl_lock to avoid changing the netdev list when default_device_exit_net() is using it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38683">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/820.html">CWE-820 Missing Synchronization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.2</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38684</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: use old 'nbands' while purging unused classes Shuang reported sch_ets test-case [1] crashing in ets_class_qlen_notify() after recent changes from Lion [2]. The problem is: in ets_qdisc_change() we purge unused DWRR queues; the value of 'q-&gt;nbands' is the new one, and the cleanup should be done with the old one. The problem is here since my first attempts to fix ets_qdisc_change(), but it surfaced again after the recent qdisc len accounting fixes. Fix it purging idle DWRR queues before assigning a new value of 'q-&gt;nbands', so that all purge operations find a consistent configuration: - old 'q-&gt;nbands' because it's needed by ets_class_find() - old 'q-&gt;nstrict' because it's needed by ets_class_is_strict() BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 62 UID: 0 PID: 39457 Comm: tc Kdump: loaded Not tainted 6.12.0-116.el10.x86_64 #1 PREEMPT(voluntary) Hardware name: Dell Inc. PowerEdge R640/06DKY5, BIOS 2.12.2 07/09/2021 RIP: 0010:__list_del_entry_valid_or_report+0x4/0x80 Code: ff 4c 39 c7 0f 84 39 19 8e ff b8 01 00 00 00 c3 cc cc cc cc 66 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa &lt;48&gt; 8b 17 48 8b 4f 08 48 85 d2 0f 84 56 19 8e ff 48 85 c9 0f 84 ab RSP: 0018:ffffba186009f400 EFLAGS: 00010202 RAX: 00000000000000d6 RBX: 0000000000000000 RCX: 0000000000000004 RDX: ffff9f0fa29b69c0 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffffffffc12c2400 R08: 0000000000000008 R09: 0000000000000004 R10: ffffffffffffffff R11: 0000000000000004 R12: 0000000000000000 R13: ffff9f0f8cfe0000 R14: 0000000000100005 R15: 0000000000000000 FS: 00007f2154f37480(0000) GS:ffff9f269c1c0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 00000001530be001 CR4: 00000000007726f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: ets_class_qlen_notify+0x65/0x90 [sch_ets] qdisc_tree_reduce_backlog+0x74/0x110 ets_qdisc_change+0x630/0xa40 [sch_ets] __tc_modify_qdisc.constprop.0+0x216/0x7f0 tc_modify_qdisc+0x7c/0x120 rtnetlink_rcv_msg+0x145/0x3f0 netlink_rcv_skb+0x53/0x100 netlink_unicast+0x245/0x390 netlink_sendmsg+0x21b/0x470 ____sys_sendmsg+0x39d/0x3d0 ___sys_sendmsg+0x9a/0xe0 __sys_sendmsg+0x7a/0xd0 do_syscall_64+0x7d/0x160 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f2155114084 Code: 89 02 b8 ff ff ff ff eb bb 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 80 3d 25 f0 0c 00 00 74 13 b8 2e 00 00 00 0f 05 &lt;48&gt; 3d 00 f0 ff ff 77 54 c3 0f 1f 00 48 83 ec 28 89 54 24 1c 48 89 RSP: 002b:00007fff1fd7a988 EFLAGS: 00000202 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 0000560ec063e5e0 RCX: 00007f2155114084 RDX: 0000000000000000 RSI: 00007fff1fd7a9f0 RDI: 0000000000000003 RBP: 00007fff1fd7aa60 R08: 0000000000000010 R09: 000000000000003f R10: 0000560ee9b3a010 R11: 0000000000000202 R12: 00007fff1fd7aae0 R13: 000000006891ccde R14: 0000560ec063e5e0 R15: 00007fff1fd7aad0 [1] https://lore.kernel.org/netdev/e08c7f4a6882f260011909a868311c6e9b54f3e4.1639153474.git.dcaratti@redhat.com/ [2] https://lore.kernel.org/netdev/d912cbd7-193b-4269-9857-525bee8bbb6a@gmail.com/</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38684">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.2</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38685</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imageblit This issue triggers when a userspace program does an ioctl FBIOPUT_CON2FBMAP by passing console number and frame buffer number. Ideally this maps console to frame buffer and updates the screen if console is visible. As part of mapping it has to do resize of console according to frame buffer info. if this resize fails and returns from vc_do_resize() and continues further. At this point console and new frame buffer are mapped and sets display vars. Despite failure still it continue to proceed updating the screen at later stages where vc_data is related to previous frame buffer and frame buffer info and display vars are mapped to new frame buffer and eventully leading to out-of-bounds write in fast_imageblit(). This bheviour is excepted only when fg_console is equal to requested console which is a visible console and updates screen with invalid struct references in fbcon_putcs().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38685">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38687</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syzbot reports a use-after-free in comedi in the below link, which is due to comedi gladly removing the allocated async area even though poll requests are still active on the wait_queue_head inside of it. This can cause a use-after-free when the poll entries are later triggered or removed, as the memory for the wait_queue_head has been freed. We need to check there are no tasks queued on any of the subdevices' wait queues before allowing the device to be detached by the `COMEDI_DEVCONFIG` ioctl. Tasks will read-lock `dev-&gt;attach_lock` before adding themselves to the subdevice wait queue, so fix the problem in the `COMEDI_DEVCONFIG` ioctl handler by write-locking `dev-&gt;attach_lock` before checking that all of the subdevices are safe to be deleted. This includes testing for any sleepers on the subdevices' wait queues. It remains locked until the device has been detached. This requires the `comedi_device_detach()` function to be refactored slightly, moving the bulk of it into new function `comedi_device_detach_locked()`. Note that the refactor of `comedi_device_detach()` results in `comedi_device_cancel_all()` now being called while `dev-&gt;attach_lock` is write-locked, which wasn't the case previously, but that does not matter. Thanks to Jens Axboe for diagnosing the problem and co-developing this patch.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38687">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38691</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix uninited ptr deref in block/scsi layout The error occurs on the third attempt to encode extents. When function ext_tree_prepare_commit() reallocates a larger buffer to retry encoding extents, the "layoutupdate_pages" page array is initialized only after the retry loop. But ext_tree_free_commitdata() is called on every iteration and tries to put pages in the array, thus dereferencing uninitialized pointers. An additional problem is that there is no limit on the maximum possible buffer_size. When there are too many extents, the client may create a layoutcommit that is larger than the maximum possible RPC size accepted by the server. During testing, we observed two typical scenarios. First, one memory page for extents is enough when we work with small files, append data to the end of the file, or preallocate extents before writing. But when we fill a new large file without preallocating, the number of extents can be huge, and counting the number of written extents in ext_tree_encode_commit() does not help much. Since this number increases even more between unlocking and locking of ext_tree, the reallocated buffer may not be large enough again and again.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38691">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/908.html">CWE-908 Use of Uninitialized Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38693</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar In w7090p_tuner_write_serpar, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on msg[0].buf would be passed. If accessing msg[0].buf[2] without sanity check, null pointer deref would happen. We add check on msg[0].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38693">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38694</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() In dib7090p_rw_on_apb, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on msg[0].buf would be passed. If accessing msg[0].buf[2] without sanity check, null pointer deref would happen. We add check on msg[0].len to prevent crash. Similar issue occurs when access msg[1].buf[0] and msg[1].buf[1]. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38694">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38695</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure If a call to lpfc_sli4_read_rev() from lpfc_sli4_hba_setup() fails, the resultant cleanup routine lpfc_sli4_vport_delete_fcp_xri_aborted() may occur before sli4_hba.hdwqs are allocated. This may result in a null pointer dereference when attempting to take the abts_io_buf_list_lock for the first hardware queue. Fix by adding a null ptr check on phba-&gt;sli4_hba.hdwq and early return because this situation means there must have been an error during port initialization.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38695">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38696</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: MIPS: Don't crash in stack_top() for tasks without ABI or vDSO Not all tasks have an ABI associated or vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will derefence the NULL ABI pointer and crash. This can for example happen when using kunit: mips_stack_top+0x28/0xc0 arch_pick_mmap_layout+0x190/0x220 kunit_vm_mmap_init+0xf8/0x138 __kunit_add_resource+0x40/0xa8 kunit_vm_mmap+0x88/0xd8 usercopy_test_init+0xb8/0x240 kunit_try_run_case+0x5c/0x1a8 kunit_generic_run_threadfn_adapter+0x28/0x50 kthread+0x118/0x240 ret_from_kernel_thread+0x14/0x1c Only dereference the ABI point if it is set. The GIC page is also included as it is specific to the vDSO. Also move the randomization adjustment into the same conditional.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38696">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38697</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG When computing the tree index in dbAllocAG, we never check if we are out of bounds realative to the size of the stree. This could happen in a scenario where the filesystem metadata are corrupted.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38697">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38698</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: jfs: Regular file corruption check The reproducer builds a corrupted file on disk with a negative i_size value. Add a check when opening this file to avoid subsequent operation failures.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38698">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38699</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe() function fails during initialization, the memory pointed to by bfad-&gt;im is freed without setting bfad-&gt;im to NULL. Subsequently, during driver uninstallation, when the state machine enters the bfad_sm_stopping state and calls the bfad_im_probe_undo() function, it attempts to free the memory pointed to by bfad-&gt;im again, thereby triggering a double-free vulnerability. Set bfad-&gt;im to NULL if probing fails.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38699">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/415.html">CWE-415 Double Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38700</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Initialize iscsi_conn-&gt;dd_data only if memory is allocated In case of an ib_fast_reg_mr allocation failure during iSER setup, the machine hits a panic because iscsi_conn-&gt;dd_data is initialized unconditionally, even when no memory is allocated (dd_size == 0). This leads invalid pointer dereference during connection teardown. Fix by setting iscsi_conn-&gt;dd_data only if memory is actually allocated. Panic trace: ------------ iser: iser_create_fastreg_desc: Failed to allocate ib_fast_reg_mr err=-12 iser: iser_alloc_rx_descriptors: failed allocating rx descriptors / data buffers BUG: unable to handle page fault for address: fffffffffffffff8 RIP: 0010:swake_up_locked.part.5+0xa/0x40 Call Trace: complete+0x31/0x40 iscsi_iser_conn_stop+0x88/0xb0 [ib_iser] iscsi_stop_conn+0x66/0xc0 [scsi_transport_iscsi] iscsi_if_stop_conn+0x14a/0x150 [scsi_transport_iscsi] iscsi_if_rx+0x1135/0x1834 [scsi_transport_iscsi] ? netlink_lookup+0x12f/0x1b0 ? netlink_deliver_tap+0x2c/0x200 netlink_unicast+0x1ab/0x280 netlink_sendmsg+0x257/0x4f0 ? _copy_from_user+0x29/0x60 sock_sendmsg+0x5f/0x70</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38700">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38701</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr A syzbot fuzzed image triggered a BUG_ON in ext4_update_inline_data() when an inode had the INLINE_DATA_FL flag set but was missing the system.data extended attribute. Since this can happen due to a maiciouly fuzzed file system, we shouldn't BUG, but rather, report it as a corrupted file system. Add similar replacements of BUG_ON with EXT4_ERROR_INODE() ii ext4_create_inline_data() and ext4_inline_data_truncate().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38701">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38702</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register_framebuffer() The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registered_fb[] 2. All array slots become occupied despite num_registered_fb &lt; FB_MAX 3. The registration loop exceeds array bounds Add boundary check to prevent registered_fb[FB_MAX] access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38702">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38706</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() snd_soc_remove_pcm_runtime() might be called with rtd == NULL which will leads to null pointer dereference. This was reproduced with topology loading and marking a link as ignore due to missing hardware component on the system. On module removal the soc_tplg_remove_link() would call snd_soc_remove_pcm_runtime() with rtd == NULL since the link was ignored, no runtime was created.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38706">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38707</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The length of the file name should be smaller than the directory entry size.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38707">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38708</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflicts With `two-primaries` enabled, DRBD tries to detect "concurrent" writes and handle write conflicts, so that even if you write to the same sector simultaneously on both nodes, they end up with the identical data once the writes are completed. In handling "superseeded" writes, we forgot a kref_get, resulting in a premature drbd_destroy_device and use after free, and further to kernel crashes with symptoms. Relevance: No one should use DRBD as a random data generator, and apparently all users of "two-primaries" handle concurrent writes correctly on layer up. That is cluster file systems use some distributed lock manager, and live migration in virtualization environments stops writes on one node before starting writes on the other node. Which means that other than for "test cases", this code path is never taken in real life. FYI, in DRBD 9, things are handled differently nowadays. We still detect "write conflicts", but no longer try to be smart about them. We decided to disconnect hard instead: upper layers must not submit concurrent writes. If they do, that's their fault.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38708">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38711</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb/server: avoid deadlock when linking with ReplaceIfExists If smb2_create_link() is called with ReplaceIfExists set and the name does exist then a deadlock will happen. ksmbd_vfs_kern_path_locked() will return with success and the parent directory will be locked. ksmbd_vfs_remove_file() will then remove the file. ksmbd_vfs_link() will then be called while the parent is still locked. It will try to lock the same parent and will deadlock. This patch moves the ksmbd_vfs_kern_path_unlock() call to *before* ksmbd_vfs_link() and then simplifies the code, removing the file_present flag variable.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38711">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38712</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() When the volume header contains erroneous values that do not reflect the actual state of the filesystem, hfsplus_fill_super() assumes that the attributes file is not yet created, which later results in hitting BUG_ON() when hfsplus_create_attributes_file() is called. Replace this BUG_ON() with -EIO error with a message to suggest running fsck tool.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38712">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38713</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() The hfsplus_readdir() method is capable to crash by calling hfsplus_uni2asc(): [ 667.121659][ T9805] ================================================================== [ 667.122651][ T9805] BUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0x902/0xa10 [ 667.123627][ T9805] Read of size 2 at addr ffff88802592f40c by task repro/9805 [ 667.124578][ T9805] [ 667.124876][ T9805] CPU: 3 UID: 0 PID: 9805 Comm: repro Not tainted 6.16.0-rc3 #1 PREEMPT(full) [ 667.124886][ T9805] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 667.124890][ T9805] Call Trace: [ 667.124893][ T9805] [ 667.124896][ T9805] dump_stack_lvl+0x10e/0x1f0 [ 667.124911][ T9805] print_report+0xd0/0x660 [ 667.124920][ T9805] ? __virt_addr_valid+0x81/0x610 [ 667.124928][ T9805] ? __phys_addr+0xe8/0x180 [ 667.124934][ T9805] ? hfsplus_uni2asc+0x902/0xa10 [ 667.124942][ T9805] kasan_report+0xc6/0x100 [ 667.124950][ T9805] ? hfsplus_uni2asc+0x902/0xa10 [ 667.124959][ T9805] hfsplus_uni2asc+0x902/0xa10 [ 667.124966][ T9805] ? hfsplus_bnode_read+0x14b/0x360 [ 667.124974][ T9805] hfsplus_readdir+0x845/0xfc0 [ 667.124984][ T9805] ? __pfx_hfsplus_readdir+0x10/0x10 [ 667.124994][ T9805] ? stack_trace_save+0x8e/0xc0 [ 667.125008][ T9805] ? iterate_dir+0x18b/0xb20 [ 667.125015][ T9805] ? trace_lock_acquire+0x85/0xd0 [ 667.125022][ T9805] ? lock_acquire+0x30/0x80 [ 667.125029][ T9805] ? iterate_dir+0x18b/0xb20 [ 667.125037][ T9805] ? down_read_killable+0x1ed/0x4c0 [ 667.125044][ T9805] ? putname+0x154/0x1a0 [ 667.125051][ T9805] ? __pfx_down_read_killable+0x10/0x10 [ 667.125058][ T9805] ? apparmor_file_permission+0x239/0x3e0 [ 667.125069][ T9805] iterate_dir+0x296/0xb20 [ 667.125076][ T9805] __x64_sys_getdents64+0x13c/0x2c0 [ 667.125084][ T9805] ? __pfx___x64_sys_getdents64+0x10/0x10 [ 667.125091][ T9805] ? __x64_sys_openat+0x141/0x200 [ 667.125126][ T9805] ? __pfx_filldir64+0x10/0x10 [ 667.125134][ T9805] ? do_user_addr_fault+0x7fe/0x12f0 [ 667.125143][ T9805] do_syscall_64+0xc9/0x480 [ 667.125151][ T9805] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 667.125158][ T9805] RIP: 0033:0x7fa8753b2fc9 [ 667.125164][ T9805] Code: 00 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 48 [ 667.125172][ T9805] RSP: 002b:00007ffe96f8e0f8 EFLAGS: 00000217 ORIG_RAX: 00000000000000d9 [ 667.125181][ T9805] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fa8753b2fc9 [ 667.125185][ T9805] RDX: 0000000000000400 RSI: 00002000000063c0 RDI: 0000000000000004 [ 667.125190][ T9805] RBP: 00007ffe96f8e110 R08: 00007ffe96f8e110 R09: 00007ffe96f8e110 [ 667.125195][ T9805] R10: 0000000000000000 R11: 0000000000000217 R12: 0000556b1e3b4260 [ 667.125199][ T9805] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 [ 667.125207][ T9805] [ 667.125210][ T9805] [ 667.145632][ T9805] Allocated by task 9805: [ 667.145991][ T9805] kasan_save_stack+0x20/0x40 [ 667.146352][ T9805] kasan_save_track+0x14/0x30 [ 667.146717][ T9805] __kasan_kmalloc+0xaa/0xb0 [ 667.147065][ T9805] __kmalloc_noprof+0x205/0x550 [ 667.147448][ T9805] hfsplus_find_init+0x95/0x1f0 [ 667.147813][ T9805] hfsplus_readdir+0x220/0xfc0 [ 667.148174][ T9805] iterate_dir+0x296/0xb20 [ 667.148549][ T9805] __x64_sys_getdents64+0x13c/0x2c0 [ 667.148937][ T9805] do_syscall_64+0xc9/0x480 [ 667.149291][ T9805] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 667.149809][ T9805] [ 667.150030][ T9805] The buggy address belongs to the object at ffff88802592f000 [ 667.150030][ T9805] which belongs to the cache kmalloc-2k of size 2048 [ 667.151282][ T9805] The buggy address is located 0 bytes to the right of [ 667.151282][ T9805] allocated 1036-byte region [ffff88802592f000, ffff88802592f40c) [ 667.1 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38713">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38714</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() The hfsplus_bnode_read() method can trigger the issue: [ 174.852007][ T9784] ================================================================== [ 174.852709][ T9784] BUG: KASAN: slab-out-of-bounds in hfsplus_bnode_read+0x2f4/0x360 [ 174.853412][ T9784] Read of size 8 at addr ffff88810b5fc6c0 by task repro/9784 [ 174.854059][ T9784] [ 174.854272][ T9784] CPU: 1 UID: 0 PID: 9784 Comm: repro Not tainted 6.16.0-rc3 #7 PREEMPT(full) [ 174.854281][ T9784] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 174.854286][ T9784] Call Trace: [ 174.854289][ T9784] [ 174.854292][ T9784] dump_stack_lvl+0x10e/0x1f0 [ 174.854305][ T9784] print_report+0xd0/0x660 [ 174.854315][ T9784] ? __virt_addr_valid+0x81/0x610 [ 174.854323][ T9784] ? __phys_addr+0xe8/0x180 [ 174.854330][ T9784] ? hfsplus_bnode_read+0x2f4/0x360 [ 174.854337][ T9784] kasan_report+0xc6/0x100 [ 174.854346][ T9784] ? hfsplus_bnode_read+0x2f4/0x360 [ 174.854354][ T9784] hfsplus_bnode_read+0x2f4/0x360 [ 174.854362][ T9784] hfsplus_bnode_dump+0x2ec/0x380 [ 174.854370][ T9784] ? __pfx_hfsplus_bnode_dump+0x10/0x10 [ 174.854377][ T9784] ? hfsplus_bnode_write_u16+0x83/0xb0 [ 174.854385][ T9784] ? srcu_gp_start+0xd0/0x310 [ 174.854393][ T9784] ? __mark_inode_dirty+0x29e/0xe40 [ 174.854402][ T9784] hfsplus_brec_remove+0x3d2/0x4e0 [ 174.854411][ T9784] __hfsplus_delete_attr+0x290/0x3a0 [ 174.854419][ T9784] ? __pfx_hfs_find_1st_rec_by_cnid+0x10/0x10 [ 174.854427][ T9784] ? __pfx___hfsplus_delete_attr+0x10/0x10 [ 174.854436][ T9784] ? __asan_memset+0x23/0x50 [ 174.854450][ T9784] hfsplus_delete_all_attrs+0x262/0x320 [ 174.854459][ T9784] ? __pfx_hfsplus_delete_all_attrs+0x10/0x10 [ 174.854469][ T9784] ? rcu_is_watching+0x12/0xc0 [ 174.854476][ T9784] ? __mark_inode_dirty+0x29e/0xe40 [ 174.854483][ T9784] hfsplus_delete_cat+0x845/0xde0 [ 174.854493][ T9784] ? __pfx_hfsplus_delete_cat+0x10/0x10 [ 174.854507][ T9784] hfsplus_unlink+0x1ca/0x7c0 [ 174.854516][ T9784] ? __pfx_hfsplus_unlink+0x10/0x10 [ 174.854525][ T9784] ? down_write+0x148/0x200 [ 174.854532][ T9784] ? __pfx_down_write+0x10/0x10 [ 174.854540][ T9784] vfs_unlink+0x2fe/0x9b0 [ 174.854549][ T9784] do_unlinkat+0x490/0x670 [ 174.854557][ T9784] ? __pfx_do_unlinkat+0x10/0x10 [ 174.854565][ T9784] ? __might_fault+0xbc/0x130 [ 174.854576][ T9784] ? getname_flags.part.0+0x1c5/0x550 [ 174.854584][ T9784] __x64_sys_unlink+0xc5/0x110 [ 174.854592][ T9784] do_syscall_64+0xc9/0x480 [ 174.854600][ T9784] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 174.854608][ T9784] RIP: 0033:0x7f6fdf4c3167 [ 174.854614][ T9784] Code: f0 ff ff 73 01 c3 48 8b 0d 26 0d 0e 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 08 [ 174.854622][ T9784] RSP: 002b:00007ffcb948bca8 EFLAGS: 00000206 ORIG_RAX: 0000000000000057 [ 174.854630][ T9784] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f6fdf4c3167 [ 174.854636][ T9784] RDX: 00007ffcb948bcc0 RSI: 00007ffcb948bcc0 RDI: 00007ffcb948bd50 [ 174.854641][ T9784] RBP: 00007ffcb948cd90 R08: 0000000000000001 R09: 00007ffcb948bb40 [ 174.854645][ T9784] R10: 00007f6fdf564fc0 R11: 0000000000000206 R12: 0000561e1bc9c2d0 [ 174.854650][ T9784] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 [ 174.854658][ T9784] [ 174.854661][ T9784] [ 174.879281][ T9784] Allocated by task 9784: [ 174.879664][ T9784] kasan_save_stack+0x20/0x40 [ 174.880082][ T9784] kasan_save_track+0x14/0x30 [ 174.880500][ T9784] __kasan_kmalloc+0xaa/0xb0 [ 174.880908][ T9784] __kmalloc_noprof+0x205/0x550 [ 174.881337][ T9784] __hfs_bnode_create+0x107/0x890 [ 174.881779][ T9784] hfsplus_bnode_find+0x2d0/0xd10 [ 174.882222][ T9784] hfsplus_brec_find+0x2b0/0x520 [ 174.882659][ T9784] hfsplus_delete_all_attrs+0x23b/0x3 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38714">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38715</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: hfs: fix slab-out-of-bounds in hfs_bnode_read() This patch introduces is_bnode_offset_valid() method that checks the requested offset value. Also, it introduces check_and_correct_requested_length() method that checks and correct the requested length (if it is necessary). These methods are used in hfs_bnode_read(), hfs_bnode_write(), hfs_bnode_clear(), hfs_bnode_copy(), and hfs_bnode_move() with the goal to prevent the access out of allocated memory and triggering the crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38715">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38721</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix refcount leak on table dump There is a reference count leak in ctnetlink_dump_table(): if (res &lt; 0) { nf_conntrack_get(&amp;ct-&gt;ct_general); // HERE cb-&gt;args[1] = (unsigned long)ct; ... While its very unlikely, its possible that ct == last. If this happens, then the refcount of ct was already incremented. This 2nd increment is never undone. This prevents the conntrack object from being released, which in turn keeps prevents cnet-&gt;count from dropping back to 0. This will then block the netns dismantle (or conntrack rmmod) as nf_conntrack_cleanup_net_list() will wait forever. This can be reproduced by running conntrack_resize.sh selftest in a loop. It takes ~20 minutes for me on a preemptible kernel on average before I see a runaway kworker spinning in nf_conntrack_cleanup_net_list. One fix would to change this to: if (res &lt; 0) { if (ct != last) nf_conntrack_get(&amp;ct-&gt;ct_general); But this reference counting isn't needed in the first place. We can just store a cookie value instead. A followup patch will do the same for ctnetlink_exp_dump_table, it looks to me as if this has the same problem and like ctnetlink_dump_table, we only need a 'skip hint', not the actual object so we can apply the same cookie strategy there as well.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38721">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38723</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix jump offset calculation in tailcall The extra pass of bpf_int_jit_compile() skips JIT context initialization which essentially skips offset calculation leaving out_offset = -1, so the jmp_offset in emit_bpf_tail_call is calculated by "#define jmp_offset (out_offset - (cur_offset))" is a negative number, which is wrong. The final generated assembly are as follow. 54: bgeu $a2, $t1, -8 # 0x0000004c 58: addi.d $a6, $s5, -1 5c: bltz $a6, -16 # 0x0000004c 60: alsl.d $t2, $a2, $a1, 0x3 64: ld.d $t2, $t2, 264 68: beq $t2, $zero, -28 # 0x0000004c Before apply this patch, the follow test case will reveal soft lock issues. cd tools/testing/selftests/bpf/ ./test_progs --allow=tailcalls/tailcall_bpf2bpf_1 dmesg: watchdog: BUG: soft lockup - CPU#2 stuck for 26s! [test_progs:25056]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38723">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38724</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client expiring and fail to get a reference. That could later lead to a UAF. Fix this by getting a reference early in the case where there is an extant confirmed client. If that fails then treat it as if there were no confirmed client found at all. In the case where the unconfirmed client is expiring, just fail and return the result from get_client_locked().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38724">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38725</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phy_polling_mode() in phy_state_machine() will directly deference member of phydev-&gt;drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phy_mask for ax88772 mdio bus to workarnoud the issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38725">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38727</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netlink: avoid infinite retry looping in netlink_unicast() netlink_attachskb() checks for the socket's read memory allocation constraints. Firstly, it has: rmem &lt; READ_ONCE(sk-&gt;sk_rcvbuf) to check if the just increased rmem value fits into the socket's receive buffer. If not, it proceeds and tries to wait for the memory under: rmem + skb-&gt;truesize &gt; READ_ONCE(sk-&gt;sk_rcvbuf) The checks don't cover the case when skb-&gt;truesize + sk-&gt;sk_rmem_alloc is equal to sk-&gt;sk_rcvbuf. Thus the function neither successfully accepts these conditions, nor manages to reschedule the task - and is called in retry loop for indefinite time which is caught as: rcu: INFO: rcu_sched self-detected stall on CPU rcu: 0-....: (25999 ticks this GP) idle=ef2/1/0x4000000000000000 softirq=262269/262269 fqs=6212 (t=26000 jiffies g=230833 q=259957) NMI backtrace for cpu 0 CPU: 0 PID: 22 Comm: kauditd Not tainted 5.10.240 #68 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc42 04/01/2014 Call Trace: dump_stack lib/dump_stack.c:120 nmi_cpu_backtrace.cold lib/nmi_backtrace.c:105 nmi_trigger_cpumask_backtrace lib/nmi_backtrace.c:62 rcu_dump_cpu_stacks kernel/rcu/tree_stall.h:335 rcu_sched_clock_irq.cold kernel/rcu/tree.c:2590 update_process_times kernel/time/timer.c:1953 tick_sched_handle kernel/time/tick-sched.c:227 tick_sched_timer kernel/time/tick-sched.c:1399 __hrtimer_run_queues kernel/time/hrtimer.c:1652 hrtimer_interrupt kernel/time/hrtimer.c:1717 __sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1113 asm_call_irq_on_stack arch/x86/entry/entry_64.S:808 netlink_attachskb net/netlink/af_netlink.c:1234 netlink_unicast net/netlink/af_netlink.c:1349 kauditd_send_queue kernel/audit.c:776 kauditd_thread kernel/audit.c:897 kthread kernel/kthread.c:328 ret_from_fork arch/x86/entry/entry_64.S:304 Restore the original behavior of the check which commit in Fixes accidentally missed when restructuring the code. Found by Linux Verification Center (linuxtesting.org).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38727">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38728</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb3: fix for slab out of bounds on mount to ksmbd With KASAN enabled, it is possible to get a slab out of bounds during mount to ksmbd due to missing check in parse_server_interfaces() (see below): BUG: KASAN: slab-out-of-bounds in parse_server_interfaces+0x14ee/0x1880 [cifs] Read of size 4 at addr ffff8881433dba98 by task mount/9827 CPU: 5 UID: 0 PID: 9827 Comm: mount Tainted: G OE 6.16.0-rc2-kasan #2 PREEMPT(voluntary) Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: Dell Inc. Precision Tower 3620/0MWYPT, BIOS 2.13.1 06/14/2019 Call Trace: dump_stack_lvl+0x9f/0xf0 print_report+0xd1/0x670 __virt_addr_valid+0x22c/0x430 ? parse_server_interfaces+0x14ee/0x1880 [cifs] ? kasan_complete_mode_report_info+0x2a/0x1f0 ? parse_server_interfaces+0x14ee/0x1880 [cifs] kasan_report+0xd6/0x110 parse_server_interfaces+0x14ee/0x1880 [cifs] __asan_report_load_n_noabort+0x13/0x20 parse_server_interfaces+0x14ee/0x1880 [cifs] ? __pfx_parse_server_interfaces+0x10/0x10 [cifs] ? trace_hardirqs_on+0x51/0x60 SMB3_request_interfaces+0x1ad/0x3f0 [cifs] ? __pfx_SMB3_request_interfaces+0x10/0x10 [cifs] ? SMB2_tcon+0x23c/0x15d0 [cifs] smb3_qfs_tcon+0x173/0x2b0 [cifs] ? __pfx_smb3_qfs_tcon+0x10/0x10 [cifs] ? cifs_get_tcon+0x105d/0x2120 [cifs] ? do_raw_spin_unlock+0x5d/0x200 ? cifs_get_tcon+0x105d/0x2120 [cifs] ? __pfx_smb3_qfs_tcon+0x10/0x10 [cifs] cifs_mount_get_tcon+0x369/0xb90 [cifs] ? dfs_cache_find+0xe7/0x150 [cifs] dfs_mount_share+0x985/0x2970 [cifs] ? check_path.constprop.0+0x28/0x50 ? save_trace+0x54/0x370 ? __pfx_dfs_mount_share+0x10/0x10 [cifs] ? __lock_acquire+0xb82/0x2ba0 ? __kasan_check_write+0x18/0x20 cifs_mount+0xbc/0x9e0 [cifs] ? __pfx_cifs_mount+0x10/0x10 [cifs] ? do_raw_spin_unlock+0x5d/0x200 ? cifs_setup_cifs_sb+0x29d/0x810 [cifs] cifs_smb3_do_mount+0x263/0x1990 [cifs]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38728">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38729</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38729">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38732</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for loopback packets recent patches to add a WARN() when replacing skb dst entry found an old bug: WARNING: include/linux/skbuff.h:1165 skb_dst_check_unset include/linux/skbuff.h:1164 [inline] WARNING: include/linux/skbuff.h:1165 skb_dst_set include/linux/skbuff.h:1210 [inline] WARNING: include/linux/skbuff.h:1165 nf_reject_fill_skb_dst+0x2a4/0x330 net/ipv4/netfilter/nf_reject_ipv4.c:234 [..] Call Trace: nf_send_unreach+0x17b/0x6e0 net/ipv4/netfilter/nf_reject_ipv4.c:325 nft_reject_inet_eval+0x4bc/0x690 net/netfilter/nft_reject_inet.c:27 expr_call_ops_eval net/netfilter/nf_tables_core.c:237 [inline] .. This is because blamed commit forgot about loopback packets. Such packets already have a dst_entry attached, even at PRE_ROUTING stage. Instead of checking hook just check if the skb already has a route attached to it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38732">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38735</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: gve: prevent ethtool ops after shutdown A crash can occur if an ethtool operation is invoked after shutdown() is called. shutdown() is invoked during system shutdown to stop DMA operations without performing expensive deallocations. It is discouraged to unregister the netdev in this path, so the device may still be visible to userspace and kernel helpers. In gve, shutdown() tears down most internal data structures. If an ethtool operation is dispatched after shutdown(), it will dereference freed or NULL pointers, leading to a kernel panic. While graceful shutdown normally quiesces userspace before invoking the reboot syscall, forced shutdowns (as observed on GCP VMs) can still trigger this path. Fix by calling netif_device_detach() in shutdown(). This marks the device as detached so the ethtool ioctl handler will skip dispatching operations to the driver.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38735">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/664.html">CWE-664 Improper Control of a Resource Through its Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38736</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization Syzbot reported shift-out-of-bounds exception on MDIO bus initialization. The PHY address should be masked to 5 bits (0-31). Without this mask, invalid PHY addresses could be used, potentially causing issues with MDIO bus operations. Fix this by masking the PHY address with 0x1f (31 decimal) to ensure it stays within the valid range.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38736">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39673</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp_fill_forward_path ppp_fill_forward_path() has two race conditions: 1. The ppp-&gt;channels list can change between list_empty() and list_first_entry(), as ppp_lock() is not held. If the only channel is deleted in ppp_disconnect_channel(), list_first_entry() may access an empty head or a freed entry, and trigger a panic. 2. pch-&gt;chan can be NULL. When ppp_unregister_channel() is called, pch-&gt;chan is set to NULL before pch is removed from ppp-&gt;channels. Fix these by using a lockless RCU approach: - Use list_first_or_null_rcu() to safely test and access the first list entry. - Convert list modifications on ppp-&gt;channels to their RCU variants and add synchronize_net() after removal. - Check for a NULL pch-&gt;chan before dereferencing it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39673">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39675</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session() The function mod_hdcp_hdcp1_create_session() calls the function get_first_active_display(), but does not check its return value. The return value is a null pointer if the display list is empty. This will lead to a null pointer dereference. Add a null pointer check for get_first_active_display() and return MOD_HDCP_STATUS_DISPLAY_NOT_FOUND if the function return null. This is similar to the commit c3e9826a2202 ("drm/amd/display: Add null pointer check for get_first_active_display()"). (cherry picked from commit 5e43eb3cd731649c4f8b9134f857be62a416c893)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39675">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39676</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: qla4xxx: Prevent a potential error pointer dereference The qla4xxx_get_ep_fwdb() function is supposed to return NULL on error, but qla4xxx_ep_connect() returns error pointers. Propagating the error pointers will lead to an Oops in the caller, so change the error pointers to NULL.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39676">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/394.html">CWE-394 Unexpected Status Code or Return Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39681</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper Since 923f3a2b48bd ("x86/resctrl: Query LLC monitoring properties once during boot") resctrl_cpu_detect() has been moved from common CPU initialization code to the vendor-specific BSP init helper, while Hygon didn't put that call in their code. This triggers a division by zero fault during early booting stage on our machines with X86_FEATURE_CQM* supported, where get_rdt_mon_resources() tries to calculate mon_l3_config with uninitialized boot_cpu_data.x86_cache_occ_scale. Add the missing resctrl_cpu_detect() in the Hygon BSP init helper. [ bp: Massage commit message. ]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39681">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/369.html">CWE-369 Divide By Zero</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39682</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted (which may be the case for TLS 1.3 where we don't know type until decryption) we queue the pending record to the rx_list. Next recvmsg() will pick it up from there. Queuing the skb to rx_list after zero-copy decrypt is not possible, since in that case we decrypted directly to the user space buffer, and we don't have an skb to queue (darg.skb points to the ciphertext skb for access to metadata like length). Only data records are allowed zero-copy, and we break the processing loop after each non-data record. So we should never zero-copy and then find out that the record type has changed. The corner case we missed is when the initial record comes from rx_list, and it's zero length.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39682">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39683</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tracing: Limit access to parser-&gt;buffer when trace_get_user failed When the length of the string written to set_ftrace_filter exceeds FTRACE_BUFF_MAX, the following KASAN alarm will be triggered: BUG: KASAN: slab-out-of-bounds in strsep+0x18c/0x1b0 Read of size 1 at addr ffff0000d00bd5ba by task ash/165 CPU: 1 UID: 0 PID: 165 Comm: ash Not tainted 6.16.0-g6bcdbd62bd56-dirty Hardware name: linux,dummy-virt (DT) Call trace: show_stack+0x34/0x50 (C) dump_stack_lvl+0xa0/0x158 print_address_description.constprop.0+0x88/0x398 print_report+0xb0/0x280 kasan_report+0xa4/0xf0 __asan_report_load1_noabort+0x20/0x30 strsep+0x18c/0x1b0 ftrace_process_regex.isra.0+0x100/0x2d8 ftrace_regex_release+0x484/0x618 __fput+0x364/0xa58 ____fput+0x28/0x40 task_work_run+0x154/0x278 do_notify_resume+0x1f0/0x220 el0_svc+0xec/0xf0 el0t_64_sync_handler+0xa0/0xe8 el0t_64_sync+0x1ac/0x1b0 The reason is that trace_get_user will fail when processing a string longer than FTRACE_BUFF_MAX, but not set the end of parser-&gt;buffer to 0. Then an OOB access will be triggered in ftrace_regex_release-&gt; ftrace_process_regex-&gt;strsep-&gt;strpbrk. We can solve this problem by limiting access to parser-&gt;buffer when trace_get_user failed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39683">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39684</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl() syzbot reports a KMSAN kernel-infoleak in `do_insn_ioctl()`. A kernel buffer is allocated to hold `insn-&gt;n` samples (each of which is an `unsigned int`). For some instruction types, `insn-&gt;n` samples are copied back to user-space, unless an error code is being returned. The problem is that not all the instruction handlers that need to return data to userspace fill in the whole `insn-&gt;n` samples, so that there is an information leak. There is a similar syzbot report for `do_insnlist_ioctl()`, although it does not have a reproducer for it at the time of writing. One culprit is `insn_rw_emulate_bits()` which is used as the handler for `INSN_READ` or `INSN_WRITE` instructions for subdevices that do not have a specific handler for that instruction, but do have an `INSN_BITS` handler. For `INSN_READ` it only fills in at most 1 sample, so if `insn-&gt;n` is greater than 1, the remaining `insn-&gt;n - 1` samples copied to userspace will be uninitialized kernel data. Another culprit is `vm80xx_ai_insn_read()` in the "vm80xx" driver. It never returns an error, even if it fails to fill the buffer. Fix it in `do_insn_ioctl()` and `do_insnlist_ioctl()` by making sure that uninitialized parts of the allocated buffer are zeroed before handling each instruction. Thanks to Arnaud Lecomte for their fix to `do_insn_ioctl()`. That fix replaced the call to `kmalloc_array()` with `kcalloc()`, but it is not always necessary to clear the whole buffer.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39684">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39685</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: comedi: pcl726: Prevent invalid irq number The reproducer passed in an irq number(0x80008000) that was too large, which triggered the oob. Added an interrupt number check to prevent users from passing in an irq number that was too large. If `it-&gt;options[1]` is 31, then `1 &lt;&lt; it-&gt;options[1]` is still invalid because it shifts a 1-bit into the sign bit (which is UB in C). Possible solutions include reducing the upper bound on the `it-&gt;options[1]` value to 30 or lower, or using `1U &lt;&lt; it-&gt;options[1]`. The old code would just not attempt to request the IRQ if the `options[1]` value were invalid. And it would still configure the device without interrupts even if the call to `request_irq` returned an error. So it would be better to combine this test with the test below.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39685">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39686</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: comedi: Make insn_rw_emulate_bits() do insn-&gt;n samples The `insn_rw_emulate_bits()` function is used as a default handler for `INSN_READ` instructions for subdevices that have a handler for `INSN_BITS` but not for `INSN_READ`. Similarly, it is used as a default handler for `INSN_WRITE` instructions for subdevices that have a handler for `INSN_BITS` but not for `INSN_WRITE`. It works by emulating the `INSN_READ` or `INSN_WRITE` instruction handling with a constructed `INSN_BITS` instruction. However, `INSN_READ` and `INSN_WRITE` instructions are supposed to be able read or write multiple samples, indicated by the `insn-&gt;n` value, but `insn_rw_emulate_bits()` currently only handles a single sample. For `INSN_READ`, the comedi core will copy `insn-&gt;n` samples back to user-space. (That triggered KASAN kernel-infoleak errors when `insn-&gt;n` was greater than 1, but that is being fixed more generally elsewhere in the comedi core.) Make `insn_rw_emulate_bits()` either handle `insn-&gt;n` samples, or return an error, to conform to the general expectation for `INSN_READ` and `INSN_WRITE` handlers.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39686">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39687</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: iio: light: as73211: Ensure buffer holes are zeroed Given that the buffer is copied to a kfifo that ultimately user space can read, ensure we zero it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39687">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39689</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ftrace: Also allocate and copy hash for reading of filter files Currently the reader of set_ftrace_filter and set_ftrace_notrace just adds the pointer to the global tracer hash to its iterator. Unlike the writer that allocates a copy of the hash, the reader keeps the pointer to the filter hashes. This is problematic because this pointer is static across function calls that release the locks that can update the global tracer hashes. This can cause UAF and similar bugs. Allocate and copy the hash for reading the filter files like it is done for the writers. This not only fixes UAF bugs, but also makes the code a bit simpler as it doesn't have to differentiate when to free the iterator's hash between writers and readers.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39689">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39691</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() helper There's issue as follows: BUG: KASAN: stack-out-of-bounds in end_buffer_read_sync+0xe3/0x110 Read of size 8 at addr ffffc9000168f7f8 by task swapper/3/0 CPU: 3 UID: 0 PID: 0 Comm: swapper/3 Not tainted 6.16.0-862.14.0.6.x86_64 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: dump_stack_lvl+0x55/0x70 print_address_description.constprop.0+0x2c/0x390 print_report+0xb4/0x270 kasan_report+0xb8/0xf0 end_buffer_read_sync+0xe3/0x110 end_bio_bh_io_sync+0x56/0x80 blk_update_request+0x30a/0x720 scsi_end_request+0x51/0x2b0 scsi_io_completion+0xe3/0x480 ? scsi_device_unbusy+0x11e/0x160 blk_complete_reqs+0x7b/0x90 handle_softirqs+0xef/0x370 irq_exit_rcu+0xa5/0xd0 sysvec_apic_timer_interrupt+0x6e/0x90 Above issue happens when do ntfs3 filesystem mount, issue may happens as follows: mount IRQ ntfs_fill_super read_cache_page do_read_cache_folio filemap_read_folio mpage_read_folio do_mpage_readpage ntfs_get_block_vbo bh_read submit_bh wait_on_buffer(bh); blk_complete_reqs scsi_io_completion scsi_end_request blk_update_request end_bio_bh_io_sync end_buffer_read_sync __end_buffer_read_notouch unlock_buffer wait_on_buffer(bh);--&gt; return will return to caller put_bh --&gt; trigger stack-out-of-bounds In the mpage_read_folio() function, the stack variable 'map_bh' is passed to ntfs_get_block_vbo(). Once unlock_buffer() unlocks and wait_on_buffer() returns to continue processing, the stack variable is likely to be reclaimed. Consequently, during the end_buffer_read_sync() process, calling put_bh() may result in stack overrun. If the bh is not allocated on the stack, it belongs to a folio. Freeing a buffer head which belongs to a folio is done by drop_buffers() which will fail to free buffers which are still locked. So it is safe to call put_bh() before __end_buffer_read_notouch().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39691">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39692</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: server: split ksmbd_rdma_stop_listening() out of ksmbd_rdma_destroy() We can't call destroy_workqueue(smb_direct_wq); before stop_sessions()! Otherwise already existing connections try to use smb_direct_wq as a NULL pointer.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39692">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39693</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid a NULL pointer dereference [WHY] Although unlikely drm_atomic_get_new_connector_state() or drm_atomic_get_old_connector_state() can return NULL. [HOW] Check returns before dereference. (cherry picked from commit 1e5e8d672fec9f2ab352be121be971877bff2af9)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39693">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39694</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Fix SCCB present check Tracing code called by the SCLP interrupt handler contains early exits if the SCCB address associated with an interrupt is NULL. This check is performed after physical to virtual address translation. If the kernel identity mapping does not start at address zero, the resulting virtual address is never zero, so that the NULL checks won't work. Subsequently this may result in incorrect accesses to the first page of the identity mapping. Fix this by introducing a function that handles the NULL case before address translation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39694">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1285.html">CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39697</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a race when updating an existing write After nfs_lock_and_join_requests() tests for whether the request is still attached to the mapping, nothing prevents a call to nfs_inode_remove_request() from succeeding until we actually lock the page group. The reason is that whoever called nfs_inode_remove_request() doesn't necessarily have a lock on the page group head. So in order to avoid races, let's take the page group lock earlier in nfs_lock_and_join_requests(), and hold it across the removal of the request in nfs_inode_remove_request().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39697">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39701</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version check The security-version-number check should be used rather than the runtime version check for driver updates. Otherwise, the firmware update would fail when the update binary had a lower runtime version number than the current one. [ rjw: Changelog edits ]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39701">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1025.html">CWE-1025 Comparison Using Wrong Factors</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39702</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39702">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/208.html">CWE-208 Observable Timing Discrepancy</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39703</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net, hsr: reject HSR frame if skb can't hold tag Receiving HSR frame with insufficient space to hold HSR tag in the skb can result in a crash (kernel BUG): [ 45.390915] skbuff: skb_under_panic: text:ffffffff86f32cac len:26 put:14 head:ffff888042418000 data:ffff888042417ff4 tail:0xe end:0x180 dev:bridge_slave_1 [ 45.392559] ------------[ cut here ]------------ [ 45.392912] kernel BUG at net/core/skbuff.c:211! [ 45.393276] Oops: invalid opcode: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI [ 45.393809] CPU: 1 UID: 0 PID: 2496 Comm: reproducer Not tainted 6.15.0 #12 PREEMPT(undef) [ 45.394433] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 45.395273] RIP: 0010:skb_panic+0x15b/0x1d0 [ 45.402911] Call Trace: [ 45.403105] [ 45.404470] skb_push+0xcd/0xf0 [ 45.404726] br_dev_queue_push_xmit+0x7c/0x6c0 [ 45.406513] br_forward_finish+0x128/0x260 [ 45.408483] __br_forward+0x42d/0x590 [ 45.409464] maybe_deliver+0x2eb/0x420 [ 45.409763] br_flood+0x174/0x4a0 [ 45.410030] br_handle_frame_finish+0xc7c/0x1bc0 [ 45.411618] br_handle_frame+0xac3/0x1230 [ 45.413674] __netif_receive_skb_core.constprop.0+0x808/0x3df0 [ 45.422966] __netif_receive_skb_one_core+0xb4/0x1f0 [ 45.424478] __netif_receive_skb+0x22/0x170 [ 45.424806] process_backlog+0x242/0x6d0 [ 45.425116] __napi_poll+0xbb/0x630 [ 45.425394] net_rx_action+0x4d1/0xcc0 [ 45.427613] handle_softirqs+0x1a4/0x580 [ 45.427926] do_softirq+0x74/0x90 [ 45.428196] This issue was found by syzkaller. The panic happens in br_dev_queue_push_xmit() once it receives a corrupted skb with ETH header already pushed in linear data. When it attempts the skb_push() call, there's not enough headroom and skb_push() panics. The corrupted skb is put on the queue by HSR layer, which makes a sequence of unintended transformations when it receives a specific corrupted HSR frame (with incomplete TAG). Fix it by dropping and consuming frames that are not long enough to contain both ethernet and hsr headers. Alternative fix would be to check for enough headroom before skb_push() in br_dev_queue_push_xmit(). In the reproducer, this is injected via AF_PACKET, but I don't easily see why it couldn't be sent over the wire from adjacent network. Further Details: In the reproducer, the following network interface chain is set up: ┌────────────────┐ ┌────────────────┐ │ veth0_to_hsr ├───┤ hsr_slave0 ┼───┐ └────────────────┘ └────────────────┘ │ │ ┌──────┐ ├─┤ hsr0 ├───┐ │ └──────┘ │ ┌────────────────┐ ┌────────────────┐ │ │┌────────┐ │ veth1_to_hsr ┼───┤ hsr_slave1 ├───┘ └┤ │ └────────────────┘ └────────────────┘ ┌┼ bridge │ ││ │ │└────────┘ │ ┌───────┐ │ │ ... ├──────┘ └───────┘ To trigger the events leading up to crash, reproducer sends a corrupted HSR fr ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39703">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1286.html">CWE-1286 Improper Validation of Syntactic Correctness of Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39706</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Destroy KFD debugfs after destroy KFD wq Since KFD proc content was moved to kernel debugfs, we can't destroy KFD debugfs before kfd_process_destroy_wq. Move kfd_process_destroy_wq prior to kfd_debugfs_fini to fix a kernel NULL pointer problem. It happens when /sys/kernel/debug/kfd was already destroyed in kfd_debugfs_fini but kfd_process_destroy_wq calls kfd_debugfs_remove_process. This line debugfs_remove_recursive(entry-&gt;proc_dentry); tries to remove /sys/kernel/debug/kfd/proc/ while /sys/kernel/debug/kfd is already gone. It hangs the kernel by kernel NULL pointer. (cherry picked from commit 0333052d90683d88531558dcfdbf2525cc37c233)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39706">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39709</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: venus: protect against spurious interrupts during probe Make sure the interrupt handler is initialized before the interrupt is registered. If the IRQ is registered before hfi_create(), it's possible that an interrupt fires before the handler setup is complete, leading to a NULL dereference. This error condition has been observed during system boot on Rb3Gen2.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39709">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39710</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: venus: Add a check for packet size after reading from shared memory Add a check to ensure that the packet size does not exceed the number of available words after reading the packet header from shared memory. This ensures that the size provided by the firmware is safe to process and prevent potential out-of-bounds memory access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39710">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39713</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() In the interrupt handler rain_interrupt(), the buffer full check on rain-&gt;buf_len is performed before acquiring rain-&gt;buf_lock. This creates a Time-of-Check to Time-of-Use (TOCTOU) race condition, as rain-&gt;buf_len is concurrently accessed and modified in the work handler rain_irq_work_handler() under the same lock. Multiple interrupt invocations can race, with each reading buf_len before it becomes full and then proceeding. This can lead to both interrupts attempting to write to the buffer, incrementing buf_len beyond its capacity (DATA_SIZE) and causing a buffer overflow. Fix this bug by moving the spin_lock() to before the buffer full check. This ensures that the check and the subsequent buffer modification are performed atomically, preventing the race condition. An corresponding spin_unlock() is added to the overflow path to correctly release the lock. This possible bug was found by an experimental static analysis tool developed by our team.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39713">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39714</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Lock resolution while streaming When an program is streaming (ffplay) and another program (qv4l2) changes the TV standard from NTSC to PAL, the kernel crashes due to trying to copy to unmapped memory. Changing from NTSC to PAL increases the resolution in the usbtv struct, but the video plane buffer isn't adjusted, so it overflows. [hverkuil: call vb2_is_busy instead of vb2_is_streaming]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39714">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39715</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: parisc: Revise gateway LWS calls to probe user read access We use load and stbys,e instructions to trigger memory reference interruptions without writing to memory. Because of the way read access support is implemented, read access interruptions are only triggered at privilege levels 2 and 3. The kernel and gateway page execute at privilege level 0, so this code never triggers a read access interruption. Thus, it is currently possible for user code to execute a LWS compare and swap operation at an address that is read protected at privilege level 3 (PRIV_USER). Fix this by probing read access rights at privilege level 3 and branching to lws_fault if access isn't allowed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39715">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39716</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: parisc: Revise __get_user() to probe user read access Because of the way read access support is implemented, read access interruptions are only triggered at privilege levels 2 and 3. The kernel executes at privilege level 0, so __get_user() never triggers a read access interruption (code 26). Thus, it is currently possible for user code to access a read protected address via a system call. Fix this by probing read access rights at privilege level 3 (PRIV_USER) and setting __gu_err to -EFAULT (-14) if access isn't allowed. Note the cmpiclr instruction does a 32-bit compare because COND macro doesn't work inside asm.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39716">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39718</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header before skb_put() When receiving a vsock packet in the guest, only the virtqueue buffer size is validated prior to virtio_vsock_skb_rx_put(). Unfortunately, virtio_vsock_skb_rx_put() uses the length from the packet header as the length argument to skb_put(), potentially resulting in SKB overflow if the host has gone wonky. Validate the length as advertised by the packet header before calling virtio_vsock_skb_rx_put().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39718">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39719</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: iio: imu: bno055: fix OOB access of hw_xlate array Fix a potential out-of-bounds array access of the hw_xlate array in bno055.c. In bno055_get_regmask(), hw_xlate was iterated over the length of the vals array instead of the length of the hw_xlate array. In the case of bno055_gyr_scale, the vals array is larger than the hw_xlate array, so this could result in an out-of-bounds access. In practice, this shouldn't happen though because a match should always be found which breaks out of the for loop before it iterates beyond the end of the hw_xlate array. By adding a new hw_xlate_len field to the bno055_sysfs_attr, we can be sure we are iterating over the correct length.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39719">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39724</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to PSLVERR When the PSLVERR_RESP_EN parameter is set to 1, the device generates an error response if an attempt is made to read an empty RBR (Receive Buffer Register) while the FIFO is enabled. In serial8250_do_startup(), calling serial_port_out(port, UART_LCR, UART_LCR_WLEN8) triggers dw8250_check_lcr(), which invokes dw8250_force_idle() and serial8250_clear_and_reinit_fifos(). The latter function enables the FIFO via serial_out(p, UART_FCR, p-&gt;fcr). Execution proceeds to the serial_port_in(port, UART_RX). This satisfies the PSLVERR trigger condition. When another CPU (e.g., using printk()) is accessing the UART (UART is busy), the current CPU fails the check (value &amp; ~UART_LCR_SPAR) == (lcr &amp; ~UART_LCR_SPAR) in dw8250_check_lcr(), causing it to enter dw8250_force_idle(). Put serial_port_out(port, UART_LCR, UART_LCR_WLEN8) under the port-&gt;lock to fix this issue. Panic backtrace: [ 0.442336] Oops - unknown exception [#1] [ 0.442343] epc : dw8250_serial_in32+0x1e/0x4a [ 0.442351] ra : serial8250_do_startup+0x2c8/0x88e ... [ 0.442416] console_on_rootfs+0x26/0x70</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39724">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39736</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock When netpoll is enabled, calling pr_warn_once() while holding kmemleak_lock in mem_pool_alloc() can cause a deadlock due to lock inversion with the netconsole subsystem. This occurs because pr_warn_once() may trigger netpoll, which eventually leads to __alloc_skb() and back into kmemleak code, attempting to reacquire kmemleak_lock. This is the path for the deadlock. mem_pool_alloc() -&gt; raw_spin_lock_irqsave(&amp;kmemleak_lock, flags); -&gt; pr_warn_once() -&gt; netconsole subsystem -&gt; netpoll -&gt; __alloc_skb -&gt; __create_object -&gt; raw_spin_lock_irqsave(&amp;kmemleak_lock, flags); Fix this by setting a flag and issuing the pr_warn_once() after kmemleak_lock is released.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39736">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/833.html">CWE-833 Deadlock</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39737</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() A soft lockup warning was observed on a relative small system x86-64 system with 16 GB of memory when running a debug kernel with kmemleak enabled. watchdog: BUG: soft lockup - CPU#8 stuck for 33s! [kworker/8:1:134] The test system was running a workload with hot unplug happening in parallel. Then kemleak decided to disable itself due to its inability to allocate more kmemleak objects. The debug kernel has its CONFIG_DEBUG_KMEMLEAK_MEM_POOL_SIZE set to 40,000. The soft lockup happened in kmemleak_do_cleanup() when the existing kmemleak objects were being removed and deleted one-by-one in a loop via a workqueue. In this particular case, there are at least 40,000 objects that need to be processed and given the slowness of a debug kernel and the fact that a raw_spinlock has to be acquired and released in __delete_object(), it could take a while to properly handle all these objects. As kmemleak has been disabled in this case, the object removal and deletion process can be further optimized as locking isn't really needed. However, it is probably not worth the effort to optimize for such an edge case that should rarely happen. So the simple solution is to call cond_resched() at periodic interval in the iteration loop to avoid soft lockup.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39737">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39738</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report that balance triggered transaction abort, with the following call trace: item 85 key (594509824 169 0) itemoff 12599 itemsize 33 extent refs 1 gen 197740 flags 2 ref#0: tree block backref root 7 item 86 key (594558976 169 0) itemoff 12566 itemsize 33 extent refs 1 gen 197522 flags 2 ref#0: tree block backref root 7 ... BTRFS error (device loop0): extent item not found for insert, bytenr 594526208 num_bytes 16384 parent 449921024 root_objectid 934 owner 1 offset 0 BTRFS error (device loop0): failed to run delayed ref for logical 594526208 num_bytes 16384 type 182 action 1 ref_mod 1: -117 ------------[ cut here ]------------ BTRFS: Transaction aborted (error -117) WARNING: CPU: 1 PID: 6963 at ../fs/btrfs/extent-tree.c:2168 btrfs_run_delayed_refs+0xfa/0x110 [btrfs] And btrfs check doesn't report anything wrong related to the extent tree. [CAUSE] The cause is a little complex, firstly the extent tree indeed doesn't have the backref for 594526208. The extent tree only have the following two backrefs around that bytenr on-disk: item 65 key (594509824 METADATA_ITEM 0) itemoff 13880 itemsize 33 refs 1 gen 197740 flags TREE_BLOCK tree block skinny level 0 (176 0x7) tree block backref root CSUM_TREE item 66 key (594558976 METADATA_ITEM 0) itemoff 13847 itemsize 33 refs 1 gen 197522 flags TREE_BLOCK tree block skinny level 0 (176 0x7) tree block backref root CSUM_TREE But the such missing backref item is not an corruption on disk, as the offending delayed ref belongs to subvolume 934, and that subvolume is being dropped: item 0 key (934 ROOT_ITEM 198229) itemoff 15844 itemsize 439 generation 198229 root_dirid 256 bytenr 10741039104 byte_limit 0 bytes_used 345571328 last_snapshot 198229 flags 0x1000000000001(RDONLY) refs 0 drop_progress key (206324 EXTENT_DATA 2711650304) drop_level 2 level 2 generation_v2 198229 And that offending tree block 594526208 is inside the dropped range of that subvolume. That explains why there is no backref item for that bytenr and why btrfs check is not reporting anything wrong. But this also shows another problem, as btrfs will do all the orphan subvolume cleanup at a read-write mount. So half-dropped subvolume should not exist after an RW mount, and balance itself is also exclusive to subvolume cleanup, meaning we shouldn't hit a subvolume half-dropped during relocation. The root cause is, there is no orphan item for this subvolume. In fact there are 5 subvolumes from around 2021 that have the same problem. It looks like the original report has some older kernels running, and caused those zombie subvolumes. Thankfully upstream commit 8d488a8c7ba2 ("btrfs: fix subvolume/snapshot deletion not triggered on mount") has long fixed the bug. [ENHANCEMENT] For repairing such old fs, btrfs-progs will be enhanced. Considering how delayed the problem will show up (at run delayed ref time) and at that time we have to abort transaction already, it is too late. Instead here we reject any half-dropped subvolume for reloc tree at the earliest time, preventing confusion and extra time wasted on debugging similar bugs.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39738">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39742</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() The function divides number of online CPUs by num_core_siblings, and later checks the divider by zero. This implies a possibility to get and divide-by-zero runtime error. Fix it by moving the check prior to division. This also helps to save one indentation level.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39742">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/369.html">CWE-369 Divide By Zero</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39743</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the inode copy from the disk by the reproducer is AGGR_RESERVED_I. When executing evict, its hard link number is 0, so its inode pages are not truncated. This causes the bugon to be triggered when executing clear_inode() because nrpages is greater than 0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39743">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39749</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: rcu: Protect -&gt;defer_qs_iw_pending from data race On kernels built with CONFIG_IRQ_WORK=y, when rcu_read_unlock() is invoked within an interrupts-disabled region of code [1], it will invoke rcu_read_unlock_special(), which uses an irq-work handler to force the system to notice when the RCU read-side critical section actually ends. That end won't happen until interrupts are enabled at the soonest. In some kernels, such as those booted with rcutree.use_softirq=y, the irq-work handler is used unconditionally. The per-CPU rcu_data structure's -&gt;defer_qs_iw_pending field is updated by the irq-work handler and is both read and updated by rcu_read_unlock_special(). This resulted in the following KCSAN splat: ------------------------------------------------------------------------ BUG: KCSAN: data-race in rcu_preempt_deferred_qs_handler / rcu_read_unlock_special read to 0xffff96b95f42d8d8 of 1 bytes by task 90 on cpu 8: rcu_read_unlock_special+0x175/0x260 __rcu_read_unlock+0x92/0xa0 rt_spin_unlock+0x9b/0xc0 __local_bh_enable+0x10d/0x170 __local_bh_enable_ip+0xfb/0x150 rcu_do_batch+0x595/0xc40 rcu_cpu_kthread+0x4e9/0x830 smpboot_thread_fn+0x24d/0x3b0 kthread+0x3bd/0x410 ret_from_fork+0x35/0x40 ret_from_fork_asm+0x1a/0x30 write to 0xffff96b95f42d8d8 of 1 bytes by task 88 on cpu 8: rcu_preempt_deferred_qs_handler+0x1e/0x30 irq_work_single+0xaf/0x160 run_irq_workd+0x91/0xc0 smpboot_thread_fn+0x24d/0x3b0 kthread+0x3bd/0x410 ret_from_fork+0x35/0x40 ret_from_fork_asm+0x1a/0x30 no locks held by irq_work/8/88. irq event stamp: 200272 hardirqs last enabled at (200272): [] finish_task_switch+0x131/0x320 hardirqs last disabled at (200271): [] __schedule+0x129/0xd70 softirqs last enabled at (0): [] copy_process+0x4df/0x1cc0 softirqs last disabled at (0): [&lt;0000000000000000&gt;] 0x0 ------------------------------------------------------------------------ The problem is that irq-work handlers run with interrupts enabled, which means that rcu_preempt_deferred_qs_handler() could be interrupted, and that interrupt handler might contain an RCU read-side critical section, which might invoke rcu_read_unlock_special(). In the strict KCSAN mode of operation used by RCU, this constitutes a data race on the -&gt;defer_qs_iw_pending field. This commit therefore disables interrupts across the portion of the rcu_preempt_deferred_qs_handler() that updates the -&gt;defer_qs_iw_pending field. This suffices because this handler is not a fast path.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39749">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39752</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ARM: rockchip: fix kernel hang during smp initialization In order to bring up secondary CPUs main CPU write trampoline code to SRAM. The trampoline code is written while secondary CPUs are powered on (at least that true for RK3188 CPU). Sometimes that leads to kernel hang. Probably because secondary CPU execute trampoline code while kernel doesn't expect. The patch moves SRAM initialization step to the point where all secondary CPUs are powered down. That fixes rarely hangs on RK3188: [ 0.091568] CPU0: thread -1, cpu 0, socket 0, mpidr 80000000 [ 0.091996] rockchip_smp_prepare_cpus: ncores 4</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39752">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/364.html">CWE-364 Signal Handler Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39756</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: Prevent file descriptor table allocations exceeding INT_MAX When sysctl_nr_open is set to a very high value (for example, 1073741816 as set by systemd), processes attempting to use file descriptors near the limit can trigger massive memory allocation attempts that exceed INT_MAX, resulting in a WARNING in mm/slub.c: WARNING: CPU: 0 PID: 44 at mm/slub.c:5027 __kvmalloc_node_noprof+0x21a/0x288 This happens because kvmalloc_array() and kvmalloc() check if the requested size exceeds INT_MAX and emit a warning when the allocation is not flagged with __GFP_NOWARN. Specifically, when nr_open is set to 1073741816 (0x3ffffff8) and a process calls dup2(oldfd, 1073741880), the kernel attempts to allocate: - File descriptor array: 1073741880 * 8 bytes = 8,589,935,040 bytes - Multiple bitmaps: ~400MB - Total allocation size: &gt; 8GB (exceeding INT_MAX = 2,147,483,647) Reproducer: 1. Set /proc/sys/fs/nr_open to 1073741816: # echo 1073741816 &gt; /proc/sys/fs/nr_open 2. Run a program that uses a high file descriptor: #include #include int main() { struct rlimit rlim = {1073741824, 1073741824}; setrlimit(RLIMIT_NOFILE, &amp;rlim); dup2(2, 1073741880); // Triggers the warning return 0; } 3. Observe WARNING in dmesg at mm/slub.c:5027 systemd commit a8b627a introduced automatic bumping of fs.nr_open to the maximum possible value. The rationale was that systems with memory control groups (memcg) no longer need separate file descriptor limits since memory is properly accounted. However, this change overlooked that: 1. The kernel's allocation functions still enforce INT_MAX as a maximum size regardless of memcg accounting 2. Programs and tests that legitimately test file descriptor limits can inadvertently trigger massive allocations 3. The resulting allocations (&gt;8GB) are impractical and will always fail systemd's algorithm starts with INT_MAX and keeps halving the value until the kernel accepts it. On most systems, this results in nr_open being set to 1073741816 (0x3ffffff8), which is just under 1GB of file descriptors. While processes rarely use file descriptors near this limit in normal operation, certain selftests (like tools/testing/selftests/core/unshare_test.c) and programs that test file descriptor limits can trigger this issue. Fix this by adding a check in alloc_fdtable() to ensure the requested allocation size does not exceed INT_MAX. This causes the operation to fail with -EMFILE instead of triggering a kernel warning and avoids the impractical &gt;8GB memory allocation request.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39756">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39757</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer sizes, too. Otherwise malicious firmware may lead to the unexpected OOB accesses.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39757">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39759</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between quota disable and quota rescan ioctl There's a race between a task disabling quotas and another running the rescan ioctl that can result in a use-after-free of qgroup records from the fs_info-&gt;qgroup_tree rbtree. This happens as follows: 1) Task A enters btrfs_ioctl_quota_rescan() -&gt; btrfs_qgroup_rescan(); 2) Task B enters btrfs_quota_disable() and calls btrfs_qgroup_wait_for_completion(), which does nothing because at that point fs_info-&gt;qgroup_rescan_running is false (it wasn't set yet by task A); 3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups from fs_info-&gt;qgroup_tree without taking the lock fs_info-&gt;qgroup_lock; 4) Task A enters qgroup_rescan_zero_tracking() which starts iterating the fs_info-&gt;qgroup_tree tree while holding fs_info-&gt;qgroup_lock, but task B is freeing qgroup records from that tree without holding the lock, resulting in a use-after-free. Fix this by taking fs_info-&gt;qgroup_lock at btrfs_free_qgroup_config(). Also at btrfs_qgroup_rescan() don't start the rescan worker if quotas were already disabled.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39759">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39760</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: usb: core: config: Prevent OOB read in SS endpoint companion parsing usb_parse_ss_endpoint_companion() checks descriptor type before length, enabling a potentially odd read outside of the buffer size. Fix this up by checking the size first before looking at any of the fields in the descriptor.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39760">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39766</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit The following setup can trigger a WARNING in htb_activate due to the condition: !cl-&gt;leaf.q-&gt;q.qlen tc qdisc del dev lo root tc qdisc add dev lo root handle 1: htb default 1 tc class add dev lo parent 1: classid 1:1 \ htb rate 64bit tc qdisc add dev lo parent 1:1 handle f: \ cake memlimit 1b ping -I lo -f -c1 -s64 -W0.001 127.0.0.1 This is because the low memlimit leads to a low buffer_limit, which causes packet dropping. However, cake_enqueue still returns NET_XMIT_SUCCESS, causing htb_enqueue to call htb_activate with an empty child qdisc. We should return NET_XMIT_CN when packets are dropped from the same tin and flow. I do not believe return value of NET_XMIT_CN is necessary for packet drops in the case of ack filtering, as that is meant to optimize performance, not to signal congestion.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39766">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39770</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel incorrectly requests checksum offload if the egress device only advertises NETIF_F_IPV6_CSUM feature, which has a strict contract: it supports checksum offload only for plain TCP or UDP over IPv6 and explicitly does not support packets with extension headers. The current GSO logic violates this contract by failing to disable the feature for packets with extension headers, such as those used in GREoIPv6 tunnels. This violation results in the device being asked to perform an operation it cannot support, leading to a `skb_warn_bad_offload` warning and a collapse of network throughput. While device TSO/USO is correctly bypassed in favor of software GSO for these packets, the GSO stack must be explicitly told not to request checksum offload. Mask NETIF_F_IPV6_CSUM, NETIF_F_TSO6 and NETIF_F_GSO_UDP_L4 in gso_features_check if the IPv6 header contains extension headers to compute checksum in software. The exception is a BIG TCP extension, which, as stated in commit 68e068cabd2c6c53 ("net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets"): "The feature is only enabled on devices that support BIG TCP TSO. The header is only present for PF_PACKET taps like tcpdump, and not transmitted by physical devices." kernel log output (truncated): WARNING: CPU: 1 PID: 5273 at net/core/dev.c:3535 skb_warn_bad_offload+0x81/0x140 ... Call Trace: skb_checksum_help+0x12a/0x1f0 validate_xmit_skb+0x1a3/0x2d0 validate_xmit_skb_list+0x4f/0x80 sch_direct_xmit+0x1a2/0x380 __dev_xmit_skb+0x242/0x670 __dev_queue_xmit+0x3fc/0x7f0 ip6_finish_output2+0x25e/0x5d0 ip6_finish_output+0x1fc/0x3f0 ip6_tnl_xmit+0x608/0xc00 [ip6_tunnel] ip6gre_tunnel_xmit+0x1c0/0x390 [ip6_gre] dev_hard_start_xmit+0x63/0x1c0 __dev_queue_xmit+0x6d0/0x7f0 ip6_finish_output2+0x214/0x5d0 ip6_finish_output+0x1fc/0x3f0 ip6_xmit+0x2ca/0x6f0 ip6_finish_output+0x1fc/0x3f0 ip6_xmit+0x2ca/0x6f0 inet6_csk_xmit+0xeb/0x150 __tcp_transmit_skb+0x555/0xa80 tcp_write_xmit+0x32a/0xe90 tcp_sendmsg_locked+0x437/0x1110 tcp_sendmsg+0x2f/0x50 ... skb linear: 00000000: e4 3d 1a 7d ec 30 e4 3d 1a 7e 5d 90 86 dd 60 0e skb linear: 00000010: 00 0a 1b 34 3c 40 20 11 00 00 00 00 00 00 00 00 skb linear: 00000020: 00 00 00 00 00 12 20 11 00 00 00 00 00 00 00 00 skb linear: 00000030: 00 00 00 00 00 11 2f 00 04 01 04 01 01 00 00 00 skb linear: 00000040: 86 dd 60 0e 00 0a 1b 00 06 40 20 23 00 00 00 00 skb linear: 00000050: 00 00 00 00 00 00 00 00 00 12 20 23 00 00 00 00 skb linear: 00000060: 00 00 00 00 00 00 00 00 00 11 bf 96 14 51 13 f9 skb linear: 00000070: ae 27 a0 a8 2b e3 80 18 00 40 5b 6f 00 00 01 01 skb linear: 00000080: 08 0a 42 d4 50 d5 4b 70 f8 1a</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39770">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/573.html">CWE-573 Improper Following of Specification by Caller</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39772</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drm/hisilicon/hibmc: fix the hibmc loaded failed bug When hibmc loaded failed, the driver use hibmc_unload to free the resource, but the mutexes in mode.config are not init, which will access an NULL pointer. Just change goto statement to return, because hibnc_hw_init() doesn't need to free anything.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39772">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39773</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix soft lockup in br_multicast_query_expired() When set multicast_query_interval to a large value, the local variable 'time' in br_multicast_send_query() may overflow. If the time is smaller than jiffies, the timer will expire immediately, and then call mod_timer() again, which creates a loop and may trigger the following soft lockup issue. watchdog: BUG: soft lockup - CPU#1 stuck for 221s! [rb_consumer:66] CPU: 1 UID: 0 PID: 66 Comm: rb_consumer Not tainted 6.16.0+ #259 PREEMPT(none) Call Trace: __netdev_alloc_skb+0x2e/0x3a0 br_ip6_multicast_alloc_query+0x212/0x1b70 __br_multicast_send_query+0x376/0xac0 br_multicast_send_query+0x299/0x510 br_multicast_query_expired.constprop.0+0x16d/0x1b0 call_timer_fn+0x3b/0x2a0 __run_timers+0x619/0x950 run_timer_softirq+0x11c/0x220 handle_softirqs+0x18e/0x560 __irq_exit_rcu+0x158/0x1a0 sysvec_apic_timer_interrupt+0x76/0x90 This issue can be reproduced with: ip link add br0 type bridge echo 1 &gt; /sys/class/net/br0/bridge/multicast_querier echo 0xffffffffffffffff &gt; /sys/class/net/br0/bridge/multicast_query_interval ip link set dev br0 up The multicast_startup_query_interval can also cause this issue. Similar to the commit 99b40610956a ("net: bridge: mcast: add and enforce query interval minimum"), add check for the query interval maximum to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39773">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/667.html">CWE-667 Improper Locking</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39776</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/debug_vm_pgtable: clear page table entries at destroy_args() The mm/debug_vm_pagetable test allocates manually page table entries for the tests it runs, using also its manually allocated mm_struct. That in itself is ok, but when it exits, at destroy_args() it fails to clear those entries with the *_clear functions. The problem is that leaves stale entries. If another process allocates an mm_struct with a pgd at the same address, it may end up running into the stale entry. This is happening in practice on a debug kernel with CONFIG_DEBUG_VM_PGTABLE=y, for example this is the output with some extra debugging I added (it prints a warning trace if pgtables_bytes goes negative, in addition to the warning at check_mm() function): [ 2.539353] debug_vm_pgtable: [get_random_vaddr ]: random_vaddr is 0x7ea247140000 [ 2.539366] kmem_cache info [ 2.539374] kmem_cachep 0x000000002ce82385 - freelist 0x0000000000000000 - offset 0x508 [ 2.539447] debug_vm_pgtable: [init_args ]: args-&gt;mm is 0x000000002267cc9e (...) [ 2.552800] WARNING: CPU: 5 PID: 116 at include/linux/mm.h:2841 free_pud_range+0x8bc/0x8d0 [ 2.552816] Modules linked in: [ 2.552843] CPU: 5 UID: 0 PID: 116 Comm: modprobe Not tainted 6.12.0-105.debug_vm2.el10.ppc64le+debug #1 VOLUNTARY [ 2.552859] Hardware name: IBM,9009-41A POWER9 (architected) 0x4e0202 0xf000005 of:IBM,FW910.00 (VL910_062) hv:phyp pSeries [ 2.552872] NIP: c0000000007eef3c LR: c0000000007eef30 CTR: c0000000003d8c90 [ 2.552885] REGS: c0000000622e73b0 TRAP: 0700 Not tainted (6.12.0-105.debug_vm2.el10.ppc64le+debug) [ 2.552899] MSR: 800000000282b033 CR: 24002822 XER: 0000000a [ 2.552954] CFAR: c0000000008f03f0 IRQMASK: 0 [ 2.552954] GPR00: c0000000007eef30 c0000000622e7650 c000000002b1ac00 0000000000000001 [ 2.552954] GPR04: 0000000000000008 0000000000000000 c0000000007eef30 ffffffffffffffff [ 2.552954] GPR08: 00000000ffff00f5 0000000000000001 0000000000000048 0000000000004000 [ 2.552954] GPR12: 00000003fa440000 c000000017ffa300 c0000000051d9f80 ffffffffffffffdb [ 2.552954] GPR16: 0000000000000000 0000000000000008 000000000000000a 60000000000000e0 [ 2.552954] GPR20: 4080000000000000 c0000000113af038 00007fffcf130000 0000700000000000 [ 2.552954] GPR24: c000000062a6a000 0000000000000001 8000000062a68000 0000000000000001 [ 2.552954] GPR28: 000000000000000a c000000062ebc600 0000000000002000 c000000062ebc760 [ 2.553170] NIP [c0000000007eef3c] free_pud_range+0x8bc/0x8d0 [ 2.553185] LR [c0000000007eef30] free_pud_range+0x8b0/0x8d0 [ 2.553199] Call Trace: [ 2.553207] [c0000000622e7650] [c0000000007eef30] free_pud_range+0x8b0/0x8d0 (unreliable) [ 2.553229] [c0000000622e7750] [c0000000007f40b4] free_pgd_range+0x284/0x3b0 [ 2.553248] [c0000000622e7800] [c0000000007f4630] free_pgtables+0x450/0x570 [ 2.553274] [c0000000622e78e0] [c0000000008161c0] exit_mmap+0x250/0x650 [ 2.553292] [c0000000622e7a30] [c0000000001b95b8] __mmput+0x98/0x290 [ 2.558344] [c0000000622e7a80] [c0000000001d1018] exit_mm+0x118/0x1b0 [ 2.558361] [c0000000622e7ac0] [c0000000001d141c] do_exit+0x2ec/0x870 [ 2.558376] [c0000000622e7b60] [c0000000001d1ca8] do_group_exit+0x88/0x150 [ 2.558391] [c0000000622e7bb0] [c0000000001d1db8] sys_exit_group+0x48/0x50 [ 2.558407] [c0000000622e7be0] [c00000000003d810] system_call_exception+0x1e0/0x4c0 [ 2.558423] [c0000000622e7e50] [c00000000000d05c] system_call_vectored_common+0x15c/0x2ec (...) [ 2.558892] ---[ end trace 0000000000000000 ]--- [ 2.559022] BUG: Bad rss-counter state mm:000000002267cc9e type:MM_ANONPAGES val:1 [ 2.559037] BUG: non-zero pgtables_bytes on freeing mm: -6144 Here the modprobe process ended up with an allocated mm_struct from the mm_struct slab that was used before by the debug_vm_pgtable test. That is not a problem, since the mm_stru ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39776">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39782</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: jbd2: prevent softlockup in jbd2_log_do_checkpoint() Both jbd2_log_do_checkpoint() and jbd2_journal_shrink_checkpoint_list() periodically release j_list_lock after processing a batch of buffers to avoid long hold times on the j_list_lock. However, since both functions contend for j_list_lock, the combined time spent waiting and processing can be significant. jbd2_journal_shrink_checkpoint_list() explicitly calls cond_resched() when need_resched() is true to avoid softlockups during prolonged operations. But jbd2_log_do_checkpoint() only exits its loop when need_resched() is true, relying on potentially sleeping functions like __flush_batch() or wait_on_buffer() to trigger rescheduling. If those functions do not sleep, the kernel may hit a softlockup. watchdog: BUG: soft lockup - CPU#3 stuck for 156s! [kworker/u129:2:373] CPU: 3 PID: 373 Comm: kworker/u129:2 Kdump: loaded Not tainted 6.6.0+ #10 Hardware name: Huawei TaiShan 2280 /BC11SPCD, BIOS 1.27 06/13/2017 Workqueue: writeback wb_workfn (flush-7:2) pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : native_queued_spin_lock_slowpath+0x358/0x418 lr : jbd2_log_do_checkpoint+0x31c/0x438 [jbd2] Call trace: native_queued_spin_lock_slowpath+0x358/0x418 jbd2_log_do_checkpoint+0x31c/0x438 [jbd2] __jbd2_log_wait_for_space+0xfc/0x2f8 [jbd2] add_transaction_credits+0x3bc/0x418 [jbd2] start_this_handle+0xf8/0x560 [jbd2] jbd2__journal_start+0x118/0x228 [jbd2] __ext4_journal_start_sb+0x110/0x188 [ext4] ext4_do_writepages+0x3dc/0x740 [ext4] ext4_writepages+0xa4/0x190 [ext4] do_writepages+0x94/0x228 __writeback_single_inode+0x48/0x318 writeback_sb_inodes+0x204/0x590 __writeback_inodes_wb+0x54/0xf8 wb_writeback+0x2cc/0x3d8 wb_do_writeback+0x2e0/0x2f8 wb_workfn+0x80/0x2a8 process_one_work+0x178/0x3e8 worker_thread+0x234/0x3b8 kthread+0xf0/0x108 ret_from_fork+0x10/0x20 So explicitly call cond_resched() in jbd2_log_do_checkpoint() to avoid softlockup.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39782">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39783</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Fix configfs group list head handling Doing a list_del() on the epf_group field of struct pci_epf_driver in pci_epf_remove_cfs() is not correct as this field is a list head, not a list entry. This list_del() call triggers a KASAN warning when an endpoint function driver which has a configfs attribute group is torn down: ================================================================== BUG: KASAN: slab-use-after-free in pci_epf_remove_cfs+0x17c/0x198 Write of size 8 at addr ffff00010f4a0d80 by task rmmod/319 CPU: 3 UID: 0 PID: 319 Comm: rmmod Not tainted 6.16.0-rc2 #1 NONE Hardware name: Radxa ROCK 5B (DT) Call trace: show_stack+0x2c/0x84 (C) dump_stack_lvl+0x70/0x98 print_report+0x17c/0x538 kasan_report+0xb8/0x190 __asan_report_store8_noabort+0x20/0x2c pci_epf_remove_cfs+0x17c/0x198 pci_epf_unregister_driver+0x18/0x30 nvmet_pci_epf_cleanup_module+0x24/0x30 [nvmet_pci_epf] __arm64_sys_delete_module+0x264/0x424 invoke_syscall+0x70/0x260 el0_svc_common.constprop.0+0xac/0x230 do_el0_svc+0x40/0x58 el0_svc+0x48/0xdc el0t_64_sync_handler+0x10c/0x138 el0t_64_sync+0x198/0x19c ... Remove this incorrect list_del() call from pci_epf_remove_cfs().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39783">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39787</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: soc: qcom: mdt_loader: Ensure we don't read past the ELF header When the MDT loader is used in remoteproc, the ELF header is sanitized beforehand, but that's not necessary the case for other clients. Validate the size of the firmware buffer to ensure that we don't read past the end as we iterate over the header. e_phentsize and e_shentsize are validated as well, to ensure that the assumptions about step size in the traversal are valid.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39787">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39788</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE On Google gs101, the number of UTP transfer request slots (nutrs) is 32, and in this case the driver ends up programming the UTRL_NEXUS_TYPE incorrectly as 0. This is because the left hand side of the shift is 1, which is of type int, i.e. 31 bits wide. Shifting by more than that width results in undefined behaviour. Fix this by switching to the BIT() macro, which applies correct type casting as required. This ensures the correct value is written to UTRL_NEXUS_TYPE (0xffffffff on gs101), and it also fixes a UBSAN shift warning: UBSAN: shift-out-of-bounds in drivers/ufs/host/ufs-exynos.c:1113:21 shift exponent 32 is too large for 32-bit type 'int' For consistency, apply the same change to the nutmrs / UTMRL_NEXUS_TYPE write.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39788">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39790</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events pointing to unexpected TREs When a remote device sends a completion event to the host, it contains a pointer to the consumed TRE. The host uses this pointer to process all of the TREs between it and the host's local copy of the ring's read pointer. This works when processing completion for chained transactions, but can lead to nasty results if the device sends an event for a single-element transaction with a read pointer that is multiple elements ahead of the host's read pointer. For instance, if the host accesses an event ring while the device is updating it, the pointer inside of the event might still point to an old TRE. If the host uses the channel's xfer_cb() to directly free the buffer pointed to by the TRE, the buffer will be double-freed. This behavior was observed on an ep that used upstream EP stack without 'commit 6f18d174b73d ("bus: mhi: ep: Update read pointer only after buffer is written")'. Where the device updated the events ring pointer before updating the event contents, so it left a window where the host was able to access the stale data the event pointed to, before the device had the chance to update them. The usual pattern was that the host received an event pointing to a TRE that is not immediately after the last processed one, so it got treated as if it was a chained transaction, processing all of the TREs in between the two read pointers. This commit aims to harden the host by ensuring transactions where the event points to a TRE that isn't local_rp + 1 are chained. [mani: added stable tag and reworded commit message]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39790">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/415.html">CWE-415 Double Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39794</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM Kasan crashes the kernel trying to check boundaries when using the normal memcpy.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39794">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39795</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors check in blk_stack_limits() In blk_stack_limits(), we check that the t-&gt;chunk_sectors value is a multiple of the t-&gt;physical_block_size value. However, by finding the chunk_sectors value in bytes, we may overflow the unsigned int which holds chunk_sectors, so change the check to be based on sectors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39795">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39798</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automounting a new filesystem Capabilities cannot be inherited when we cross into a new filesystem. They need to be reset to the minimal defaults, and then probed for again.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39798">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/273.html">CWE-273 Improper Check for Dropped Privileges</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39800</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generation at btrfs_copy_root() If we find an unexpected generation for the extent buffer we are cloning at btrfs_copy_root(), we just WARN_ON() and don't error out and abort the transaction, meaning we allow to persist metadata with an unexpected generation. Instead of warning only, abort the transaction and return -EUCLEAN.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39800">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39801</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint command timeouts This commit addresses a rarely observed endpoint command timeout which causes kernel panic due to warn when 'panic_on_warn' is enabled and unnecessary call trace prints when 'panic_on_warn' is disabled. It is seen during fast software-controlled connect/disconnect testcases. The following is one such endpoint command timeout that we observed: 1. Connect ======= -&gt;dwc3_thread_interrupt -&gt;dwc3_ep0_interrupt -&gt;configfs_composite_setup -&gt;composite_setup -&gt;usb_ep_queue -&gt;dwc3_gadget_ep0_queue -&gt;__dwc3_gadget_ep0_queue -&gt;__dwc3_ep0_do_control_data -&gt;dwc3_send_gadget_ep_cmd 2. Disconnect ========== -&gt;dwc3_thread_interrupt -&gt;dwc3_gadget_disconnect_interrupt -&gt;dwc3_ep0_reset_state -&gt;dwc3_ep0_end_control_data -&gt;dwc3_send_gadget_ep_cmd In the issue scenario, in Exynos platforms, we observed that control transfers for the previous connect have not yet been completed and end transfer command sent as a part of the disconnect sequence and processing of USB_ENDPOINT_HALT feature request from the host timeout. This maybe an expected scenario since the controller is processing EP commands sent as a part of the previous connect. It maybe better to remove WARN_ON in all places where device endpoint commands are sent to avoid unnecessary kernel panic due to warn.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39801">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39806</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() A malicious HID device can trigger a slab out-of-bounds during mt_report_fixup() by passing in report descriptor smaller than 607 bytes. mt_report_fixup() attempts to patch byte offset 607 of the descriptor with 0x25 by first checking if byte offset 607 is 0x15 however it lacks bounds checks to verify if the descriptor is big enough before conducting this check. Fix this bug by ensuring the descriptor size is at least 608 bytes before accessing it. Below is the KASAN splat after the out of bounds access happens: [ 13.671954] ================================================================== [ 13.672667] BUG: KASAN: slab-out-of-bounds in mt_report_fixup+0x103/0x110 [ 13.673297] Read of size 1 at addr ffff888103df39df by task kworker/0:1/10 [ 13.673297] [ 13.673297] CPU: 0 UID: 0 PID: 10 Comm: kworker/0:1 Not tainted 6.15.0-00005-gec5d573d83f4-dirty #3 [ 13.673297] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/04 [ 13.673297] Call Trace: [ 13.673297] [ 13.673297] dump_stack_lvl+0x5f/0x80 [ 13.673297] print_report+0xd1/0x660 [ 13.673297] kasan_report+0xe5/0x120 [ 13.673297] __asan_report_load1_noabort+0x18/0x20 [ 13.673297] mt_report_fixup+0x103/0x110 [ 13.673297] hid_open_report+0x1ef/0x810 [ 13.673297] mt_probe+0x422/0x960 [ 13.673297] hid_device_probe+0x2e2/0x6f0 [ 13.673297] really_probe+0x1c6/0x6b0 [ 13.673297] __driver_probe_device+0x24f/0x310 [ 13.673297] driver_probe_device+0x4e/0x220 [ 13.673297] __device_attach_driver+0x169/0x320 [ 13.673297] bus_for_each_drv+0x11d/0x1b0 [ 13.673297] __device_attach+0x1b8/0x3e0 [ 13.673297] device_initial_probe+0x12/0x20 [ 13.673297] bus_probe_device+0x13d/0x180 [ 13.673297] device_add+0xe3a/0x1670 [ 13.673297] hid_add_device+0x31d/0xa40 [...]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39806">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39808</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() in ntrig_report_version(), hdev parameter passed from hid_probe(). sending descriptor to /dev/uhid can make hdev-&gt;dev.parent-&gt;parent to null if hdev-&gt;dev.parent-&gt;parent is null, usb_dev has invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned when usb_rcvctrlpipe() use usb_dev,it trigger page fault error for address(0xffffffffffffff58) add null check logic to ntrig_report_version() before calling hid_to_usb_dev()</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39808">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39812</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: sctp: initialize more fields in sctp_v6_from_sk() syzbot found that sin6_scope_id was not properly initialized, leading to undefined behavior. Clear sin6_scope_id and sin6_flowinfo. BUG: KMSAN: uninit-value in __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649 __sctp_v6_cmp_addr+0x887/0x8c0 net/sctp/ipv6.c:649 sctp_inet6_cmp_addr+0x4f2/0x510 net/sctp/ipv6.c:983 sctp_bind_addr_conflict+0x22a/0x3b0 net/sctp/bind_addr.c:390 sctp_get_port_local+0x21eb/0x2440 net/sctp/socket.c:8452 sctp_get_port net/sctp/socket.c:8523 [inline] sctp_listen_start net/sctp/socket.c:8567 [inline] sctp_inet_listen+0x710/0xfd0 net/sctp/socket.c:8636 __sys_listen_socket net/socket.c:1912 [inline] __sys_listen net/socket.c:1927 [inline] __do_sys_listen net/socket.c:1932 [inline] __se_sys_listen net/socket.c:1930 [inline] __x64_sys_listen+0x343/0x4c0 net/socket.c:1930 x64_sys_call+0x271d/0x3e20 arch/x86/include/generated/asm/syscalls_64.h:51 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Local variable addr.i.i created at: sctp_get_port net/sctp/socket.c:8515 [inline] sctp_listen_start net/sctp/socket.c:8567 [inline] sctp_inet_listen+0x650/0xfd0 net/sctp/socket.c:8636 __sys_listen_socket net/socket.c:1912 [inline] __sys_listen net/socket.c:1927 [inline] __do_sys_listen net/socket.c:1932 [inline] __se_sys_listen net/socket.c:1930 [inline] __x64_sys_listen+0x343/0x4c0 net/socket.c:1930</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39812">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39813</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix potential warning in trace_printk_seq during ftrace_dump When calling ftrace_dump_one() concurrently with reading trace_pipe, a WARN_ON_ONCE() in trace_printk_seq() can be triggered due to a race condition. The issue occurs because: CPU0 (ftrace_dump) CPU1 (reader) echo z &gt; /proc/sysrq-trigger !trace_empty(&amp;iter) trace_iterator_reset(&amp;iter) &lt;- len = size = 0 cat /sys/kernel/tracing/trace_pipe trace_find_next_entry_inc(&amp;iter) __find_next_entry ring_buffer_empty_cpu &lt;- all empty return NULL trace_printk_seq(&amp;iter.seq) WARN_ON_ONCE(s-&gt;seq.len &gt;= s-&gt;seq.size) In the context between trace_empty() and trace_find_next_entry_inc() during ftrace_dump, the ring buffer data was consumed by other readers. This caused trace_find_next_entry_inc to return NULL, failing to populate `iter.seq`. At this point, due to the prior trace_iterator_reset, both `iter.seq.len` and `iter.seq.size` were set to 0. Since they are equal, the WARN_ON_ONCE condition is triggered. Move the trace_printk_seq() into the if block that checks to make sure the return value of trace_find_next_entry_inc() is non-NULL in ftrace_dump_one(), ensuring the 'iter.seq' is properly populated before subsequent operations.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39813">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39817</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare Observed on kernel 6.6 (present on master as well): BUG: KASAN: slab-out-of-bounds in memcmp+0x98/0xd0 Call trace: kasan_check_range+0xe8/0x190 __asan_loadN+0x1c/0x28 memcmp+0x98/0xd0 efivarfs_d_compare+0x68/0xd8 __d_lookup_rcu_op_compare+0x178/0x218 __d_lookup_rcu+0x1f8/0x228 d_alloc_parallel+0x150/0x648 lookup_open.isra.0+0x5f0/0x8d0 open_last_lookups+0x264/0x828 path_openat+0x130/0x3f8 do_filp_open+0x114/0x248 do_sys_openat2+0x340/0x3c0 __arm64_sys_openat+0x120/0x1a0 If dentry-&gt;d_name.len &lt; EFI_VARIABLE_GUID_LEN , 'guid' can become negative, leadings to oob. The issue can be triggered by parallel lookups using invalid filename: T1 T2 lookup_open -&gt;lookup simple_lookup d_add // invalid dentry is added to hash list lookup_open d_alloc_parallel __d_lookup_rcu __d_lookup_rcu_op_compare hlist_bl_for_each_entry_rcu // invalid dentry can be retrieved -&gt;d_compare efivarfs_d_compare // oob Fix it by checking 'guid' before cmp.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39817">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39819</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs/smb: Fix inconsistent refcnt update A possible inconsistent update of refcount was identified in `smb2_compound_op`. Such inconsistent update could lead to possible resource leaks. Why it is a possible bug: 1. In the comment section of the function, it clearly states that the reference to `cfile` should be dropped after calling this function. 2. Every control flow path would check and drop the reference to `cfile`, except the patched one. 3. Existing callers would not handle refcount update of `cfile` if -ENOMEM is returned. To fix the bug, an extra goto label "out" is added, to make sure that the cleanup logic would always be respected. As the problem is caused by the allocation failure of `vars`, the cleanup logic between label "finished" and "out" can be safely ignored. According to the definition of function `is_replayable_error`, the error code of "-ENOMEM" is not recoverable. Therefore, the replay logic also gets ignored.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39819">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39823</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are guest-controlled indices. Using array_index_nospec() after the bounds checks clamps these values to mitigate speculative execution side-channels.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39823">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39824</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: HID: asus: fix UAF via HID_CLAIMED_INPUT validation After hid_hw_start() is called hidinput_connect() will eventually be called to set up the device with the input layer since the HID_CONNECT_DEFAULT connect mask is used. During hidinput_connect() all input and output reports are processed and corresponding hid_inputs are allocated and configured via hidinput_configure_usages(). This process involves slot tagging report fields and configuring usages by setting relevant bits in the capability bitmaps. However it is possible that the capability bitmaps are not set at all leading to the subsequent hidinput_has_been_populated() check to fail leading to the freeing of the hid_input and the underlying input device. This becomes problematic because a malicious HID device like a ASUS ROG N-Key keyboard can trigger the above scenario via a specially crafted descriptor which then leads to a user-after-free when the name of the freed input device is written to later on after hid_hw_start(). Below, report 93 intentionally utilises the HID_UP_UNDEFINED Usage Page which is skipped during usage configuration, leading to the frees. 0x05, 0x0D, // Usage Page (Digitizer) 0x09, 0x05, // Usage (Touch Pad) 0xA1, 0x01, // Collection (Application) 0x85, 0x0D, // Report ID (13) 0x06, 0x00, 0xFF, // Usage Page (Vendor Defined 0xFF00) 0x09, 0xC5, // Usage (0xC5) 0x15, 0x00, // Logical Minimum (0) 0x26, 0xFF, 0x00, // Logical Maximum (255) 0x75, 0x08, // Report Size (8) 0x95, 0x04, // Report Count (4) 0xB1, 0x02, // Feature (Data,Var,Abs) 0x85, 0x5D, // Report ID (93) 0x06, 0x00, 0x00, // Usage Page (Undefined) 0x09, 0x01, // Usage (0x01) 0x15, 0x00, // Logical Minimum (0) 0x26, 0xFF, 0x00, // Logical Maximum (255) 0x75, 0x08, // Report Size (8) 0x95, 0x1B, // Report Count (27) 0x81, 0x02, // Input (Data,Var,Abs) 0xC0, // End Collection Below is the KASAN splat after triggering the UAF: [ 21.672709] ================================================================== [ 21.673700] BUG: KASAN: slab-use-after-free in asus_probe+0xeeb/0xf80 [ 21.673700] Write of size 8 at addr ffff88810a0ac000 by task kworker/1:2/54 [ 21.673700] [ 21.673700] CPU: 1 UID: 0 PID: 54 Comm: kworker/1:2 Not tainted 6.16.0-rc4-g9773391cf4dd-dirty #36 PREEMPT(voluntary) [ 21.673700] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 [ 21.673700] Call Trace: [ 21.673700] [ 21.673700] dump_stack_lvl+0x5f/0x80 [ 21.673700] print_report+0xd1/0x660 [ 21.673700] kasan_report+0xe5/0x120 [ 21.673700] __asan_report_store8_noabort+0x1b/0x30 [ 21.673700] asus_probe+0xeeb/0xf80 [ 21.673700] hid_device_probe+0x2ee/0x700 [ 21.673700] really_probe+0x1c6/0x6b0 [ 21.673700] __driver_probe_device+0x24f/0x310 [ 21.673700] driver_probe_device+0x4e/0x220 [...] [ 21.673700] [ 21.673700] Allocated by task 54: [ 21.673700] kasan_save_stack+0x3d/0x60 [ 21.673700] kasan_save_track+0x18/0x40 [ 21.673700] kasan_save_alloc_info+0x3b/0x50 [ 21.673700] __kasan_kmalloc+0x9c/0xa0 [ 21.673700] __kmalloc_cache_noprof+0x139/0x340 [ 21.673700] input_allocate_device+0x44/0x370 [ 21.673700] hidinput_connect+0xcb6/0x2630 [ 21.673700] hid_connect+0xf74/0x1d60 [ 21.673700] hid_hw_start+0x8c/0x110 [ 21.673700] asus_probe+0x5a3/0xf80 [ 21.673700] hid_device_probe+0x2ee/0x700 [ 21.673700] really_probe+0x1c6/0x6b0 [ 21.673700] __driver_probe_device+0x24f/0x310 [ 21.673700] driver_probe_device+0x4e/0x220 [...] [ 21.673700] [ 21.673700] Freed by task 54: [ 21.673700] kasan_save_stack+0x3d/0x60 [ 21.673700] kasan_save_track+0x18/0x40 [ 21.673700] kasan_save_free_info+0x3f/0x60 [ 21.673700] __kasan_slab_free+0x3c/0x50 [ 21.673700] kfre ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39824">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39825</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rename(2) Besides sending the rename request to the server, the rename process also involves closing any deferred close, waiting for outstanding I/O to complete as well as marking all existing open handles as deleted to prevent them from deferring closes, which increases the race window for potential concurrent opens on the target file. Fix this by unhashing the dentry in advance to prevent any concurrent opens on the target.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39825">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39826</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: rose: convert 'use' field to refcount_t The 'use' field in struct rose_neigh is used as a reference counter but lacks atomicity. This can lead to race conditions where a rose_neigh structure is freed while still being referenced by other code paths. For example, when rose_neigh-&gt;use becomes zero during an ioctl operation via rose_rt_ioctl(), the structure may be removed while its timer is still active, potentially causing use-after-free issues. This patch changes the type of 'use' from unsigned short to refcount_t and updates all code paths to use rose_neigh_hold() and rose_neigh_put() which operate reference counts atomically.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39826">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39827</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: rose: include node references in rose_neigh refcount Current implementation maintains two separate reference counting mechanisms: the 'count' field in struct rose_neigh tracks references from rose_node structures, while the 'use' field (now refcount_t) tracks references from rose_sock. This patch merges these two reference counting systems using 'use' field for proper reference management. Specifically, this patch adds incrementing and decrementing of rose_neigh-&gt;use when rose_neigh-&gt;count is incremented or decremented. This patch also modifies rose_rt_free(), rose_rt_device_down() and rose_clear_route() to properly release references to rose_neigh objects before freeing a rose_node through rose_remove_node(). These changes ensure rose_neigh structures are properly freed only when all references, including those from rose_node structures, are released. As a result, this resolves a slab-use-after-free issue reported by Syzbot.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39827">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39828</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). syzbot reported the splat below. [0] When atmtcp_v_open() or atmtcp_v_close() is called via connect() or close(), atmtcp_send_control() is called to send an in-kernel special message. The message has ATMTCP_HDR_MAGIC in atmtcp_control.hdr.length. Also, a pointer of struct atm_vcc is set to atmtcp_control.vcc. The notable thing is struct atmtcp_control is uAPI but has a space for an in-kernel pointer. struct atmtcp_control { struct atmtcp_hdr hdr; /* must be first */ ... atm_kptr_t vcc; /* both directions */ ... } __ATM_API_ALIGN; typedef struct { unsigned char _[8]; } __ATM_API_ALIGN atm_kptr_t; The special message is processed in atmtcp_recv_control() called from atmtcp_c_send(). atmtcp_c_send() is vcc-&gt;dev-&gt;ops-&gt;send() and called from 2 paths: 1. .ndo_start_xmit() (vcc-&gt;send() == atm_send_aal0()) 2. vcc_sendmsg() The problem is sendmsg() does not validate the message length and userspace can abuse atmtcp_recv_control() to overwrite any kptr by atmtcp_control. Let's add a new -&gt;pre_send() hook to validate messages from sendmsg(). [0]: Oops: general protection fault, probably for non-canonical address 0xdffffc00200000ab: 0000 [#1] SMP KASAN PTI KASAN: probably user-memory-access in range [0x0000000100000558-0x000000010000055f] CPU: 0 UID: 0 PID: 5865 Comm: syz-executor331 Not tainted 6.17.0-rc1-syzkaller-00215-gbab3ce404553 #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025 RIP: 0010:atmtcp_recv_control drivers/atm/atmtcp.c:93 [inline] RIP: 0010:atmtcp_c_send+0x1da/0x950 drivers/atm/atmtcp.c:297 Code: 4d 8d 75 1a 4c 89 f0 48 c1 e8 03 42 0f b6 04 20 84 c0 0f 85 15 06 00 00 41 0f b7 1e 4d 8d b7 60 05 00 00 4c 89 f0 48 c1 e8 03 &lt;42&gt; 0f b6 04 20 84 c0 0f 85 13 06 00 00 66 41 89 1e 4d 8d 75 1c 4c RSP: 0018:ffffc90003f5f810 EFLAGS: 00010203 RAX: 00000000200000ab RBX: 0000000000000000 RCX: 0000000000000000 RDX: ffff88802a510000 RSI: 00000000ffffffff RDI: ffff888030a6068c RBP: ffff88802699fb40 R08: ffff888030a606eb R09: 1ffff1100614c0dd R10: dffffc0000000000 R11: ffffffff8718fc40 R12: dffffc0000000000 R13: ffff888030a60680 R14: 000000010000055f R15: 00000000ffffffff FS: 00007f8d7e9236c0(0000) GS:ffff888125c1c000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000000045ad50 CR3: 0000000075bde000 CR4: 00000000003526f0 Call Trace: vcc_sendmsg+0xa10/0xc60 net/atm/common.c:645 sock_sendmsg_nosec net/socket.c:714 [inline] __sock_sendmsg+0x219/0x270 net/socket.c:729 ____sys_sendmsg+0x505/0x830 net/socket.c:2614 ___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668 __sys_sendmsg net/socket.c:2700 [inline] __do_sys_sendmsg net/socket.c:2705 [inline] __se_sys_sendmsg net/socket.c:2703 [inline] __x64_sys_sendmsg+0x19b/0x260 net/socket.c:2703 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f8d7e96a4a9 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 51 18 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f8d7e923198 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f8d7e9f4308 RCX: 00007f8d7e96a4a9 RDX: 0000000000000000 RSI: 0000200000000240 RDI: 0000000000000005 RBP: 00007f8d7e9f4300 R08: 65732f636f72702f R09: 65732f636f72702f R10: 65732f636f72702f R11: 0000000000000246 R12: 00007f8d7e9c10ac R13: 00007f8d7e9231a0 R14: 0000200000000200 R15: 0000200000000250 Modules linked in:</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39828">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39835</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: xfs: do not propagate ENODATA disk errors into xattr code ENODATA (aka ENOATTR) has a very specific meaning in the xfs xattr code; namely, that the requested attribute name could not be found. However, a medium error from disk may also return ENODATA. At best, this medium error may escape to userspace as "attribute not found" when in fact it's an IO (disk) error. At worst, we may oops in xfs_attr_leaf_get() when we do: error = xfs_attr_leaf_hasname(args, &amp;bp); if (error == -ENOATTR) { xfs_trans_brelse(args-&gt;trans, bp); return error; } because an ENODATA/ENOATTR error from disk leaves us with a null bp, and the xfs_trans_brelse will then null-deref it. As discussed on the list, we really need to modify the lower level IO functions to trap all disk errors and ensure that we don't let unique errors like this leak up into higher xfs functions - many like this should be remapped to EIO. However, this patch directly addresses a reported bug in the xattr code, and should be safe to backport to stable kernels. A larger-scope patch to handle more unique errors at lower levels can follow later. (Note, prior to 07120f1abdff we did not oops, but we did return the wrong error code to userspace.)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39835">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39838</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL pointer dereference in UTF16 conversion There can be a NULL pointer dereference bug here. NULL is passed to __cifs_sfu_make_node without checks, which passes it unchecked to cifs_strndup_to_utf16, which in turn passes it to cifs_local_to_utf16_bytes where '*from' is dereferenced, causing a crash. This patch adds a check for NULL 'src' in cifs_strndup_to_utf16 and returns NULL early to prevent dereferencing NULL pointer. Found by Linux Verification Center (linuxtesting.org) with SVACE</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39838">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39839</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding decode batadv_nc_skb_decode_packet() trusts coded_len and checks only against skb-&gt;len. XOR starts at sizeof(struct batadv_unicast_packet), reducing payload headroom, and the source skb length is not verified, allowing an out-of-bounds read and a small out-of-bounds write. Validate that coded_len fits within the payload area of both destination and source sk_buffs before XORing.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39839">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39841</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred receive path Fix a use-after-free window by correcting the buffer release sequence in the deferred receive path. The code freed the RQ buffer first and only then cleared the context pointer under the lock. Concurrent paths (e.g., ABTS and the repost path) also inspect and release the same pointer under the lock, so the old order could lead to double-free/UAF. Note that the repost path already uses the correct pattern: detach the pointer under the lock, then free it after dropping the lock. The deferred path should do the same.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39841">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39842</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ocfs2: prevent release journal inode after journal shutdown Before calling ocfs2_delete_osb(), ocfs2_journal_shutdown() has already been executed in ocfs2_dismount_volume(), so osb-&gt;journal must be NULL. Therefore, the following calltrace will inevitably fail when it reaches jbd2_journal_release_jbd_inode(). ocfs2_dismount_volume()-&gt; ocfs2_delete_osb()-&gt; ocfs2_free_slot_info()-&gt; __ocfs2_free_slot_info()-&gt; evict()-&gt; ocfs2_evict_inode()-&gt; ocfs2_clear_inode()-&gt; jbd2_journal_release_jbd_inode(osb-&gt;journal-&gt;j_journal, Adding osb-&gt;journal checks will prevent null-ptr-deref during the above execution path.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39842">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39843</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm: slub: avoid wake up kswapd in set_track_prepare set_track_prepare() can incur lock recursion. The issue is that it is called from hrtimer_start_range_ns holding the per_cpu(hrtimer_bases)[n].lock, but when enabled CONFIG_DEBUG_OBJECTS_TIMERS, may wake up kswapd in set_track_prepare, and try to hold the per_cpu(hrtimer_bases)[n].lock. Avoid deadlock caused by implicitly waking up kswapd by passing in allocation flags, which do not contain __GFP_KSWAPD_RECLAIM in the debug_objects_fill_pool() case. Inside stack depot they are processed by gfp_nested_mask(). Since ___slab_alloc() has preemption disabled, we mask out __GFP_DIRECT_RECLAIM from the flags there. The oops looks something like: BUG: spinlock recursion on CPU#3, swapper/3/0 lock: 0xffffff8a4bf29c80, .magic: dead4ead, .owner: swapper/3/0, .owner_cpu: 3 Hardware name: Qualcomm Technologies, Inc. Popsicle based on SM8850 (DT) Call trace: spin_bug+0x0 _raw_spin_lock_irqsave+0x80 hrtimer_try_to_cancel+0x94 task_contending+0x10c enqueue_dl_entity+0x2a4 dl_server_start+0x74 enqueue_task_fair+0x568 enqueue_task+0xac do_activate_task+0x14c ttwu_do_activate+0xcc try_to_wake_up+0x6c8 default_wake_function+0x20 autoremove_wake_function+0x1c __wake_up+0xac wakeup_kswapd+0x19c wake_all_kswapds+0x78 __alloc_pages_slowpath+0x1ac __alloc_pages_noprof+0x298 stack_depot_save_flags+0x6b0 stack_depot_save+0x14 set_track_prepare+0x5c ___slab_alloc+0xccc __kmalloc_cache_noprof+0x470 __set_page_owner+0x2bc post_alloc_hook[jt]+0x1b8 prep_new_page+0x28 get_page_from_freelist+0x1edc __alloc_pages_noprof+0x13c alloc_slab_page+0x244 allocate_slab+0x7c ___slab_alloc+0x8e8 kmem_cache_alloc_noprof+0x450 debug_objects_fill_pool+0x22c debug_object_activate+0x40 enqueue_hrtimer[jt]+0xdc hrtimer_start_range_ns+0x5f8 ...</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39843">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39844</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm: move page table sync declarations to linux/pgtable.h During our internal testing, we started observing intermittent boot failures when the machine uses 4-level paging and has a large amount of persistent memory: BUG: unable to handle page fault for address: ffffe70000000034 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 0 P4D 0 Oops: 0002 [#1] SMP NOPTI RIP: 0010:__init_single_page+0x9/0x6d Call Trace: __init_zone_device_page+0x17/0x5d memmap_init_zone_device+0x154/0x1bb pagemap_range+0x2e0/0x40f memremap_pages+0x10b/0x2f0 devm_memremap_pages+0x1e/0x60 dev_dax_probe+0xce/0x2ec [device_dax] dax_bus_probe+0x6d/0xc9 [... snip ...] It turns out that the kernel panics while initializing vmemmap (struct page array) when the vmemmap region spans two PGD entries, because the new PGD entry is only installed in init_mm.pgd, but not in the page tables of other tasks. And looking at __populate_section_memmap(): if (vmemmap_can_optimize(altmap, pgmap)) // does not sync top level page tables r = vmemmap_populate_compound_pages(pfn, start, end, nid, pgmap); else // sync top level page tables in x86 r = vmemmap_populate(start, end, nid, altmap); In the normal path, vmemmap_populate() in arch/x86/mm/init_64.c synchronizes the top level page table (See commit 9b861528a801 ("x86-64, mem: Update all PGDs for direct mapping and vmemmap mapping changes")) so that all tasks in the system can see the new vmemmap area. However, when vmemmap_can_optimize() returns true, the optimized path skips synchronization of top-level page tables. This is because vmemmap_populate_compound_pages() is implemented in core MM code, which does not handle synchronization of the top-level page tables. Instead, the core MM has historically relied on each architecture to perform this synchronization manually. We're not the first party to encounter a crash caused by not-sync'd top level page tables: earlier this year, Gwan-gyeong Mun attempted to address the issue [1] [2] after hitting a kernel panic when x86 code accessed the vmemmap area before the corresponding top-level entries were synced. At that time, the issue was believed to be triggered only when struct page was enlarged for debugging purposes, and the patch did not get further updates. It turns out that current approach of relying on each arch to handle the page table sync manually is fragile because 1) it's easy to forget to sync the top level page table, and 2) it's also easy to overlook that the kernel should not access the vmemmap and direct mapping areas before the sync. # The solution: Make page table sync more code robust and harder to miss To address this, Dave Hansen suggested [3] [4] introducing {pgd,p4d}_populate_kernel() for updating kernel portion of the page tables and allow each architecture to explicitly perform synchronization when installing top-level entries. With this approach, we no longer need to worry about missing the sync step, reducing the risk of future regressions. The new interface reuses existing ARCH_PAGE_TABLE_SYNC_MASK, PGTBL_P*D_MODIFIED and arch_sync_kernel_mappings() facility used by vmalloc and ioremap to synchronize page tables. pgd_populate_kernel() looks like this: static inline void pgd_populate_kernel(unsigned long addr, pgd_t *pgd, p4d_t *p4d) { pgd_populate(&amp;init_mm, pgd, p4d); if (ARCH_PAGE_TABLE_SYNC_MASK &amp; PGTBL_PGD_MODIFIED) arch_sync_kernel_mappings(addr, addr); } It is worth noting that vmalloc() and apply_to_range() carefully synchronizes page tables by calling p*d_alloc_track() and arch_sync_kernel_mappings(), and thus they are not affected by ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39844">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39845</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() Define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() to ensure page tables are properly synchronized when calling p*d_populate_kernel(). For 5-level paging, synchronization is performed via pgd_populate_kernel(). In 4-level paging, pgd_populate() is a no-op, so synchronization is instead performed at the P4D level via p4d_populate_kernel(). This fixes intermittent boot failures on systems using 4-level paging and a large amount of persistent memory: BUG: unable to handle page fault for address: ffffe70000000034 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 0 P4D 0 Oops: 0002 [#1] SMP NOPTI RIP: 0010:__init_single_page+0x9/0x6d Call Trace: __init_zone_device_page+0x17/0x5d memmap_init_zone_device+0x154/0x1bb pagemap_range+0x2e0/0x40f memremap_pages+0x10b/0x2f0 devm_memremap_pages+0x1e/0x60 dev_dax_probe+0xce/0x2ec [device_dax] dax_bus_probe+0x6d/0xc9 [... snip ...] It also fixes a crash in vmemmap_set_pmd() caused by accessing vmemmap before sync_global_pgds() [1]: BUG: unable to handle page fault for address: ffffeb3ff1200000 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 0 P4D 0 Oops: Oops: 0002 [#1] PREEMPT SMP NOPTI Tainted: [W]=WARN RIP: 0010:vmemmap_set_pmd+0xff/0x230 vmemmap_populate_hugepages+0x176/0x180 vmemmap_populate+0x34/0x80 __populate_section_memmap+0x41/0x90 sparse_add_section+0x121/0x3e0 __add_pages+0xba/0x150 add_pages+0x1d/0x70 memremap_pages+0x3dc/0x810 devm_memremap_pages+0x1c/0x60 xe_devm_add+0x8b/0x100 [xe] xe_tile_init_noalloc+0x6a/0x70 [xe] xe_device_probe+0x48c/0x740 [xe] [... snip ...]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39845">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39846</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() In __iodyn_find_io_region(), pcmcia_make_resource() is assigned to res and used in pci_bus_alloc_resource(). There is a dereference of res in pci_bus_alloc_resource(), which could lead to a NULL pointer dereference on failure of pcmcia_make_resource(). Fix this bug by adding a check of res.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39846">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39847</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ppp: fix memory leak in pad_compress_skb If alloc_skb() fails in pad_compress_skb(), it returns NULL without releasing the old skb. The caller does: skb = pad_compress_skb(ppp, skb); if (!skb) goto drop; drop: kfree_skb(skb); When pad_compress_skb() returns NULL, the reference to the old skb is lost and kfree_skb(skb) ends up doing nothing, leading to a memory leak. Align pad_compress_skb() semantics with realloc(): only free the old skb if allocation and compression succeed. At the call site, use the new_skb variable so the original skb is not lost when pad_compress_skb() fails.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39847">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39848</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ax25: properly unshare skbs in ax25_kiss_rcv() Bernard Pidoux reported a regression apparently caused by commit c353e8983e0d ("net: introduce per netns packet chains"). skb-&gt;dev becomes NULL and we crash in __netif_receive_skb_core(). Before above commit, different kind of bugs or corruptions could happen without a major crash. But the root cause is that ax25_kiss_rcv() can queue/mangle input skb without checking if this skb is shared or not. Many thanks to Bernard Pidoux for his help, diagnosis and tests. We had a similar issue years ago fixed with commit 7aaed57c5c28 ("phonet: properly unshare skbs in phonet_rcv()").</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39848">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39849</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() If the ssid-&gt;datalen is more than IEEE80211_MAX_SSID_LEN (32) it would lead to memory corruption so add some bounds checking.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39849">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39853</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: i40e: Fix potential invalid access when MAC list is empty list_first_entry() never returns NULL - if the list is empty, it still returns a pointer to an invalid object, leading to potential invalid memory access when dereferenced. Fix this by using list_first_entry_or_null instead of list_first_entry.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39853">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39857</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() BUG: kernel NULL pointer dereference, address: 00000000000002ec PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP PTI CPU: 28 UID: 0 PID: 343 Comm: kworker/28:1 Kdump: loaded Tainted: G OE 6.17.0-rc2+ #9 NONE Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 Workqueue: smc_hs_wq smc_listen_work [smc] RIP: 0010:smc_ib_is_sg_need_sync+0x9e/0xd0 [smc] ... Call Trace: smcr_buf_map_link+0x211/0x2a0 [smc] __smc_buf_create+0x522/0x970 [smc] smc_buf_create+0x3a/0x110 [smc] smc_find_rdma_v2_device_serv+0x18f/0x240 [smc] ? smc_vlan_by_tcpsk+0x7e/0xe0 [smc] smc_listen_find_device+0x1dd/0x2b0 [smc] smc_listen_work+0x30f/0x580 [smc] process_one_work+0x18c/0x340 worker_thread+0x242/0x360 kthread+0xe7/0x220 ret_from_fork+0x13a/0x160 ret_from_fork_asm+0x1a/0x30 If the software RoCE device is used, ibdev-&gt;dma_device is a null pointer. As a result, the problem occurs. Null pointer detection is added to prevent problems.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39857">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39860</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() syzbot reported the splat below without a repro. In the splat, a single thread calling bt_accept_dequeue() freed sk and touched it after that. The root cause would be the racy l2cap_sock_cleanup_listen() call added by the cited commit. bt_accept_dequeue() is called under lock_sock() except for l2cap_sock_release(). Two threads could see the same socket during the list iteration in bt_accept_dequeue(): CPU1 CPU2 (close()) ---- ---- sock_hold(sk) sock_hold(sk); lock_sock(sk) &lt;-- block close() sock_put(sk) bt_accept_unlink(sk) sock_put(sk) &lt;-- refcnt by bt_accept_enqueue() release_sock(sk) lock_sock(sk) sock_put(sk) bt_accept_unlink(sk) sock_put(sk) &lt;-- last refcnt bt_accept_unlink(sk) &lt;-- UAF Depending on the timing, the other thread could show up in the "Freed by task" part. Let's call l2cap_sock_cleanup_listen() under lock_sock() in l2cap_sock_release(). [0]: BUG: KASAN: slab-use-after-free in debug_spin_lock_before kernel/locking/spinlock_debug.c:86 [inline] BUG: KASAN: slab-use-after-free in do_raw_spin_lock+0x26f/0x2b0 kernel/locking/spinlock_debug.c:115 Read of size 4 at addr ffff88803b7eb1c4 by task syz.5.3276/16995 CPU: 3 UID: 0 PID: 16995 Comm: syz.5.3276 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xcd/0x630 mm/kasan/report.c:482 kasan_report+0xe0/0x110 mm/kasan/report.c:595 debug_spin_lock_before kernel/locking/spinlock_debug.c:86 [inline] do_raw_spin_lock+0x26f/0x2b0 kernel/locking/spinlock_debug.c:115 spin_lock_bh include/linux/spinlock.h:356 [inline] release_sock+0x21/0x220 net/core/sock.c:3746 bt_accept_dequeue+0x505/0x600 net/bluetooth/af_bluetooth.c:312 l2cap_sock_cleanup_listen+0x5c/0x2a0 net/bluetooth/l2cap_sock.c:1451 l2cap_sock_release+0x5c/0x210 net/bluetooth/l2cap_sock.c:1425 __sock_release+0xb3/0x270 net/socket.c:649 sock_close+0x1c/0x30 net/socket.c:1439 __fput+0x3ff/0xb70 fs/file_table.c:468 task_work_run+0x14d/0x240 kernel/task_work.c:227 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop+0xeb/0x110 kernel/entry/common.c:43 exit_to_user_mode_prepare include/linux/irq-entry-common.h:225 [inline] syscall_exit_to_user_mode_work include/linux/entry-common.h:175 [inline] syscall_exit_to_user_mode include/linux/entry-common.h:210 [inline] do_syscall_64+0x3f6/0x4c0 arch/x86/entry/syscall_64.c:100 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f2accf8ebe9 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffdb6cb1378 EFLAGS: 00000246 ORIG_RAX: 00000000000001b4 RAX: 0000000000000000 RBX: 00000000000426fb RCX: 00007f2accf8ebe9 RDX: 0000000000000000 RSI: 000000000000001e RDI: 0000000000000003 RBP: 00007f2acd1b7da0 R08: 0000000000000001 R09: 00000012b6cb166f R10: 0000001b30e20000 R11: 0000000000000246 R12: 00007f2acd1b609c R13: 00007f2acd1b6090 R14: ffffffffffffffff R15: 00007ffdb6cb1490 Allocated by task 5326: kasan_save_stack+0x33/0x60 mm/kasan/common.c:47 kasan_save_track+0x14/0x30 mm/kasan/common.c:68 poison_kmalloc_redzone mm/kasan/common.c:388 [inline] __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:405 kasan_kmalloc include/linux/kasan.h:260 [inline] __do_kmalloc_node mm/slub.c:4365 [inline] __kmalloc_nopro ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39860">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39864</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix use-after-free in cmp_bss() Following bss_free() quirk introduced in commit 776b3580178f ("cfg80211: track hidden SSID networks properly"), adjust cfg80211_update_known_bss() to free the last beacon frame elements only if they're not shared via the corresponding 'hidden_beacon_bss' pointer.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39864">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39865</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tee: fix NULL pointer dereference in tee_shm_put tee_shm_put have NULL pointer dereference: __optee_disable_shm_cache --&gt; shm = reg_pair_to_ptr(...);//shm maybe return NULL tee_shm_free(shm); --&gt; tee_shm_put(shm);//crash Add check in tee_shm_put to fix it. panic log: Unable to handle kernel paging request at virtual address 0000000000100cca Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 user pgtable: 4k pages, 48-bit VAs, pgdp=0000002049d07000 [0000000000100cca] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 0000000096000004 [#1] SMP CPU: 2 PID: 14442 Comm: systemd-sleep Tainted: P OE ------- ---- 6.6.0-39-generic #38 Source Version: 938b255f6cb8817c95b0dd5c8c2944acfce94b07 Hardware name: greatwall GW-001Y1A-FTH, BIOS Great Wall BIOS V3.0 10/26/2022 pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : tee_shm_put+0x24/0x188 lr : tee_shm_free+0x14/0x28 sp : ffff001f98f9faf0 x29: ffff001f98f9faf0 x28: ffff0020df543cc0 x27: 0000000000000000 x26: ffff001f811344a0 x25: ffff8000818dac00 x24: ffff800082d8d048 x23: ffff001f850fcd18 x22: 0000000000000001 x21: ffff001f98f9fb88 x20: ffff001f83e76218 x19: ffff001f83e761e0 x18: 000000000000ffff x17: 303a30303a303030 x16: 0000000000000000 x15: 0000000000000003 x14: 0000000000000001 x13: 0000000000000000 x12: 0101010101010101 x11: 0000000000000001 x10: 0000000000000001 x9 : ffff800080e08d0c x8 : ffff001f98f9fb88 x7 : 0000000000000000 x6 : 0000000000000000 x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 x2 : ffff001f83e761e0 x1 : 00000000ffff001f x0 : 0000000000100cca Call trace: tee_shm_put+0x24/0x188 tee_shm_free+0x14/0x28 __optee_disable_shm_cache+0xa8/0x108 optee_shutdown+0x28/0x38 platform_shutdown+0x28/0x40 device_shutdown+0x144/0x2b0 kernel_power_off+0x3c/0x80 hibernate+0x35c/0x388 state_store+0x64/0x80 kobj_attr_store+0x14/0x28 sysfs_kf_write+0x48/0x60 kernfs_fop_write_iter+0x128/0x1c0 vfs_write+0x270/0x370 ksys_write+0x6c/0x100 __arm64_sys_write+0x20/0x30 invoke_syscall+0x4c/0x120 el0_svc_common.constprop.0+0x44/0xf0 do_el0_svc+0x24/0x38 el0_svc+0x24/0x88 el0t_64_sync_handler+0x134/0x150 el0t_64_sync+0x14c/0x15</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39865">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39866</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of switching. CPU: 1 PID: 562 Comm: systemd-random- Not tainted 6.6.56-gb4403bd46a8e #1 ...... pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __mark_inode_dirty+0x124/0x418 lr : __mark_inode_dirty+0x118/0x418 sp : ffffffc08c9dbbc0 ........ Call trace: __mark_inode_dirty+0x124/0x418 generic_update_time+0x4c/0x60 file_modified+0xcc/0xd0 ext4_buffered_write_iter+0x58/0x124 ext4_file_write_iter+0x54/0x704 vfs_write+0x1c0/0x308 ksys_write+0x74/0x10c __arm64_sys_write+0x1c/0x28 invoke_syscall+0x48/0x114 el0_svc_common.constprop.0+0xc0/0xe0 do_el0_svc+0x1c/0x28 el0_svc+0x40/0xe4 el0t_64_sync_handler+0x120/0x12c el0t_64_sync+0x194/0x198 Root cause is: systemd-random-seed kworker ---------------------------------------------------------------------- ___mark_inode_dirty inode_switch_wbs_work_fn spin_lock(&amp;inode-&gt;i_lock); inode_attach_wb locked_inode_to_wb_and_lock_list get inode-&gt;i_wb spin_unlock(&amp;inode-&gt;i_lock); spin_lock(&amp;wb-&gt;list_lock) spin_lock(&amp;inode-&gt;i_lock) inode_io_list_move_locked spin_unlock(&amp;wb-&gt;list_lock) spin_unlock(&amp;inode-&gt;i_lock) spin_lock(&amp;old_wb-&gt;list_lock) inode_do_switch_wbs spin_lock(&amp;inode-&gt;i_lock) inode-&gt;i_wb = new_wb spin_unlock(&amp;inode-&gt;i_lock) spin_unlock(&amp;old_wb-&gt;list_lock) wb_put_many(old_wb, nr_switched) cgwb_release old wb released wb_wakeup_delayed() accesses wb, then trigger the use-after-free issue Fix this race condition by holding inode spinlock until wb_wakeup_delayed() finished.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39866">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40300</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). Existing mitigations already protect kernel/KVM from a malicious guest. Userspace can additionally be protected by flushing the branch predictors after a VMexit. Since it is the userspace that consumes the poisoned branch predictors, conditionally issue an IBPB after a VMexit and before returning to userspace. Workloads that frequently switch between hypervisor and userspace will incur the most overhead from the new IBPB. This new IBPB is not integrated with the existing IBPB sites. For instance, a task can use the existing speculation control prctl() to get an IBPB at context switch time. With this implementation, the IBPB is doubled up: one at context switch and another before running userspace. The intent is to integrate and optimize these cases post-embargo. [ dhansen: elaborate on suboptimal IBPB solution ]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40300">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/402.html">CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-43368</a></h3>
<div class="csaf-accordion-content">
<p>A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-43368">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-47219</a></h3>
<div class="csaf-accordion-content">
<p>In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-47219">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-48989</a></h3>
<div class="csaf-accordion-content">
<p>Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-48989">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404 Improper Resource Shutdown or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-53057</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-53057">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-53066</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-53066">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200 Exposure of Sensitive Information to an Unauthorized Actor</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-55752</a></h3>
<div class="csaf-accordion-content">
<p>Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-55752">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/23.html">CWE-23 Relative Path Traversal</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-55754</a></h3>
<div class="csaf-accordion-content">
<p>Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-55754">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/150.html">CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.6</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-61748</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 21.0.8 and 25; Oracle GraalVM for JDK: 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-61748">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-61795</a></h3>
<div class="csaf-accordion-content">
<p>Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-61795">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404 Improper Resource Shutdown or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-2673</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported. As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction). OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers. The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included. The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security. Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group. The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary. OpenSSL 3.6 and 3.5 are vulnerable to this issue. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released. OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-2673">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/757.html">CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21925</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-21925">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21932</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-21932">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.4</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21933</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-21933">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21945</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-21945">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/400.html">CWE-400 Uncontrolled Resource Consumption</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21947</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-21947">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/79.html">CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.1</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22924</a></h3>
<div class="csaf-accordion-content">
<p>The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially impacting system availability and integrity.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22924">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/306.html">CWE-306 Missing Authentication for Critical Function</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22925</a></h3>
<div class="csaf-accordion-content">
<p>The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker to render the service unavailable and cause denial-of-service conditions by overwhelming system resources.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22925">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/770.html">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-28387</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-28387">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-28388</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference. Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it. The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-28388">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-28389</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-28389">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-28390</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-28390">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31789</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow. Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31789">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31790</a></h3>
<div class="csaf-accordion-content">
<p>Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext. As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue. The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31790">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC CN 4100</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V5.0 or later version<br><a href="https://support.industry.siemens.com/cs/ww/en/view/109814144/">https://support.industry.siemens.com/cs/ww/en/view/109814144/</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/754.html">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>General Recommendations</h2>
<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>
<hr>
<h2>Additional Resources</h2>
<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>
<hr>
<h2>Terms of Use</h2>
<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-032379 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-05-12</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-05-12</td>
<td>1</td>
<td>Publication Date</td>
</tr>
<tr>
<td>2026-05-14</td>
<td>2</td>
<td>Initial CISA Republication of Siemens ProductCERT SSA-032379 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[CERN Open Sources Its KiCad Component Libraries]]></title>
<description><![CDATA[Ancient Slashdot reader ewhac writes: CERN, a longtime Open Source pioneer, has made several contributions over the years to KiCad ("KEE-kad"), an Open Source EDA (Electronic Design Automation) package widely used in the hobbyist and professional electronics communities. It's gotten so widely use...]]></description>
<link>https://tsecurity.de/de/3513443/it-security-nachrichten/cern-open-sources-its-kicad-component-libraries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513443/it-security-nachrichten/cern-open-sources-its-kicad-component-libraries/</guid>
<pubDate>Wed, 13 May 2026 13:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ancient Slashdot reader ewhac writes: CERN, a longtime Open Source pioneer, has made several contributions over the years to KiCad ("KEE-kad"), an Open Source EDA (Electronic Design Automation) package widely used in the hobbyist and professional electronics communities. It's gotten so widely used that users can now submit their KiCad design files directly to several electronics fabricators (rather than the traditional step of converting the layouts to Gerber files). Over the years, CERN has also developed their own symbol and footprint libraries to support their own internal electronic designs. Last week, CERN released those KiCad component libraries, containing over 17,000 symbols, under the CERN Open Hardware License.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=CERN+Open+Sources+Its+KiCad+Component+Libraries%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F13%2F077203%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F13%2F077203%2Fcern-open-sources-its-kicad-component-libraries%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/05/13/077203/cern-open-sources-its-kicad-component-libraries?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TikTok now wants to be the place you book the trip you just saw on TikTok]]></title>
<description><![CDATA[TikTok is systematically converting its discovery engine into a transaction layer, which both deepens user retention and opens entirely new revenue streams for its new owners.]]></description>
<link>https://tsecurity.de/de/3510347/it-nachrichten/tiktok-now-wants-to-be-the-place-you-book-the-trip-you-just-saw-on-tiktok/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510347/it-nachrichten/tiktok-now-wants-to-be-the-place-you-book-the-trip-you-just-saw-on-tiktok/</guid>
<pubDate>Tue, 12 May 2026 15:02:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[TikTok is systematically converting its discovery engine into a transaction layer, which both deepens user retention and opens entirely new revenue streams for its new owners.]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new and exciting in JDK 26]]></title>
<description><![CDATA[With the release of JDK 26, which arrived March 17, we’ve now seen 17 versions of Java delivered under the time-based six-month release cadence. Nobody can call this anything other than a huge success for Java. In the last eight years, we’ve seen the Java platform move forward faster than at any ...]]></description>
<link>https://tsecurity.de/de/3509684/ai-nachrichten/whats-new-and-exciting-in-jdk-26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509684/ai-nachrichten/whats-new-and-exciting-in-jdk-26/</guid>
<pubDate>Tue, 12 May 2026 11:33:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With the <a href="https://www.infoworld.com/article/4050993/jdk-26-the-new-features-in-java-26.html" data-type="link" data-id="https://www.infoworld.com/article/4050993/jdk-26-the-new-features-in-java-26.html">release of JDK 26</a>, which arrived March 17, we’ve now seen 17 versions of Java delivered under the time-based six-month release cadence. Nobody can call this anything other than a huge success for <a href="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html" data-type="link" data-id="https://www.infoworld.com/article/2335996/9-reasons-java-is-still-great.html">Java</a>. In the last eight years, we’ve seen the Java platform move forward faster than at any time in its history. In addition, the faster release cadence has made preview features and incubator modules a practical reality. This allows fully developed features to be tested by developers, with feedback incorporated before the feature is finalized. Within practical limits, Java developers get exactly what they want in new features.</p>



<p>As an interesting note, JDK 26 is the first Java version in which no preview features have been made final. What then does JDK 26 deliver?</p>



<p>There are 10 <a href="https://www.infoworld.com/article/2335544/better-java-jdk-enhancement-proposals-jep-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2335544/better-java-jdk-enhancement-proposals-jep-explained.html">JDK Enhancement Proposals</a> (JEPs), which are the mechanism for defining new features in the OpenJDK project. This is slightly below average, but it’s worth noting that it is not a long-term support (LTS) release. LTS versions of Java are the ones that OpenJDK distributions commit to providing extended maintenance and support for, so they are more likely to be used in production. This does not mean JDK 26 is not production quality; if you use a <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a> pipeline with frequent deployments, JDK 26 will be great for running your applications.</p>



<p>Let’s break down the new features by category: the Java language, the libraries, and the runtime.</p>



<h2 class="wp-block-heading">Improvements in the Java language </h2>



<p>The only language-specific feature is the continued development of primitive types in patterns, <code>instanceof</code>, and <code>switch</code> (JEP 530), which is in its fourth preview. Although Java is an object-oriented language, Java does not treat everything as an object; it has primitive values to improve performance. This JEP allows primitive types to be used in places where previously, you would have needed a reference type. Changes have been made to resolve issues found when combining primitive types (like <code>int</code>) with reference types (like the wrapper class <code>Integer</code>).</p>



<h2 class="wp-block-heading">Improvements in the Java libraries</h2>



<p>The bulk of the changes in JDK 26 are in the libraries.</p>



<ul class="wp-block-list">
<li>JEP 517: HTTP/3 for the HTTP Client API. The HTTP Client API has been enhanced to include support for the latest HTTP/3 protocol. Rather than using TCP, which HTTP/2 and earlier versions rely on, HTTP/3 uses the UDP-based QUIC protocol. This delivers better performance without requiring any code changes, other than specifying the protocol when creating the connection.</li>



<li>JEP 524: PEM Encoding for Cryptographic Objects. Cryptographic objects such as public keys, private keys, certificates, and certificate revocation lists are often transmitted using e-mail, and the Privacy-Enhanced Mail (PEM) format is ideal for this. This JEP adds a concise API for converting between PEM text and cryptographic objects, and back again.</li>



<li>JEP 525: Structured Concurrency. Writing cooperative multi-threaded code is notoriously difficult to get right. Over its history, Java has added many features to make this easier, from the Concurrency Utilities APIs to the ForkJoin framework and, more recently, Virtual Threads. Structured Concurrency adds to this toolbox, treating groups of related tasks running in different threads as single units of work. This allows streamlined error handling and cancellation, improving reliability and enhancing observability. Developers will be familiar with the approach, since it is like the try-with-resources syntax.</li>



<li>JEP 526: Lazy Constants. This was previously called “stable values,” but the new name better reflects the goal of this feature: to provide objects that hold unmodifiable data. Although Java has final fields, Lazy Constants offer greater flexibility in the timing of their initialisation.</li>



<li>JEP 529: The Vector API. This JEP is now incubating for the eleventh time, which is a record for a JEP. As this API is part of the larger Project Valhalla, it will not be finalized until more of that project is incorporated into the Java platform. In this API, vectors refer to the very wide registers available in modern processors. Specific instructions allow for multiple values to have the same operation applied to them across these registers in a single clock cycle, greatly improving performance for numerically intensive operations (like AI). Although the JIT compiler will auto-vectorize code it recognizes, it is unable to do this in all situations where vectors can be used. With the Vector API, a developer can explicitly specify how they want the vector operations to be used by the JIT compiler.</li>



<li>JEP 504: Remove the Applet API. Applets were what really set Java on its road to success when it was first launched. However, browsers (where Applets were used) have long since moved on, and no mainstream browser supports the Java Plugin required to run Applets. The Java Plugin was <a href="https://docs.oracle.com/en/java/javase/25/migrate/significant-changes-jdk-11.html" data-type="link" data-id="https://docs.oracle.com/en/java/javase/25/migrate/significant-changes-jdk-11.html">removed from Oracle JDK 11</a>, is not part of the OpenJDK project, and remains closed-source. The Applet API is the final remaining component and has been deprecated for removal since JDK 17.</li>
</ul>



<h2 class="wp-block-heading">Improvements in the Java runtime</h2>



<p>Finally, we have runtime changes:</p>



<ul class="wp-block-list">
<li>JEP 500: Prepare to make <code>final</code> mean final. As mentioned earlier, Java has the concept of <code>final</code> fields, whose value can be set only once. Although a <code>final</code> field cannot be modified simply by assigning it a new value, it is still possible to change its value in certain cases through a feature called deep reflection. This limits what the <a href="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html" data-type="link" data-id="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html">JVM</a> can do to optimize performance, since it still needs to accommodate the possibility of a change. This JEP makes it clear to developers that in a future release, they will no longer be able to use deep reflection in this way and should change their code in preparation.</li>



<li>JEP 516: Ahead-of-time (AOT) object caching with any GC. This is part of the larger OpenJDK Project Leyden, whose goal is to reduce the time an application takes to warm up to its optimum performance level. The need to identify frequently used code and compile it as the application is running is why performance does not start at full speed. This JEP enables the AOT cache, which is data about loaded and initialized classes, to work with any garbage collector. This was necessary because the ZGC collector did not work with the AOT cache.</li>



<li>JEP 522: G1 GC improve throughput by reducing synchronization. G1 is the default garbage collector in the HotSpot VM and works well in many situations. This JEP improves efficiency for this collector by reducing the amount of synchronization required between the GC and application threads. This is transparent to application code.</li>
</ul>



<p>In conclusion, despite not including as many JEPs as some releases, there are still useful and interesting new additions to the Java platform. Although JDK 26 is not an LTS version, developers should still test their applications with this release to avoid accumulated issues when JDK 29, the next LTS release, appears next year.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Coding Implementation to Portfolio Optimization with skfolio for Building Testing, Tuning, and Comparing Modern Investment Strategies]]></title>
<description><![CDATA[In this tutorial, we explore skfolio, a scikit-learn compatible portfolio optimization library that helps us build, compare, and evaluate different investment strategies in a structured Python workflow. We start by loading S&P 500 price data, converting it into returns, and creating a time-based ...]]></description>
<link>https://tsecurity.de/de/3509305/ai-nachrichten/a-coding-implementation-to-portfolio-optimization-with-skfolio-for-building-testing-tuning-and-comparing-modern-investment-strategies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509305/ai-nachrichten/a-coding-implementation-to-portfolio-optimization-with-skfolio-for-building-testing-tuning-and-comparing-modern-investment-strategies/</guid>
<pubDate>Tue, 12 May 2026 09:05:43 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this tutorial, we explore skfolio, a scikit-learn compatible portfolio optimization library that helps us build, compare, and evaluate different investment strategies in a structured Python workflow. We start by loading S&amp;P 500 price data, converting it into returns, and creating a time-based train-test split suitable for financial analysis. From there, we build simple baseline […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/05/12/a-coding-implementation-to-portfolio-optimization-with-skfolio-for-building-testing-tuning-and-comparing-modern-investment-strategies/">A Coding Implementation to Portfolio Optimization with skfolio for Building Testing, Tuning, and Comparing Modern Investment Strategies</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/6481e783337a99ab2f9988eb8578c0ed3e72e5ca: [Docathon 2026] Convert torch.rst to MyST Markdown (#182713)]]></title>
<description><![CDATA[Description
This PR converts the core docs/source/torch.rst file to MyST Markdown (.md).
Fixes #182512
Changes Made
File Migration: Used git mv to rename docs/source/torch.rst to docs/source/torch.md to preserve the git history and log.
File Conversion: Used rst-to-myst tool for converting the fi...]]></description>
<link>https://tsecurity.de/de/3507979/downloads/trunk6481e783337a99ab2f9988eb8578c0ed3e72e5ca-docathon-2026-convert-torchrst-to-myst-markdown-182713/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507979/downloads/trunk6481e783337a99ab2f9988eb8578c0ed3e72e5ca-docathon-2026-convert-torchrst-to-myst-markdown-182713/</guid>
<pubDate>Mon, 11 May 2026 19:46:54 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Description<br>
This PR converts the core docs/source/torch.rst file to MyST Markdown (.md).<br>
Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4385689986" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/182512" data-hovercard-type="issue" data-hovercard-url="/pytorch/pytorch/issues/182512/hovercard" href="https://github.com/pytorch/pytorch/issues/182512">#182512</a></p>
<p>Changes Made<br>
File Migration: Used git mv to rename docs/source/torch.rst to docs/source/torch.md to preserve the git history and log.</p>
<p>File Conversion: Used rst-to-myst tool for converting the file</p>
<p>Test<br>
Local Build: Successfully ran make html and verified the documentation builds without errors.</p>
<p>Visual Verification: Used make serve to verify that the rendered HTML for torch.md is identical in appearance and functionality to the original .rst version.</p>
<p>Linting: Ran lintrunner -m main from the root; no issues were found.</p>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4394426288" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/182713" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/182713/hovercard" href="https://github.com/pytorch/pytorch/pull/182713">#182713</a><br>
Approved by: <a href="https://github.com/svekars">https://github.com/svekars</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Detect Go’s silent arithmetic bugs with go-panikint]]></title>
<description><![CDATA[Go’s arithmetic operations on standard integer types are silent by default, meaning overflows “wrap around” without panicking. This behavior has hidden an entire class of security vulnerabilities from fuzzing campaigns. Today we’re changing that by releasing go-panikint, a modified Go compiler th...]]></description>
<link>https://tsecurity.de/de/3501447/it-security-nachrichten/detect-gos-silent-arithmetic-bugs-with-go-panikint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501447/it-security-nachrichten/detect-gos-silent-arithmetic-bugs-with-go-panikint/</guid>
<pubDate>Fri, 08 May 2026 23:20:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Go’s arithmetic operations on standard integer types are silent by default, meaning overflows “wrap around” without panicking. This behavior has hidden an entire class of security vulnerabilities from fuzzing campaigns. Today we’re changing that by releasing <a href="https://github.com/trailofbits/go-panikint">go-panikint</a>, a modified Go compiler that turns silent integer overflows into explicit panics. We used it to find a live integer overflow in the Cosmos SDK’s RPC pagination logic, showing how this approach eliminates a major blind spot for anyone fuzzing Go projects. (The issue in the Cosmos SDK has not been fixed, but a <a href="https://github.com/cosmos/cosmos-sdk/pull/25049">pull request</a> has been created to mitigate it.)</p>
<h2>The sound of silence</h2>
<p>In Rust, debug builds are designed to panic on integer overflow, a feature that is highly valuable for fuzzing. Go, however, takes a different approach. In Go, arithmetic overflows on standard integer types are silent by default. The operations simply “wrap around,” which can be a risky behavior and a potential source of serious vulnerabilities.</p>
<p>This is not an oversight but a deliberate, long-debated <a href="https://github.com/golang/go/issues/30613">design choice</a> in the Go community. While Go’s memory safety prevents entire classes of vulnerabilities, its integers are not safe from overflow. Unchecked arithmetic operations can lead to logic bugs that bypass critical security checks.</p>
<p>Of course, static analysis tools can identify potential integer overflows. The problem is that they often produce a high number of false positives. It’s difficult to know if a flagged line of code is truly reachable by an attacker or if the overflow is actually harmless due to mitigating checks in the surrounding code. Fuzzing, on the other hand, provides a definitive answer: if you can trigger it with a fuzzer, the bug is real and reachable. However, the problem remained that Go’s default behavior wouldn’t cause a crash, letting these bugs go undetected.</p>
<h2>How go-panikint works</h2>
<p>To solve this, we forked the Go compiler and modified its backend. The <a href="https://github.com/trailofbits/go-panikint/blob/eb29f694a03fbe38df5ab618acdd0f8b75d4ddd8/src/cmd/compile/internal/ssagen/ssa.go#L5320-L5987">core</a> of go-panikint’s functionality is injected during the compiler’s conversion of code into <a href="https://en.wikipedia.org/wiki/Static_single-assignment_form">Static Single Assignment</a> (SSA) form, a lower-level intermediate representation (IR). At this stage, for every mathematical operation, our compiler inserts additional checks. If one of these checks fails at runtime, it triggers a panic with a detailed error message. These runtime checks are compiled directly into the final binary.</p>
<p>In addition to arithmetic overflows, go-panikint can also detect integer truncation issues, where converting a value to a smaller integer type causes data loss. Here’s an example:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">var</span><span class="w"> </span><span class="nx">x</span><span class="w"> </span><span class="kt">uint16</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="mi">256</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nx">result</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="nb">uint8</span><span class="p">(</span><span class="nx">x</span><span class="p">)</span><span class="w"> </span></span></span></code></pre>
 <figcaption><span>Figure 1: Conversion leading to data loss due to unsafe casting</span></figcaption>
</figure>
<p>While this feature is functional, we found that it generated false positives during our fuzzing campaigns. For this reason, we will not investigate further and will focus on arithmetic issues.</p>
<p>Let’s analyze the checks for a program that adds up two numbers. If we compile this program and then decompile it, we can clearly see how these checks are inserted. Here, the <code>if</code> condition is used to detect signed integer overflow:</p>
<ul>
<li>
<p>Case 1: Both operands are negative. The result should also be negative. If instead the result (<code>sVar23</code>) becomes larger (less negative or even positive), this indicates signed overflow.</p>
</li>
<li>
<p>Case 2: Both operands are non-negative. The result should be greater than or equal to each operand. If instead the result becomes smaller than one operand, this indicates signed overflow.</p>
</li>
<li>
<p>Case 3: Only one operand is negative. In this case, signed overflow cannot occur.</p>
</li>
</ul>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">if</span> <span class="p">(</span><span class="o">*</span><span class="n">x_00</span> <span class="o">==</span> <span class="sc">'+'</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">val</span> <span class="o">=</span> <span class="p">(</span><span class="n">uint32</span><span class="p">)</span><span class="o">*</span><span class="p">(</span><span class="n">undefined8</span> <span class="o">*</span><span class="p">)(</span><span class="n">puVar9</span> <span class="o">+</span> <span class="mh">0x60</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">sVar23</span> <span class="o">=</span> <span class="n">val</span> <span class="o">+</span> <span class="n">sVar21</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">puVar17</span> <span class="o">=</span> <span class="n">puVar9</span> <span class="o">+</span> <span class="mi">8</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(((</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span> <span class="o">&lt;</span> <span class="mi">0</span> <span class="o">&amp;&amp;</span> <span class="n">sVar21</span> <span class="o">&lt;</span> <span class="mi">0</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="p">(</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span> <span class="o">&lt;</span> <span class="n">sVar23</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="p">((</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span> <span class="o">&gt;=</span> <span class="mi">0</span> <span class="o">&amp;&amp;</span> <span class="n">sVar21</span> <span class="o">&gt;=</span> <span class="mi">0</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">sVar23</span> <span class="o">&lt;</span> <span class="p">(</span><span class="n">sdword</span><span class="p">)</span><span class="n">val</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">runtime</span><span class="p">.</span><span class="nf">panicoverflow</span><span class="p">();</span> <span class="c1">// &lt;-- panic if overflow caught
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="k">goto</span> <span class="n">LAB_1000a10d4</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
 <figcaption><span>Figure 2: Example of a decompiled multiplication from a Go program</span></figcaption>
</figure>
<p>Using go-panikint is straightforward. You simply compile the tool and then use the resulting Go binary in place of the official one. All other commands and build processes remain exactly the same, making it easy to integrate into existing workflows.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">git clone https://github.com/trailofbits/go-panikint
</span></span><span class="line"><span class="cl"><span class="nb">cd</span> go-panikint/src <span class="o">&amp;&amp;</span> ./make.bash
</span></span><span class="line"><span class="cl"><span class="nb">export</span> <span class="nv">GOROOT</span><span class="o">=</span>/path/to/go-panikint <span class="c1"># path to the root of go-panikint</span>
</span></span><span class="line"><span class="cl">./bin/go <span class="nb">test</span> -fuzz<span class="o">=</span>FuzzIntegerOverflow <span class="c1"># fuzz our harness</span></span></span></code></pre>
 <figcaption><span>Figure 3: Installation and usage of go-panikint</span></figcaption>
</figure>
<p>Let’s try with a very simple program. This program has no fuzzing harness, only a main function to execute for illustration purposes.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kn">package</span><span class="w"> </span><span class="nx">main</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kn">import</span><span class="w"> </span><span class="s">"fmt"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kd">func</span><span class="w"> </span><span class="nf">main</span><span class="p">()</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kd">var</span><span class="w"> </span><span class="nx">a</span><span class="w"> </span><span class="kt">int8</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="mi">120</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kd">var</span><span class="w"> </span><span class="nx">b</span><span class="w"> </span><span class="kt">int8</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="mi">20</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nx">result</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="nx">a</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="nx">b</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nx">fmt</span><span class="p">.</span><span class="nf">Printf</span><span class="p">(</span><span class="s">"%d + %d = %d\n"</span><span class="p">,</span><span class="w"> </span><span class="nx">a</span><span class="p">,</span><span class="w"> </span><span class="nx">b</span><span class="p">,</span><span class="w"> </span><span class="nx">result</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">}</span></span></span></code></pre>
 <figcaption><span>Figure 4: Simple integer overflow bug</span></figcaption>
</figure>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">$ go run poc.go <span class="c1"># native compiler </span>
</span></span><span class="line"><span class="cl"><span class="m">120</span> + <span class="nv">20</span> <span class="o">=</span> -116
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ <span class="nv">GOROOT</span><span class="o">=</span><span class="nv">$pwd</span> ./bin/go run poc.go <span class="c1"># go-panikint</span>
</span></span><span class="line"><span class="cl">panic: runtime error: integer overflow in int8 addition operation
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">goroutine <span class="m">1</span> <span class="o">[</span>running<span class="o">]</span>:
</span></span><span class="line"><span class="cl">main.main<span class="o">()</span>
</span></span><span class="line"><span class="cl">	./go-panikint/poc.go:8 +0xb8
</span></span><span class="line"><span class="cl"><span class="nb">exit</span> status <span class="m">2</span></span></span></code></pre>
 <figcaption><span>Figure 5: Running poc.go with both compilers</span></figcaption>
</figure>
<p>However, not all overflows are bugs; some are intentional, especially in low-level code like the Go compiler itself, used for randomness or cryptographic algorithms. To handle these cases, we built two filtering mechanisms:</p>
<ol>
<li>
<p>Source-location-based filtering: This allows us to ignore known, intentional overflows within the Go compiler’s own source code by whitelisting some given file paths.</p>
</li>
<li>
<p>In-code comments: Any arithmetic operation can be marked as a non-issue by adding a simple comment, like <code>// overflow_false_positive</code> or <code>// truncation_false_positive</code>. This prevents <code>go-panikint</code> from panicking on code that relies on wrapping behavior.</p>
</li>
</ol>
<h2>Finding a real-world bug</h2>
<p>To validate our tool, we used it in a fuzzing campaign against the Cosmos SDK and discovered an <a href="https://github.com/cosmos/cosmos-sdk/issues/25006">integer overflow vulnerability</a> in the RPC pagination logic. When the sum of the offset and limit parameters in a query exceeded the maximum value for a <code>uint64</code>, the query would return an empty list of validators instead of the expected set.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="c1">// Paginate does pagination of all the results in the PrefixStore based on the</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="c1">// provided PageRequest. onResult should be used to do actual unmarshaling.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kd">func</span><span class="w"> </span><span class="nf">Paginate</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">prefixStore</span><span class="w"> </span><span class="nx">types</span><span class="p">.</span><span class="nx">KVStore</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">pageRequest</span><span class="w"> </span><span class="o">*</span><span class="nx">PageRequest</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">onResult</span><span class="w"> </span><span class="kd">func</span><span class="p">(</span><span class="nx">key</span><span class="p">,</span><span class="w"> </span><span class="nx">value</span><span class="w"> </span><span class="p">[]</span><span class="kt">byte</span><span class="p">)</span><span class="w"> </span><span class="kt">error</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">)</span><span class="w"> </span><span class="p">(</span><span class="o">*</span><span class="nx">PageResponse</span><span class="p">,</span><span class="w"> </span><span class="kt">error</span><span class="p">)</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="o">...</span><span class="w"> 
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nx">end</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="nx">pageRequest</span><span class="p">.</span><span class="nx">Offset</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="nx">pageRequest</span><span class="p">.</span><span class="nx">Limit</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="o">...</span><span class="w"> </span></span></span></code></pre>
 <figcaption><span>Figure 6: end can overflow uint64 and return an empty validator list if user provides a large Offset</span></figcaption>
</figure>
<p>This finding demonstrates the power of combining fuzzing with runtime checks: <code>go-panikint</code> turned the silent overflow into a clear panic, which the fuzzer reported as a crash with a reproducible test case. A <a href="https://github.com/cosmos/cosmos-sdk/pull/25049">pull request</a> has been created to mitigate the issue.</p>
<h2>Use cases for researchers and developers</h2>
<p>We built <code>go-panikint</code> with two main use cases in mind:</p>
<ol>
<li>
<p><strong>Security research and fuzzing:</strong> For security researchers, <code>go-panikint</code> is a great new tool for bug discovery. By simply replacing the Go compiler in a fuzzing environment, researchers can uncover two whole new classes of vulnerabilities that were previously invisible to dynamic analysis.</p>
</li>
<li>
<p><strong>Continuous deployment and integration:</strong> Developers can integrate <code>go-panikint</code> into their CI/CD pipelines and potentially uncover bugs that standard test runs would miss.</p>
</li>
</ol>
<p>We invite the community to try <code>go-panikint</code> on your own projects, integrate it into your CI pipelines, and help us uncover the next wave of hidden arithmetic bugs.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Git and hg]]></title>
<description><![CDATA[John Goerzen recently posted about  Git, Mercurial and Bzr that I found interesting, especially since I used to be in the hg camp, but have been gradually using git more and more, even to the point making minor improvements to the git documentation and writing the git mergetool, since being able ...]]></description>
<link>https://tsecurity.de/de/3501050/unix-server/git-and-hg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501050/unix-server/git-and-hg/</guid>
<pubDate>Fri, 08 May 2026 23:03:05 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://changelog.complete.org/">John Goerzen</a> recently posted about  <a href="http://changelog.complete.org/posts/594-More-on-Git,-Mercurial,-and-Bzr.html">Git, Mercurial and Bzr</a> that I found interesting, especially since I used to be in the hg camp, but have been gradually using git more and more, even to the point making minor improvements to the git documentation and writing the <a href="http://www.kernel.org/pub/software/scm/git/docs/git-mergetool.html">git mergetool</a>, since being able to automatically fire up a graphical merge tool was one of the features which I missed from hg. So while I haven’t yet converted the primary SCM repository for e2fsprogs to use git (yet), I’ve reached an opposite concolusion from John, and yet, I can’t really argue with his observations.</p>
<p><!-- raw HTML omitted -->The main reason why I’ve come out in favor of git is that I see its potential as being greater than hg, and so while it definitely has some ease-of-use and documentation shortcomings, in the long run I think it has “more legs” than hg, and with the release of git 1.5.0, it became clear that the git community was willing to work on these particular shortcomings, which is why I started working on it and making plans to migrate e2fsprogs to use git. The main reasons why I think git is more powerful is that not just that it supports lightweight branches inside a single repository (although I really do like that a lot since it makes it a lot easier to run multiple experiments in parallel and switch back and forth between them), but also because git is much more Unix-like; there are lots of tools that enable scripting for either new git extensions or for ad-hoc shell pipelines that you can’t really easily do in hg without breaking into Python. <!-- raw HTML omitted --></p>
<p>But git definitely does have shortcomings, and John is on the mark with most of them. Git’s documentation is very poor. Part of the problem stems for tutorials that were written to work with older versions of git (don’t try using anything older than git 1.5 if you are a git newbie; git 1.4.x is far more user-hostile) or were written for use with systems built on top of git 1.4.x, such as Cogito. (I don’t recommend Cogito, since git 1.5 is significantly more usable, and I’ve always found Cogito to be more confusing that just using stack git.) The tutorials that are distributed with git 1.5 are much better, but they clear do need more work.</p>
<p>It is true that the many of the man pages in git are lacking, and John’s criticism of the fact that many man pages do not list all of the options that they take, but rather refer to other man pages is on point and accurate. It has gotten better (take a look at the git-diff man page from the git 1.4.x days, and laugh or cry, depending on your point of view) but there is still much work to be done. In practice, the better way to use the git man pages is to skip past the options section, and take a look at the Examples section. This shows a number of ways that a particular command might be used, just as a Unix master might say, “Grasshoper, see how you can use awk to do all of these amazing things.”</p>
<p>I do take issue with John’s assertion that git’s philosophy has been to make life easy for the central maintainer, and not to pay much attention to the needs of individual contributors. That may have been Linus’s development priorities but with Junio having taking over maintenance, there have been a lot of improvements in git 1.5.0 to make life easier for people who are tracking remote repositories and making changes, in particular the <a href="http://www.kernel.org/pub/software/scm/git/docs/git-remote.html">git remote</a> command.</p>
<p>The most interesting observation which John made was the non-intuitive semantics of git-format-patches, and I did find it interesting that one commenter posted a solution which made perfect sense given other git commands, and yet didn’t work. Obviously the person who posted the comment didn’t bother to try it first, probably because in most other places git is actually pretty consistent; but git-format-patch is one of the places where most painfully is not. I view this as a bug that should be fixed, and fortunately I think it can be fixed without breaking the git-format-patches is currently being used. (The problem is that it doesn’t use the standard notation so it is more convenient in the common case of how it is normally used, where the end point is not specified and is always the the tip of the current branch. I believe we can avoid the UI surprise by making git-format-patch use the standard revision range parsing if parameter contains the “..” or “…” operators. I’ll have to try to prepare a patch which does this and see whether it gets accepted.)</p>
<p>So basically git does have short-comings, yes, but people will come out in different places about which tools is best for them, and that’s OK. Actually, I think the ultimate solution for this problem is to build a bidrectoinal hg/git gateway. There are tools that will export from hg to git, and vice versa, and they are actually pretty sophisticated. I don’t think it should be that painful to create a tool that does incremental exports in both directions, maintaining state so that the right thing happens when a commit gets made on the git side, and gets exported into hg, or vice versa. Ultimately I think that’s the best solution, since that way people can use whatever tool they want, and still contribute and development as first class citizens. This is the main reason why I’ve held off on converting e2fsprogs to git (although I have made some private test repositories which I’ll use to take advantage of git’s superior annotation and query/log utilities); I don’t want to make a git repository of e2fsprogs public until I’m sure that a bidrectional gateway tool won’t require me to make any changes that affect the commit-id’s, since that would invalidate any work that people have done that was based on a clone of the coverted git repository.</p>
<p>I have a rough design for how to do the bidirectional gateway, but the issue is finding time to implement it. Anyone with free time looking for a project? If so, contact me. I probably should have written this up as a potential Google Summer of Code project, but it’s too late for this year. Oh, well.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reflections on a complaint from a frustrated git user]]></title>
<description><![CDATA[Last week, Scott James Remnant posted a series of “Git Sucks” on his blog, starting with this one here, with follow up entries here and here.  His problem?  To quote Scott, “I want to put a branch I have somewhere so somebody else can get it.  That’s the whole point of distributed revision-contro...]]></description>
<link>https://tsecurity.de/de/3500969/unix-server/reflections-on-a-complaint-from-a-frustrated-git-user/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500969/unix-server/reflections-on-a-complaint-from-a-frustrated-git-user/</guid>
<pubDate>Fri, 08 May 2026 23:00:41 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last week, Scott James Remnant posted a series of “Git Sucks” on his blog, starting with this one <!-- raw HTML omitted -->here<!-- raw HTML omitted -->, with follow up entries <!-- raw HTML omitted -->here<!-- raw HTML omitted --> and <!-- raw HTML omitted -->here<!-- raw HTML omitted -->.  His problem?  To quote Scott, “I want to put a branch I have somewhere so somebody else can get it.  That’s the whole point of distributed revision-control, <em>collaboration</em>.”   He thought this was a “mind-numbingly trivial” operation, and was frustrated when it wasn’t a one-line command in git.</p>
<p>Part of the problem here is that for most git workflows, <em>most people don’t actually use “git push”</em>.   That’s why it’s not covered in the git tutorial (this was a point of frustration for Scott).   In fact, in most large projects, the number of people need to use the “scm push” command is a very small percentage of the developer population, just as very few developers have commit privileges and are allowed to use the “svn commit” command in a project using Subversion.  When you have a centralized repository, only the privileged few will given commit privileges, for obvious security and quality control reasons.</p>
<p>Ah, but in a distributed SCM world, things are more democratic — anyone can have their own repository, and so everyone can type the commands “git commit” or “bzr commit”.   While this is true, the number of people who need to be able to publish their own branch is small.  After all, the overhead in setting up your own server just so people can “pull” changes from you is quite large; and if you are just getting started, and only need to submit one or two patches, or even a large series of patches, e-mail is a far more convenient route.  This is especially true in the early days of git’s development, before web sites such as <a href="http://git.or.cz/">git.or.cz</a>, <!-- raw HTML omitted -->github<!-- raw HTML omitted -->, and <!-- raw HTML omitted -->gitorious<!-- raw HTML omitted --> made it much easier for people to publish their own git repository.   Even for a large series of changes, tools such as “<!-- raw HTML omitted -->git format-patch<!-- raw HTML omitted -->” and “<!-- raw HTML omitted -->git send-email<!-- raw HTML omitted -->” are very convenient for sending a patch series, and on the receiving side, the maintainer can use “<!-- raw HTML omitted -->git am<!-- raw HTML omitted -->” to apply a patch series sent via e-mail.</p>
<p>It turns out that from a maintainer’s point of view, reviewing patches via e-mail is often much more convenient.  Especially for developers who are just starting out with submitting patches to a project, it’s rare that a patch is of sufficiently high quality that it can be applied directly into the repository without needing fixups of one kind or another.   The patch might not have the right coding style compared to the surrounding code, or it might be fundamentally buggy because the patch submitter didn’t understand the code completely.   Indeed, more often than not, when someone submits a patch to me, it is more useful for indicating the location of the bug more than anything else, and I often have to completely rewrite the patch before it enters into the e2fsprogs mainline repository.    Given that, publishing a patch that will require modification in a public repository where it is ready to be pulled just doesn’t make sense for many entry-level patch submitters.   E-mail is in fact less work, and more appropriate for review purposes.</p>
<p>It is only when a mid-level to senior developer is trusted to create high quality patches that do not need review that publishing their branch in a pull-ready form really makes sense.   And that is fairly rare, and why it is not covered in most entry-level git documentation and tutorials.   Unfortunately, many people expect to see the command “scm push” in a distributed SCM, and since “git pull” <strong>is</strong> a commonly used command for beginning git users, they expect that they should use “git push” as well — not realizing that in a distributed SCM, “push” and “pull” are <strong>not</strong> symmetric operations.   Therefore, while most git users won’t <em>need</em> to use “git push”, git tutorials and other web pages which are attempting to introduce git to new users probably do need to do a better job explaining why most beginning participants in a project probably don’t need their own publically accessible repository that other people can pull from, and which they can push changes for publication.</p>
<p>There is one exception to this, of course, and this is a developer who wants to get started using git for a new project which he or she is starting and is the author/maintainer, or someone who is interested in converting their project to git.   And this is where bzr has an advantage over git, in that bzr is primarily funded by Canonical, which has a strong interest in pushing an on-line web service, Launchpad.   This makes it easier for bzr to have relatively simple recipes for sharing a bzr repository, since the user doesn’t need to have access to a server with a public IP address, or need to set up a web or bzr server; they can simply take advantage of Launchpad.</p>
<p>Of course, there are web sites which make it easy for people to publish their git repositories; earlier, I had mentioned <a href="http://git.or.cz/">git.or.cz</a>, <!-- raw HTML omitted -->github<!-- raw HTML omitted -->, and <!-- raw HTML omitted -->gitorious<!-- raw HTML omitted -->.   Currently, the git documentation and tutorials don’t mention them since they aren’t formally affiliated with the git project (although they are used by many git users and developers and the maintainers of these sites have contributed a large amount of code and documentation to git).   This should change, I think.   Scott’s frustrations which kicked off his “git sucks” complaints would have been solved if the Git tutorial recommended that the easist ways for someone to publicly publish their repository is via one of these public web sites (although people who want to set up their own server certainly free to do so).</p>
<p>Most of these public repositories probably won’t have much reason to exist, but they don’t do much harm, and who knows?  While most of the repositories published at github and gitoriuous will be like the hundreds of thousands of abandoned projects on Sourceforge, one or two of the new projects which someone starts experimenting on at github or gitorious could turn out to be the next Ruby on Rails or Python or Linux.  And hopefully, they will allow more developers to be able to experiment with publishing commits on their own repositories, and lessen the frustrations of people like Scott who thought they needed their own repositories; whether or not a public repository is the best way for them to do what they need to do, at least this way they won’t get as frustrated about git.  🙂</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Embroidery.. gaah]]></title>
<description><![CDATA[So for Christmas, Tove got this embroidery machine from Santa Claus. Since then, she's busily been filling the kids clothes with names, re-doing their Tae-Kwon-Do uniforms etc etc.And why do I care?  It turns out that all those embroidery machines can be extended with new patterns, and most of th...]]></description>
<link>https://tsecurity.de/de/3500921/unix-server/embroidery-gaah/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500921/unix-server/embroidery-gaah/</guid>
<pubDate>Fri, 08 May 2026 22:59:24 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5sJWmUdvYU5kDX5ftKR50rrwb-hsbbR2tnTejOWpW_0H1hnlGXnVXKM11ZX15fJnbQmirz5bORSj7Y979zH0FmVe4Ackraq6A7VF-kaDOTtC5SmjeDL-LL6QDX7vOxzHxdwsh2VVNrWBx/s1600-h/s512.png"><img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5sJWmUdvYU5kDX5ftKR50rrwb-hsbbR2tnTejOWpW_0H1hnlGXnVXKM11ZX15fJnbQmirz5bORSj7Y979zH0FmVe4Ackraq6A7VF-kaDOTtC5SmjeDL-LL6QDX7vOxzHxdwsh2VVNrWBx/s320/s512.png" alt="" border="0"></a><br>So for Christmas, Tove got this embroidery machine from Santa Claus. Since then, she's busily been filling the kids clothes with names, re-doing their Tae-Kwon-Do uniforms etc etc.<br><br>And why do I care?  It turns out that all those embroidery machines can be extended with new patterns, and most of them - including the one Tove has - seem to use this special and pretty much undocumented "PES" format that was designed by Brother. So Tove has been buying embroidery patterns, but actually seeing them on the computer and transferring them to the sewing machine is a big pain.<br><br>So the above beautiful png file is what I did today. It's the result of me doing a thumbnailer for those PES files (and yes, "PES" stands for "PESky", I'm convinced), so that Tove can see the designs in her file manager as she moves them around.<br><br>I can read them (largely thanks to converting a <a href="http://bobosch.dyndns.org/embroidery/showFile.php?pes.php">php script</a> written by Robert Heel - which in turn seems to be based on a GPL C# project from <a href="http://www.njcrawford.com/embroidery-reader/">njcrawford.com</a> - into C code) and then drawing them and writing the result out as a png out with cairo. Sadly, it seems that the embroidery machine itself sometimes has a rather harder time. When uploading the designs to the machine, a number of them just say "Data Error", which is very annoying.<br><br>I wonder what those embroidery machine firmware people were thinking. No diagnostics, no nothing. If a design is too large for the hoop of the machine, the machine accepts it (no "Data Error"), but doesn't actually show or use the design - it just silently ignores it.<br><br>Whee. Undocumented formats, bad firmware, lack of sane error messages.  And did I mention crazy interfaces? The embroidery machine itself shows up as a USB storage device when you connect it, except it for some reason takes about half a minute to calm down enough to be mounted. And forget about the embroidery card reader/writer - that one needs some magic USB driver too.<br><br>But hey, if somebody else is fighting with PES files, here's a pointer to '<a href="http://git.kernel.org/?p=linux/kernel/git/torvalds/pesconvert.git;a=summary">pesconvert</a>', my git source tree for that silly thumbnailer that created the above png. You'll need pnglib-devel and cairo-devel to compile it, but it's small and simple. And in case you wonder about the source PES file, it's <a href="http://brotheraccessories.com/HomeSewing/GetCreative/free-designs.aspx?PARAM=heart">Jan_heartsdelight.pes</a>, a demonstration PES image from brother.]]></content:encoded>
</item>
<item>
<title><![CDATA[Towards a real SIGTRAN/SS7 stack in libosmo-sigtran]]></title>
<description><![CDATA[In the good old days ever since the late 1980ies - and a surprising
amount even still today - telecom signaling traffic is still carried
over circuit-switched SS7 with its TDM lines as physical layer, and not
an IP/Ethernet based transport.
When Holger first created OsmoBSC, the BSC-only version ...]]></description>
<link>https://tsecurity.de/de/3500769/unix-server/towards-a-real-sigtranss7-stack-in-libosmo-sigtran/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500769/unix-server/towards-a-real-sigtranss7-stack-in-libosmo-sigtran/</guid>
<pubDate>Fri, 08 May 2026 22:54:32 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In the good old days ever since the late 1980ies - and a surprising
amount even still today - telecom signaling traffic is still carried
over circuit-switched SS7 with its TDM lines as physical layer, and not
an IP/Ethernet based transport.</p>
<p>When Holger first created OsmoBSC, the BSC-only version of OpenBSC some
7-8 years ago, he needed to implement a minimal subset of SCCP wrapped
in TCP called <em>SCCP Lite</em>.  This was due to the simple fact that the MSC
to which it should operate implemented this non-standard protocol
stacking that was developed + deployed before the IETF SIGTRAN WG
specified M3UA or SUA came around.  But even after those were specified
in 2004, the 3GPP didn't specify how to carry A over IP in a standard
way until the end of 2008, when a first <a class="reference external" href="http://www.etsi.org/deliver/etsi_tr/143900_143999/143903/08.03.00_60/tr_143903v080300p.pdf">A interface over IP study</a>
was released.</p>
<p>As time passese, more modern MSCs of course still implement classic
circuit-switched SS7, but appear to have dropped SCCPlite in favor of
real AoIP as specified by 3GPP meanwhile.  So it's time to add this to
the osmocom universe and OsmoBSC.</p>
<p>A couple of years ago (2010-2013) implemented both classic SS7
(MTP2/MTP3/SCCP) as well as SIGTRAN stackings (M2PA/M2UA/M3UA/SUA in
Erlang. The result has been used in some production deployments, but
only with a relatively limited feature set.  Unfortunately, this code
has nto received any contributions in the time since, and I have to say
that as an open source community project, it has failed.  Also, while
Erlang might be fine for core network equipment, running it on a BSC
really is overkill.  Keep in miond that we often run OpenBSC on
really small ARM926EJS based embedded systems, much more resource
constrained than any single smartphone during the late decade.</p>
<p>In the meantime (2015/2016) we also implemented some minimal SUA support
for interfacing with UMTS femto/small cells via Iuh (see <a class="reference external" href="https://osmocom.org/projects/osmohnbgw/wiki">OsmoHNBGW</a>).</p>
<p>So in order to proceed to implement the required
SCCP-over-M3UA-over-SCTP stacking, I originally thought well, take
Holgers old SCCP code, remove it from the IPA multiplex below, stack it
on top of a new M3UA codebase that is copied partially from SUA.</p>
<p>However, this falls short of the goals in several ways:</p>
<ul class="simple">
<li><p>The application shouldn't care whether it runs on top of SUA or SCCP,
it should use a unified interface towards the SCCP Provider.
OsmoHNBGW and the SUA code already introduce such an interface baed on
the SCCP-User-SAP implemented using <a class="reference external" href="http://ftp.osmocom.org/api/latest/libosmocore/core/html/group__prim.html">Osmocom primitives (osmo_prim)</a>.
However, the old OsmoBSC/SCCPlite code doesn't have such abstraction.</p></li>
<li><p>The code should be modular and reusable for other SIGTRAN stackings
as required in the future</p></li>
</ul>
<p>So I found myself sketching out what needs to be done and I ended up
pretty much with a re-implementation of large parts.  Not quite fun, but
definitely worth it.</p>
<p>The strategy is:</p>
<ul class="simple">
<li><p>Implement the SCCP SCOC state machines for connection-oriented SCCP
(of which Iu and A interface are probably the only users) using
<a class="reference external" href="http://ftp.osmocom.org/api/latest/libosmocore/core/html/group__fsm.html">Osmcoom Finite State Machines (osmo_fsm)</a>.</p></li>
<li><p>Migrate the existing SUA code on top of that, maintaining the existing
osmo_prim based <a class="reference external" href="http://git.osmocom.org/libosmo-sccp/tree/include/osmocom/sigtran/sccp_sap.h">SCCP User SAP</a></p></li>
<li><p>Implement <a class="reference external" href="http://git.osmocom.org/libosmo-sccp/commit/?h=laforge/sigtran&amp;id=dc923e49cd3b623dab05f6016a3e935d7c652cb3">SCCP to SUA and vice-versa message transcoding</a>
to makes sure the bulk of the code has to deal only with one message
format (parsed SUA).</p></li>
<li><p>Introduce a <a class="reference external" href="http://git.osmocom.org/libosmo-sccp/commit/?h=laforge/sigtran&amp;id=21c8a1bcc8f853f3da05d71c4b4fbea6faf53b24">MTP SAP</a>
at the lower boundary of the SCCP code</p></li>
<li><p>Implement <a class="reference external" href="http://git.osmocom.org/libosmo-sccp/commit/?h=laforge/sigtran&amp;id=50e931338dfa1ad570734b80cce065ab611929aa">xUA ASP and AS statemachines using osmo_fsm</a>
and add ASPTM/ASPSM support to SUA (was missing so far) * Implement</p></li>
<li><p>Implement M3UA using the xUA ASP and AS FSMs as well as the general
<a class="reference external" href="http://git.osmocom.org/libosmo-sccp/tree/src/xua_msg.c">xUA message encoder/decoder</a>,
offering the MTP SAP toward SCCP</p></li>
</ul>
<p>And then finally stack all those bits on top of each other, rendering a
fairly clean and modern implementation that can be used with the IuCS of
the virtually unmodified OsmmoHNBGW, OsmoCSCN and OsmoSGSN for testing.</p>
<p>Next steps in the direction of the AoIP are:</p>
<ul class="simple">
<li><p>Implementation of the MTP-SAP based on the IPA transport</p></li>
<li><p>Binding the new SCCP code on top of that</p></li>
<li><p>Converting OsmoBSC code base to use the SCCP-User-SAP for its
signaling connection</p></li>
</ul>
<p>From that point onwards, OsmoBSC doesn't care anymore whether it
transports the BSSAP/BSSMAP messages of the A interface over
SCCP/IPA/TCP/IP (SCCPlite) SCCP/M3UA/SCTP/IP (3GPP AoIP), or even
something like SUA/SCTP/IP.</p>
<p>However, the 3GPP AoIP specs (unlike SCCPlite) actually modify the
BSSAP/BSSMAP payload.  Rather than using Circuit Identifier Codes and
then mapping the CICs to UDP ports based on some secret conventions,
they actually encapsulate the IP address and UDP port information for
the RTP streams.  This is of course the cleaner and more flexible
approach, but it means we'll have to do some further changes inside the
actual BSC code to accommodate this.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Converting Engines to OpenSSL-3 Providers]]></title>
<description><![CDATA[Engines in OpenSSL have a long history of providing new algorithms (Russian GOST hash/signature etc) but they can also be used to interface external crypto tokens (pkcs#11) or even key managers like my own TPM engine. I’ve actually been using my TPM2 engine for nearly a decade so that I no longer...]]></description>
<link>https://tsecurity.de/de/3500586/unix-server/converting-engines-to-openssl-3-providers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500586/unix-server/converting-engines-to-openssl-3-providers/</guid>
<pubDate>Fri, 08 May 2026 22:49:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Engines in OpenSSL have a long history of providing new algorithms (Russian GOST hash/signature etc) but they can also be used to interface external crypto tokens (pkcs#11) or even key managers like my own TPM engine. I’ve actually been using my TPM2 engine for nearly a decade so that I no longer have to have […]]]></content:encoded>
</item>
<item>
<title><![CDATA[API Security Operations: How to Move from Visibility to Measurable Risk Reduction]]></title>
<description><![CDATA[A five-level operating model for turning API security visibility into measurable risk reduction, faster remediation, and confident digital growth — without slowing development. What is API security operationalization? API security operationalization is the process of converting API discovery and ...]]></description>
<link>https://tsecurity.de/de/3492559/it-security-nachrichten/api-security-operations-how-to-move-from-visibility-to-measurable-risk-reduction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492559/it-security-nachrichten/api-security-operations-how-to-move-from-visibility-to-measurable-risk-reduction/</guid>
<pubDate>Wed, 06 May 2026 13:54:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A five-level operating model for turning API security visibility into measurable risk reduction, faster remediation, and confident digital growth — without slowing development. What is API security operationalization? API security operationalization is the process of converting API discovery and visibility into continuous, measurable risk reduction across discovery, vulnerability identification, prioritization, mitigation, and scaling. It moves […]</p>
<p>The post <a href="https://www.imperva.com/blog/api-security-operations-from-visibility-to-risk-reduction/">API Security Operations: How to Move from Visibility to Measurable Risk Reduction</a> appeared first on <a href="https://www.imperva.com/blog">Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[API Security Operations: How to Move from Visibility to Measurable Risk Reduction]]></title>
<description><![CDATA[A five-level operating model for turning API security visibility into measurable risk reduction, faster remediation, and confident digital growth — without slowing development. What is API security operationalization? API security operationalization is the process of converting API discovery and ...]]></description>
<link>https://tsecurity.de/de/3492501/it-security-nachrichten/api-security-operations-how-to-move-from-visibility-to-measurable-risk-reduction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492501/it-security-nachrichten/api-security-operations-how-to-move-from-visibility-to-measurable-risk-reduction/</guid>
<pubDate>Wed, 06 May 2026 13:38:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A five-level operating model for turning API security visibility into measurable risk reduction, faster remediation, and confident digital growth — without slowing development. What is API security operationalization? API security operationalization is the process of converting API discovery and visibility…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/api-security-operations-how-to-move-from-visibility-to-measurable-risk-reduction/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/api-security-operations-how-to-move-from-visibility-to-measurable-risk-reduction/">API Security Operations: How to Move from Visibility to Measurable Risk Reduction</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One command turns any open-source repo into an AI agent backdoor. OpenClaw proved no supply-chain scanner has a detection category for it]]></title>
<description><![CDATA[Just two months ago, researchers at the Data Intelligence Lab at the University of Hong Kong introduced CLI-Anything, a new state-of-the-art tool that analyzes any repo’s source code and generates a structured command line interface (CLI) that AI coding agents can operate with a single command. C...]]></description>
<link>https://tsecurity.de/de/3491027/it-nachrichten/one-command-turns-any-open-source-repo-into-an-ai-agent-backdoor-openclaw-proved-no-supply-chain-scanner-has-a-detection-category-for-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491027/it-nachrichten/one-command-turns-any-open-source-repo-into-an-ai-agent-backdoor-openclaw-proved-no-supply-chain-scanner-has-a-detection-category-for-it/</guid>
<pubDate>Wed, 06 May 2026 01:17:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Just two months ago, researchers at the <a href="https://github.com/HKUDS">Data Intelligence Lab at the University of Hong Kong</a> introduced <a href="https://github.com/HKUDS/CLI-Anything">CLI-Anything</a>, a new state-of-the-art tool that analyzes any repo’s source code and generates a structured command line interface (CLI) that AI coding agents can operate with a single command. </p><p>Claude Code, Codex, OpenClaw, Cursor, and GitHub Copilot CLI are all supported, and since its launch in March, CLI‑Anything has climbed to more than 30,000 GitHub stars. </p><p>But the same mechanism that makes software agent-native opens the door to agent-level poisoning. <!-- -->T<!-- -->he attack community is already discussing the implications on X and security forums, translating CLI-Anything's architecture into offensive playbooks. </p><p>The security problem is not what <a href="https://github.com/HKUDS/CLI-Anything">CLI-Anything</a> does. It is what CLI-Anything represents. </p><p>CLI-Anything generates SKILL.md files, the same instruction-layer artifacts that <a href="https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/">Snyk’s ToxicSkills research</a> found laced with 76 confirmed malicious payloads across ClawHub and skills.sh in February 2026. A poisoned skill definition does not trigger a CVE and never appears in a software bill of materials (SBOM). No mainstream security scanner has a detection category for malicious instructions embedded in agent skill definitions, because the category simply did not exist eighteen months ago.</p><p>Cisco confirmed the gap in April. “Traditional application security tools were not designed for this,” Cisco’s engineering team <a href="https://blogs.cisco.com/ai/introducing-the-ai-agent-security-scanner-for-ides-verify-your-agents">wrote in a blog post</a> announcing its AI Agent Security Scanner for IDEs. “SAST [static application security testing] scanners analyze source code syntax. SCA [software composition analysis] tools check dependency versions. Neither understands the semantic layer where MCP [Model Context Protocol] tool descriptions, agent prompts, and skill definitions operate.”</p><p>Merritt Baer, CSO of Enkrypt AI and former Deputy CISO at Amazon Web Services (AWS), told VentureBeat in an exclusive interview: “SAST and SCA were built for code and dependencies. They don’t inspect instructions.”</p><p>This is not a single-vendor vulnerability. It is a structural gap in how the entire security industry monitors software supply chains. This is the pre-exploitation window. CLI-Anything is live, the attack community is discussing it, and security directors who act now get ahead of the first incident report.</p><h2>The integration layer no stack can see</h2><p>Traditional supply-chain security operates on two layers. The code layer is where SAST works, scanning source files for insecure patterns, injection flaws, and hardcoded secrets. The dependency layer is where SCA works, checking package versions against known vulnerabilities, generating SBOMs, and flagging outdated libraries.</p><p>Agent bridge tools like CLI-Anything, MCP connectors, Cursor rules files, and Claude Code skills operate on a third layer between the other two. Call it the agent integration layer: configuration files, skill definitions, and natural-language instruction sets tell an AI agent what software can do and how to operate it. None of it looks like code. All of it executes like code. </p><p>Carter Rees, VP of AI at <a href="https://reputation.com/">Reputation</a>, told VentureBeat in an exclusive interview: “Modern LLMs [large language models] rely on third-party plugins, introducing supply chain vulnerabilities where compromised tools can inject malicious data into the conversation flow, bypassing internal safety training.”</p><p>Researchers at Griffith University, Nanyang Technological University, the University of New South Wales, and the University of Tokyo documented the attack chain in an April paper, “<a href="https://arxiv.org/abs/2604.03081">Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems</a>.” The team introduced Document-Driven Implicit Payload Execution (DDIPE), a technique that embeds malicious logic inside code examples within skill documentation. </p><p>Across four agent frameworks and five large language models, DDIPE achieved bypass rates between 11.6% and 33.5%. Static analysis caught most samples, but 2.5% evaded all four detection layers. Responsible disclosure led to four confirmed vulnerabilities and two vendor fixes.</p><h2>The kill chain security leaders need to audit</h2><p>Here's the anatomy of the kill chain: An attacker submits a SKILL.md file to an open-source project containing setup instructions, code examples, and configuration templates. It looks like standard documentation. A code reviewer would wave it through because none of it is executable. But the code examples contain embedded instructions that an agent will parse as operational directives.</p><p>A developer uses an agent bridge tool to connect their coding agent to the repository. The agent ingests the skill definition and trusts it, because no verification layer exists to distinguish benign from malicious intent at the instruction level.</p><p>The agent executes the embedded instruction using its own legitimate credentials. Endpoint detection and response (EDR) sees an approved API call from an authorized process and passes it. Data exfiltration, configuration changes, and credential harvesting are all moving through channels that the monitoring stack considers normal traffic.</p><p>Rees identified the structural flaw that makes this chain lethal. “A significant vulnerability in enterprise AI is broken access control, where the flat authorization plane of an LLM fails to respect user permissions,” he told VentureBeat. A compromised skill definition riding that flat authorization plane does not need to escalate privileges. It already has them. Every link in that chain is invisible to the current security stack.</p><p><a href="https://www.pillar.security/blog/the-agent-security-paradox-when-trusted-commands-in-cursor-become-attack-vectors">Pillar Security demonstrated</a> a variant of this chain against Cursor in January 2026 (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22708">CVE-2026-22708</a>). Implicitly trusted shell built-in commands could be poisoned through indirect prompt injection, converting benign developer commands into arbitrary code execution vectors. Users saw only the final command. The poisoning happened through other commands the IDE never surfaced for approval.</p><h2>The evidence is already in production</h2><p>In a <a href="https://findskill.ai/blog/cursor-security-review-prompt-injection-4-patterns/">documented attack chain</a> from April 2026, a crafted GitHub issue title triggered an AI triage bot wired into Cline. The bot exfiltrated a GITHUB_TOKEN, which the attacker used to publish a compromised npm dependency that installed a second agent on roughly 4,000 developer machines for eight hours. There was just one issue title. Attackers had eight hours of access. No human approved the action.</p><p>Snyk’s ToxicSkills audit scanned 3,984 agent skills from <a href="https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/">ClawHub</a>, the public marketplace for the OpenClaw agent framework, and skills.sh in February 2026. The results: 13.4% of all skills contained at least one critical security issue. Daily skill submissions jumped from less than 50 in mid-January to more than 500 by early February. The barrier to publishing was a SKILL.md markdown file and a GitHub account one week old. No code signing. No security review. No sandbox.</p><p>OpenClaw is not an outlier. It is the pattern. “The bar to entry is extremely low,” Baer said. “Adding a skill can be as simple as uploading a Word doc or lightweight config file. That’s a radically different risk profile than compiled code.” She pointed to projects like <a href="https://github.com/topics/clawpatrol">ClawPatrol</a> that have started cataloging and scanning for malicious skills, evidence the ecosystem is moving faster than enterprise defenses.</p><p>The <a href="https://snyk.io/articles/skill-md-shell-access/">ClawHavoc campaign</a>, first reported by Koi Security in late January 2026, initially identified 341 malicious skills on ClawHub. A follow-up analysis by Antiy CERT expanded the count to 1,184 compromised packages across the platform. The campaign delivered Atomic Stealer (AMOS) through skill definitions with professional documentation. Skills named solana-wallet-tracker and polymarket-trader matched what developers actively searched for.</p><p>The MCP protocol layer carries similar exposure. <a href="https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/">OX Security reported</a> in April that researchers poisoned nine out of 11 MCP marketplaces using proof-of-concept servers. Trend Micro initially found 492 MCP servers exposed to the internet with zero authentication; by April, that number had grown to 1,467. As <a href="https://www.theregister.com/2026/04/16/anthropic_mcp_design_flaw/">The Register reported</a>, the root issue lies in Anthropic’s MCP software development kit (SDK) transport mechanism. Any developer using the official SDK inherits the vulnerability class.</p><h2>VentureBeat Prescriptive Matrix: Three-layer agent supply-chain audit</h2><p>VentureBeat developed a Prescriptive Matrix by mapping the three attack layers documented in the research and incident reports above against the detection capabilities of current SAST, SCA, and agent-layer tools. Each row identifies what security teams should verify and where no scanner has coverage today.</p><table><tbody><tr><td><p><b>Layer</b></p></td><td><p><b>Threat</b></p></td><td><p><b>Current detection</b></p></td><td><p><b>Why it misses</b></p></td><td><p><b>Recommended action</b></p></td></tr><tr><td><p>1. Code</p></td><td><p>Prompt injection in AI-generated code</p></td><td><p>SAST scanners</p></td><td><p>Most SAST tools have no detection category for prompt injection in AI-generated code</p></td><td><p>Confirm that SAST scans AI-generated code for prompt injection. If not, have an open vendor conversation this quarter.</p></td></tr><tr><td><p>2. Dependencies</p></td><td><p>Malicious MCP servers, agent skills, plugin registries</p></td><td><p>SCA tools</p></td><td><p>SCA generates no AI-specific bill of materials. Agent-layer dependencies are invisible.</p></td><td><p>Confirm SCA includes MCP servers, agent skills, and plugin registries in the dependency inventory.</p></td></tr><tr><td><p>3. Agent integration</p></td><td><p>Poisoned SKILL.md files, malicious instruction sets, adversarial rules files</p></td><td><p>None until April 2026</p></td><td><p>No tool inspects the semantic meaning of agent instruction files. Baer: “We’re not inspecting intent.”</p></td><td><p>Deploy Cisco Skill Scanner or Snyk mcp-scan. Assign a team to own this layer.</p></td></tr></tbody></table><p>Baer’s diagnosis of Layer 3 applies across the entire matrix: “Current scanners look for known bad artifacts, not adversarial instructions embedded in otherwise valid skills.” <a href="https://github.com/cisco-ai-defense/skill-scanner">Cisco’s open-source Skill Scanner</a> and <a href="https://github.com/invariantlabs-ai/mcp-scan">Snyk’s mcp-scan</a> represent the first tools purpose-built for this layer.</p><h2>Security director action plan</h2><p>Here's how security leaders can get ahead of the problem. </p><p><b>Inventory every agent bridge tool in the environment. </b>This includes <a href="https://github.com/HKUDS/CLI-Anything">CLI-Anything</a>, MCP connectors, Cursor rules files, <a href="https://docs.anthropic.com/en/docs/claude-code">Claude Code</a> skills, <a href="https://github.com/features/copilot">GitHub Copilot</a> extensions. If the development team is using agent bridge tools that have not been inventoried, the risk cannot be assessed.</p><p><b>Audit agent skill sources the same way package registries get audited. </b>Baer’s framing is precise: “A skill is effectively untrusted executable intent, even if it’s just text.” <a href="https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/">Shut off ungoverned ingestion paths</a> until controls are in place. Stand up a review and allowlisting process for skills. The <a href="https://owasp.org/www-project-agentic-skills-top-10/">OWASP Agentic Skills Top 10</a> (AST01: Malicious Skills) provides the procurement framework to align controls against.</p><p><b>Deploy agent-layer scanning. </b>Evaluate <a href="https://github.com/cisco-ai-defense/skill-scanner">Cisco’s open-source Skill Scanner</a> and <a href="https://github.com/invariantlabs-ai/mcp-scan">Snyk’s mcp-scan</a> for behavioral analysis of agent instruction files. If dedicated tooling is unavailable, require a second engineer to read every SKILL.md before installation.</p><p><b>Restrict agent execution privileges and instrument runtime. </b>AI coding agents should not run with the same credential scope as the developer who invoked them. Rees confirmed the structural flaw: The flat authorization plane means a compromised skill does not need to escalate privileges. Baer’s prescription: “Instrument runtime observability. What data is the agent accessing, what actions is it taking, and are those aligned with expected behavior?”</p><p><b>Assign ownership for the gap between layers. </b>The most dangerous attacks succeed because they fall between detection categories. Assign a team to own the agent integration layer. Review every SKILL.md, MCP config, and rules file before it enters the environment.</p><h2>The gap that already has a name</h2><p>Baer underscored the dangers of this new attack vector. “This feels very similar to early container security, but we’re still in the ‘we’ll get to it’ phase across most orgs," she said. She added that, at AWS, it took a few high-profile wake-up calls before container security became table stakes. The difference this time is speed. “There’s no build pipeline, no compilation barrier. Just content," she said. </p><p>CLI-Anything is not the threat. It is the proof case that the agent integration layer exists, that it is growing fast, and that the attacker community has already found it. The 33,000 developers who starred the repository are telling security teams where software development is heading. Eighteen months ago, the detection category for agent-integration-layer poisoning did not exist. Cisco and Snyk shipped the first tools for it in April. The window between those two facts is closing. Security directors who have not begun inventory are already behind.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.4-beta.2]]></title>
<description><![CDATA[2026.5.4
Highlights

Google Meet/Voice Call: make Twilio dial-in joins speak through the realtime Gemini voice bridge with paced audio streaming, backpressure-aware buffering, barge-in queue clearing, and no TwiML fallback during realtime speech, giving Meet participants a much snappier OpenClaw ...]]></description>
<link>https://tsecurity.de/de/3488084/downloads/openclaw-202654-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488084/downloads/openclaw-202654-beta2/</guid>
<pubDate>Tue, 05 May 2026 03:46:07 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.4</h2>
<h3>Highlights</h3>
<ul>
<li>Google Meet/Voice Call: make Twilio dial-in joins speak through the realtime Gemini voice bridge with paced audio streaming, backpressure-aware buffering, barge-in queue clearing, and no TwiML fallback during realtime speech, giving Meet participants a much snappier OpenClaw voice agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373796027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77064" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77064/hovercard" href="https://github.com/openclaw/openclaw/pull/77064">#77064</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Plugins/migration: emit catalog-backed install hints when <code>plugins.entries</code> or <code>plugins.allow</code> references an official external plugin that is not installed, so upgraded configs point operators to <code>openclaw plugins install &lt;spec&gt;</code> instead of telling them to remove valid plugin config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379011890" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77483" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77483/hovercard" href="https://github.com/openclaw/openclaw/issues/77483">#77483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>OpenAI/Codex media: advertise Codex audio transcription in runtime and manifest metadata and route active Codex chat models to the OpenAI transcription default instead of sending chat model ids to audio transcription. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies: refresh runtime and provider packages including Pi 0.73.0, ACPX adapters, OpenAI, Anthropic, Slack, and TypeScript native preview, while keeping the Bedrock runtime installer override pinned below the Windows ARM Node 24 npm resolver failure.</li>
<li>Agents/performance: pass the resolved workspace through BTW, compaction, embedded-run model generation, and PDF model setup so explicit agent-dir model refreshes can reuse the current workspace-scoped plugin metadata snapshot instead of falling back to cold plugin metadata scans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379470874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77519/hovercard" href="https://github.com/openclaw/openclaw/issues/77519">#77519</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379682883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77532/hovercard" href="https://github.com/openclaw/openclaw/issues/77532">#77532</a>)</li>
<li>Plugins/performance: let unscoped model catalog and manifest-contract readers reuse the current workspace-compatible plugin metadata snapshot, avoiding repeated cold plugin metadata scans on hot control-plane paths while preserving env/config/workspace compatibility checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379470874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77519/hovercard" href="https://github.com/openclaw/openclaw/issues/77519">#77519</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379682883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77532/hovercard" href="https://github.com/openclaw/openclaw/issues/77532">#77532</a>)</li>
<li>Config/plugin auto-enable: prefer the claiming plugin manifest id over a built-in channel alias when auto-allowlisting a configured channel, so WeCom/Yuanbao-style aliases resolve to the installed plugin id. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>.</li>
<li>Secrets/apply: preserve auth-profile <code>keyRef</code> and <code>tokenRef</code> fields when scrubbing provider-target secrets, so the canonical SecretRef metadata survives <code>secrets apply</code> without keeping plaintext values. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>.</li>
<li>Plugins/active-memory: skip session-store channel entries that contain <code>:</code> when resolving the recall subagent's channel, so QQ c2c agent IDs (e.g. <code>c2c:10D4F7C2…</code>) and other scoped conversation IDs do not reach bundled-plugin <code>dirName</code> validation and crash the recall run. The same guard already applied to explicit <code>channelId</code> params (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371944266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76704/hovercard" href="https://github.com/openclaw/openclaw/issues/76704">#76704</a>); this extends it to store-derived channels. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377923292" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77396/hovercard" href="https://github.com/openclaw/openclaw/issues/77396">#77396</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Secrets/external channel contracts: also look in <code>&lt;rootDir&gt;/dist/</code> when resolving the <code>secret-contract-api</code> sidecar, so npm-published externalized channel plugins (e.g. <code>@openclaw/discord</code> since 2026.5.2) whose compiled artifacts live under <code>dist/</code> actually contribute their channel SecretRef contracts to the runtime snapshot. Without this, env-backed <code>channels.discord.token</code> SecretRefs silently failed to resolve at gateway start on 2026.5.3, leaving the channel <code>not configured</code> even though <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370882504" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76449" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76449/hovercard" href="https://github.com/openclaw/openclaw/pull/76449">#76449</a> had landed the generic external-contract loader. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mogglemoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mogglemoss">@mogglemoss</a>.</li>
<li>Models/auth: add <code>openclaw models auth list [--provider &lt;id&gt;] [--json]</code> so users can inspect saved per-agent auth profiles without dumping secrets or hitting the old “too many arguments” path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI/header: show the active agent name in dashboard breadcrumbs without adding the current session key, keeping non-chat views oriented without crowding the topbar.</li>
<li>Control UI/cron: make the New Job sidebar collapsible so the jobs list can reclaim space while keeping the form one click away. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Gateway/startup: keep model-catalog test helpers, run-session lookup code, QR pairing helpers, and TypeBox memory-tool schema construction out of hot startup import paths, reducing default gateway benchmark plugin-load and memory pressure.</li>
<li>Control UI/performance: record browser long animation frame or long task entries in the debug event log when supported, making slow dashboard renders easier to attribute from the UI.</li>
<li>Slack/streaming: add <code>streaming.progress.render: "rich"</code> for Block Kit progress drafts backed by structured progress line data.</li>
<li>Slack/streaming: keep the newest rich progress lines when Block Kit limits trim long progress drafts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/streaming: cap progress-draft tool lines by default so edited progress boxes avoid jumpy reflow from long wrapped lines.</li>
<li>Agents/verbose: use compact explain-mode tool summaries for <code>/verbose</code> and progress drafts by default, with <code>agents.defaults.toolProgressDetail: "raw"</code> and per-agent overrides for debugging raw command/detail output.</li>
<li>Control UI/chat: add an agent-first filter to the chat session picker, keep chat controls/composer responsive across phone/tablet/desktop widths, keep desktop chat controls on one row, avoid duplicate avatar refreshes during initial chat load, and hide that row while scrolling down the transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: collapse consecutive duplicate text messages into one bubble with a count so no-op heartbeat acknowledgements stay compact without hiding nearby context.</li>
<li>Agents/subagents: preserve every grouped child result when direct completion fallback has to bypass the requester-agent announce turn. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TTS/telephony: honor provider voice/model overrides in telephony synthesis providers so Google Meet agent speech logs match the backend that actually produced the audio. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Voice Call/realtime: bound the paced Twilio audio queue and close overloaded realtime streams before provider audio can pile up behind the websocket backpressure guard. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs: clarify that IRC uses raw TCP/TLS sockets outside operator-managed forward proxy routing, so direct IRC egress should be explicitly approved before enabling IRC. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Gateway/performance: defer non-readiness sidecars until after the ready signal, avoid hot-path channel plugin barrel imports, and fast-path trusted bundled plugin metadata during Gateway startup.</li>
<li>Gateway/performance: avoid importing <code>jiti</code> on native-loadable plugin startup paths, so compiled bundled plugin surfaces do not pay source-transform loader cost unless fallback loading is actually needed.</li>
<li>Gateway/diagnostics: add startup phase spans, active work labels, stale terminal bridge markers, and default sync-I/O tracing in <code>pnpm gateway:watch</code> so slow Gateway turns are easier to attribute from logs and stability diagnostics.</li>
<li>Plugins/loader: preserve real compiled plugin module evaluation errors on the native fast path instead of treating every thrown <code>.js</code> module as a source-transform fallback miss. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Mantis: add <code>pnpm openclaw qa mantis slack-desktop-smoke</code> to run Slack live QA inside a Crabbox VNC desktop, open Slack Web, and capture desktop screenshots beside the Slack QA artifacts.</li>
<li>QA/Mantis: pass the runtime env through desktop-browser Crabbox and artifact-copy child commands, so embedded Mantis callers can provide Crabbox credentials without mutating the parent process. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Mantis: return the copied Slack desktop screenshot path even when remote Slack QA fails, so the CLI still prints the failure screenshot artifact. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Mantis: accept Blacksmith Testbox <code>tbx_...</code> lease ids from desktop smoke warmup, so provider overrides do not fail before inspect/run. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Codex harness: add targeted live Docker/Testbox diagnostics, auth preflight checks, cache mount fixes, and app-server protocol checkout discovery so maintainer harness failures are easier to reproduce. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: treat official externalized bundled npm migrations and ClawHub-to-npm fallbacks as trusted source-linked installs, so prerelease-only official plugin packages can migrate from bundled builds without being rejected as unsafe prerelease resolutions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: move ClawHub-preferred externalized plugin installs back to ClawHub after an earlier npm fallback once the ClawHub package becomes available. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: clean stale bundled load paths for already-externalized pinned npm and ClawHub plugin installs, so release-channel sync does not leave removed bundled paths ahead of the installed external package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: accept plugin-owned numeric forum-topic targets in the agent message tool and keep reply-dispatch provider chunks behind a real stable runtime alias during in-place package updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374314127" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77137/hovercard" href="https://github.com/openclaw/openclaw/issues/77137">#77137</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richardmqq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richardmqq">@richardmqq</a>.</li>
<li>Google Meet: preserve <code>realtime.introMessage: ""</code> so realtime Chrome joins can stay silent instead of restoring the default spoken intro. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/SDK: add bounded <code>before_agent_finalize</code> retry instructions so workflow plugins can request one more model pass. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Discord/status: add degraded Discord transport and gateway event-loop starvation signals to <code>openclaw channels status</code>, <code>openclaw status --deep</code>, and fetch-timeout logs so intermittent socket resets do not look like a healthy running channel. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370424830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76327/hovercard" href="https://github.com/openclaw/openclaw/pull/76327">#76327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Providers/OpenRouter: add opt-in response caching params that send OpenRouter's <code>X-OpenRouter-Cache</code>, <code>X-OpenRouter-Cache-TTL</code>, and cache-clear headers only on verified OpenRouter routes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/OpenRouter: expand app-attribution categories so OpenClaw advertises coding, programming, writing, chat, and personal-agent usage on verified OpenRouter routes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: make package upgrades swap pnpm/npm-prefix installs cleanly, keep legacy plugin install runtime chunks working, and on the beta channel fall back default-line npm plugins to default/latest when plugin beta releases are missing or fail install validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels/WhatsApp: support explicit WhatsApp Channel/Newsletter <code>@newsletter</code> outbound message targets with channel session metadata instead of DM routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921599881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13417/hovercard" href="https://github.com/openclaw/openclaw/issues/13417">#13417</a>; carries forward the narrow outbound target idea from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921655588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/13424/hovercard" href="https://github.com/openclaw/openclaw/pull/13424">#13424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agentz-manfred/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agentz-manfred">@agentz-manfred</a>.</li>
<li>Exec approvals: add a tree-sitter-backed shell command explainer for future approval and command-review surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356957695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75004/hovercard" href="https://github.com/openclaw/openclaw/pull/75004">#75004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Agents/sandbox: store sandbox container and browser registry entries as per-runtime shard files, reducing unrelated session lock contention while <code>openclaw doctor --fix</code> migrates legacy monolithic registry files. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355267442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74831" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74831/hovercard" href="https://github.com/openclaw/openclaw/pull/74831">#74831</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luckylhb90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luckylhb90">@luckylhb90</a>.</li>
<li>Plugins/ClawHub: annotate 429 errors from ClawHub with the reset window from <code>RateLimit-Reset</code>/<code>Retry-After</code> and append a <code>Sign in for higher rate limits.</code> hint when the request was unauthenticated, so users can see when downloads will recover and how to lift the cap. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Plugins/runtime state: add <code>registerIfAbsent</code> for atomic keyed-store dedupe claims that return whether a plugin successfully claimed a key without overwriting an existing live value. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugin SDK: add plugin-owned <code>SessionEntry</code> slot projection and scoped trusted-policy session extension reads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364052304" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75609" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75609/hovercard" href="https://github.com/openclaw/openclaw/pull/75609">#75609</a>; replaces part of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341413994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73384/hovercard" href="https://github.com/openclaw/openclaw/pull/73384">#73384</a>/<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352304216" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74483/hovercard" href="https://github.com/openclaw/openclaw/pull/74483">#74483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Infra/Windows: skip the POSIX <code>/tmp/openclaw</code> preferred path on Windows in <code>resolvePreferredOpenClawTmpDir</code> so log files, TTS temp files, and other writes land in <code>%TEMP%\openclaw-&lt;uid&gt;</code> instead of <code>C:\tmp\openclaw</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203795758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60713/hovercard" href="https://github.com/openclaw/openclaw/issues/60713">#60713</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Media/Windows: open saved attachment temp files read/write before fsync so Windows WebChat and <code>chat.send</code> media offloads no longer fail with EPERM during durability flush. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371379191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76593/hovercard" href="https://github.com/openclaw/openclaw/pull/76593">#76593</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qq230849622-a11y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qq230849622-a11y">@qq230849622-a11y</a>.</li>
<li>Agents/tools: honor narrow runtime tool allowlists when constructing embedded-runner tool families and bundled MCP/LSP runtimes, so cron/subagent runs that request tools such as <code>update_plan</code>, <code>browser</code>, <code>x_search</code>, channel login tools, or <code>group:plugins</code> no longer start with missing tools or unrelated bootstrap work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379470874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77519/hovercard" href="https://github.com/openclaw/openclaw/issues/77519">#77519</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379682883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77532/hovercard" href="https://github.com/openclaw/openclaw/issues/77532">#77532</a>)</li>
<li>Codex plugin: mirror the experimental upstream app-server protocol and format generated TypeScript before drift checks, keeping OpenClaw's <code>experimentalApi</code> bridge compatible with latest Codex while preserving formatter gates.</li>
<li>Telegram/media: derive no-caption inbound media placeholders from saved MIME metadata instead of the Telegram <code>photo</code> shape, so non-image and mixed attachments no longer reach the model as <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304175260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69793/hovercard" href="https://github.com/openclaw/openclaw/issues/69793">#69793</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aspalagin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aspalagin">@aspalagin</a>.</li>
<li>Agents/cache: keep per-turn runtime context out of ordinary chat system prompts while still delivering hidden current-turn context, restoring prompt-cache reuse on chat continuations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378353164" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77431" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77431/hovercard" href="https://github.com/openclaw/openclaw/issues/77431">#77431</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Udjin79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Udjin79">@Udjin79</a>.</li>
<li>Gateway/startup: include resolved thinking and fast-mode defaults in the <code>agent model</code> startup log line, defaulting unset startup thinking to <code>medium</code> without mixing in reasoning visibility.</li>
<li>Agents/Tools: add post-compaction loop guard in <code>pi-embedded-runner</code> that arms after auto-compaction-retry and aborts the run with <code>compaction_loop_persisted</code> when the agent emits the same <code>(tool, args, result)</code> triple <code>windowSize</code> times (default 3) within that window. Disable via existing <code>tools.loopDetection.enabled</code>; tune via <code>tools.loopDetection.postCompactionGuard.windowSize</code>. Targets the failure mode where context-overflow + compaction does not break a tool-call loop. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378890322" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77474/hovercard" href="https://github.com/openclaw/openclaw/issues/77474">#77474</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3966514344" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/21597" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/21597/hovercard" href="https://github.com/openclaw/openclaw/issues/21597">#21597</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efpiva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efpiva">@efpiva</a>.</li>
<li>Gateway/watch: suppress sync-I/O trace output during <code>pnpm gateway:watch --benchmark</code> unless explicitly requested, so CPU profiling no longer floods the terminal with stack traces.</li>
<li>Gateway/watch: when benchmark sync-I/O tracing is explicitly enabled, tee trace blocks to the benchmark output log and filter them from the terminal pane while keeping normal Gateway logs visible.</li>
<li>Plugins/runtime-deps: include <code>json5</code> in the memory-core plugin runtime dependency set so packaged <code>memory_search</code> sandboxes can resolve generated OpenClaw runtime chunks that parse JSON5 config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378779937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77461" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77461/hovercard" href="https://github.com/openclaw/openclaw/issues/77461">#77461</a>.</li>
<li>Codex harness: preserve app-server usage-limit reset details and deliver OpenClaw-owned runtime failure notices through tool-only source-reply mode, so Telegram and other chat channels tell users when Codex subscription limits or API failures block a turn instead of going silent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379971002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77557" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77557/hovercard" href="https://github.com/openclaw/openclaw/pull/77557">#77557</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/OpenAI: default direct OpenAI Responses models to the SSE transport instead of WebSocket auto-selection, preventing pi runtime chat turns from hanging on servers where the WebSocket path stalls while the OpenAI HTTP stream works. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/replies: treat failed final reply delivery as a failed turn instead of counting it as a delivered automatic visible reply, so guild/channel turns no longer show done when the final message was dropped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379472823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77520/hovercard" href="https://github.com/openclaw/openclaw/issues/77520">#77520</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Discord: prefer IPv4 for Discord REST and gateway WebSocket startup paths so IPv4-only networks no longer stall before Gateway READY and inbound message dispatch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377964492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77398" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77398/hovercard" href="https://github.com/openclaw/openclaw/issues/77398">#77398</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379608404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77526" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77526/hovercard" href="https://github.com/openclaw/openclaw/issues/77526">#77526</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>.</li>
<li>Channels/plugins: key bundled package-state probes, env/config presence, and read-only command defaults by channel id instead of manifest plugin id, preserving setup and native-command detection for channel plugins whose package id differs from the channel alias. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docker: prune package-excluded plugin dist directories from runtime images unless the build explicitly opts that plugin in, so official external plugins such as Feishu stay install-on-demand instead of shipping partial metadata without compiled runtime output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378224775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77424" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77424/hovercard" href="https://github.com/openclaw/openclaw/issues/77424">#77424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Model switching: include the exact additive allowlist repair command when <code>/model ... --runtime ...</code> targets a blocked model, and make Telegram's model picker say that it changes only the session model while leaving the runtime unchanged. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost: clarify that the model picker only changes the session model and that runtime switches require <code>/oc_model &lt;provider/model&gt; --runtime &lt;runtime&gt;</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/config: keep active <code>auth.profiles</code> metadata intact when <code>doctor --fix</code> strips stale secret fields from configs, repairing legacy <code>&lt;provider&gt;:default</code> API-key profile metadata when model fallbacks or explicit <code>model@profile</code> refs still depend on it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377984968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77400/hovercard" href="https://github.com/openclaw/openclaw/issues/77400">#77400</a>.</li>
<li>Doctor/plugins: include <code>plugins.allow</code>-only official plugin ids in the release configured-plugin repair set, so <code>doctor --fix</code> installs official external plugins that are configured but not yet loaded instead of removing them as stale allow entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374471276" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77155/hovercard" href="https://github.com/openclaw/openclaw/issues/77155">#77155</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Doctor/sessions: clear auto-created stale session routing state from the sessions store when <code>doctor --fix</code> sees plugin-owned model/runtime/auth/session bindings outside the current configured route, while leaving explicit user model choices for manual review. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288418906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68615" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68615/hovercard" href="https://github.com/openclaw/openclaw/issues/68615">#68615</a>.</li>
<li>CLI/update: disable and skip plugins that fail package-update plugin sync, so a broken npm/ClawHub/git/marketplace plugin cannot turn a successful OpenClaw package update into a failed update result. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: use an absolute POSIX npm script shell during package-manager updates, so restricted PATH environments can still run dependency lifecycle scripts while updating from <code>--tag main</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379671077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77530" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77530/hovercard" href="https://github.com/openclaw/openclaw/issues/77530">#77530</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PeterTremonti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PeterTremonti">@PeterTremonti</a>.</li>
<li>Diagnostics: grant the internal diagnostics event bus to official installed diagnostics exporter plugins, so npm-installed <code>@openclaw/diagnostics-prometheus</code> can emit metrics without broadening the capability to arbitrary global plugins. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371535418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76628/hovercard" href="https://github.com/openclaw/openclaw/issues/76628">#76628</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RayWoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RayWoo">@RayWoo</a>.</li>
<li>Browser: enforce strict SSRF current-URL checks before existing-session screenshots, matching existing-session snapshot handling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: give timeout partial transcript recovery enough abort-settle headroom so temporary recall summaries are returned before cleanup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/chat: clear the active reply-run guard before draining queued same-session follow-up turns, so sequential <code>chat.send</code> calls no longer trip <code>ReplyRunAlreadyActiveError</code> every other request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379026753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77485/hovercard" href="https://github.com/openclaw/openclaw/issues/77485">#77485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bws14email/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bws14email">@bws14email</a>.</li>
<li>Agents/media: avoid sending generated image, video, and music attachments twice when streamed reply text arrives before the final <code>MEDIA:</code> directive.</li>
<li>CLI/sessions: cap <code>openclaw sessions</code> output to the newest 100 rows by default and add <code>--limit &lt;n|all&gt;</code> plus JSON pagination metadata, so repeated machine polling of large session stores cannot fan out into unbounded per-row enrichment/output work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379239968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77500" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77500/hovercard" href="https://github.com/openclaw/openclaw/issues/77500">#77500</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaotic3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaotic3">@Kaotic3</a>.</li>
<li>Doctor/config: restore legacy group chat config migrations for <code>routing.allowFrom</code>, <code>routing.groupChat.*</code>, and <code>channels.telegram.requireMention</code> so upgrades keep WhatsApp, Telegram, and iMessage group mention gates and history settings instead of leaving configs invalid or silently blocked. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>CLI/update: make package-update follow-up processes write completion results and exit explicitly, so Windows packaged upgrades do not hang after the new package finishes post-core plugin work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Release validation: skip Slack live QA unless Slack credentials are explicitly configured, so release gates can keep proving non-Slack surfaces while Slack is still local and credential-gated. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: treat OpenClaw CalVer correction versions like <code>2026.5.3-1</code> as satisfying base plugin API ranges, so correction builds can install plugins that require the base runtime API. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376348978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77293/hovercard" href="https://github.com/openclaw/openclaw/issues/77293">#77293</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378597699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77450/hovercard" href="https://github.com/openclaw/openclaw/pull/77450">#77450</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>Discord/Gateway startup: retry Discord READY waits with backoff, defer startup <code>sessions.list</code> and native approval readiness failures until sidecars recover, and preserve component-only Discord payloads when final reply scrubbing removes all text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378961577" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77478" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77478/hovercard" href="https://github.com/openclaw/openclaw/pull/77478">#77478</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NikolaFC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NikolaFC">@NikolaFC</a>.</li>
<li>CLI/launcher: forward termination signals to compile-cache respawn children, so killing a wrapper process no longer leaves the security audit worker orphaned. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378715767" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77458/hovercard" href="https://github.com/openclaw/openclaw/issues/77458">#77458</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jaikharbanda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jaikharbanda">@jaikharbanda</a>.</li>
<li>Plugins/registry: recover managed-npm external plugins from the owned npm root when a stale persisted registry would otherwise hide them after package-manager upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376104443" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77266" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77266/hovercard" href="https://github.com/openclaw/openclaw/issues/77266">#77266</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>fix(gateway): clamp unbound websocket auth scopes [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378170535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77413" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77413/hovercard" href="https://github.com/openclaw/openclaw/pull/77413">#77413</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Gate zalouser startup name matching [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378152152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77411" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77411/hovercard" href="https://github.com/openclaw/openclaw/pull/77411">#77411</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory: send a bounded latest-message search query to the recall worker so channel/runtime metadata does not become the memory search string. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247741968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65309/hovercard" href="https://github.com/openclaw/openclaw/issues/65309">#65309</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/westley3601/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/westley3601">@westley3601</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pimenov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pimenov">@pimenov</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tasi333/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tasi333">@tasi333</a>.</li>
<li>fix(device-pair): require pairing scope for pair command [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370614193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76377" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76377/hovercard" href="https://github.com/openclaw/openclaw/pull/76377">#76377</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Providers/OpenRouter: keep DeepSeek V4 <code>reasoning_effort</code> on OpenRouter-supported values, mapping stale <code>max</code> thinking overrides to <code>xhigh</code> so <code>openrouter/deepseek/deepseek-v4-pro</code> no longer fails with OpenRouter's invalid-effort 400. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377137286" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77350" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77350/hovercard" href="https://github.com/openclaw/openclaw/issues/77350">#77350</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378204338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77423/hovercard" href="https://github.com/openclaw/openclaw/pull/77423">#77423</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krllagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krllagent">@krllagent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>fix(qqbot): keep private commands off framework surface [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375172453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77212" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77212/hovercard" href="https://github.com/openclaw/openclaw/pull/77212">#77212</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Claude CLI: honor non-off <code>/think</code> levels by passing Claude Code's session-scoped <code>--effort</code> flag through the CLI backend seam, so chat bridges no longer show an inert thinking control. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376451827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77303/hovercard" href="https://github.com/openclaw/openclaw/issues/77303">#77303</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Petr1t/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Petr1t">@Petr1t</a>.</li>
<li>Agents/subagents: refresh deferred final-delivery payloads when same-session completion output changes, so retried parent notifications use the final child summary instead of stale progress text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/media: route async music and video completion results back through the requester agent, preserving automatic replies while requiring the message tool only for message-tool-only group/channel delivery.</li>
<li>active-memory: skip the memory sub-agent gracefully instead of logging a confusing allowlist error when no memory plugin (<code>memory-core</code> or <code>memory-lancedb</code>) is loaded, so active-memory with no memory backend no longer produces misleading "No callable tools remain" warnings in the gateway log. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379314303" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77506/hovercard" href="https://github.com/openclaw/openclaw/issues/77506">#77506</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Memory/wiki: preserve representation from both corpora in <code>corpus=all</code> searches while backfilling unused result capacity, so memory hits are not starved by numerically higher wiki integer scores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377040368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77337/hovercard" href="https://github.com/openclaw/openclaw/issues/77337">#77337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Docker/compose: pin container-side <code>OPENCLAW_CONFIG_DIR</code> and <code>OPENCLAW_WORKSPACE_DIR</code> on both gateway and CLI services so the host paths written into <code>.env</code> by <code>scripts/docker/setup.sh</code> (used as Compose bind-mount sources) cannot leak into runtime code via the <code>env_file</code> import. Fixes regressions on macOS Docker setups where the first agent reply died with <code>EACCES: permission denied, mkdir '/Users'</code> because the host-style workspace path got persisted into <code>agents.defaults.workspace</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378378867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77436/hovercard" href="https://github.com/openclaw/openclaw/issues/77436">#77436</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a>.</li>
<li>Telegram: clean up tool-only draft previews after assistant message boundaries so transient <code>Surfacing...</code> tool-status bubbles do not linger when no matching final preview arrives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Slack: report <code>unknown error</code> instead of <code>undefined</code> in socket-mode startup retry logs and label the retry reason explicitly.</li>
<li>Telegram: let explicit forum-topic <code>requireMention</code> settings override persisted <code>/activate</code> and <code>/deactivate</code> state, so per-topic mention gates work consistently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095745250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49864/hovercard" href="https://github.com/openclaw/openclaw/issues/49864">#49864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Panniantong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Panniantong">@Panniantong</a>.</li>
<li>Cron: surface failed isolated-run diagnostics in <code>cron show</code>, status, and run history when requested tools are unavailable, so blocked cron runs report the actual tool-policy failure instead of a misleading green result. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365767696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75763" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75763/hovercard" href="https://github.com/openclaw/openclaw/issues/75763">#75763</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</li>
<li>TUI/escape abort: track the in-flight runId after <code>chat.send</code> resolves so pressing Esc during the gap before the first gateway event aborts the run instead of repeatedly printing <code>no active run</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3832865940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/1296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/1296/hovercard" href="https://github.com/openclaw/openclaw/issues/1296">#1296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lukavyi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lukavyi">@Lukavyi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>TUI/render: stop the long-token sanitizer from injecting literal spaces inside inline code spans, fenced code blocks, table borders, and bare hyphenated/dotted identifiers, so copied package names, entity IDs, and shell line-continuations stay byte-for-byte intact while narrow-terminal protection still chunks unidentifiable long prose tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084135042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48432" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48432/hovercard" href="https://github.com/openclaw/openclaw/issues/48432">#48432</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040518999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39505/hovercard" href="https://github.com/openclaw/openclaw/issues/39505">#39505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DocOellerson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DocOellerson">@DocOellerson</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xeusoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xeusoc">@xeusoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CCcassiusdjs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CCcassiusdjs">@CCcassiusdjs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akramcodez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akramcodez">@akramcodez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Plugin skills: publish plugin-declared skills through the generated plugin skills directory (<code>~/.openclaw/plugin-skills/</code>) while keeping direct prompt loading intact, so agent file-based discovery paths find plugin skill <code>SKILL.md</code> files and inactive plugin links are cleaned up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376387154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77296/hovercard" href="https://github.com/openclaw/openclaw/issues/77296">#77296</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4376911387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77328" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77328/hovercard" href="https://github.com/openclaw/openclaw/pull/77328">#77328</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Gateway/status: label Linux managed gateway services as <code>systemd user</code>, making status output explicit about the user-service scope instead of implying a system-level unit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: remove the previous managed plugin directory when a reinstall switches sources, so stale ClawHub and npm copies no longer keep duplicate plugin ids in discovery after the new install wins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: let official plugin reinstall recovery repair source-only installed runtime shadows, so <code>openclaw plugins install npm:@openclaw/discord --force</code> can replace the bad package instead of stopping at stale config validation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: stage pnpm-detected npm-layout global package updates through a clean npm prefix swap, keep plugin install runtime imports behind a stable alias, and ship legacy install-runtime aliases back to <code>2026.3.22</code>, preventing stale overlay chunks from breaking plugin post-update sync. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/commands: allow the official ClawHub Codex plugin package to keep reserved <code>/codex</code> command ownership, matching the existing npm-managed Codex package behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auth/OpenAI Codex: rewrite invalidated per-agent Codex auth-order and session profile overrides toward a healthy relogin profile, so revoked OAuth accounts do not stay pinned after signing in again. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Plugins/commands: scope QQBot framework slash commands to the QQBot channel so <code>/bot-*</code> command handlers and native specs do not leak onto unrelated chat surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>fix: harden backend message action gateway routing [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370609226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76374" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76374/hovercard" href="https://github.com/openclaw/openclaw/pull/76374">#76374</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Gate QQBot streaming command auth [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370611629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76375/hovercard" href="https://github.com/openclaw/openclaw/pull/76375">#76375</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Plugins/discovery: ignore managed npm plugin packages that only expose TypeScript source entries without compiled runtime output, so stale/broken installs cannot hide a working bundled or reinstallable channel plugin during setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: treat OpenClaw stable correction versions like <code>2026.5.3-1</code> as newer than their base stable release, so package updates no longer ask for downgrade confirmation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: suppress dangerous-pattern scanner warnings for trusted official OpenClaw npm installs, so installing <code>@openclaw/discord</code> no longer prints credential-harvesting warnings for the official package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/commands: suppress dangerous-pattern scanner warnings for trusted catalog npm installs from owner-gated <code>/plugins install</code> commands, so chat-driven installs match the CLI install trust path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/release: make the published npm runtime verifier reject blank <code>openclaw.runtimeExtensions</code> entries instead of treating them as absent and passing via inferred outputs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/security: ignore inline and block comments when matching source-rule context in plugin install scans, so comment-only <code>fetch</code>/<code>post</code> references near environment defaults do not block clean plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: remove stale managed install records for bundled plugins even when the bundled plugin is not explicitly configured, so doctor cleanup cannot leave orphaned install metadata behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web fetch: scope provider fallback cache entries by the selected fetch provider so config reloads cannot reuse another provider's cached fallback payload. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web search: honor late-bound <code>tools.web.search.enabled: false</code> during tool execution so config reloads cannot leave an already-created <code>web_search</code> tool runnable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/packages: reject inferred built runtime entries that exist but fail package-boundary checks instead of falling back to TypeScript source for installed packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/loader: do not retry native-loaded JavaScript plugin modules through the source transformer after native evaluation has already reached a missing dependency, avoiding duplicate top-level side effects. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/packages: reject blank <code>openclaw.runtimeExtensions</code> entries instead of silently ignoring them and falling back to inferred TypeScript runtime entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: remove stale managed npm plugin shadow entries from the managed package lock as well as <code>package.json</code> and <code>node_modules</code>, so future npm operations do not keep referencing repaired bundled-plugin shadows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime state: keep the key being registered when namespace eviction runs in the same millisecond as existing entries, so <code>register</code> and <code>registerIfAbsent</code> do not report success while evicting their own fresh value. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/providers: make bundled provider discovery honor restrictive <code>plugins.allow</code> by default for new configs, while doctor migrates legacy restrictive allowlist configs to <code>plugins.bundledDiscovery: "compat"</code> to preserve upgrade behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dougbtv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dougbtv">@dougbtv</a>.</li>
<li>Control UI/Talk: make failed Talk startup errors dismissable and clear the stale Talk error state when dismissed, so missing realtime voice provider configuration does not leave a permanent chat banner. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373812807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77071/hovercard" href="https://github.com/openclaw/openclaw/issues/77071">#77071</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ijoshdavis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ijoshdavis">@ijoshdavis</a>.</li>
<li>Control UI/Talk: stop and clear failed realtime Talk sessions when dismissing runtime error banners, so the next Talk click starts a fresh session instead of only stopping the stale one. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI/Talk: retry from a failed realtime Talk session on the next Talk click instead of requiring a separate stale-session stop click first. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Canvas host: preserve the Gateway TLS scheme in browser canvas host URLs and startup mount logs, so direct HTTPS gateways do not advertise insecure canvas links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WhatsApp/login: route login success and failure messages through the injected runtime, so setup/onboarding surfaces capture all login output instead of only the QR. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Chat: create an isolated Google auth transport per auth client, so google-auth-library interceptor mutations do not accumulate across webhook verification and access-token clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: remove orphaned or recovered managed npm copies of bundled <code>@openclaw/*</code> plugins during <code>doctor --fix</code>, so stale package manifests cannot shadow the current bundled plugin config schema.</li>
<li>Control UI/performance: cap long-task and long-animation-frame diagnostics in the shared event log, so slow-render telemetry does not evict gateway/plugin events from the Debug and Overview views. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/startup: log the canvas host mount only after the HTTP server has bound, so startup logs no longer report the canvas host as mounted before it can serve requests.</li>
<li>Control UI/i18n: render the Sessions active filter tooltip with the configured minute count in every locale and make the i18n check reject placeholder drift. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Web fetch: late-bind <code>web_fetch</code> config and provider fallback metadata from the active runtime snapshot, matching <code>web_search</code> so long-lived tools do not use stale fetch provider settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord: clear stale startup probe bot/application status when the async bot probe throws, not just when it returns a degraded probe result. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web search: scope explicit bundled <code>web_search</code> provider runtime loading through manifest ownership, so selecting DuckDuckGo/Gemini/etc. does not import unrelated bundled providers or log their optional dependency failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/discovery: demote the source-only TypeScript runtime check on already-installed <code>origin: "global"</code> plugin packages from a config-blocking error to a warning and let the runtime fall through to the TypeScript source via jiti, so a single broken installed package no longer blocks <code>plugins install</code> for unrelated plugins; install-time rejection of newly-installed source-only packages is unchanged. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Providers/OpenAI Codex: stop the OAuth progress spinner before showing the manual redirect paste prompt, so callback timeouts do not spam <code>Browser callback did not finish</code> across terminals.</li>
<li>Providers/OpenAI Codex: fail closed on malformed <code>/codex</code> control commands and diagnostics confirmations before changing bindings, permissions, model overrides, active turns, or feedback uploads. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/OpenAI Codex: sanitize Codex app-server command readouts, failure replies, approval prompts, elicitation prompts, and <code>request_user_input</code> text before posting them back into chat. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/OpenAI Codex: preserve local bound-turn image paths, reject stale same-thread turn notifications, enforce option-only user input prompts, and return failed dynamic tool results to Codex as unsuccessful tool calls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/DeepSeek: expose DeepSeek V4 <code>xhigh</code> and <code>max</code> thinking levels through the lightweight provider-policy surface, so Control UI <code>/think</code> pickers keep showing the max reasoning options when the runtime plugin registry is not active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374344456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77139/hovercard" href="https://github.com/openclaw/openclaw/issues/77139">#77139</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Release/beta smoke: resolve the dispatched Telegram beta E2E run from <code>gh run list</code> when <code>gh workflow run</code> returns no run URL, so the maintainer helper does not fail immediately after dispatch. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Media/images: keep HEIC/HEIF attachments fail-closed when optional Sharp conversion is unavailable instead of sending originals that still need conversion. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: fork the caller's current agent transcript into agent-mode meeting consultant sessions, so Meet replies inherit the context from the tool call that joined the meeting.</li>
<li>iOS/mobile pairing: reject non-loopback <code>ws://</code> setup URLs before QR/setup-code issuance and let the iOS Gateway settings screen scan QR codes or paste full setup-code messages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI: keep Gateway Access inputs and locale picker contained inside the card at narrow and tablet widths.</li>
<li>Agents/trajectory: bound runtime trajectory capture and yield queued sidecar writes so oversized traces stop recording instead of monopolizing Gateway cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374205763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77124" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77124/hovercard" href="https://github.com/openclaw/openclaw/issues/77124">#77124</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loyur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loyur">@loyur</a>.</li>
<li>Telegram/streaming: sanitize tool-progress draft preview backticks before shared compaction, so long backtick-heavy progress text still renders inside the safe code-formatted preview instead of collapsing to an ellipsis.</li>
<li>UI/chat: remove the unsupported <code>line-clamp</code> declaration from the chat queue text rule to eliminate Firefox console noise without changing visible truncation behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ZanderH-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ZanderH-code">@ZanderH-code</a>.</li>
<li>Control UI: add explicit feedback for repeated actions by announcing session switches, flashing the active session selector, showing inline Save/Apply/Update progress, and distinguishing filtered-empty session lists from genuinely empty session stores. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/Pi: suppress persistence for synthetic mid-turn overflow continuation prompts, so transcript-retry recovery does not write the "continue from transcript" prompt as a new user turn. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/tools: strip reasoning text from visible rich presentation titles, blocks, buttons, and select labels before message-tool sends, so structured channel payloads cannot leak hidden planning. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: keep reply-dispatch lazy provider runtime chunks behind stable dist names and delete <code>/reasoning stream</code> previews after final delivery so package updates and live reasoning drafts do not leave Telegram turns broken or noisy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Discord: start the gateway monitor without waiting for the startup bot/application probe, so WSL2 hosts with a slow <code>/users/@me</code> REST path still bring the channel online while status enrichment finishes asynchronously. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373996492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77103" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77103/hovercard" href="https://github.com/openclaw/openclaw/issues/77103">#77103</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Suited78/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Suited78">@Suited78</a>.</li>
<li>Exec approvals: detect <code>env -S</code> split-string command-carrier risks when <code>-S</code>/<code>-s</code> is combined with other env short options, so approval explanations do not miss split payloads hidden behind <code>env -iS...</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: log the concrete agent-mode TTS provider, model, voice, output format, and sample rate after speech synthesis, so Meet logs show which voice backend spoke each reply.</li>
<li>Voice Call: mark realtime calls completed when the realtime provider closes normally, so Twilio/OpenAI/Google realtime stop events do not leave active call records behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/update: keep the shutdown close path behind a stable runtime chunk and ship compatibility aliases for recent <code>server-close-*</code> hashes, so manual npm package replacement cannot leave an already-running Gateway unable to shut down cleanly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373865331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77087/hovercard" href="https://github.com/openclaw/openclaw/issues/77087">#77087</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/westlife219/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/westlife219">@westlife219</a>.</li>
<li>Control UI/media: mint short-lived scoped tickets for assistant media fetches and render ticketed URLs instead of exposing long-lived auth tokens in chat image URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319425097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70830" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70830/hovercard" href="https://github.com/openclaw/openclaw/issues/70830">#70830</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373888329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77097/hovercard" href="https://github.com/openclaw/openclaw/issues/77097">#77097</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Exec approvals: treat POSIX <code>exec</code> as a command carrier for inline eval, shell-wrapper, and eval/source detection, so approval explanations and command-risk checks do not miss payloads hidden behind <code>exec</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: log the resolved audio provider model when starting Chrome and paired-node Meet talk-back bridges, so agent-mode joins show the STT model and bidi joins show the realtime voice model.</li>
<li>Diagnostics: handle missing session-tail files in cron recovery context without tripping extension test typecheck. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Slack: update the Slack dispatch preview fallback test SDK mock for structured progress draft helpers, so the rich progress draft regression suite covers the new imports instead of failing before assertions run. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Release validation: allow focused QA live reruns to select Matrix and Telegram without running Slack, so known Slack credential-pool outages do not block non-Slack live proof. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/loader: keep bundled plugin package <code>test-api.js</code> aliases behind private QA mode, so source transforms do not expose test-only public surfaces during normal plugin loading. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/startup: start cron and record the post-ready memory trace even when deferred maintenance timers fail after readiness, so a non-fatal timer setup issue does not silently leave scheduled jobs idle. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Exec approvals: unwrap BSD/macOS <code>env -P &lt;path&gt;</code> carrier commands before approval-command and strict inline-eval checks, so <code>/approve</code> shell execution and inline interpreter payloads are still blocked behind that env form.</li>
<li>Agents/session status: keep semantic <code>session_status({ sessionKey: "current" })</code> on the live run session even before that run has a persisted session-store entry, instead of falling back to the sandbox policy key. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Slack: resolve bundled official plugin public-surface package aliases during source-mode QA runs, so release Slack live validation can load <code>@openclaw/slack/api.js</code> without workspace symlinks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: pass the live run session key into app-server dynamic tools when sandbox policy uses a separate session key, so <code>session_status({ sessionKey: "current" })</code> reports the active run instead of the sandbox policy key. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Web search: keep first-class assistant <code>web_search</code> auto-detect and configured runtime providers visible when active runtime metadata or the active plugin registry is incomplete. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373814331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77073" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77073/hovercard" href="https://github.com/openclaw/openclaw/issues/77073">#77073</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>Plugins/tools: mark manifest-optional sibling tools as optional even when they come from a shared non-optional factory, so cached/status/MCP metadata keeps opt-in tool policy accurate. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Matrix: keep <code>streaming.progress.toolProgress</code> scoped to progress draft mode, so partial and quiet Matrix previews do not lose tool progress unless <code>streaming.preview.toolProgress</code> is disabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/validation: isolate gateway server validation files, ignore unrelated startup logs in request-trace coverage, and fail fast on stuck shared-auth sockets, reducing false main-branch CI failures for contributors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Channels/streaming: keep <code>streaming.progress.toolProgress</code> scoped to progress draft mode, so disabling compact progress lines does not silence partial/block preview tool updates. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: treat OpenClaw stable correction versions like <code>2026.5.3-1</code> as stable releases for npm installs, plugin updates, and bundled-version comparisons, so <code>latest</code> can advance official plugins without prerelease opt-in. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI: point the Appearance tweakcn browse action and docs at the live tweakcn editor route instead of the removed <code>/themes</code> page. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373717554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77048" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77048/hovercard" href="https://github.com/openclaw/openclaw/issues/77048">#77048</a>.</li>
<li>Control UI: render Dream Diary prose through the sanitized markdown pipeline, so diary bold/italic/header markdown no longer appears as literal source text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216740824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62413" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62413/hovercard" href="https://github.com/openclaw/openclaw/issues/62413">#62413</a>.</li>
<li>Control UI: render tool results whose output arrives as text-block arrays and give expanded tool output a scrollable block, so read/exec output remains visible in WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373739359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77054/hovercard" href="https://github.com/openclaw/openclaw/issues/77054">#77054</a>.</li>
<li>MCP: include serialized conversation/message payloads in the primary text content for <code>conversations_list</code> and <code>messages_read</code>, while preserving <code>structuredContent</code> for capable clients. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373517492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77024/hovercard" href="https://github.com/openclaw/openclaw/issues/77024">#77024</a>.</li>
<li>Media: treat <code>EPERM</code> from the post-write media fsync step as best-effort, allowing WebChat and channel uploads to finish on Windows filesystems that reject <code>fsync</code> after a successful write. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372472680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76844" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76844/hovercard" href="https://github.com/openclaw/openclaw/issues/76844">#76844</a>.</li>
<li>Media/Telegram: send in-limit original images when optional image optimization is unavailable, so Telegram MEDIA replies and message-tool image sends do not fail just because <code>sharp</code> is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373855031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77081/hovercard" href="https://github.com/openclaw/openclaw/issues/77081">#77081</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374137500" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77117" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77117/hovercard" href="https://github.com/openclaw/openclaw/pull/77117">#77117</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfrederiksen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfrederiksen">@pfrederiksen</a>.</li>
<li>Diagnostics: include last progress, cron job/run ids, stopped cron job name, and the last assistant transcript snippet in stalled-session and stuck-session recovery logs so cron stalls show what was stopped.</li>
<li>Streaming channels: add <code>streaming.preview.commandText: "status"</code> / <code>streaming.progress.commandText: "status"</code> to hide command/exec text in preview progress lines while keeping the released raw command text default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373812831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77072" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77072/hovercard" href="https://github.com/openclaw/openclaw/issues/77072">#77072</a>.</li>
<li>Agents/cron: let explicit cron <code>timeoutSeconds</code> drive both CLI no-output and embedded LLM idle watchdogs instead of being capped by resume defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370262867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76289" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76289/hovercard" href="https://github.com/openclaw/openclaw/issues/76289">#76289</a>.</li>
<li>Plugins/catalog: suppress missing <code>channelConfigs</code> compatibility diagnostics for external channel plugins that are disabled, denied, or outside a restrictive allowlist. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369072769" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76095/hovercard" href="https://github.com/openclaw/openclaw/issues/76095">#76095</a>.</li>
<li>Diagnostics: keep webhook/message OTEL attributes and Prometheus delivery labels low-cardinality and omit raw chat/message IDs from spans, so progress-draft and message-tool modes do not leak high-cardinality messaging identifiers.</li>
<li>Google Meet: stop advertising legacy <code>mode: "realtime"</code> to agents and config UIs, while keeping it as a hidden compatibility alias for <code>mode: "agent"</code>, so new joins use the STT -&gt; OpenClaw agent -&gt; TTS path instead of selecting the direct realtime voice fallback.</li>
<li>Google Meet: add <code>chrome.audioBufferBytes</code> for generated command-pair SoX audio commands and lower the default buffer from SoX's 8192 bytes to 4096 bytes to reduce Chrome talk-back latency.</li>
<li>Google Meet: split realtime provider config into agent-mode transcription and bidi-mode voice providers, and migrate legacy Gemini Live bidi configs with <code>doctor --fix</code>, so Gemini Live can back direct bidi fallback without breaking the default OpenClaw agent talk-back path.</li>
<li>Google Meet: keep waiting for the Meet microphone to unmute during join intro readiness instead of permanently skipping talk-back when Meet briefly reports the local mic as muted.</li>
<li>Google Meet: expose <code>voiceCall.postDtmfSpeechDelayMs</code> in the plugin manifest schema and setup hints, so manifest-based config editing accepts the runtime-supported Twilio delay key. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: keep explicit non-Google <code>realtime.provider</code> values as the transcription provider compatibility fallback when <code>realtime.transcriptionProvider</code> is unset. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: make Twilio setup status require an enabled <code>voice-call</code> plugin entry instead of treating a missing entry as ready. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: render shared interactive reply buttons in reply delivery so plugin approval messages show inline keyboards. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369897432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76238/hovercard" href="https://github.com/openclaw/openclaw/pull/76238">#76238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Cron/sessions: keep cron metadata rows without an on-disk transcript non-resumable until a transcript exists, so doctor and <code>sessions cleanup --fix-missing</code> no longer report or prune pre-transcript cron rows as broken sessions. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373427724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77011/hovercard" href="https://github.com/openclaw/openclaw/issues/77011">#77011</a>.</li>
<li>Agents/cli-runner: drop a saved <code>claude-cli</code> resume sessionId at preparation time when its on-disk transcript no longer exists in <code>~/.claude/projects/</code>, so a stale binding from a half-installed <code>update.run</code> cannot trap follow-up runs (auto-reply / Telegram direct) in a <code>claude --resume</code> timeout loop; the run starts fresh and the new sessionId is written back through the existing post-run flow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373541733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77030" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77030/hovercard" href="https://github.com/openclaw/openclaw/pull/77030">#77030</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373427724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77011/hovercard" href="https://github.com/openclaw/openclaw/issues/77011">#77011</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Release validation: install the cross-OS TypeScript harness through Windows-safe Node/npm shims so native Windows package checks reach the OpenClaw smoke suites instead of exiting before artifact capture. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Release validation: let Windows packaged-upgrade checks continue after the shipped 2026.5.2 updater hits its native-module swap cleanup fallback, verifying the fallback-installed candidate through package metadata and downstream smoke instead of crashing on the immediate update-status probe. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: skip channel-derived official plugin installs when another configured plugin is the effective owner for the same channel, so <code>doctor --repair</code> does not reinstall <code>feishu</code> while <code>openclaw-lark</code> handles <code>channels.feishu</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371528550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76623" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76623/hovercard" href="https://github.com/openclaw/openclaw/issues/76623">#76623</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuyizheng3120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuyizheng3120">@fuyizheng3120</a>.</li>
<li>Gateway/sessions: memoize repeated thinking-option enrichment and skip unused cost fallback checks while listing sessions, reducing per-row work on large multi-agent stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372926733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76931" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76931/hovercard" href="https://github.com/openclaw/openclaw/issues/76931">#76931</a>.</li>
<li>Gateway/sessions: bound default <code>sessions.list</code> RPC responses and report truncation metadata, preventing Slack-heavy long-lived stores from forcing unbounded Gateway row construction. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373782015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77062" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/77062/hovercard" href="https://github.com/openclaw/openclaw/issues/77062">#77062</a>.</li>
<li>Agents/tools: use config-only runtime snapshots for plugin tool registration and live runtime config getters, avoiding expensive full secrets snapshot clones on the core-plugin-tools prep path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370292544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76295/hovercard" href="https://github.com/openclaw/openclaw/issues/76295">#76295</a>.</li>
<li>Agents/tools: honor the effective tool denylist before constructing optional PDF/media tool factories, so <code>tools.deny: ["pdf"]</code> skips PDF setup before later policy filtering. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373278886" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76997" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76997/hovercard" href="https://github.com/openclaw/openclaw/issues/76997">#76997</a>.</li>
<li>MCP/plugin tools: apply global <code>tools.profile</code>, <code>tools.alsoAllow</code>, and <code>tools.deny</code> policy while exposing plugin tools over the standalone MCP bridge, so ACP clients do not see policy-hidden plugin tools or miss opt-in optional tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin tools: honor explicit tool denylists while selecting plugin tool runtimes, so denied plugin tools are not materialized for direct command or gateway surfaces before later policy filtering. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin tools: filter factory-returned tools by manifest per-tool optional policy, so optional sibling tools from a shared runtime factory stay hidden unless explicitly allowed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/transcripts: retry context-overflow compaction from the current transcript only after the inbound user turn was actually persisted, and keep WebChat agent-run live delivery from writing duplicate Pi-managed assistant turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370788206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76424" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76424/hovercard" href="https://github.com/openclaw/openclaw/issues/76424">#76424</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373573118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77033/hovercard" href="https://github.com/openclaw/openclaw/pull/77033">#77033</a>)</li>
<li>Agents/bootstrap: keep pending <code>BOOTSTRAP.md</code> and bootstrap truncation notices in system-prompt Project Context instead of copying setup text or raw warning diagnostics into WebChat user/runtime context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373002853" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76946/hovercard" href="https://github.com/openclaw/openclaw/issues/76946">#76946</a>.</li>
<li>Gateway/install: keep <code>.env</code>-managed values in the macOS LaunchAgent env file while still tracking <code>OPENCLAW_SERVICE_MANAGED_ENV_KEYS</code>, so regenerated services do not boot without managed auth/provider keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362491875" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75374" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75374/hovercard" href="https://github.com/openclaw/openclaw/issues/75374">#75374</a>.</li>
<li>Gateway/restart: verify listener PIDs by argv when <code>lsof</code> reports only the Node process name, so stale gateway cleanup can find macOS <code>cnode</code> listeners. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317145646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70664" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70664/hovercard" href="https://github.com/openclaw/openclaw/issues/70664">#70664</a>.</li>
<li>Gateway/logging: expand leading <code>~</code> in <code>logging.file</code> before creating the file logger, preventing startup crash loops for home-relative log paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343599652" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73587/hovercard" href="https://github.com/openclaw/openclaw/issues/73587">#73587</a>.</li>
<li>Channels/CLI: keep <code>openclaw channels list --json</code> usable when provider usage fetching fails, and report per-provider usage errors without aborting the channel list. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274421080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67595/hovercard" href="https://github.com/openclaw/openclaw/issues/67595">#67595</a>.</li>
<li>Doctor/plugins: do not treat <code>plugins.allow</code> entries as configured plugins during missing-plugin repair, so restrictive allowlists no longer install allowed-but-unused plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/messaging: deliver distinct final commentary after same-target <code>message</code> tool sends while still deduping text/media already sent by the tool, so short closing remarks are no longer silently dropped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372829643" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76915/hovercard" href="https://github.com/openclaw/openclaw/issues/76915">#76915</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Agents/messaging: preserve string thread IDs when matching message-tool reply dedupe routes, avoiding precision loss on numeric-looking topic IDs before channel plugin comparison. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/streaming: honor <code>agents.defaults.toolProgressDetail: "raw"</code> in Slack, Discord, Telegram, Matrix, and Microsoft Teams progress drafts, so tool-start lines include raw command/detail output when debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/streaming: strip unmatched inline-code backticks from compacted raw progress draft lines, avoiding stray markdown markers after long command details are shortened. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/Slack/Mattermost: align draft preview tool-progress config help with the runtime behavior that hides interim tool updates when <code>streaming.preview.toolProgress</code> is false. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu: use the shared channel progress formatter for streaming-card tool status lines, including raw command/detail output and message-tool filtering. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost: use the shared progress draft formatter for tool status previews, including raw command/detail output when <code>agents.defaults.toolProgressDetail: "raw"</code> is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost: suppress standalone default tool-progress messages while draft previews are active, including when draft tool lines are disabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Telegram: deliver button-only interactive replies by sending the shared fallback button-label text with the inline keyboard instead of dropping the reply as empty. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OpenAI Codex: honor <code>auth.order.openai-codex</code> when starting app-server clients without an explicit auth profile, so status/model probes and implicit startup use the configured Codex account instead of falling back to the default profile. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OpenAI Codex: let SSRF-guarded provider requests inherit OpenClaw's undici IPv4/IPv6 fallback policy, so ChatGPT-backed Codex runs recover on IPv4-working hosts when DNS still returns unreachable IPv6 addresses. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372541165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76857" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76857/hovercard" href="https://github.com/openclaw/openclaw/issues/76857">#76857</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jplavoiemtl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jplavoiemtl">@jplavoiemtl</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Plugin updates: do not short-circuit trusted official npm updates as unchanged when the default/latest spec still resolves to an already-installed prerelease that the installer should replace with a stable fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin updates: clean stale bundled load paths for already-externalized npm installs whose legacy install record only preserved the resolved package name. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin tools: keep auth-unavailable optional tools hidden even when another default tool from the same plugin is available and <code>tools.alsoAllow</code> names the optional tool. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Realtime transcription: report socket closes before provider readiness as closed-before-ready failures instead of mislabeling them as connection timeouts for OpenAI, xAI, and Deepgram streaming transcription. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OpenAI/Google Meet: fail realtime voice connection attempts when the socket closes before <code>session.updated</code>, avoiding stuck Meet joins waiting on a bridge that never became ready. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: avoid treating repeated participant words as multiple assistant-overlap matches when suppressing realtime echo transcripts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: make <code>mode: "agent"</code> the default Chrome talk-back path, using realtime transcription for input and regular OpenClaw TTS for speech output, while keeping direct realtime voice answers available as <code>mode: "bidi"</code> and accepting <code>mode: "realtime"</code> as an agent-mode compatibility alias.</li>
<li>Codex harness: keep <code>codex_app_server.*</code> telemetry publication owned by the harness instead of republishing the same callback event from core runners. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/Discord: suppress standalone tool-progress chatter when partial preview streaming has <code>streaming.preview.toolProgress: false</code>, matching the documented quiet-preview behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Matrix: bind native approval reaction targets before publishing option reactions, so fast approver reactions on threaded prompts are not dropped while the approval handler finishes setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet: make realtime talk-back agent-driven by default with <code>realtime.strategy: "agent"</code>, keep the previous direct bidirectional model behavior available as <code>realtime.strategy: "bidi"</code>, route the Meet tab speaker output to <code>BlackHole 2ch</code> automatically for local Chrome realtime joins, coalesce nearby speech transcript fragments before consulting the agent, and avoid cutting off agent speech from server VAD or stale playback pipe errors.</li>
<li>Google Meet: suppress queued assistant playback and assistant-like transcript echoes from the realtime input path, so the meeting does not hear the agent's own speech as a new user turn and loop or cut itself off.</li>
<li>Google Meet: keep Chrome realtime transport tests hermetic on Linux prerelease shards while preserving the macOS-only runtime guard. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: let the live tool-progress preview and error checks verify progress replacement events without depending on the preview saying <code>Working</code>, <code>tool: read</code>, an unlabelled/pathless <code>read from</code>, or the original draft root being observed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: keep the target=both approval scenario focused on channel and DM metadata delivery by resolving the accepted approval through the gateway after both Matrix events are observed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: wait for live approval reactions to echo before starting the threaded approval decision timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QA/Matrix: reuse the primed driver sync stream when confirming approval reaction echoes, avoiding missed self-reactions in live release runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/WhatsApp: apply the shared group/channel visible-reply mode during inbound dispatch so group replies stay message-tool-only by default without overriding direct-chat harness defaults. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359986231" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75178/hovercard" href="https://github.com/openclaw/openclaw/issues/75178">#75178</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271747463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67394/hovercard" href="https://github.com/openclaw/openclaw/issues/67394">#67394</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Plugins/Codex: preserve Codex-native OAuth routing for <code>/codex bind</code> app-server turns so bound sessions keep the selected Codex auth profile instead of falling back to public OpenAI credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371977999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76714" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76714/hovercard" href="https://github.com/openclaw/openclaw/pull/76714">#76714</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Telegram: keep status checks pointed at the active chat so asking for the current session no longer reports an old direct-message conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371945919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76708/hovercard" href="https://github.com/openclaw/openclaw/issues/76708">#76708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Gateway/install: prefer supported system Node over nvm/fnm/volta/asdf/mise when regenerating managed gateway services, so <code>gateway install --force</code> no longer recreates service definitions that doctor immediately flags as version-manager-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370479446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76339/hovercard" href="https://github.com/openclaw/openclaw/issues/76339">#76339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Google Chat: normalize Google auth certificate response headers before google-auth-library reads cache-control, so inbound webhook auth no longer rejects with <code>res?.headers.get is not a function</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372631806" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76880/hovercard" href="https://github.com/openclaw/openclaw/issues/76880">#76880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donbowman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donbowman">@donbowman</a>.</li>
<li>WhatsApp: route terminal login QR output through the active runtime for initial and restart sockets, so <code>openclaw channels login --channel whatsapp</code> does not lose the QR behind direct stdout writes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369745219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76213" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76213/hovercard" href="https://github.com/openclaw/openclaw/issues/76213">#76213</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dougvk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dougvk">@dougvk</a>.</li>
<li>Proxy/debugging: disable debug proxy direct upstream forwarding for proxy requests and CONNECT tunnels while managed proxy mode is active unless <code>OPENCLAW_DEBUG_PROXY_ALLOW_DIRECT_CONNECT_WITH_MANAGED_PROXY=1</code> is explicitly set for approved local diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Direct APNs: route direct HTTP/2 delivery through the active managed proxy with redacted proxy diagnostics, so push requests honor configured egress controls and <code>openclaw proxy validate --apns-reachable</code> can prove APNs is reachable through the proxy before deployment. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355818960" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74905" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74905/hovercard" href="https://github.com/openclaw/openclaw/pull/74905">#74905</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Agents/subagents: detect prefix-only completion announce replies and fall back to the captured child result so requester chats no longer lose most of long sub-agent reports silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370755013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76412" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76412/hovercard" href="https://github.com/openclaw/openclaw/issues/76412">#76412</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/inxaos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/inxaos">@inxaos</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davemorin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davemorin">@davemorin</a>.</li>
<li>TUI: replace the stale-response watchdog notice with plain user-facing copy so stalled replies no longer surface backend or streaming internals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374171377" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77120" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77120/hovercard" href="https://github.com/openclaw/openclaw/pull/77120">#77120</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davemorin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davemorin">@davemorin</a>.</li>
<li>Security/Windows: validate <code>SystemRoot</code>/<code>WINDIR</code> env values through the Windows install-root validator and add them to the dangerous-host-env policy when resolving <code>icacls.exe</code>/<code>whoami.exe</code> for <code>openclaw security audit</code>, so workspace <code>.env</code> overrides and bare command names cannot redirect Windows ACL helpers to attacker-controlled binaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351894295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74458" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74458/hovercard" href="https://github.com/openclaw/openclaw/pull/74458">#74458</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Security/Windows: pin Windows registry-probe <code>reg.exe</code> resolution to the canonical Windows install root in install-root probing, so <code>SystemRoot</code>/<code>WINDIR</code> env overrides cannot redirect registry queries during Windows host detection. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351875825" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74454" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74454/hovercard" href="https://github.com/openclaw/openclaw/pull/74454">#74454</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>QQBot: preserve the framework command authorization decision when converting framework command contexts into engine slash command contexts, so downstream slash handlers see <code>commandAuthorized</code> matching the channel's resolved <code>isAuthorizedSender</code> instead of a hardcoded <code>true</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378626375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77453/hovercard" href="https://github.com/openclaw/openclaw/pull/77453">#77453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Security/Windows: block <code>LOCALAPPDATA</code> from workspace <code>.env</code> and resolve Windows update-flow portable Git path prepends from the trusted process-local <code>LOCALAPPDATA</code> only, so workspace-supplied values cannot redirect <code>git</code> discovery during <code>openclaw update</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378845160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77470/hovercard" href="https://github.com/openclaw/openclaw/pull/77470">#77470</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Browser/SSRF: enforce the existing current-tab URL navigation policy before tab-scoped debug, export, and read routes (console, page errors, network requests, trace start/stop, response body, screenshot, snapshot, storage, etc.) collect from an already-selected tab, so blocked tabs return a policy error instead of being read first and redacted only at response time. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365339565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75731" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75731/hovercard" href="https://github.com/openclaw/openclaw/pull/75731">#75731</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Security/Windows: route the <code>.cmd</code>/<code>.bat</code> process wrapper through the shared Windows install-root resolver instead of <code>process.env.ComSpec</code>, so workspace dotenv-blocked <code>SystemRoot</code>/<code>WINDIR</code> overrides and unsafe values like UNC paths or path-lists cannot redirect <code>cmd.exe</code> selection on Windows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378853582" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77472/hovercard" href="https://github.com/openclaw/openclaw/pull/77472">#77472</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Agents/bootstrap: honor <code>BOOTSTRAP.md</code> content injected by <code>agent:bootstrap</code> hooks when deciding whether bootstrap is pending, so hook-provided required setup instructions are included in the system prompt. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379258956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77501/hovercard" href="https://github.com/openclaw/openclaw/pull/77501">#77501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.99.0]]></title>
<description><![CDATA[Installer Hashes



Description
Filename
sha256 hash




Per user - x64
PowerToysUserSetup-0.99.0-x64.exe
1E3586A2ECD454B86FE61C44B003E0027FCC24DCB5135958B73D04A58285618C


Per user - ARM64
PowerToysUserSetup-0.99.0-arm64.exe
2BCA2A1EDB0077FAF752DDE95C8D02A0A7A70F8E5128F43EA58432BBBE4E3C62


Mach...]]></description>
<link>https://tsecurity.de/de/3487608/downloads/release-v0990/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487608/downloads/release-v0990/</guid>
<pubDate>Tue, 05 May 2026 01:45:57 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583896700-a19cdc77-c1f0-4430-b43b-ad6c561d5457.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NjcwMC1hMTljZGM3Ny1jMWYwLTQ0MzAtYjQzYi1hZDZjNTYxZDU0NTcucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9Yzg5NDM1Y2VkMWE2ZWVmNzNmZTJlYjdiMmI2OWE1ODRkMTcwNTRmNzU5NmY2NGI3ZTVjYzBmYWI5NjQwNDJkOSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.-V0R-2m5qreW0Vh2CLxWq6VlOvQdOQucEL4k1vS7wGk"><img src="https://private-user-images.githubusercontent.com/9866362/583896700-a19cdc77-c1f0-4430-b43b-ad6c561d5457.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NjcwMC1hMTljZGM3Ny1jMWYwLTQ0MzAtYjQzYi1hZDZjNTYxZDU0NTcucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9Yzg5NDM1Y2VkMWE2ZWVmNzNmZTJlYjdiMmI2OWE1ODRkMTcwNTRmNzU5NmY2NGI3ZTVjYzBmYWI5NjQwNDJkOSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.-V0R-2m5qreW0Vh2CLxWq6VlOvQdOQucEL4k1vS7wGk" alt="Hero image of what's new in version 0.99" content-type-secured-asset="image/png"></a></p>
<h2>Installer Hashes</h2>
<table>
<thead>
<tr>
<th>Description</th>
<th>Filename</th>
<th>sha256 hash</th>
</tr>
</thead>
<tbody>
<tr>
<td>Per user - x64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.99.0/PowerToysUserSetup-0.99.0-x64.exe">PowerToysUserSetup-0.99.0-x64.exe</a></td>
<td>1E3586A2ECD454B86FE61C44B003E0027FCC24DCB5135958B73D04A58285618C</td>
</tr>
<tr>
<td>Per user - ARM64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.99.0/PowerToysUserSetup-0.99.0-arm64.exe">PowerToysUserSetup-0.99.0-arm64.exe</a></td>
<td>2BCA2A1EDB0077FAF752DDE95C8D02A0A7A70F8E5128F43EA58432BBBE4E3C62</td>
</tr>
<tr>
<td>Machine wide - x64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.99.0/PowerToysSetup-0.99.0-x64.exe">PowerToysSetup-0.99.0-x64.exe</a></td>
<td>47D193F77A99FFB606A5E7132B0736BB0FB86BED6F30D68C4269DBDD6928C0AF</td>
</tr>
<tr>
<td>Machine wide - ARM64</td>
<td><a href="https://github.com/microsoft/PowerToys/releases/download/v0.99.0/PowerToysSetup-0.99.0-arm64.exe">PowerToysSetup-0.99.0-arm64.exe</a></td>
<td>B9E9CDDBFE17F785A1A05420636AD716A323FC26B8D55D3B554879BB1F0BF2E8</td>
</tr>
</tbody>
</table>
<h4>Highlights</h4>
<p>PowerToys 0.99 introduces <strong>Power Display for controlling your monitors</strong> from the system tray, <strong>Grab And Move for quickly moving and resizing windows</strong>, and a wave of improvements to Command Palette and the Dock, along with updates across the utility suite.</p>
<hr>
<h2>🪟 Introducing Grab And Move - drag and resize windows from anywhere (Preview)</h2>
<p>This release introduces <strong>Grab And Move</strong>, a new utility that lets you drag and resize windows without having to target the title bar or window edges. Hold <strong>Alt + Left Click</strong> anywhere on a window to drag it, or <strong>Alt + Right Click</strong> to resize it from wherever your cursor is. For users who already use Alt as a system modifier, you can now choose to use the <strong>Win</strong> key instead.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583896796-27e33d8a-0110-447e-83c5-5467afdc791a.gif?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5Njc5Ni0yN2UzM2Q4YS0wMTEwLTQ0N2UtODNjNS01NDY3YWZkYzc5MWEuZ2lmP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NGE4MTY3MWE3Mzg2OGJmNDUxNzBmNGViOTUzY2ZmNDlhZDYyNzRkYTE5YmY3YTAxNDdlYjA4YjQxMzE3MmQxZiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGZ2lmIn0.1Chd4gudqctV99RQNFApMv6h_IlgngZh3od5PFKMs-A"><img width="680" height="241" alt="GrabAndMove" src="https://private-user-images.githubusercontent.com/9866362/583896796-27e33d8a-0110-447e-83c5-5467afdc791a.gif?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5Njc5Ni0yN2UzM2Q4YS0wMTEwLTQ0N2UtODNjNS01NDY3YWZkYzc5MWEuZ2lmP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NGE4MTY3MWE3Mzg2OGJmNDUxNzBmNGViOTUzY2ZmNDlhZDYyNzRkYTE5YmY3YTAxNDdlYjA4YjQxMzE3MmQxZiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGZ2lmIn0.1Chd4gudqctV99RQNFApMv6h_IlgngZh3od5PFKMs-A" content-type-secured-asset="image/gif"></a>
<p>Grab And Move is ideal for large monitors or windows that have moved off-screen, and it integrates with the existing Settings experience including GPO policy support, an OOBE page, and a modifier-agnostic configuration UI.</p>
<p><a href="https://github.com/microsoft/PowerToys/pull/47024" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47024/hovercard">#47024</a> by <a href="https://github.com/foxmsft">@foxmsft</a></p>
<br>
<hr>
<h2>🖥️ Meet Power Display: control your monitors right from the system tray (Preview)</h2>
<p>Meet <strong>Power Display</strong>, a new utility that lets you control your hardware monitors right from the system tray. Once enabled, you can open the flyout from the tray icon or a configurable shortcut to quickly access your connected monitors. Power Display automatically detects your displays and, if supported, lets you adjust settings like volume, brightness, contrast, and color profile. No more reaching for those hard to find buttons on the back of your screen!</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583896918-32c8b96e-3644-47fc-a466-33daa859f944.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NjkxOC0zMmM4Yjk2ZS0zNjQ0LTQ3ZmMtYTQ2Ni0zM2RhYTg1OWY5NDQucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NjZlNzcxZDAyY2QwZDk1OGYzNjI3ODBjYWIxMzJkMzBiZTMwYTU0MzUxNTdiMjE3OTg0M2Y2YThlNjM5ZjM3ZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.XmzCWuOmuO5rhxoJZ5sS7g6aUYSlr4xt-HlZeU4X2RI"><img width="680" height="557" alt="PowerDisplay" src="https://private-user-images.githubusercontent.com/9866362/583896918-32c8b96e-3644-47fc-a466-33daa859f944.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NjkxOC0zMmM4Yjk2ZS0zNjQ0LTQ3ZmMtYTQ2Ni0zM2RhYTg1OWY5NDQucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NjZlNzcxZDAyY2QwZDk1OGYzNjI3ODBjYWIxMzJkMzBiZTMwYTU0MzUxNTdiMjE3OTg0M2Y2YThlNjM5ZjM3ZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.XmzCWuOmuO5rhxoJZ5sS7g6aUYSlr4xt-HlZeU4X2RI" content-type-secured-asset="image/png"></a>
<p>You can also create profiles to quickly switch between different setups with a single click. Profiles can be configured in Settings and will appear directly in the flyout for easy access.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583896950-830c222f-7287-4f9e-8df8-188f69e573d3.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5Njk1MC04MzBjMjIyZi03Mjg3LTRmOWUtOGRmOC0xODhmNjllNTczZDMucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9OTU1YjliYjgwYzAxYTRiNTE3Mzc1YmE5NzE1MDIwYzEzMTUwODBjZmViYTU1NmU3ZGExNGE3MTY1NjQ1ZTA4NSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.Cs4Pe9g_nwqoDvze_Ka6yNTW7D8CppNegilofSvS230"><img width="680" height="509" alt="Profiles" src="https://private-user-images.githubusercontent.com/9866362/583896950-830c222f-7287-4f9e-8df8-188f69e573d3.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5Njk1MC04MzBjMjIyZi03Mjg3LTRmOWUtOGRmOC0xODhmNjllNTczZDMucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9OTU1YjliYjgwYzAxYTRiNTE3Mzc1YmE5NzE1MDIwYzEzMTUwODBjZmViYTU1NmU3ZGExNGE3MTY1NjQ1ZTA4NSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.Cs4Pe9g_nwqoDvze_Ka6yNTW7D8CppNegilofSvS230" content-type-secured-asset="image/png"></a>
<p>Lastly, Power Display profiles can now be automatically switched with Light Switch. In the Light Switch settings, you can select a profile as an action, making it easy to adjust your monitor settings based on the current light or dark theme.<br>
<br></p>
<hr>
<h2>⚡ Command Palette: Compact Dock, Calculator history, and reliability</h2>
<p>This release brings a large set of <strong>fixes and improvements to Command Palette and the Dock</strong>. Alongside a wide range of performance and stability improvements, this release also introduces new capabilities, including support for plain text and image viewer content types for extensions, making it possible to display raw text and zoomable images directly in the content pane, as well as a persistent calculator history with options to save, reuse, delete, and clear entries, plus a configurable primary action and the ability to replace the query on enter.</p>
<p>We've also made several improvements to the Dock experience. You can now choose to <strong>keep the Dock always on top of other windows</strong>. When the Dock is positioned at the top or bottom of the screen, <strong>a new Compact mode is available, offering a more condensed layout that hides the subtitle</strong>!</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583897007-616e2395-1f05-48f3-b326-d4a4417f9966.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzAwNy02MTZlMjM5NS0xZjA1LTQ4ZjMtYjMyNi1kNGE0NDE3Zjk5NjYucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9MTk4OWQyOTk4YjUzZWY0OWNiNWI2NzM5NmM5MGM3ZWE4Njg2YTkxMzY1MzJkNWQ2MDkxZjU1YTE1MDU3YWMwMiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.2fA4RAZOMjZMw8DQU8xp0qS8ACc7Ne8zvP_UwW0z3L4"><img width="680" height="91" alt="Compact mode" src="https://private-user-images.githubusercontent.com/9866362/583897007-616e2395-1f05-48f3-b326-d4a4417f9966.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzAwNy02MTZlMjM5NS0xZjA1LTQ4ZjMtYjMyNi1kNGE0NDE3Zjk5NjYucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9MTk4OWQyOTk4YjUzZWY0OWNiNWI2NzM5NmM5MGM3ZWE4Njg2YTkxMzY1MzJkNWQ2MDkxZjU1YTE1MDU3YWMwMiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.2fA4RAZOMjZMw8DQU8xp0qS8ACc7Ne8zvP_UwW0z3L4" content-type-secured-asset="image/png"></a>
<p>Pinning has also been improved. When you pin a command from Command Palette, a new dialog lets you choose where it appears in the Dock and whether to show or hide the title and subtitle.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583897035-37f06def-79d7-428c-b7b2-b8e37d706e6e.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzAzNS0zN2YwNmRlZi03OWQ3LTQyOGMtYjdiMi1iOGUzN2Q3MDZlNmUucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9ZDgxNGY2ZWUyMDA1YTUxOGE4NGY5YzA5NTAyYTA3MzAwMTY1OTc5MTVjMDVlNTM3ZDA5ZjMzMmY1Njk2ZjllZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.On3f8VXSjFuAEMd537WRhu5M1e_2h_Q_x9vNy4mahaw"><img width="680" height="434" alt="Pin" src="https://private-user-images.githubusercontent.com/9866362/583897035-37f06def-79d7-428c-b7b2-b8e37d706e6e.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzAzNS0zN2YwNmRlZi03OWQ3LTQyOGMtYjdiMi1iOGUzN2Q3MDZlNmUucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9ZDgxNGY2ZWUyMDA1YTUxOGE4NGY5YzA5NTAyYTA3MzAwMTY1OTc5MTVjMDVlNTM3ZDA5ZjMzMmY1Njk2ZjllZCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.On3f8VXSjFuAEMd537WRhu5M1e_2h_Q_x9vNy4mahaw" content-type-secured-asset="image/png"></a>
<p>This release also <strong>fixes two separate typing-crash scenarios</strong>, <strong>hardens extension loading</strong> so one faulty extension no longer takes down the whole list, <strong>improves indexer search with filename broadening</strong> and Windows Search availability indicators, and <strong>adds Windows Terminal profile pinning with per-profile icons</strong>.</p>
<p>Massive thanks to <a href="https://github.com/jiripolasek">@jiripolasek</a> for the sustained Command Palette work across this release!</p>
<br>
<hr>
<h2>⌨️ Keyboard Manager improvements</h2>
<p>In the last release, we introduced a new Keyboard Manager Editor that makes it easier to create and manage remappings. In this release, we are refining that experience further. You can now manually tweak recorded keys. After recording a remapping, <strong>each key becomes a dropdown, allowing you to adjust it or select keys that may not exist on your physical keyboard.</strong></p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583897263-fc341912-e14f-4432-8bc5-449beca684ba.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzI2My1mYzM0MTkxMi1lMTRmLTQ0MzItOGJjNS00NDliZWNhNjg0YmEucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9ZTdkODVkZWQ4NzQ0ODg4ZGQ2ZjIxMjFhMGM5YWI4ZDBkNWRkM2MzZmQ3M2YxYmZjMzdlYTMzMjE3ZTM5YmIyOSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.oLYqB4onnj_gl9YsANrM5Wis7zSPkYBCjad0ra4aVqY"><img width="680" height="475" alt="KBM1" src="https://private-user-images.githubusercontent.com/9866362/583897263-fc341912-e14f-4432-8bc5-449beca684ba.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzI2My1mYzM0MTkxMi1lMTRmLTQ0MzItOGJjNS00NDliZWNhNjg0YmEucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9ZTdkODVkZWQ4NzQ0ODg4ZGQ2ZjIxMjFhMGM5YWI4ZDBkNWRkM2MzZmQ3M2YxYmZjMzdlYTMzMjE3ZTM5YmIyOSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.oLYqB4onnj_gl9YsANrM5Wis7zSPkYBCjad0ra4aVqY" content-type-secured-asset="image/png"></a>
<p>We also added a new action called <strong>Disabled</strong>, which lets you quickly disable specific keys or shortcuts.</p>
<a target="_blank" rel="noopener noreferrer" href="https://private-user-images.githubusercontent.com/9866362/583897293-2fa8a703-ec2a-46fa-b90d-1c71aba33787.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzI5My0yZmE4YTcwMy1lYzJhLTQ2ZmEtYjkwZC0xYzcxYWJhMzM3ODcucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9Yzc1NDRkYWYzZDkwNTQ5NjY2NTc0MWUzYThjZDJmMWJkNzMxOGRmYjliZjgyNGE3YjVkYmFlNzBjNmQ1ZGJiZiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.8gB6mgd39XJnYfazxtVKFumqDPGCdVXGnsd3ff9Tbw4"><img width="680" height="307" alt="KBM2" src="https://private-user-images.githubusercontent.com/9866362/583897293-2fa8a703-ec2a-46fa-b90d-1c71aba33787.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc5Mzg2NTUsIm5iZiI6MTc3NzkzODM1NSwicGF0aCI6Ii85ODY2MzYyLzU4Mzg5NzI5My0yZmE4YTcwMy1lYzJhLTQ2ZmEtYjkwZC0xYzcxYWJhMzM3ODcucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDUwNCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA1MDRUMjM0NTU1WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9Yzc1NDRkYWYzZDkwNTQ5NjY2NTc0MWUzYThjZDJmMWJkNzMxOGRmYjliZjgyNGE3YjVkYmFlNzBjNmQ1ZGJiZiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.8gB6mgd39XJnYfazxtVKFumqDPGCdVXGnsd3ff9Tbw4" content-type-secured-asset="image/png"></a>
<p>We also <strong>fixed an important issue with multi line text replacement</strong>, significantly improving reliability in chat apps and plain text editors.</p>
<br>
<hr>
<h3>🔍 ZoomIt gets scrolling screenshots</h3>
<p>ZoomIt also brings several enhancements to productivity and capture workflows. <strong>You can now take scrolling screenshots</strong>, making it easier to capture long pages or content that extends beyond the visible screen. We've also added text extraction directly when snipping, so you can quickly grab and reuse text without extra steps. In addition, <strong>the break timer has been improved with a new screen saver mode</strong>, helping you step away and take breaks more effectively.</p>
<br>
<hr>
<h3>🧩 Other notable changes</h3>
<ul>
<li><strong>Image Resizer</strong>: The UI has been migrated from WPF to WinUI 3, bringing a more modern look and improved consistency with the rest of PowerToys.</li>
<li><strong>Advanced Paste</strong>: Fixed auto-copy failing on Electron/Chromium apps like Teams and VS Code by releasing held modifier keys before injecting Ctrl+C.</li>
<li><strong>Settings</strong>: Multiple UI and usability improvements across different utilities.</li>
<li><strong>General</strong>: Streamlined default module states so new installations start with a lighter initial experience</li>
<li><strong>System tray icon</strong>: We've updated the monochrome PowerToys system tray icon and added a badge that appears when an update is available.</li>
</ul>
<hr>
<h2>Full release notes</h2>
<h3>Advanced Paste</h3>
<ul>
<li>Eliminated 13 XAML compiler warnings by switching x:Bind expressions on non-observable properties from OneWay to OneTime mode in <a href="https://github.com/microsoft/PowerToys/pull/46726" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46726/hovercard">#46726</a></li>
<li>Fixed auto-copy failing on Electron/Chromium apps (e.g. Teams, VS Code) by releasing held modifier keys before injecting Ctrl+C in <a href="https://github.com/microsoft/PowerToys/pull/46486" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46486/hovercard">#46486</a></li>
</ul>
<h3>Always On Top</h3>
<ul>
<li>Fixed the pin/unpin sound playing even when the operation failed by gating sound playback on whether SetWindowPos actually succeeded in <a href="https://github.com/microsoft/PowerToys/pull/46910" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46910/hovercard">#46910</a></li>
</ul>
<h3>Command Palette</h3>
<h4>Dock</h4>
<ul>
<li>Added a new pin-to-Dock dialog that gives users more control over how commands are pinned, replacing the previous one-click pin behavior in <a href="https://github.com/microsoft/PowerToys/pull/46436" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46436/hovercard">#46436</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
<li>Added a Compact Dock mode (28px tall, subtitle hidden) for Top/Bottom dock positions, and hid the Dock Size setting for Left/Right positions in <a href="https://github.com/microsoft/PowerToys/pull/46699" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46699/hovercard">#46699</a></li>
<li>Made the Dock window stay on top of all other windows by default, automatically yielding when a full-screen app is detected in <a href="https://github.com/microsoft/PowerToys/pull/46163" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46163/hovercard">#46163</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Decoupled the Dock context menu from the Command Bar's active item so it no longer updates when a different list item is selected, and made the Dock search box position follow the Dock position in <a href="https://github.com/microsoft/PowerToys/pull/46420" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46420/hovercard">#46420</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed duplicate dock bands caused by missing duplicate check when pinning in <a href="https://github.com/microsoft/PowerToys/pull/46438" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46438/hovercard">#46438</a></li>
<li>Fixed a build-breaking merge inconsistency in DockWindow.xaml.cs in <a href="https://github.com/microsoft/PowerToys/pull/46639" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46639/hovercard">#46639</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed the Dock not reflecting pin/unpin changes until restart in <a href="https://github.com/microsoft/PowerToys/pull/47169" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47169/hovercard">#47169</a></li>
<li>Fixed the Dock window showing a visible frame on startup by hiding the DWM border during window creation in <a href="https://github.com/microsoft/PowerToys/pull/47187" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47187/hovercard">#47187</a></li>
</ul>
<h4>Extensions &amp; SDK</h4>
<ul>
<li>Added plain text viewer and image viewer IContent types to the extension SDK in <a href="https://github.com/microsoft/PowerToys/pull/43964" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/43964/hovercard">#43964</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Added persistent calculator history with save, reuse, delete, and clear actions, configurable primary action, and replace-query-on-enter behavior in <a href="https://github.com/microsoft/PowerToys/pull/45307" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45307/hovercard">#45307</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Added a NetworkSpeedUnit choice setting to the Performance Monitor extension (bits/s, decimal bytes/s, IEC binary bytes/s) in <a href="https://github.com/microsoft/PowerToys/pull/46320" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46320/hovercard">#46320</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
<li>Enabled dock pinning of Windows Terminal profiles with per-profile icons, and hardened GUID parsing so a malformed profile entry no longer breaks the whole list in <a href="https://github.com/microsoft/PowerToys/pull/46372" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46372/hovercard">#46372</a></li>
<li>Assigned stable IDs to FancyZones layout commands in the PowerToys extension so users can pin individual layouts to the dock in <a href="https://github.com/microsoft/PowerToys/pull/46198" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46198/hovercard">#46198</a> by <a href="https://github.com/vanzue">@vanzue</a>.</li>
<li>Hardened the Performance Monitor extension with exception handling and crash recovery via a sentinel file mechanism in <a href="https://github.com/microsoft/PowerToys/pull/46541" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46541/hovercard">#46541</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Gave each built-in extension its own settings file with transparent one-time migration from the legacy shared settings.json in <a href="https://github.com/microsoft/PowerToys/pull/46685" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46685/hovercard">#46685</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a>.</li>
<li>Shipped Copilot instructions and 5 skills (publish-extension, add-adaptive-card-form, add-extension-settings, add-dock-band, add-fallback-commands) inside the extension template in <a href="https://github.com/microsoft/PowerToys/pull/46683" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46683/hovercard">#46683</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
<li>Fixed invisible/corrupted icons in newly created extensions by extracting template expansion into a dedicated service that no longer rewrites binary files in <a href="https://github.com/microsoft/PowerToys/pull/46490" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46490/hovercard">#46490</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed a Watson crash where a single extension in a bad state would kill the entire extension-loading loop in <a href="https://github.com/microsoft/PowerToys/pull/47032" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47032/hovercard">#47032</a></li>
<li>Fixed right-click context menus failing to open on the first attempt for slow out-of-process third-party extensions in <a href="https://github.com/microsoft/PowerToys/pull/46626" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46626/hovercard">#46626</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed the Settings toggle for disabling fallback commands from out-of-process extensions by switching the type check from a concrete class to the WinRT interface in <a href="https://github.com/microsoft/PowerToys/pull/47127" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47127/hovercard">#47127</a></li>
<li>Simplified the Time &amp; Date extension page to recalculate results on every query rather than caching, breaking a potential infinite update loop in <a href="https://github.com/microsoft/PowerToys/pull/46396" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46396/hovercard">#46396</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed Calculator extension unit tests failing under non-English cultures in <a href="https://github.com/microsoft/PowerToys/pull/46911" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46911/hovercard">#46911</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
</ul>
<h4>Search &amp; Indexer</h4>
<ul>
<li>Improved indexer search with implicit filename broadening for plain free-text queries, retry-with-literal matching for punctuation-heavy searches, and a Windows Search availability indicator in <a href="https://github.com/microsoft/PowerToys/pull/46907" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46907/hovercard">#46907</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed a crash when converting large calculator results to hex/oct/bin by switching the secondary-results base conversion to BigInteger with a custom base converter in <a href="https://github.com/microsoft/PowerToys/pull/46176" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46176/hovercard">#46176</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Split the full-screen shortcut guard into separate full-screen and busy checks with an opt-in IgnoreShortcutWhenBusy setting, added a live diagnostic InfoBar, and introduced an opt-in triple-press breakthrough to bypass suppression in <a href="https://github.com/microsoft/PowerToys/pull/45891" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45891/hovercard">#45891</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed the Window Walker Close window command to respect the "Keep open after closing window" setting and automatically refreshed the window list in <a href="https://github.com/microsoft/PowerToys/pull/45721" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45721/hovercard">#45721</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
</ul>
<h4>Reliability &amp; UX</h4>
<ul>
<li>Fixed a 100% reproducible crash when typing in the search box by adding a reentrancy guard around filtered-items mutations in <a href="https://github.com/microsoft/PowerToys/pull/47148" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47148/hovercard">#47148</a> by <a href="https://github.com/MuyuanMS">@MuyuanMS</a>.</li>
<li>Fixed a second typing crash that occurred when the indexer fallback was enabled by correcting a P/Invoke function signature in <a href="https://github.com/microsoft/PowerToys/pull/47186" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47186/hovercard">#47186</a></li>
<li>Hardened ListViewModel item-fetch synchronization with copy-on-write cache publication, latest-fetch-wins semantics, and improved cancellation cleanup in <a href="https://github.com/microsoft/PowerToys/pull/46429" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46429/hovercard">#46429</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Refactored settings and app state to be immutable end-to-end to eliminate concurrency race conditions in <a href="https://github.com/microsoft/PowerToys/pull/46451" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46451/hovercard">#46451</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a>.</li>
<li>Added a CanGoBack guard to Frame.GoBack, preventing a crash when navigating back with an empty navigation stack in <a href="https://github.com/microsoft/PowerToys/pull/46493" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46493/hovercard">#46493</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed duplicate and contradictory Pin to Dock/Unpin from dock context menu entries appearing on top-level home-page items in <a href="https://github.com/microsoft/PowerToys/pull/46458" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46458/hovercard">#46458</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a>.</li>
<li>Prevented PgUp/PgDown paging from landing on non-interactive entries like separators and section headers in <a href="https://github.com/microsoft/PowerToys/pull/46439" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46439/hovercard">#46439</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed keyboard focus restoration on the Extensions settings page so Shift+Tab returns to the previously selected extension card in <a href="https://github.com/microsoft/PowerToys/pull/45903" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45903/hovercard">#45903</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Reverted focus-restoration on the Extensions settings page that was causing clicks to open the wrong extension item in <a href="https://github.com/microsoft/PowerToys/pull/46642" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46642/hovercard">#46642</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed inline code (backtick text) in the Details and Content panels being invisible on light-theme backgrounds in <a href="https://github.com/microsoft/PowerToys/pull/46739" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46739/hovercard">#46739</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a>.</li>
<li>Fixed the Window Walker "Not Responding" tag being illegible in dark mode in <a href="https://github.com/microsoft/PowerToys/pull/46924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46924/hovercard">#46924</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
<li>Fixed a WinUI layout bug where the settings page content was visually offset when wrapped in a ScrollViewer with MaxWidth in <a href="https://github.com/microsoft/PowerToys/pull/46568" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46568/hovercard">#46568</a></li>
<li>Fixed a regression in PinToDockDialogContent.xaml where a type rename was missed during a merge gap in <a href="https://github.com/microsoft/PowerToys/pull/46599" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46599/hovercard">#46599</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Fixed a screen reader accessibility issue where the Alias text box announced "Enter Alias" instead of just "Alias" in <a href="https://github.com/microsoft/PowerToys/pull/45906" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45906/hovercard">#45906</a></li>
<li>Added screen reader announcements for shortcut key information on the settings button in <a href="https://github.com/microsoft/PowerToys/pull/46164" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46164/hovercard">#46164</a> by <a href="https://github.com/chatasweetie">@chatasweetie</a> and <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Removed redundant container-level tab stops in the details panel for improved keyboard accessibility in <a href="https://github.com/microsoft/PowerToys/pull/46346" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46346/hovercard">#46346</a> by <a href="https://github.com/chatasweetie">@chatasweetie</a>.</li>
</ul>
<h4>Infrastructure &amp; Code Quality</h4>
<ul>
<li>Extracted persistence and file I/O logic from SettingsModel and AppStateModel into dedicated service classes in <a href="https://github.com/microsoft/PowerToys/pull/46312" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46312/hovercard">#46312</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a>.</li>
<li>Introduced CmdPalLogger, CmdPalLoggerProvider, and an extension method integrating Microsoft.Extensions.Logging with ManagedCommon.Logger in <a href="https://github.com/microsoft/PowerToys/pull/46768" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46768/hovercard">#46768</a> by <a href="https://github.com/michaeljolley">@michaeljolley</a>.</li>
<li>Bumped all CommunityToolkit.WinUI packages from 8.2.250402 to 8.2.251219 and removed three SearchBar workaround hacks in <a href="https://github.com/microsoft/PowerToys/pull/46027" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46027/hovercard">#46027</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
<li>Enabled telemetry event firing correctly in AOT builds by adding EventSourceSupport in <a href="https://github.com/microsoft/PowerToys/pull/47121" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47121/hovercard">#47121</a></li>
<li>Updated the extension solution filter files to include new transitive dependencies and added a leaner SLNF for faster developer builds in <a href="https://github.com/microsoft/PowerToys/pull/46896" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46896/hovercard">#46896</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Updated the Microsoft.CmdPal.Ext.PowerToys solution filter file to include missing project dependencies in <a href="https://github.com/microsoft/PowerToys/pull/46136" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46136/hovercard">#46136</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a> and <a href="https://github.com/vanzue">@vanzue</a>.</li>
<li>Removed a legacy workaround for FontIconSource.CreateIconElement (fixed in WinAppSDK 1.8.4) in <a href="https://github.com/microsoft/PowerToys/pull/45790" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45790/hovercard">#45790</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Moved developer documentation to doc/devdocs/modules/cmdpal to align with other PowerToys modules in <a href="https://github.com/microsoft/PowerToys/pull/46926" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46926/hovercard">#46926</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
<li>Bumped Command Palette version to 0.10 in <a href="https://github.com/microsoft/PowerToys/pull/47181" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47181/hovercard">#47181</a></li>
</ul>
<h3>Image Resizer</h3>
<ul>
<li>Migrated Image Resizer from WPF to WinUI 3, unblocking future AOT compilation and aligning with Windows 11 design language in <a href="https://github.com/microsoft/PowerToys/pull/45288" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45288/hovercard">#45288</a> by <a href="https://github.com/moooyo">@moooyo</a> and <a href="https://github.com/niels9001">@niels9001</a>.</li>
<li>Restored honoring the user-configured JPEG quality setting when resizing JPEGs, which had been silently ignored at a fixed ~Q90 default after the WinUI 3 migration in <a href="https://github.com/microsoft/PowerToys/pull/47134" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47134/hovercard">#47134</a></li>
<li>Fixed missing PNG encoder settings by applying codec-specific encoder properties in the transcode path in <a href="https://github.com/microsoft/PowerToys/pull/46695" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46695/hovercard">#46695</a> by <a href="https://github.com/moooyo">@moooyo</a>.</li>
<li>Fixed a regression where JsonPropertyName attributes were not forwarded by the ObservableProperty generator, restoring correct JSON serialization in <a href="https://github.com/microsoft/PowerToys/pull/47056" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47056/hovercard">#47056</a></li>
</ul>
<h3>Keyboard Manager</h3>
<ul>
<li>Reverted multiline text replacement back to character-by-character sending with Shift+Enter for newlines, fixing multiline replacements in chat apps and plain editors in <a href="https://github.com/microsoft/PowerToys/pull/46794" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46794/hovercard">#46794</a></li>
<li>Addressed code review feedback on manual key selection: fixed localization, centralized VK_DISABLED constants, added validation for disable mappings, fixed dropdown revert logic, and plugged Process handle leaks in <a href="https://github.com/microsoft/PowerToys/pull/46377" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46377/hovercard">#46377</a></li>
</ul>
<h3>Light Switch</h3>
<ul>
<li>Fixed Light Switch and PowerDisplay integration by re-enabling the Apply monitor settings expander and disabled-warning InfoBar in Settings, and ensuring every hotkey press notifies PowerDisplay instead of only every other press in <a href="https://github.com/microsoft/PowerToys/pull/47190" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47190/hovercard">#47190</a></li>
</ul>
<h3>Mouse Utilities</h3>
<ul>
<li>Refactored PadImage in PowerOCR (Text Extractor) to improve memory management and nullability clarity in <a href="https://github.com/microsoft/PowerToys/pull/44906" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/44906/hovercard">#44906</a> by <a href="https://github.com/adelobosko">@adelobosko</a>.</li>
</ul>
<h3>Peek</h3>
<ul>
<li>Added auto-detection of file name encoding when previewing zip files, fixing garbled text for archives created on non-UTF-8 systems in <a href="https://github.com/microsoft/PowerToys/pull/44799" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/44799/hovercard">#44799</a> by <a href="https://github.com/oxygen-dioxide">@oxygen-dioxide</a>.</li>
</ul>
<h3>Power Display</h3>
<ul>
<li>Re-enabled the PowerDisplay module with a new icon/logo, DPI fixes, UI/UX improvements, and installer integration in <a href="https://github.com/microsoft/PowerToys/pull/46489" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46489/hovercard">#46489</a></li>
<li>Cleaned up the PowerDisplay module by fixing resource leaks, removing dead code, converting a recursive parser to iterative, and changing the default activation shortcut to Win+Ctrl+Shift+P in <a href="https://github.com/microsoft/PowerToys/pull/46979" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46979/hovercard">#46979</a></li>
<li>Fixed thread safety by marking shared fields as volatile, guarding color temperature writes behind a capability check, and correcting a misleading log message in <a href="https://github.com/microsoft/PowerToys/pull/47008" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47008/hovercard">#47008</a></li>
<li>Fixed PowerDisplay startup restore, volume initialization, and Identify window lifecycle in <a href="https://github.com/microsoft/PowerToys/pull/47051" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47051/hovercard">#47051</a></li>
<li>Introduced a shared flyout positioning helper used by PowerDisplay and Quick Access, fixing taskbar overlap at 100% scaling and off-screen rendering after DPI changes in <a href="https://github.com/microsoft/PowerToys/pull/47097" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47097/hovercard">#47097</a></li>
<li>Polished Power Display by standardizing the module name, shrinking the flyout slightly, and removing dead code in <a href="https://github.com/microsoft/PowerToys/pull/47163" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47163/hovercard">#47163</a></li>
</ul>
<h3>PowerToys Run</h3>
<ul>
<li>Fixed a command breakout in the Shell plugin by escaping double quotes in the command string, while still allowing environment variables to expand in <a href="https://github.com/microsoft/PowerToys/pull/45554" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45554/hovercard">#45554</a> by <a href="https://github.com/RinZ27">@RinZ27</a>.</li>
<li>Removed unused XAML namespace declarations from PowerLauncher XAML files in <a href="https://github.com/microsoft/PowerToys/pull/46221" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46221/hovercard">#46221</a> by <a href="https://github.com/niels9001">@niels9001</a>.</li>
</ul>
<h3>Quick Accent</h3>
<ul>
<li>Added subscript and superscript Unicode characters to the Special Characters set for keys 0-9, A, E, N, X, Y, Z, and math operators in <a href="https://github.com/microsoft/PowerToys/pull/45540" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45540/hovercard">#45540</a> by <a href="https://github.com/Salehnaz">@Salehnaz</a>.</li>
<li>Added the missing Icelandic accented letter í to the VK_I key definition in <a href="https://github.com/microsoft/PowerToys/pull/46424" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46424/hovercard">#46424</a> by <a href="https://github.com/squirrelslair">@squirrelslair</a>.</li>
<li>Added Shift+N capitalization support for superscript Latin small letter n in <a href="https://github.com/microsoft/PowerToys/pull/46571" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46571/hovercard">#46571</a> by <a href="https://github.com/PesBandi">@PesBandi</a>.</li>
<li>Restored the en-dash character under the VK_MINUS key in the Special Characters set in <a href="https://github.com/microsoft/PowerToys/pull/47106" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47106/hovercard">#47106</a></li>
<li>Fixed the default "All available" language setting silently falling back to a small character set due to parsing issues, added case-insensitive parsing with invalid-entry warnings, and added two new Hungarian character mappings in <a href="https://github.com/microsoft/PowerToys/pull/47117" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47117/hovercard">#47117</a> by <a href="https://github.com/daverayment">@daverayment</a>.</li>
</ul>
<h3>Settings</h3>
<ul>
<li>Fixed the Settings shortcut/key visuals so arrow glyphs (up/down/left/right) render as proper FontIcon glyphs instead of literal text in <a href="https://github.com/microsoft/PowerToys/pull/46454" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46454/hovercard">#46454</a> by <a href="https://github.com/vanzue">@vanzue</a>.</li>
<li>Formatted the last checked for updates timestamp as friendly relative strings (Today at 1:22 PM, Yesterday at 3:45 PM) in <a href="https://github.com/microsoft/PowerToys/pull/46923" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46923/hovercard">#46923</a></li>
<li>Fixed Dashboard layout issues by removing excessive empty scroll space, restoring responsive behavior, and correcting a 1-pixel vertical alignment mismatch in <a href="https://github.com/microsoft/PowerToys/pull/46922" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46922/hovercard">#46922</a></li>
<li>Fixed the Quick Accent character-sets grid being clipped and showing an inner horizontal scrollbar, so the list reflows from 3 to 2 to 1 columns on resize in <a href="https://github.com/microsoft/PowerToys/pull/45986" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/45986/hovercard">#45986</a> by <a href="https://github.com/daverayment">@daverayment</a>.</li>
<li>Renamed the shortcut conflict checkbox label from "Ignore shortcut" to "Ignore conflict" for clarity in <a href="https://github.com/microsoft/PowerToys/pull/46318" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46318/hovercard">#46318</a></li>
<li>Fixed the backup folder path being visually clipped on the General and Image Resizer pages in <a href="https://github.com/microsoft/PowerToys/pull/46920" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46920/hovercard">#46920</a></li>
<li>Refreshed Settings UI assets and copy: fixed a ZoomIt page regression, updated the Command Palette settings page with current links and screenshots, and added missing overview screenshots in <a href="https://github.com/microsoft/PowerToys/pull/47132" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47132/hovercard">#47132</a></li>
<li>Fixed missing images in the Settings UI by adjusting the project file so image assets are packaged correctly in <a href="https://github.com/microsoft/PowerToys/pull/47165" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47165/hovercard">#47165</a></li>
<li>Tweaked wording on a handful of Settings strings for clarity and consistency in <a href="https://github.com/microsoft/PowerToys/pull/47164" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47164/hovercard">#47164</a></li>
</ul>
<h3>Text Extractor</h3>
<ul>
<li>Removed the third-party WPF-UI library in favor of native WPF Fluent theming with custom control templates in <a href="https://github.com/microsoft/PowerToys/pull/46218" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46218/hovercard">#46218</a></li>
</ul>
<h3>Window Manager (Grab And Move)</h3>
<ul>
<li>Added the Grab And Move module enabling Alt+Left Click window dragging and Alt+Right Click window resizing, without needing to target title bars in <a href="https://github.com/microsoft/PowerToys/pull/47024" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47024/hovercard">#47024</a></li>
<li>Unstuck the Alt key after Ctrl+Alt+Del or Alt+Tab into an admin process, made Win selectable as the move/resize activation modifier, and made the window geometry readout opaque in <a href="https://github.com/microsoft/PowerToys/pull/47052" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47052/hovercard">#47052</a> by <a href="https://github.com/foxmsft">@foxmsft</a>.</li>
<li>Updated Grab And Move Settings strings to be modifier-agnostic now that Win is selectable alongside Alt in <a href="https://github.com/microsoft/PowerToys/pull/47178" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47178/hovercard">#47178</a></li>
</ul>
<h3>ZoomIt</h3>
<ul>
<li>Added panoramic/scrolling screenshot capture, text extraction when snipping, and break timer improvements with screen saver mode and optional computer lock in <a href="https://github.com/microsoft/PowerToys/pull/46506" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46506/hovercard">#46506</a> by <a href="https://github.com/foxmsft">@foxmsft</a>, <a href="https://github.com/MarioHewardt">@MarioHewardt</a>, and <a href="https://github.com/markrussinovich">@markrussinovich</a>.</li>
<li>Fixed ZoomIt x86 build compatibility by emulating the _mm_cvtsi128_si64 intrinsic with _mm_storel_epi64 for 32-bit targets in <a href="https://github.com/microsoft/PowerToys/pull/46529" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46529/hovercard">#46529</a> by <a href="https://github.com/foxmsft">@foxmsft</a>.</li>
</ul>
<h3>Development</h3>
<ul>
<li>Added a full OOBE page for Grab And Move, high-resolution icons and overview images for both Grab And Move and PowerDisplay, NEW badges on Settings nav items, and refreshed the README utilities table in <a href="https://github.com/microsoft/PowerToys/pull/47033" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47033/hovercard">#47033</a></li>
<li>Added an update-available badged tray icon, a new "Update available" tray menu entry that opens Settings to General, and raised the update InfoBar severity to Warning in <a href="https://github.com/microsoft/PowerToys/pull/47030" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47030/hovercard">#47030</a></li>
<li>Updated the dark-mode PowerToys tray icons to use the correct shade of black for the outline in <a href="https://github.com/microsoft/PowerToys/pull/47166" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47166/hovercard">#47166</a></li>
<li>Changed default-on state for new installations by disabling 7 modules by default to streamline the initial experience for new users in <a href="https://github.com/microsoft/PowerToys/pull/47027" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47027/hovercard">#47027</a></li>
<li>Added explicit default-disabled overrides to eight module interfaces so the native Runner defaults match the managed enabled-modules list, eliminating first-launch enable/disable flicker in <a href="https://github.com/microsoft/PowerToys/pull/47144" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47144/hovercard">#47144</a></li>
<li>Updated the Windows Implementation Library (WIL) from 1.0.231216.1 to 1.0.250325.1 via Central Package Management in <a href="https://github.com/microsoft/PowerToys/pull/43503" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/43503/hovercard">#43503</a></li>
<li>Fixed the build.ps1 script so the -RestoreOnly switch works correctly and added support for the newer .slnf solution filter file format in <a href="https://github.com/microsoft/PowerToys/pull/46012" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46012/hovercard">#46012</a> by <a href="https://github.com/raycheung">@raycheung</a>.</li>
<li>Upgraded the check-spelling CI action to v0.0.26 which fixes spell-check failures on fork PRs and updates exclusion patterns in <a href="https://github.com/microsoft/PowerToys/pull/46851" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46851/hovercard">#46851</a> by <a href="https://github.com/jsoref">@jsoref</a>.</li>
<li>Refreshed the check-spelling action to 0.0.26 and synced dictionaries, patterns, and expect/reject lists across docs, source, and resource files in <a href="https://github.com/microsoft/PowerToys/pull/47119" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47119/hovercard">#47119</a> by <a href="https://github.com/jsoref">@jsoref</a>.</li>
<li>Pinned the check-spelling GitHub Action to v0.0.26 to attempt to fix the CI pipeline blocking PRs from forked repositories in <a href="https://github.com/microsoft/PowerToys/pull/46746" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46746/hovercard">#46746</a></li>
<li>Reverted the pinning of the check-spelling action after determining that the pin was unrelated to the pipeline issue in <a href="https://github.com/microsoft/PowerToys/pull/46749" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46749/hovercard">#46749</a> by <a href="https://github.com/moooyo">@moooyo</a>.</li>
<li>Added contributor names from a recent PR to the spellchecker allow-list to prevent CI spelling errors in <a href="https://github.com/microsoft/PowerToys/pull/46765" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46765/hovercard">#46765</a> by <a href="https://github.com/jiripolasek">@jiripolasek</a>.</li>
<li>Added comprehensive DSC (Desired State Configuration) documentation with per-module reference pages, settings examples, and an overview guide covering 25+ PowerToys modules in <a href="https://github.com/microsoft/PowerToys/pull/42554" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/42554/hovercard">#42554</a> by <a href="https://github.com/Gijsreyn">@Gijsreyn</a>.</li>
<li>Cleaned up root-folder Markdown files by consolidating bullet styles, fixing spelling and grammar, converting HTML to Markdown, and applying sentence-case headers in <a href="https://github.com/microsoft/PowerToys/pull/46582" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46582/hovercard">#46582</a> by <a href="https://github.com/Jay-o-Way">@Jay-o-Way</a>.</li>
<li>Documented three missing telemetry events (ModuleLaunchedFromSettings, CmdPal_DockConfiguration, KeyboardManager_LaunchEditor) in <a href="https://github.com/microsoft/PowerToys/pull/46371" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46371/hovercard">#46371</a></li>
<li>Added telemetry event logging to CLI entry points for FileLocksmith, Awake, and Image Resizer so command-line invocations are tracked alongside GUI usage in <a href="https://github.com/microsoft/PowerToys/pull/46872" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46872/hovercard">#46872</a> by <a href="https://github.com/MuyuanMS">@MuyuanMS</a>.</li>
<li>Added 75+ MSTest unit tests covering Hosts ValidationHelper (IPv4/IPv6/hostname validation) and ColorPicker ColorFormatHelper conversions (CMYK, HSB/HSI/HWB, CIE XYZ/LAB, Oklab/Oklch, sRGB-linear, NCol) in <a href="https://github.com/microsoft/PowerToys/pull/46679" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46679/hovercard">#46679</a></li>
<li>Fixed MSTEST0017 analyzer warnings by correcting assertion argument order in 22 Assert calls across 8 test files in <a href="https://github.com/microsoft/PowerToys/pull/46712" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46712/hovercard">#46712</a></li>
<li>Fixed a CI test hang where Common.Interop.UnitTests.TestSend could block for 80 minutes when a prior run left a named-pipe handle alive, by ensuring pipe names are unique per run and bounding handshake waits in <a href="https://github.com/microsoft/PowerToys/pull/47123" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/47123/hovercard">#47123</a></li>
<li>Resolved StyleCop SA1614, SA1616, SA1622, and SA1623 warnings across Command Palette, Power Display, Settings UI, DSC, and Extensions Toolkit code in <a href="https://github.com/microsoft/PowerToys/pull/46706" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46706/hovercard">#46706</a>, <a href="https://github.com/microsoft/PowerToys/pull/46707" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46707/hovercard">#46707</a>, <a href="https://github.com/microsoft/PowerToys/pull/46717" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46717/hovercard">#46717</a>, <a href="https://github.com/microsoft/PowerToys/pull/46718" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46718/hovercard">#46718</a></li>
<li>Bumped the azure/login GitHub Action from v2 to v3 in the MS Store submissions workflow in <a href="https://github.com/microsoft/PowerToys/pull/46323" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46323/hovercard">#46323</a></li>
<li>Bumped the azure/cli GitHub Action from v2 to v3 in the MS Store submissions workflow in <a href="https://github.com/microsoft/PowerToys/pull/46562" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/PowerToys/pull/46562/hovercard">#46562</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft takes Agent 365 out of preview as shadow AI becomes an enterprise threat]]></title>
<description><![CDATA[Microsoft last week took Agent 365, its management platform for AI agents, out of preview and into general availability — a move that signals the software giant believes the governance challenge around autonomous AI is no longer theoretical but operational and urgent.The product, first announced ...]]></description>
<link>https://tsecurity.de/de/3487282/it-nachrichten/microsoft-takes-agent-365-out-of-preview-as-shadow-ai-becomes-an-enterprise-threat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487282/it-nachrichten/microsoft-takes-agent-365-out-of-preview-as-shadow-ai-becomes-an-enterprise-threat/</guid>
<pubDate>Mon, 04 May 2026 21:32:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://microsoft.com/">Microsoft</a> last week took <a href="https://www.microsoft.com/en-us/microsoft-agent-365">Agent 365</a>, its management platform for AI agents, out of preview and into <a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/">general availability</a> — a move that signals the software giant believes the governance challenge around autonomous AI is no longer theoretical but operational and urgent.</p><p>The product, first announced at <a href="https://ignite.microsoft.com/en-US/home">Microsoft's Ignite conference</a> in November, positions itself as a unified control plane that lets enterprise IT and security teams observe, govern, and secure AI agents wherever they run: inside Microsoft's own ecosystem, on third-party cloud platforms like <a href="https://aws.amazon.com/bedrock/">AWS Bedrock</a> and <a href="https://cloud.google.com/?hl=en">Google Cloud</a>, on employee endpoints, and increasingly across a sprawling ecosystem of SaaS agents built by partner software companies.</p><p>But the most striking element of the launch isn't the general availability milestone itself. It's Microsoft's aggressive push into discovering and managing <i>local</i> AI agents — the coding assistants, personal productivity tools, and autonomous workflows that employees are installing on their own devices, often without IT's knowledge or blessing. Microsoft calls this phenomenon "<a href="https://www.ibm.com/think/topics/shadow-ai">shadow AI</a>," and it is an entirely new category of enterprise security risk that most organizations are only beginning to grapple with.</p><p>"Most enterprises are trying to figure out how to harness the potential of autonomous agents," David Weston, Corporate Vice President of AI Security at Microsoft, told VentureBeat in an exclusive interview. "They're trying to find a balance between what we call YOLO — just let anything run — and 'oh no,' where nothing works at all."</p><h2><b>Why Microsoft says rogue AI agents are already a security crisis inside the enterprise</b></h2><p>The timing of Agent 365's <a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/">general availability</a> reflects an uncomfortable reality: AI agents have already outpaced the governance infrastructure designed to manage them. Enterprises that spent years building controls for cloud applications and SaaS software now face a fundamentally different kind of sprawl — one where autonomous software can invoke tools, access sensitive data, chain together with other agents, and take actions on behalf of users or entirely on their own.</p><p>Weston described three specific categories of security incidents that Microsoft is already observing across its enterprise customer base. The first, and most common, involves developers rushing to connect agents to backend systems and inadvertently exposing sensitive infrastructure. "A canonical thing we're seeing a lot across the board is these MCP servers that are then being connected to a sensitive back end system and then exposed unauthenticated to the internet," Weston said. "That can lead to PII or data leaks."</p><p>The second category involves what security researchers call cross-prompt injection — attackers embedding malicious instructions in data sources like software tickets, websites, or wikis that an agent is likely to ingest. "We are seeing attackers use untrusted data sources to put in what we call cross-prompt injection prompts, which will basically direct your agent to do whatever the attacker wants," Weston explained. While he noted this attack vector remains less common, "when we do see it, it's higher impact."</p><p>The third and perhaps most pervasive issue is more mundane but no less dangerous: agents connected to data sources and DLP systems that simply aren't designed to understand agentic access patterns. "Data sources and DLP systems that are not agent-aware are exposing high-sensitive data down to maybe a vendor," Weston said, adding that such incidents carry "a lot of costs and a lot of risk."</p><h2><b>Inside Agent 365, the $15-per-user control plane for governing AI agents at scale</b></h2><p>At its core, <a href="https://www.microsoft.com/en-us/microsoft-agent-365">Agent 365</a> functions as a centralized registry and policy engine for AI agents. It provides IT administrators with a single view of every agent operating within their environment — whether that agent was built with <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/microsoft-copilot-studio">Microsoft Copilot Studio</a>, deployed on <a href="https://aws.amazon.com/bedrock/">AWS Bedrock</a>, running as a SaaS integration from a partner like <a href="https://www.zendesk.com/lp/brand/?utm_source=google&amp;utm_medium=Search-Paid&amp;utm_network=g&amp;utm_campaign=SE_AW_AM_US_EN_N_Sup_Brand_TM_Alpha_D_H&amp;matchtype=e&amp;utm_term=zendesk&amp;utm_content=683398971102&amp;theme=Zendesk_Trademark&amp;gad_source=1&amp;gad_campaignid=8401696302&amp;gbraid=0AAAAADn4z6jni6f5jVlpk6sPeiF9cYTlh&amp;gclid=Cj0KCQjwh-HPBhCIARIsAC0p3cdg6n5uQAq0XCscNSVv3J3xBvWTyM0uf2BwBx_3m2atBwqf0Nf5rxMaAhO4EALw_wcB">Zendesk</a> or <a href="https://www.sap.com/index.html">SAP</a>, or installed locally on a developer's Windows machine.</p><p>The platform supports three distinct categories of agents, each with different availability status at launch. Agents working on behalf of users through delegated access — such as an inbox organizer operating with a user's permissions — are now generally available within the control plane. Agents operating behind the scenes with their own access credentials, like an autonomous system triaging support tickets, are also generally available. A third category, agents participating in team workflows with their own access, enters public preview today.</p><p><a href="https://www.microsoft.com/en-us/microsoft-agent-365">Agent 365 </a>is available as part of the new <a href="https://microsoftpartners.microsoft.com/abs/Blog/?title=Introducing%20Microsoft%20365%20E7%3A%20The%20Frontier%20Suite">Microsoft 365 E7 suite</a> or as a standalone product priced at $15 per user per month. Each license covers an individual who manages, sponsors, or uses agents to work on their behalf. The pricing model is designed to scale predictably: organizations pay per person who interacts with the agent ecosystem, not per agent — a structure that acknowledges the reality that agent counts are a moving target in most enterprises.</p><h2><b>How Microsoft hunts for unauthorized AI tools hiding on employee laptops</b></h2><p>Perhaps the most significant new capability in today's launch is Agent 365's ability to discover and manage local AI agents — the tools that developers and knowledge workers are installing directly on their Windows devices, often without any oversight from IT.</p><p>Starting today, organizations enrolled in <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/frontier-features">Microsoft's Frontier program</a> can use Agent 365, powered by Microsoft Defender and Intune, to detect OpenClaw agents running on managed Windows devices. Administrators can view which devices are running <a href="https://openclaw.ai/">OpenClaw</a>, and they can apply Intune policies to block common execution methods. A new "<a href="https://learn.microsoft.com/en-us/microsoft-365/admin/manage/agent-shadow-ai?view=o365-worldwide">Shadow AI</a>" page in the Microsoft 365 admin center serves as the central dashboard for this discovery process.</p><p>The choice to begin with OpenClaw was deliberate. "Our criteria is simply customer demand," Weston told VentureBeat. "We're hearing across the board that enterprises understand OpenClaw represents a new type of software. They want to be on the frontier, they want to leverage all the benefits, but they also want the deterministic control that lets them establish a clear boundary in their enterprise."</p><p>Microsoft plans to expand local agent discovery to <a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/">18 different agent types by June 2026</a>, including <a href="https://github.com/features/copilot/cli">GitHub Copilot CLI</a> and <a href="https://code.claude.com/docs/en/overview">Claude Code</a>. The company is leveraging its existing endpoint telemetry to identify applications calling inference endpoints, then surfacing that information to IT and security teams. "Using our visibility on the endpoint, we can see the variety of apps that are basically calling inference endpoints," Weston explained. "And then we can give a collection of that to the IT and security folks, and they can decide whether that's appropriate or something that's putting them at risk."</p><h2><b>Microsoft Defender maps the 'blast radius' when an AI agent goes wrong</b></h2><p>Starting in June, <a href="https://www.microsoft.com/en-us/microsoft-365/microsoft-defender-for-individuals">Microsoft Defender</a> will provide what the company calls "asset context mapping" for each discovered agent. This feature builds a relationship graph showing which devices an agent runs on, which MCP servers it connects to, which identities are associated with it, and which cloud resources those identities can reach. The goal is to let security teams assess the potential blast radius if an agent is compromised or misbehaves.</p><p>Weston explained the technical underpinning: "Blast radius is computed by taking an asset inventory and converting each asset into a node in a graph. The edges represent how different assets or data sources are connected." The system overlays contextual detail onto each node — for instance, flagging that a particular device runs an untrusted AI agent and is simultaneously connected to a critical business database or a machine with thousands of user accounts.</p><p>"It's highly accurate because it's computed from an asset graph that's typically cloud-based, or built from endpoint data if you've got something like NDE deployed," Weston said. "We're computing it based on what you already have — which is essentially ground truth." This kind of exposure mapping is precisely what CISOs are asking for, Weston added. "One of the first things you want to know when assessing agent risk is: what is this connected to? Is it connected to something I care about, or is it something moderate?"</p><p>The platform doesn't stop at visibility. <a href="https://www.microsoft.com/en-us/microsoft-agent-365">Agent 365</a> introduces policy-based controls that let administrators set guardrails for what agents can and cannot do. If a managed agent exhibits malicious behavior patterns — such as attempting to access or exfiltrate sensitive data — <a href="https://www.microsoft.com/en-us/microsoft-365/microsoft-defender-for-individuals">Microsoft Defender</a> can block the agent at runtime and generate alerts with rich incident context for investigation. Weston emphasized that Defender's existing classification capabilities translate directly to the agentic world. "Injecting code into the process that manages logins, whether you're OpenClaw or browser, that's always going to be a strong signal," he said. Context mapping, policy-based controls, and runtime blocking will enter public preview through Intune and Defender in June 2026.</p><h2><b>Agent 365 reaches into AWS and Google Cloud to govern agents across rival platforms</b></h2><p>In a notable competitive move, Microsoft is extending Agent 365's governance reach to rival cloud platforms. A new public preview of Agent 365 registry sync enables IT teams to connect with <a href="https://aws.amazon.com/bedrock/">AWS Bedrock</a> and <a href="https://cloud.google.com/?hl=en">Google Cloud</a> (specifically, Google Gemini Enterprise Agent Platform, formerly Google Vertex AI). Through these connections, administrators can automatically discover and inventory agents running on those platforms and perform basic lifecycle governance actions such as starting, stopping, or deleting agents.</p><p>"If we're going to be a single control plane, we have to meet customers where they are, and many of them are multi-cloud," Weston told VentureBeat. He acknowledged that the depth of available controls varies somewhat by cloud provider. "Once you know it's there, what kind of guardrails or blocking can you provide? And that's going to be slightly different depending on what the cloud provider works with." But he added that the platforms offer "pretty comparable capabilities" in most scenarios and expressed optimism that cross-cloud consistency will improve over time.</p><p>Also generally available today: Agent 365 extends <a href="https://www.microsoft.com/en-us/security/business/microsoft-entra">Microsoft Entra</a> network controls to cover agent traffic from Microsoft Copilot Studio agents and local agents like OpenClaw. These controls let security teams inspect agent network activity, identify unsanctioned AI usage, restrict connections to approved web destinations, filter risky file transfers, and help block malicious prompt-based attacks at the network layer before they result in harmful actions. The combination of cloud registry sync and network-layer enforcement gives Microsoft an unusually broad governance surface — one that spans cloud, endpoint, and network in a way few competitors currently match.</p><h2><b>Windows 365 for Agents gives enterprises a sandbox for high-risk AI workloads</b></h2><p>For organizations that want the productivity benefits of autonomous agents but aren't comfortable running them directly on employee endpoints, Microsoft is also launching <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-for-agents-now-in-public-preview-run-ai-agents-securely-at-scale/4513479">Windows 365 for Agents</a> in public preview, currently limited to the United States. The offering creates a new class of Cloud PCs purpose-built for agentic workloads, managed through Intune, and governed by the same identity and security controls applied to human employees.</p><p>Weston framed the capability as a segmentation play. "From a security principle standpoint, the more segmentation you can achieve, the better," he said. "If you don't want this on your endpoint, but you still want the capability, you can choose to have it sandboxed, isolated. We've seen large companies like Nvidia talk about doing this. We're creating this pattern for everyone."</p><p>How critical that isolation is, Weston added, depends on context. "If you're working in a military installation, it goes without saying, you probably want to segment away that information. If you're working in a company that's primarily creative and you have a little higher risk tolerance, you may not want to do that." The public preview requires an Agent 365 license, an Intune license, and an active Azure subscription.</p><h2><b>Microsoft builds a broad partner network to manage the agentic AI ecosystem</b></h2><p>Microsoft is positioning Agent 365 not as a walled garden but as an open management layer. The company announced that ecosystem partner agents from <a href="https://www.genspark.ai/">Genspark</a>, <a href="https://zensai.com/">Zensai</a>, <a href="https://www.egnyte.com/">Egnyte</a>, <a href="https://www.zendesk.com/">Zendesk</a>, and agents built on platforms including <a href="https://kasisto.com/">Kasisto</a>, <a href="http://kore.ai/">Kore.ai</a>, and <a href="https://n8n.io/">n8n</a> are now fully enabled for management through Agent 365 — with no integration work required from IT teams. Additional software development company launch partners include <a href="https://www.adobe.com/">Adobe</a>, <a href="https://www.sap.com/index.html">SAP</a>, <a href="https://manus.im/">Manus</a>, <a href="https://www.nvidia.com/en-us/">Nvidia</a>, and <a href="https://www.celonis.com/">Celonis</a>.</p><p>For partner-built SaaS agents, onboarding begins with identity. "We have the ability for you to simply give it an identity and or use our SDK depending on the level of capability you need," Weston explained. "Just starting with the identity, we're able to basically see, especially for Entra users, what capabilities the application needs and what constraints should be put on that." Deeper SDK integration provides richer observability data, but identity alone gives the platform substantial governance leverage.</p><p>On the services side, Microsoft has enlisted firms including <a href="https://www.accenture.com/us-en">Accenture</a>, <a href="https://kpmg.com/us/en.html">KPMG</a>, <a href="https://www.capgemini.com/us-en/">Capgemini</a>, <a href="https://www.protiviti.com/">Protiviti</a>, <a href="https://www.slalom.com/us/en">Slalom</a>, and nearly two dozen others as Agent 365 Launch Partners. These firms have collaborated with Microsoft engineering to build offerings around inventory assessment, least-privilege enforcement, compliance, multi-platform threat analysis, and ongoing lifecycle management.</p><h2><b>Microsoft's bigger bet: agents are the new apps, and they need the same enterprise controls</b></h2><p>Microsoft's bet with <a href="https://www.microsoft.com/en-us/microsoft-agent-365">Agent 365</a> arrives at a moment when the enterprise software industry is racing to define what the "agentic era" actually looks like in production. Competitors including <a href="https://www.google.com/">Google</a>, <a href="https://www.amazon.com/">Amazon</a>, and <a href="https://www.salesforce.com/">Salesforce</a> are all developing their own agent orchestration and governance tools, but Microsoft's approach — leveraging its deeply entrenched position in endpoint management (<a href="https://www.microsoft.com/en-us/security/business/microsoft-intune">Intune</a>), threat detection (<a href="https://www.microsoft.com/en-us/microsoft-365/microsoft-defender-for-individuals">Defender</a>), identity (<a href="https://www.microsoft.com/en-us/security/business/microsoft-entra">Entra</a>), and productivity (<a href="https://www.microsoft.com/en-us/microsoft-365/what-is-microsoft-365">Microsoft 365</a>) — gives it an unusual cross-surface advantage.</p><p>For enterprises considering Agent 365, Weston outlined a phased adoption model. "First things first, they'll get visibility and an inventory — you can't really secure what you don't know about," he said. "The next thing they're able to do is assign identities and start to manage the access those agents have, which is a huge first step in managing the risk." The deeper capabilities — isolation through Windows 365 for Agents, runtime blocking, blast radius mapping — come next. "Crawl is inventory. Walk is getting identity and access. Run is getting isolation, better control, deeper visibility," Weston summarized. "I think that's something that's reasonable in a 90-day period."</p><p>Whether enterprises actually move that fast will depend on the maturity of their existing security infrastructure and the pace at which shadow AI proliferates within their walls. A live "<a href="https://techcommunity.microsoft.com/blog/agent-365-blog/register-now-for-agent-365-live-ama-on-may-12/4511734">Ask Microsoft Anything</a>" session on Agent 365 is scheduled for May 12, giving IT and security professionals a chance to press the engineering team on specifics.</p><p>But the most telling detail from the interview may have been the most offhand. "I have 18 agents running behind my team chat right now," Weston said. If even Microsoft's own security chief has a small army of autonomous agents operating in his daily workflow, the question for every other enterprise is no longer whether to govern the agentic workforce — it's whether they can do it before the workforce governs itself.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Musk v. Altman is just getting started]]></title>
<description><![CDATA[Elon Musk spent the better part of three days on the witness stand this week in his lawsuit against OpenAI, and it’s already getting messy. Emails, texts, and his own tweets are surfacing in court, and there are plenty more witnesses to come. Musk’s argument against OpenAI? By converting the comp...]]></description>
<link>https://tsecurity.de/de/3480969/it-nachrichten/musk-v-altman-is-just-getting-started/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480969/it-nachrichten/musk-v-altman-is-just-getting-started/</guid>
<pubDate>Fri, 01 May 2026 20:02:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Elon Musk spent the better part of three days on the witness stand this week in his lawsuit against OpenAI, and it’s already getting messy. Emails, texts, and his own tweets are surfacing in court, and there are plenty more witnesses to come. Musk’s argument against OpenAI? By converting the company to a for-profit model, Sam Altman betrayed the “nonprofit for the […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Serving the Linux community (VFX + Music Software/Plugins)]]></title>
<description><![CDATA[Hey all, I make software for visual artists and musicians. I'm considering converting an old computer to Linux as I'm getting tired of microspyware with each update, but I don't have direct experience outside of hosting. I also can't outright switch due to Ableton and some other choice software. ...]]></description>
<link>https://tsecurity.de/de/3479310/linux-tipps/serving-the-linux-community-vfx-music-softwareplugins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479310/linux-tipps/serving-the-linux-community-vfx-music-softwareplugins/</guid>
<pubDate>Fri, 01 May 2026 04:37:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey all, I make software for visual artists and musicians. I'm considering converting an old computer to Linux as I'm getting tired of microspyware with each update, but I don't have direct experience outside of hosting. I also can't outright switch due to Ableton and some other choice software.</p> <p>I'd love to understand how to better serve the Linux community though. What are your go to applications for video editing and music making?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/hairybone"> /u/hairybone </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1szw72v/serving_the_linux_community_vfx_music/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1szw72v/serving_the_linux_community_vfx_music/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft and OpenAI gut their exclusive deal, freeing OpenAI to sell on AWS and Google Cloud]]></title>
<description><![CDATA[Microsoft and OpenAI on Monday announced a sweeping overhaul of the partnership that has defined the commercial AI era, dismantling key pillars of exclusivity and revenue-sharing that bound the two companies together for years and replacing them with a looser, time-limited arrangement that gives ...]]></description>
<link>https://tsecurity.de/de/3469642/it-nachrichten/microsoft-and-openai-gut-their-exclusive-deal-freeing-openai-to-sell-on-aws-and-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469642/it-nachrichten/microsoft-and-openai-gut-their-exclusive-deal-freeing-openai-to-sell-on-aws-and-google-cloud/</guid>
<pubDate>Tue, 28 Apr 2026 02:01:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.microsoft.com/en-us">Microsoft</a> and <a href="https://openai.com/">OpenAI</a> on Monday announced a sweeping overhaul of the <a href="https://openai.com/index/next-phase-of-microsoft-partnership/">partnership</a> that has defined the commercial AI era, dismantling key pillars of exclusivity and revenue-sharing that bound the two companies together for years and replacing them with a looser, time-limited arrangement that gives both sides far more freedom to pursue rival relationships.</p><p>The amended agreement, disclosed simultaneously in blog posts from <a href="https://openai.com/index/next-phase-of-microsoft-partnership/">both</a> <a href="https://blogs.microsoft.com/blog/2026/04/27/the-next-phase-of-the-microsoft-openai-partnership/">companies</a>, marks the most significant restructuring since <a href="https://news.microsoft.com/source/2019/07/22/openai-forms-exclusive-computing-partnership-with-microsoft-to-build-new-azure-ai-supercomputing-technologies/">Microsoft first invested $1 billion in OpenAI in 2019</a> — and it transforms what was once the most consequential exclusive technology alliance in a generation into something that more closely resembles a strategic but arm's-length commercial relationship.</p><div></div><p>Under the new terms, <a href="https://openai.com/index/next-phase-of-microsoft-partnership/">Microsoft will no longer pay any revenue share to OpenAI</a> when customers access OpenAI models through Azure. OpenAI, meanwhile, will continue paying a revenue share to Microsoft through 2030 — at the same 20 percent rate — but that obligation is now <a href="https://openai.com/index/next-phase-of-microsoft-partnership/">subject to a total cap</a>. Microsoft retains a license to OpenAI's intellectual property for models and products through 2032, but that license is now explicitly non-exclusive. And OpenAI, critically, can now serve all of its products to customers on any cloud provider — including Amazon Web Services and Google Cloud — ending the exclusivity that had been a cornerstone of the original deal.</p><p>"The rapid pace of innovation requires us to continue to evolve our partnership to benefit our customers and both companies," Microsoft wrote in its blog post Monday. OpenAI echoed the framing, calling the amended agreement a move "grounded in flexibility, certainty, and a focus on delivering the benefits of AI broadly."</p><p>The diplomatic language belies the drama that led to this moment — months of behind-the-scenes tension, competing deal announcements, public contradictions, and even the specter of litigation between two companies whose fates have been intertwined since the earliest days of the generative AI revolution.</p><h2><b>How a billion-dollar bet on AI created the most powerful exclusive partnership in tech</b></h2><p>To understand why Monday's announcement matters so much, it helps to understand what came before it. When <a href="https://news.microsoft.com/source/2019/07/22/openai-forms-exclusive-computing-partnership-with-microsoft-to-build-new-azure-ai-supercomputing-technologies/">Microsoft poured its initial $1 billion into OpenAI in 2019</a>, and then followed with a cumulative investment <a href="https://www.cnbc.com/2023/04/08/microsofts-complex-bet-on-openai-brings-potential-and-uncertainty.html">exceeding $13 billion</a>, it secured something extraordinary: exclusive commercial access to OpenAI's models and intellectual property. <a href="https://blogs.microsoft.com/blog/2026/02/27/microsoft-and-openai-joint-statement-on-continuing-partnership/">Azure became the sole cloud provider for OpenAI's API products</a>. Microsoft <a href="https://news.microsoft.com/source/features/ai/openai-gpt-5/">integrated OpenAI's GPT models</a> into everything from Bing to Office to GitHub Copilot. The arrangement was, by any measure, one of the most lopsided technology licensing deals in modern history — Microsoft got privileged access to the most capable AI models on the planet, and OpenAI got the capital and infrastructure it needed to scale.</p><p>The deal even contained an unusual provision: Microsoft's exclusive rights would remain in force <a href="https://www.theverge.com/ai-artificial-intelligence/918981/openai-microsoft-renegotiate-contract">until OpenAI achieved artificial general intelligence</a>, or AGI — a loosely defined milestone referring to AI systems that rival or exceed human intelligence across a broad range of tasks. OpenAI's board retained the authority to declare when AGI had been reached, at which point certain commercial terms would change. It was, in effect, <a href="https://www.reuters.com/commentary/breakingviews/openais-agi-chase-is-tricky-concept-contract-2026-03-16/">a philosophical tripwire</a> embedded in a business contract.</p><p>That structure worked well enough when OpenAI was a research lab with a modest commercial footprint. But as ChatGPT <a href="https://www.reuters.com/technology/chatgpt-sets-record-fastest-growing-user-base-analyst-note-2023-02-01/">exploded into the mainstream</a> in late 2022 and OpenAI's annualized revenue <a href="https://www.theinformation.com/articles/openais-revenue-crossed-1-3-billion-annualized-rate-ceo-tells-staff">rocketed into the billions</a>, the constraints began to chafe. OpenAI found itself locked into a single cloud ecosystem at precisely the moment when enterprises — its fastest-growing customer segment — were demanding multi-cloud flexibility. In an internal memo earlier this month, OpenAI's revenue chief Denise Dresser put it bluntly, telling staff that the Microsoft partnership had "<a href="https://www.theverge.com/ai-artificial-intelligence/911118/openai-memo-cro-ai-competition-anthropic">limited our ability to meet enterprises where they are</a>," according to a report from The Verge.</p><h2><b>Amazon's $50 billion OpenAI investment created a legal crisis that forced the restructuring</b></h2><p>The proximate cause of Monday's restructuring was not a philosophical disagreement about AI safety or corporate governance. It was a $50 billion check from Amazon. In February, OpenAI announced that <a href="https://www.reuters.com/business/retail-consumer/amazons-50-billion-openai-investment-may-depend-ipo-or-agi-milestone-information-2026-02-26/">Amazon would invest up to $50 billion</a> in the company — $15 billion upfront, with another $35 billion to follow when certain unspecified conditions were met. In exchange, OpenAI agreed to expand its existing cloud agreement with AWS by $100 billion over eight years and, most controversially, <a href="https://openai.com/index/amazon-partnership/">committed to making AWS the exclusive third-party distribution provider for Frontier</a>, its new enterprise agent-building platform. OpenAI also agreed to co-develop "stateful runtime technology" on AWS Bedrock, the infrastructure layer that allows AI agents to maintain memory and context over extended tasks.</p><p>The problem was that OpenAI's existing contract with Microsoft almost certainly prohibited these arrangements. Microsoft held exclusive rights to any OpenAI product accessed through an API — a category that plainly included Frontier. On the very day OpenAI announced the Amazon deal, Microsoft issued a pointed public statement insisting that "Azure remains the exclusive cloud provider of stateless OpenAI APIs" and that "OpenAI's first party products, including Frontier, will continue to be hosted on Azure." The contradiction between the two announcements was stark, and it created immediate legal exposure. The <a href="https://www.ft.com/content/e814f4c3-4fb5-4e2e-90a6-470044436b39?syn-25a6b1a6=1">Financial Times</a> reported in March that Microsoft was actively considering legal action to enforce its contractual rights. The situation placed OpenAI in an impossible position: it had made promises to Amazon that it seemingly could not keep under the terms of its Microsoft agreement.</p><div></div><p>Monday's deal resolves that impasse entirely. By converting Microsoft's license from exclusive to non-exclusive and explicitly granting OpenAI the right to serve products on any cloud, the new terms retroactively validate the Amazon arrangement and eliminate the legal overhang. Amazon CEO Andy Jassy wasted no time celebrating. "We're excited to make OpenAI's models available directly to customers on Bedrock in the coming weeks, alongside the upcoming Stateful Runtime Environment," he wrote on X, adding that the company would share more details at an event in San Francisco on Tuesday.</p><h2><b>Inside the new financial terms that shift billions of dollars between the two AI giants</b></h2><p>The financial mechanics of the new deal deserve careful parsing, because they reveal which side gave up what — and who came out ahead. Under the old arrangement, money flowed in both directions. When customers bought ChatGPT subscriptions or accessed OpenAI models through their own applications, OpenAI paid Microsoft a cut — <a href="https://www.cnbc.com/2026/04/27/openai-microsoft-partnership-revenue-cap.html">reportedly 20 percent</a>. Conversely, when enterprise customers accessed OpenAI models through Azure's API, Microsoft paid OpenAI a share of that revenue. This <a href="https://blogs.microsoft.com/blog/2023/01/23/microsoftandopenaiextendpartnership/">bilateral structure</a> reflected the deep integration between the two companies: Microsoft was simultaneously OpenAI's investor, cloud provider, distribution partner, and largest customer.</p><p>The <a href="https://openai.com/index/next-phase-of-microsoft-partnership/">new deal</a> makes the cash flow one-directional. Microsoft stops paying OpenAI entirely. OpenAI continues paying Microsoft its 20 percent share, but only through 2030, and now subject to a total cap whose precise dollar figure has not been disclosed. Given that OpenAI's revenue is growing rapidly — the company was reportedly on pace to generate tens of billions annually — that cap could become material relatively quickly.</p><p>For Microsoft, the trade-off is straightforward: it sacrifices the exclusivity that made Azure the only gateway to OpenAI's models, but it gains immediate financial relief by eliminating its outbound revenue-share payments while continuing to collect inbound payments for several more years. And it retains approximately 27 percent ownership of OpenAI's for-profit entity, meaning it participates in the company's growth regardless of which cloud serves the workloads. Last quarter alone, Microsoft reported $7.5 billion in revenue from its OpenAI investment in a single quarter, according to TechCrunch's reporting. For OpenAI, the calculus is different. It accepts a continued obligation to pay Microsoft through 2030, but it gains the commercial freedom to sell everywhere — a freedom that is arguably worth far more than the revenue-share savings. Enterprise customers overwhelmingly operate in multi-cloud environments. Being locked into Azure was not just a technical constraint; it was a sales objection that OpenAI's competitors, particularly Anthropic and Google, exploited relentlessly.</p><h2><b>Why the disappearance of the AGI clause signals a new era for AI governance</b></h2><p>One of the more philosophically intriguing aspects of Monday's announcement is what it does to the AGI provision that once governed the partnership. Under the original agreement, Microsoft's <a href="https://www.wired.com/story/openai-five-levels-agi-paper-microsoft-negotiations/">exclusive commercial rights were tied to a trigger</a>: if OpenAI's board determined that the company had achieved AGI, certain terms — including Microsoft's access to the most advanced models — would change. The provision was meant to ensure that a truly superintelligent system would remain under the nonprofit board's control rather than being commercially exploited. In practice, it created perverse incentives: OpenAI had a financial reason to never declare AGI, and Microsoft had a financial reason to argue that AGI had not been reached regardless of what the technology could actually do.</p><p>The new deal sidesteps this entirely. Microsoft's license now runs through a fixed calendar date — 2032 — "independent of OpenAI's technology progress," as the companies put it. The AGI trigger, a concept that once sat at the philosophical heart of the partnership, has been replaced by a spreadsheet. Andrew Curran, a close observer of OpenAI's governance, noted on X that language defining AGI had been removed from OpenAI's website, sharing a screenshot showing the change. The move drew sharp reactions. One commenter observed that "removing the definition = removing the accountability. whoever controls when AGI is declared controls a lot of commercial terms."</p><div></div><p>The shift reflects a broader maturation — or perhaps disillusionment — within the AI industry regarding AGI as a meaningful commercial or governance concept. When the original deal was struck, AGI felt like a distant, almost mythical threshold. Now, with models like GPT-5.5 demonstrating increasingly general capabilities, the term has become more of a marketing slogan than a technical benchmark. Replacing it with fixed dates and dollar caps is, in some sense, an admission that the industry has moved beyond the framework that once defined this partnership.</p><h2><b>Multi-cloud AI competition intensifies as enterprises gain the power to choose</b></h2><p>The most immediate beneficiary of the new arrangement is the enterprise customer. For years, organizations that wanted access to OpenAI's models had essentially one option: Azure. That constraint is now gone. Within weeks, <a href="https://x.com/ajassy/status/2048806022253609115">according to Jassy</a>, OpenAI's models will be available on AWS Bedrock alongside the stateful runtime environment that powers long-running AI agents. Google Cloud is presumably not far behind.</p><p>This multi-cloud availability arrives at a moment when the AI infrastructure market is undergoing rapid consolidation and expansion simultaneously. <a href="https://finance.yahoo.com/markets/stocks/articles/meta-spending-48-billion-coreweave-142800061.html">Meta recently committed $48 billion to cloud providers CoreWeave and Nebius</a>. Amazon's investment in OpenAI, combined with its existing relationship with Anthropic — in which Amazon has invested up to $4 billion — positions AWS as a model-agnostic platform where enterprises can mix and match AI capabilities. Microsoft, meanwhile, has developed its own relationship with Anthropic, using Claude to power agentic products — a hedge against the very OpenAI dependency it spent billions creating.</p><p>The competitive dynamics are now genuinely complex. Microsoft competes with OpenAI in AI products (Copilot vs. ChatGPT), partners with OpenAI's rival Anthropic, and remains OpenAI's largest shareholder. OpenAI sells on Azure, AWS, and soon everywhere else, while building its own data centers. Amazon invests in both OpenAI and Anthropic. <a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/model-garden/explore-models">Google builds its own models </a>while also hosting competitors on Vertex AI. <a href="https://x.com/jehangeer_hasan/status/2048818167682847084">Jehangeer Hasan</a>, a technology commentator, captured the mood on X, calling the announcement a "notable shift in the cloud AI landscape" that signals "intensifying multi-cloud competition and a push toward giving developers more flexibility instead of locking them into a single ecosystem." <a href="https://x.com/pazzo83/status/2048833610325586323">Chris Alexander</a>, an engineer, offered a more candid assessment: "honestly Azure's OpenAI endpoints are so unreliable, we mostly just hit you all directly," adding that "it would be nice to have options in AWS or GCP for sure."</p><h2><b>What the restructured deal means for the future of AI's biggest partnership</b></h2><p>Several open questions remain. The precise dollar amount of the revenue-share cap has not been disclosed, and it will matter enormously as OpenAI's revenue scales. The meaning of "<a href="https://openai.com/index/next-phase-of-microsoft-partnership/">first on Azure</a>" — whether it implies a meaningful exclusivity window or merely simultaneous availability — remains deliberately ambiguous. And OpenAI's own infrastructure ambitions, including plans to build proprietary data centers, could eventually reduce its dependence on any third-party cloud, including Azure.</p><p>Microsoft's position, while less dominant than before, is not as diminished as some early commentary suggested. It remains OpenAI's primary cloud provider, its largest shareholder, and a licensee of its technology through the end of the decade. It has diversified its own AI strategy with <a href="https://blogs.microsoft.com/blog/2025/11/18/microsoft-nvidia-and-anthropic-announce-strategic-partnerships/">investments in Anthropic</a>, <a href="https://venturebeat.com/technology/microsoft-launches-3-new-ai-models-in-direct-shot-at-openai-and-google">its own Phi and MAI model families</a>, and deep integration of AI across its product portfolio. The company <a href="https://www.microsoft.com/en-us/investor/earnings/fy-2026-q2/press-release-webcast">reported $7.5 billion</a> in OpenAI-related revenue last quarter — a figure that demonstrates the sheer financial scale of the relationship even in its loosened form.</p><p>For OpenAI, <a href="https://openai.com/index/next-phase-of-microsoft-partnership/">the new agreement</a> is a coming-of-age moment. The company that once depended on Microsoft for everything — capital, compute, distribution, and credibility — now operates as an independent force capable of striking multi-billion-dollar deals with Microsoft's biggest rivals. Sam Altman announced the changes on X with characteristic brevity: "We have updated our partnership with Microsoft."</p><p>Seven years ago, when Microsoft CEO Satya Nadella and Altman first shook hands on a deal to commercialize artificial intelligence, the arrangement rested on the assumption that OpenAI needed Microsoft more than Microsoft needed OpenAI. Every clause — the exclusivity, the AGI trigger, the revenue share — reflected that original imbalance. Monday's restructuring is proof that the assumption no longer holds. The partnership that launched the generative AI revolution has survived, but the power dynamics that created it have not. In the AI industry, it turns out, the only thing that moves faster than the technology is the leverage.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[You selected the right vendors. Now govern them like you mean it.]]></title>
<description><![CDATA[Waiting for your vendor to fix a program isn’t a strategy. It’s a cost, accumulating quietly while everyone in the room maintains the fiction that the process is working.



I’ve been in both rooms. The room where the client already knows something is wrong and needs the language and the evidence...]]></description>
<link>https://tsecurity.de/de/3467611/it-security-nachrichten/you-selected-the-right-vendors-now-govern-them-like-you-mean-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3467611/it-security-nachrichten/you-selected-the-right-vendors-now-govern-them-like-you-mean-it/</guid>
<pubDate>Mon, 27 Apr 2026 12:06:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Waiting for your vendor to fix a program isn’t a strategy. It’s a cost, accumulating quietly while everyone in the room maintains the fiction that the process is working.</p>



<p>I’ve been in both rooms. The room where the client already knows something is wrong and needs the language and the evidence to act, and the room where the client doesn’t know yet. The program feels manageable, the vendor is professional, the steering committee meetings run on time, and the warning signs are sitting in plain sight waiting for someone to name them.</p>



<p>That second room is the more important one. Because the window to act is still open. And most clients don’t move until it’s started to close.</p>



<h2 class="wp-block-heading">Warning signs most clients miss appear in design</h2>



<p>The earliest signal is rarely a missed milestone or a failed deliverable. It appears in language. When the phrase “path to green” starts appearing in status reports and steering committee decks, the program has already accepted it’s not green. It’s shifted from managing execution to managing the narrative.</p>



<p>Watch what the steering committee is actually doing. If it’s consistently hearing about what happened last month rather than what’s forecast for next month, leadership has been converted from a decision-making body into an audience. <a href="https://www.cio.com/article/4133234/does-vendor-influence-turn-into-cio-bias.html?utm=hybrid_search">The vendor controls the agenda</a>, the framing, and the cadence of what gets surfaced.</p>



<p>The most serious signal is when a program sponsor hears about material issues from their own direct reports that the vendor hasn’t raised in the room. That’s not a communication gap but a calculated decision about what leadership is ready to hear. When that pattern appears in SAP, Oracle, or Salesforce programs, the trust that makes the governance model function has already eroded.</p>



<p>When you see these signals, don’t wait for the next steering committee. Start demanding data that can be independently corroborated. Ask the vendor to forecast, not report. If they can’t tell you where the program will be in 60 days, they’re managing your perception, not your program.</p>



<h2 class="wp-block-heading">Your master conductor has a conflict of interest you’re not addressing</h2>



<p>A pattern I’ve seen consistently across multi-vendor programs involving Accenture, Deloitte, PwC, and others is the master conductor, or program integration coordinator, is quick to name client’s gaps, other vendors’ shortcomings, and third-party dependencies running behind. What they almost never do is name their own firm’s failures with the same directness in the same room.</p>



<p>That’s not a personality issue but a structural conflict. The firm serving as master conductor is delivering against its own statement of work (SOW), and the governance position gives them access to information, reporting authority, and narrative control they’ll use to, consciously or not, protect their own delivery track.</p>



<p>This is why I advise clients to treat the master conductor and program integration coordinator role as structurally separate from the vendor delivery role. That means a, entirely separate firm, an independent integrator with no delivery stake in the outcome. In practice, it’s more often a designated individual or a group within the project management or transformation office carved from one of the existing vendors, reporting directly to the client and accountable to the steering committee, not to their own firm’s <a href="https://www.cio.com/article/4120226/rethinking-it-leadership-to-unlock-the-agility-of-teamship.html?utm=hybrid_search">engagement leadership</a>.</p>



<p>There’s no true firewall in that model, but there’s a behavioral test. Watch what that role or team does with information that reflects badly on their own firm. Do they surface it or escalate it with the same urgency they bring to client gaps? Do they forecast problems on their own track, or only on everyone else’s?</p>



<p>A master conductor who’ll escalate failures that implicate their own delivery team is doing the job. One who only calls out the client and the other vendors is protecting the engagement.</p>



<p>Before the next SOW is signed, make it structural. Define the master conductor role separately from the delivery role, name the individual or team, set the reporting line directly to the client, and use the behavioral test to determine whether the role is being performed or merely filled.</p>



<h2 class="wp-block-heading">Waiting isn’t neutral</h2>



<p>The financial cost of waiting is more specific than most clients realize. In a multi-vendor environment where two or three system integrators are billing against active SOWs, every month of schedule extension carries a material cost, potentially millions to tens of millions of dollars per firm, not because scope expanded, but because governance didn’t hold the timeline.</p>



<p>The commercial exposure appears even earlier. When scope boundaries are unclear and the integrated plan is unstable, vendors have no reliable baseline to price against. The result is predictable: a significant spread between a time-and-materials estimate and a fixed fee quote for the same scope. That spread is not a pricing difference. It’s the vendor converting your governance uncertainty into their contract protection. The client absorbs it either way.</p>



<p>What makes the waiting feel reasonable is the vendor’s day-to-day team is usually professional and working hard. So the problem is authority and incentive, not effort. The program manager running the engagement can’t authorize additional resources nor commit spend across organizational lines. Their job is to manage the relationship, protect their firm’s margin, and keep the engagement profitable. Fixing your program isn’t the same job.</p>



<p>The window to act is real and short. A senior executive at the vendor can absorb costs, <a href="https://www.cio.com/article/4100412/it-talent-heres-how-cios-curate-engagement-and-retention.html?utm=hybrid_search">bring new talent</a>, and make commitments the delivery team has no authority to make. But that authority diminishes as the program ages. The more that’s been billed and the more scope has shifted, the harder it is for even a motivated senior executive to make the client whole. Clients who act in design or early build have options that clients who wait until three months before go-live don’t.</p>



<h2 class="wp-block-heading">The intervention that works is a leadership one</h2>



<p>When the signals are clear and the client is ready to act, the intervention that moves the needle isn’t a governance document or a scorecard meeting but a top-to-top conversation between client and vendor senior leadership. This includes execs who aren’t running the day-to-day program but have something personal at stake in the outcome.</p>



<p>That conversation works because it activates a different set of incentives. The vendor’s senior executive, the sector partner and industry leader whose name is on the relationship, needs your program to be referenceable. They don’t want a PR failure on a flagship engagement, nor do they want to explain to their firm’s leadership why a major client program collapsed. They have authority their delivery team doesn’t: power to assign their best resources, ability to absorb costs the SOW or change order doesn’t cover, and they can accelerate staffing decisions and make commitments that change what the program can do. They have skin in the game their team doesn’t.</p>



<p>Also, structure the engagement deliberately. Have senior executives on both sides and new talent brought in as a visible signal of vendor investment. And have a cadence that continues until the data shows the program is back on track, with time-bound accountability on both sides. And have explicit understanding that the relationship itself is under review, not just the program.</p>



<p>This is sustained leadership engagement, not a one-time meeting, and it doesn’t replace <a href="https://www.cio.com/article/4128980/the-struggle-for-good-ai-governance-is-real.html?utm=hybrid_search">the governance model</a>. It enforces it.</p>



<h2 class="wp-block-heading">The only recovery signal worth trusting</h2>



<p>When the top-to-top works, you’ll know it by what the vendor brings back to the table. Not reassurances or a revised plan with optimistic milestone dates, but facts about where they failed, what they’re changing, and, most critically, where the client has performance gaps that also need to close.</p>



<p>A vendor who comes back and accepts blame still manages the relationship. A vendor who says we failed here and here, these are the specific changes we’re making, and you have a gap here we need you to address, that vendor is engaged and mutually accountable. That’s the integrity test.</p>



<p>It runs both ways because program failure almost always does. Slow client decisions. Unavailable business resources. Requirements that shifted after design was locked. A vendor who names those things alongside their own failures isn’t deflecting, they’re investing in an outcome. That’s the signal the recovery is real.</p>



<p>If the executive meeting produces only promises and general commitment, keep the pressure on. Real engagement looks like specific admissions, named resources, and a willingness to hold the mirror up to both sides of the table.</p>



<h2 class="wp-block-heading">You hold the accountability. Be the human in the middle.</h2>



<p>Through all of it, the client holds the ultimate accountability. The master conductor holds the responsibility for execution and integration across the vendor ecosystem. That distinction isn’t administrative. It means the client can’t outsource their judgment, regardless of how rigorous the governance model looks on paper.</p>



<p>Think of it like the vendor can hallucinate. Not out of malice, but because every status report is a curated narrative produced by people whose compensation, future work, and professional reputation depend on how that narrative lands. The program deck isn’t neutral data, it’s information filtered through interests. What’s present tells you something. What’s absent, however, tells you more.</p>



<p>Be the human in the middle. Verify, cross-reference, ask questions the deck didn’t answer, and notice what’s missing as much as what’s there. If the steering committee is only hearing good news, that’s a sign someone is deciding what leadership is ready to hear, not that the program is running well.</p>



<p>Demand forecasts, not status reports. Look for hard evidence that can be independently corroborated. When the vendor names a client performance gap alongside their own, take it seriously. That’s the accountability model working the way it’s supposed to, not a deflection.</p>



<p>The warning signs may not always be apparent, though. The window is open, but won’t stay that way, so waiting isn’t a strategy<strong>.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hyperlinks not working in PDF [Fix]]]></title>
<description><![CDATA[If hyperlinks are not working in PDF files on your Windows 11/10 PC, you are not alone. Many users report this issue, and it often appears in different forms. For some, links appear clickable but do nothing, while for others, hyperlinks work correctly in the original Word or Excel file but stop w...]]></description>
<link>https://tsecurity.de/de/3464130/windows-tipps/hyperlinks-not-working-in-pdf-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464130/windows-tipps/hyperlinks-not-working-in-pdf-fix/</guid>
<pubDate>Sat, 25 Apr 2026 15:54:11 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="700" height="400" src="https://www.thewindowsclub.com/wp-content/uploads/2026/04/Hyperlinks-not-working-in-PDF.jpg" class="attachment-full size-full wp-post-image" alt="Hyperlinks not working in PDF" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/04/Hyperlinks-not-working-in-PDF.jpg 700w, https://www.thewindowsclub.com/wp-content/uploads/2026/04/Hyperlinks-not-working-in-PDF-500x286.jpg 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/04/Hyperlinks-not-working-in-PDF-300x171.jpg 300w" sizes="(max-width: 700px) 100vw, 700px">If hyperlinks are not working in PDF files on your Windows 11/10 PC, you are not alone. Many users report this issue, and it often appears in different forms. For some, links appear clickable but do nothing, while for others, hyperlinks work correctly in the original Word or Excel file but stop working after converting […]</p>
<p>This article <a href="https://www.thewindowsclub.com/hyperlinks-not-working-in-pdf-fix">Hyperlinks not working in PDF [Fix]</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 Best Encryption Software & Tools in 2026]]></title>
<description><![CDATA[Encryption software protects data by converting it into secure code. Explore the best encryption tools of 2026 to keep your information safe. The post 8 Best Encryption Software & Tools in 2026 appeared first on eSecurity Planet. This article has…
Read more →
The post 8 Best Encryption Software &...]]></description>
<link>https://tsecurity.de/de/3462953/it-security-nachrichten/8-best-encryption-software-tools-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462953/it-security-nachrichten/8-best-encryption-software-tools-in-2026/</guid>
<pubDate>Sat, 25 Apr 2026 01:50:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Encryption software protects data by converting it into secure code. Explore the best encryption tools of 2026 to keep your information safe. The post 8 Best Encryption Software &amp; Tools in 2026 appeared first on eSecurity Planet. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/8-best-encryption-software-tools-in-2026-2/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/8-best-encryption-software-tools-in-2026-2/">8 Best Encryption Software &amp; Tools in 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HeidiSQL Linux v12.14.1.1]]></title>
<description><![CDATA[12.14.1.1 - 2025-12-11
⛰️  Features

Shell script for creating macOS app bundle - (af24108)
Support XML formatting in grid popup text editor - (913fc9d)
Switch to grayscale icons on inactive query tabs - (917e046)
Support SSH tunnel configuration per commandline - (35a5225)
Display some known fil...]]></description>
<link>https://tsecurity.de/de/3461080/downloads/heidisql-linux-v121411/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461080/downloads/heidisql-linux-v121411/</guid>
<pubDate>Fri, 24 Apr 2026 12:47:13 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/HeidiSQL/HeidiSQL/compare/v12.13.1.1..v12.14.1.1">12.14.1.1</a> - 2025-12-11</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Shell script for creating macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/af24108493cb76c42a87977151a260620f63a4e8">af24108</a>)</li>
<li>Support XML formatting in grid popup text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/913fc9dcded9aa75b4fd53a74e611757850cf888">913fc9d</a>)</li>
<li>Switch to grayscale icons on inactive query tabs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/917e04624eaa94074491fe98e38d17c253b6c697">917e046</a>)</li>
<li>Support SSH tunnel configuration per commandline - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/35a52251984b48beadc46b7a4dec1e1c11f66207">35a5225</a>)</li>
<li>Display some known file type icons in file open/save dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b4c0566635fe88df05de8f04f975caee5ffe2253">b4c0566</a>)</li>
<li>Finalize keyboard shortcut customization in preferences - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/637d2d6578fe483b2855644447a30a398edeca3e">637d2d6</a>)</li>
<li>Add new keyboard shortcut editors on preferences dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cc4e6f17d43f61fcb465e7b6817a2a74dae2780a">cc4e6f1</a>)</li>
<li>Keep time fractions intact for CSV exports - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/06322de926b95f0ca7347f03bf05a8e8a3b49c86">06322de</a>)</li>
<li>Use custom folder icons in tree on file dialogs, in non-Windows mode - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3094d79c524603e22e68819cd5afb53694b90bfe">3094d79</a>)</li>
<li>Show NULL values in system variables listing - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/06b44eb483d99c164e4ced3c52185bf032ef77f6">06b44eb</a>)</li>
<li>Highlight same text in grids based on all selected rows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/afc9d8c24fba99b41a11daaee2d8bfdc8d0856ca">afc9d8c</a>)</li>
<li>Support fractional UNIX timestamps in grids - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/65c14727d50f88028799c22999c59eea70292efa">65c1472</a>)</li>
<li>Add "source table: xyz" hint to query result column headers - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2863a80b68ec8fd84e3e6360ab58d2d87ee79280">2863a80</a>)</li>
<li>Support click on path parts on top label of file dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/98b796b6889a3e5ad83e36bcdc29b0fea55402fb">98b796b</a>)</li>
<li>Convert all save/open dialogs to the new custom one - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4a8c53c4e034e38866fa731ab3225a5d83448f04">4a8c53c</a>)</li>
<li>Create file-save dialog with linebreaks selector - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d5d34add5f707b71ce77c7a64868791044535463">d5d34ad</a>)</li>
<li>Recreate basic TExtFileOpenDialog without OS owned dialog and room for customization - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bac0d7a5856c2be98b03d3823f77e016f2d4513b">bac0d7a</a>)</li>
<li>Full support for different icon packs, Silk and Icons8 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dbca69d2b09021960ce49e2feabbd3d4a3c19e9a">dbca69d</a>)</li>
<li>Add 206 Silk icons into new TImageList - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/769afa51950078e46f09ba27ee86cc9525459935">769afa5</a>)</li>
<li>Require libsybdb5 in DEB package - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e1781f96dcbc8a01abaad32b8b7159203b8d529e">e1781f9</a>)</li>
<li>Mark MS SQL protocols like named pipe as unsupported, advise the user to change to TCP/IP - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b20f12146605d48c71f46823b0de0de0dd4b5bcd">b20f121</a>)</li>
<li>Dirty and basic support for MS SQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3df3673a50f43009c5ce55e308a322e6fa72b432">3df3673</a>)</li>
<li>Show more detailed backtrace in crash dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bc0a7dec67a60cef7902124631c155a25db38263">bc0a7de</a>)</li>
<li>Support SSH passwords via sshpass - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f2b2dc371c58585d0e674c5daf7aa48799a9ab03">f2b2dc3</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Position session manager centered over main form, ignore position set by user - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/571c671be3f0511c9ed6e511a79ed7e070e3233e">571c671</a>)</li>
<li>Align bottom buttons on session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ca7aad68a4889c783fdc07ac3f1fa8586946754f">ca7aad6</a>)</li>
<li>Set font style and color of size column in tree - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f987c81cae43aa27d1850a1a42db15970d0df415">f987c81</a>)</li>
<li>Move RightEdge on SQL editors out of sight - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2a23e26f8101294feb4ba673106b013e024c6739">2a23e26</a>)</li>
<li>Light text color instead of ghosted/ugly icon for unseen tree nodes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/76aefb351caed61023cd6a03da70c630e17b6efb">76aefb3</a>)</li>
<li>Disable tree option asDoubleClickInsertsNodeText by default - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1c9321c825e523f1a1e75c1994bc6f50ee03eb07">1c9321c</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>Connect MS SQL query to session transaction, run .ExecSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/59191da66bf1a7758a2576d66a560a1542009adb">59191da</a>)</li>
<li>Prevent SQL delimiter being set to PostgreSQL quotes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a3acc047e83f14d0cde52ce94a89106652dd865f">a3acc04</a>)</li>
<li>Crash when grid-exporting without required key - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ff6050ff1e636a4aa90ed2d3862028badc16d82f">ff6050f</a>)</li>
<li>Delete CLI-created session settings from registry after disconnect - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8778d404d7e65112906cd6281faaa17a06dac5ce">8778d40</a>)</li>
<li>Another broken thousand separator - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/24f3e36d58054f0c1d9db0c88348029a7fd1f155">24f3e36</a>)</li>
<li>New attempt to hide SynEdit caret when unfocused - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/03f4a5f073d4a55502bfd3ed76849af1122bc1ce">03f4a5f</a>)</li>
<li>A TSpeedButton connected to a TAction, and a TMenuItem were not auto-checking - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/42abf46ae3a951763cfda83a242962928e1fecdb">42abf46</a>)</li>
<li>Database icon in Icons8 list too small - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dda44be05c82fd77ae9938ddd0e1e7279a22d2a7">dda44be</a>)</li>
<li>Cannot save new table when added column was removed - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1fe709a8d6e857c4f1fe9f5ecb27976600d2a250">1fe709a</a>)</li>
<li>Compile without MS SQL support on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9a4d841028e7840270798c4553a1aa86c4a0cc5c">9a4d841</a>)</li>
<li>Query batch stops at second last query if it has errors but StopOnErrors is off - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6e40c6270ffc7d83d7a90b492c1b727585dfd37d">6e40c62</a>)</li>
<li>Drag'n drop on Linux requires VT.DragType = dtVCL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4fd646c829269cf625af84212e850e7ac2dac437">4fd646c</a>)</li>
<li>Enable drag'n drop in table editor and session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9afc60f087dd46353f6a407a3acea1381a99779f">9afc60f</a>)</li>
<li>Detected empty text DEFAULT value for table columns - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4c0617d0a83efdec4b9e0f58247b281a6b502154">4c0617d</a>)</li>
<li>Append quick filter without linebreak - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8ea3b9444ec160675039a517251e13ec2518b634">8ea3b94</a>)</li>
<li>Wrong icon sizes, disable right-click select for column list so selection is kept - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a145fc57f076e883131f883192ecd1b60c3200ed">a145fc5</a>)</li>
<li>Remove dead code, fix some compiler hints - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79bcd1d4867d71059dea4e34b5e5fef5ef1a7c26">79bcd1d</a>)</li>
<li>Bad position of TEdit on TInplaceEditorLink - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8d119a011a21c20d8ad20bba8d4eba76e95bb293">8d119a0</a>)</li>
<li>Quick filter &gt; "more values" submenu not created/shown - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8696e61127e2577dddf289e14565cf086fb42421">8696e61</a>)</li>
<li>Empty KeyStrokes list on text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/db00c836651443bec7fbdfdcbba885bbf9da8de3">db00c83</a>)</li>
<li>Broken caption on inline text edit button - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1730956488251dcd6ebdb674e1e3074309d70b37">1730956</a>)</li>
<li>User queries not showing up in log panel - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/222a386039560ae4e0304b9fb8f28048cf35e358">222a386</a>)</li>
<li>Do not edit grid cell on right-click, and set HotCursor on DBtree - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0257867dff7798de701d7b9e6d72731ff23ee8ba">0257867</a>)</li>
<li>Flashing main form in background after cancel session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0563b4d683180a7baa7f15d9f53a062b236bc1e4">0563b4d</a>)</li>
<li>Work around empty space artifact in ShellListView - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cf9ed85900c0cde27ab4f0911a3c573f310af3fd">cf9ed85</a>)</li>
<li>Move all Application event assignments to .lpr file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/64919d6aa6dfc92204607ec34da8411bc3ee1285">64919d6</a>)</li>
<li>Confusion with (selected) folder icons - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b488ca23aeea42d93cf72fbd1f7d9d24bf2a5e18">b488ca2</a>)</li>
<li>Tree with keyboard actions shows wrong captions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5e20c53e21d0c96a56abda53e490602bd555b57a">5e20c53</a>)</li>
<li>Binary result values displayed as 000... - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4322372c3008087ea1f88f0731d77952802fac82">4322372</a>)</li>
<li>TMySQLQuery.TableName() returns wrong string, and introduce apphelpers.GetAppDir - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bb517d79e2cfd606ed061b95a72018815315dad0">bb517d7</a>)</li>
<li>Crash in AnyGridPaintText with no query result - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/59659f074113cd83bda8640b70496cf5a178dbc9">59659f0</a>)</li>
<li>Error: (4004) Variable identifier expected - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/13a0127d69cf2384a4df785d201e2ce94cfe9b45">13a0127</a>)</li>
<li>Crash in printer dialog with 0 printers available - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6eecdd8a5fe4f0b67fb330fb3a8155e10ca4f52a">6eecdd8</a>)</li>
<li>Missing file for previous commit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/857cca865ccef1f207a771bcf7080405b386f967">857cca8</a>)</li>
<li>Some remaining issues in the new file-open/save dialogs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/34e3f32a07bc83af8b2b8ccd83e5ddaf9005b4ed">34e3f32</a>)</li>
<li>Work around out-of-view item in left tree after FormShow - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ec4c237caecfe0633bcb6d08fe261f77358903a5">ec4c237</a>)</li>
<li>Navigate to directory of currently loaded file when user opens dialog for loading another file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/251f632a2ada8d7951e0c47971f474285a15ef66">251f632</a>)</li>
<li>Broken support for non UTF-8 encoding - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fe652313abcc2d5516cf081b1074377fae2f6791">fe65231</a>)</li>
<li>Prompt to overwrite only if file exists - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/91de2fc30d05fadcd92314851b25962302c4cbb8">91de2fc</a>)</li>
<li>Add encoding selector to file-open dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/56b783d8292b0acb72d45e1a2aed6546cb71fcbe">56b783d</a>)</li>
<li>Crash when app exits, with deleted TSynGutterSeparator - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/00627ae2846a56c1f5dceec223d20a8931f000c5">00627ae</a>)</li>
<li>Optical stuff, add bookmark icons for SynEdit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/29d1abc23c6ea5a524931efe62e98078f69532d6">29d1abc</a>)</li>
<li>Use GetApplicationName in InitMoFile as well, plus documentation - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93bf989ac704c5931342de969d95f12bec04a32a">93bf989</a>)</li>
<li>Make LCLTranslator independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0469dd9f51edb341ab05aad9c4e3db1cc80546d9">0469dd9</a>)</li>
<li>Make GetAppConfigDir independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9e2611e54d954a4f87b7c8dc25a38038b85c9d2b">9e2611e</a>)</li>
<li>Make translation filename independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5d487bb352679b8bfc1805328c760291036325ad">5d487bb</a>)</li>
<li>More painting related crashes on QT, this time in OperationRunning() - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fbe32db87594e6b3bba78a8d5fc91bb74f9911c3">fbe32db</a>)</li>
<li>Compiler warnings, re-enable active line background - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a1c84ae578ef3bca71e39f26033b5c2560e71bb3">a1c84ae</a>)</li>
<li>Two crashes in QT caused by aggressive control repainting - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7650efe74056513e3a481785bbfaebd5f7107dc5">7650efe</a>)</li>
<li>Hide library files which ldconfig shows up but don't exist - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/85cf23029993f5702cebde631219a88cda045843">85cf230</a>)</li>
<li>Provide at least one libmysql for macOS, plus its dependencies - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1fbc2aba11bc23b8f7372fbd35e21b73d5c2e964">1fbc2ab</a>)</li>
<li>Fix compiler errors on macOS, set DYLD_LIBRARY_PATH run param to fix wrong path for libssl - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/58b210af469ade5b43d56478aabe815a4252beb5">58b210a</a>)</li>
<li>Wrong integer size/type for ClientFlag in mysql_real_connect - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3213fe94460af85fa8076036381dc772fbb8856c">3213fe9</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bump version to 12.14.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1a2f1f37723be894a1d70cfc109bad66d7963bd3">1a2f1f3</a>)</li>
<li>Use Lazarus logo in readme - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/aa49736545d452b9dfd82a896d489a2acd819776">aa49736</a>)</li>
<li>Remove now unused doc, written for converting to Lazarus - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b01e732a10a1c89a1634be22ba6ef300e1d1b17e">b01e732</a>)</li>
<li>Fix generation of <code>.deb</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e95aca86d6a39ae3e38ef036b9b1fe27ee3b6c08">e95aca8</a>)</li>
<li>Fix missing <code>Package</code> variable - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/13c55ce2ee5895f1e3fdc6b13972bdb98d775c3c">13c55ce</a>)</li>
<li>Using <code>v4</code> of <code>git-cliff-action</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/81d613b08b2ec97c1898a29cb87de614163ecf60">81d613b</a>)</li>
</ul>
<h2>Contributors</h2>
<ul>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a></li>
<li><a href="https://github.com/gcarreno">@gcarreno</a></li>
</ul>
<h2>[12.13.1.1] - 2025-11-03</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Sort session folders at top per setting - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93dc93680327beb4e24422e7cae9c97b71a9ba24">93dc936</a>)</li>
<li>Filter box in user manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b57b76443bfc6c31dd81ea50d7c0238278f78301">b57b764</a>)</li>
<li>Add checkbox "Open file after creation" to grid export dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/613f4d8a23f80fe9542b90724a1cab5e6e9f96b6">613f4d8</a>)</li>
<li>Allow sorting columns in table designer - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8541eb404de942a0b3e976201430cbc65964887a">8541eb4</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Make file exit action OS friendly - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1f19d004905a39a6a1d49df698bd4194735aa29c">1f19d00</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>List procedures in PostgreSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/db902f7da1133c05bcaf67ca92e273582328fdf3">db902f7</a>)</li>
<li>Missing DELETE HISTORY privilege on MariaDB - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f7b80dbb51f802e166528308f35106ada0ae0883">f7b80db</a>)</li>
<li>Prevent crash in auto-refresh action - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2c25e04baf90d3912749421fadac798b7d1db786">2c25e04</a>)</li>
<li>Bad message with no library selected - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f9a486b40352da9426f2575579271d25ffb16ec5">f9a486b</a>)</li>
<li>Generate missing values for geometry columns - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb1b5eac59100605b0a5b749037a6297ff9d6fb7">eb1b5ea</a>)</li>
<li>Allow modify length of index with binary column - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/173efeb6aa4f920c14c961aa3458cfe2fbddf2fd">173efeb</a>)</li>
<li>End global "edit function" mode for grid editing early - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5cac85089a58dcc8e11c540e1499e001df76d69a">5cac850</a>)</li>
<li>Take care for escaped ENUM definitions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/328fb7287b6597a663c465bcece8c05218753f13">328fb72</a>)</li>
<li>Support return data type of stored function containing white spaces - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d7b1faa637869472ffbdabd28d5885caa3a33dc9">d7b1faa</a>)</li>
<li>Safety replacement for folder separator when renaming a session or folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/18a21ef9e4f1f450391b40a1cb8ee3aef036fa36">18a21ef</a>)</li>
<li>Leave away schema when double-click table for inserting into query editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b72f2595c55644daf55b76086ab38f99fa3d93ce">b72f259</a>)</li>
<li>Sticky empty-password warning after setting a non-empty one - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f2028e135e4e3ded46612d30b4687db413c2bb0f">f2028e1</a>)</li>
<li>Support double dollar quotes on PostgreSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/caeae88f25d7b7118836f22c7223a24523a0ba2d">caeae88</a>)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li><em>(CHANGELOG)</em> Proper changelog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79bb279a15998756d040ad3830b7e7bb5f27f8cc">79bb279</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bumping version to 12.13.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bf23332cc1731f521330a61e7fb5cebff87687c3">bf23332</a>)</li>
<li>Using correct target of <code>build-*</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/16a54a57aa6974c819801c3e304367fab7ec07af">16a54a5</a>)</li>
<li>Fixing some blantant mistakes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/76dfa98217d4eabaf30e96a938fb982fdabb221d">76dfa98</a>)</li>
<li>New category: Enhancements - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dd1ad34317215a16178fc6bf5de04146358e29aa">dd1ad34</a>)</li>
<li>Removing unnecessary <code>tx-push</code> recipe - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d293d648d8cc933d01e269619cc041f2833b6a3f">d293d64</a>)</li>
<li>Forgot to copy <code>.ini</code> files on <code>run-*</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c513e535d916d414312481828bdc5a241047a7db">c513e53</a>)</li>
<li>Completing <code>run-gtk2</code>, <code>run-qt5</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/04650d93a7c0a24e8c53b800791b9511d6a1bb30">04650d9</a>)</li>
<li>Adding empty <code>tx-push</code> to <code>Makefile</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3ceed3936c24f3b9034b558a16c490f826c90b34">3ceed39</a>)</li>
<li>Adjusting workflow to skip secrets detection - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/14dd9ce9a590e9e1a768f32db1dcb6412c857eab">14dd9ce</a>)</li>
<li>Adding usage of <code>secrets.mk</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/123a2e7d36f0478cd8e9ce24b6c25ed85386517b">123a2e7</a>)</li>
<li>Forgot to change the output folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/78f1415c210c9bea2fdb0edf27cfa1dd89909f15">78f1415</a>)</li>
<li>First batch of changes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2bee126353676a3387cfd10ae4f348a2488e5938">2bee126</a>)</li>
</ul>
<h2>New Contributors ❤️</h2>
<ul>
<li><a href="https://github.com/gcarreno">@gcarreno</a> made their first contribution</li>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a> made their first contribution</li>
<li><a href="https://github.com/">@</a> made their first contribution</li>
</ul>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p>
<p>For a list of all the changes up to date, please read <a href="https://github.com/HeidiSQL/HeidiSQL/blob/lazarus/CHANGELOG.md">CHANGELOG.md</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HeidiSQL v12.15.1.1]]></title>
<description><![CDATA[12.15.1.1 - 2026-01-30
⛰️  Features

Add a few items to the top of the grid's header context menu - (eb9cd8b)
Add a newer FreetTDS library for Windows, from the last successful VS 2022 build on https://ci.appveyor.com/project/FreeTDS/freetds - (93bfda0)
Make grid-highlight-same-text-color part of...]]></description>
<link>https://tsecurity.de/de/3461073/downloads/heidisql-v121511/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461073/downloads/heidisql-v121511/</guid>
<pubDate>Fri, 24 Apr 2026 12:47:04 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/HeidiSQL/HeidiSQL/compare/v12.14.1.1..v12.15.1.1">12.15.1.1</a> - 2026-01-30</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Add a few items to the top of the grid's header context menu - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb9cd8b57bd5de0c70b6432fdab9513578fae690">eb9cd8b</a>)</li>
<li>Add a newer FreetTDS library for Windows, from the last successful VS 2022 build on <a href="https://ci.appveyor.com/project/FreeTDS/freetds" rel="nofollow">https://ci.appveyor.com/project/FreeTDS/freetds</a> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93bfda0acc29355ab6646f6e360b549618410ae1">93bfda0</a>)</li>
<li>Make grid-highlight-same-text-color part of the predefined color schemes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7854157fccdcc32f98d130a17b06ef1bcdcb0eaf">7854157</a>)</li>
<li>Switch color scheme from Tools main menu - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c8c3b23eaebc0433c21aaf8d4805a10a301b14e1">c8c3b23</a>)</li>
<li>Introduce global AppColorSchemes for managing SQL and grid colors, and sync both with the app's dark mode (still only on Windows) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d313a596b30fba50f6f42499decc1e35f1afbf0e">d313a59</a>)</li>
<li>Sync active line color and brace highlight with the app's dark or light mode - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/351072849a18e089d3437edc48ae2cc075444c37">3510728</a>)</li>
<li>Auto-switch to dark or light SQL colors in sync with the app's dark mode - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8a08e77afd4f5d1566e79db82436258ae465a7df">8a08e77</a>)</li>
<li>Support dark mode, using MetaDarkStyle from OPM, and provide the 3 known custom settings: automatic, light and dark - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3f9e867dd5647a3803c784c611064f151fa31f99">3f9e867</a>)</li>
<li>Re-enable dropping files from file manager to "insert files to BLOB" dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/23fc9c09875cb8ea1a2947a3b0cdff901a2dbef2">23fc9c0</a>)</li>
<li>Upgrade DPI awareness to Per-Monitor v2, add TMainForm.FormChangeBounds as a replacement for the missing OnAfter/OnBeforeMonitorDpiChanged events - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9eab28ea642b1efe232eb5256163f0516f6f9082">9eab28e</a>)</li>
<li>Re-enable menu item on list header context menu: "Toggle visibility of all columns" - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/41169f773de71534062e88699fdb164fb385340c">41169f7</a>)</li>
<li>Support European umlauts/accents as \w (word char) in some regular expression areas - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/304cd26a05b438fb6f5519504d83ab41417ae609">304cd26</a>)</li>
<li>Auto-uppercase keywords, data types and functions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/62cda84bed0caccd484276ce13cbb1463f838ffe">62cda84</a>)</li>
<li>Recreate previous state of trigger after realizing the user edited code has errors - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e7e5e11cb45bf324e25d1d781cbe2af9dffd4a71">e7e5e11</a>)</li>
<li>Create a TSynEditMarkup descendant and use it for highlighting selected text occurrences - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8a667f297a4e732f4252813147108ce6cae61c6b">8a667f2</a>)</li>
<li>Create custom setting so the user may define a terminal app himself, and auto-detect terminal app if the setting is yet empty - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/613e207b726122a26667bb6f2e210e1820c75516">613e207</a>)</li>
<li>Enable InnoSetup script for creating Windows installer - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/317edcd529bb0a31e24f61e1cb759c48c040df43">317edcd</a>)</li>
<li>Re-enable codepage =&gt; charset mapping using GetACP from DelphiCompat unit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79e4654fc072646cd34d85fc553cf2dbd4953782">79e4654</a>)</li>
<li>Re-enable ValidFilename function with platform specific lists of disallowed characters - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f3a0594a4628470b406ee9f6cf359a57d7f9a3b6">f3a0594</a>)</li>
<li>Re-enable support for hyperlinks in message dialogues, and use TTaskDialog again for simple messages on Windows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/15eb52b1d98f20fb229730de80c3da80043b1158">15eb52b</a>)</li>
<li>Support portable mode with a portable.lock file in the app folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c528c5de3baa685be7491c4bdad3ae9f393d6033">c528c5d</a>)</li>
<li>Re-enable hints on query result tabs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/88115acea27029192d0a117ee95dbbe1c3f639e0">88115ac</a>)</li>
<li>Show connection details as a hint over status bar - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e1ad5c3ab5f8f650cdfd8895df2d6fc81f2ae29a">e1ad5c3</a>)</li>
<li>Add missing LCL translations, compiled to .mo files with msgfmt from Poedit with support for msgctxt - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/505e3ec141491b86a70e76f39a584be11a7dc927">505e3ec</a>)</li>
<li>Use the more native MessageDlg on all platforms when we don't need additional dialog features - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8c0e61f372bfdd774123e1aedaa155693b1f22fc">8c0e61f</a>)</li>
<li>Show only mono-space fonts in SQL font selector - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3388d9f543afe601fe106fbed82600d50a322fd1">3388d9f</a>)</li>
<li>Support compilation and usage on FreeBSD - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/425d099dc12692655c0884c680c461546c318cd2">425d099</a>)</li>
<li>Include libssl 1.1 in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f51d2a9662de23b2cbff5e3938aa7f33259e32ae">f51d2a9</a>)</li>
<li>Include libmysql plugins in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/85a15f839ae16581ea6825eef2e181dc0a9ad76d">85a15f8</a>)</li>
<li>Provide libmariadb plugins in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2967ad28b4e3172e302cb8d487c0d3a5c752b3fe">2967ad2</a>)</li>
<li>Assign OK button to Enter and Cancel button to Esc - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3ea4a903d488960a8a975211dcf6c09bade7184c">3ea4a90</a>)</li>
<li>Add translation files to macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/08735bc11adbe33cca9a95d00ff74a058463670d">08735bc</a>)</li>
<li>Provide libmariadb in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2a1c7259e75c5cf5bfb9774341b35e19dbf90369">2a1c725</a>)</li>
<li>Support SynEdit hints when mouse is over function names, tables etc - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/82ef10e5a0c7f562de7e10347e751fbec26955e2">82ef10e</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Turn two more TButtons into TBitBtn with icon - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9300cbc67b19c8f9cf0ef5782a07433d35a0311d">9300cbc</a>)</li>
<li>Immediately show new log lines on heavy operations, enhancing user experience - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b100479b7ee609bf6b03c54dd708a1e2ddebdcab">b100479</a>)</li>
<li>Turn export options button into TBitBtn and give it an arrow-down icon - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4864900c658112973d517e94ae38013f597e0769">4864900</a>)</li>
<li>Indicate drop-down menu through arrow-down image on buttons - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/288b346f1aea68ea5f1c0dfc19fd44a15cf527f6">288b346</a>)</li>
<li>Reduce width of left gutter in popup text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4215aeeaaf347f9bd25c8024c2a280dcf8afd969">4215aee</a>)</li>
<li>Hide grid cell border lines in most VirtualStringTree's - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b31f78acd0c16f05baf9a89bde220f386879f159">b31f78a</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li><em>(ci)</em> Get libqt6pas on ubuntu via 3rd party repo - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4205774ae3a7a4be8bce06ba33cd9141a13cfa5a">4205774</a>)</li>
<li>Remove MetaDarkStyle from the required packages, instead add a latest snapshot of the relevant files from <a href="https://github.com/zamtmn/metadarkstyle/">https://github.com/zamtmn/metadarkstyle/</a> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9f9cde005c6fd6a18fb9fc99103ead9e84bf02a7">9f9cde0</a>)</li>
<li>ERangeError when editing text grid values which allow more than 2^31 chars, e.g. LONGTEXT - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/42b5d52fbbb77c38b27ba41485ff41c8e6cb4db8">42b5d52</a>)</li>
<li>Set default value for ThemeIsDark for cases where AppleInterfaceStyle does not exist (= light mode) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/26ca75e8f458b5bb2b1d64e5a2365bcb2c67a93e">26ca75e</a>)</li>
<li>Reload color scheme after auto-apply, reintroduce ThemeIsDark with a detection for Windows and macOS, use MetaDarkStyle units only on Windows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b4afc3af279c776f6424d53f1232a8b975f7ce1f">b4afc3a</a>)</li>
<li>Invalid typecast in List.Add(BaseForm.Components[i]), when running debug builds - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/38faf5787d04fea1043ebd33517baa81827b73f0">38faf57</a>)</li>
<li>Wrong length of text detected (always 0) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/930a815d6ab9bec2b8cdb8f7c3f4dbfe43f84df2">930a815</a>)</li>
<li>Crash in data grid when switching to an empty table on ArchLinux - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e9b6835e47bd34fdd5933fbb98ba7029d58523ab">e9b6835</a>)</li>
<li>Next attempt to fix ERangeError crash in TBaseVirtualTree.UpdateVerticalRange - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c8e8beddbf397af9fcd0c169dd4319f09dd2ec97">c8e8bed</a>)</li>
<li>Wrong ModalResult on "Replace all" button - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2367ac681f12804f50ee62f861f6ba3e0535260c">2367ac6</a>)</li>
<li>Increase too tight node height - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/60ad998715bb5da9ba57d59f144ed3c3ad2399cb">60ad998</a>)</li>
<li>Auto fit columns in search-on-server results, taking the header caption into account - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4ce827b3583abec94aeaf308783ceed5241aa499">4ce827b</a>)</li>
<li>Remove space eating gutter from SynEdit in search text dialog, disable scrollbars as long as not required - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7423aa356110d33394ce78e62ddd00f160b69507">7423aa3</a>)</li>
<li>Form dimensions reset to default values each time, and wrong check for empty SynEdit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dab1cda93e0af7a0a88aca3c792a62033fb0819d">dab1cda</a>)</li>
<li>Confusion about modified default setting for DoubleClickInsertsNodeText, reset to old value - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f8dc7963e836ad15c21dfde22c95050a50200a48">f8dc796</a>)</li>
<li>Wrong BOM characters written to grid export files, when encoding is set to "UTF-8 BOM" for instance - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f951b78c0e831bec296b06e9cdd2054b404135ae">f951b78</a>)</li>
<li>Auto-uppercase when pressing Enter immediately after a keyword - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d34be7f7b4881e1c51f29cae5e7b1550ef4db40b">d34be7f</a>)</li>
<li>Missing selection highlighting and auto-uppercasing in data tab filter editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2e31c5e0eca476ea90952bfa8c883d515b579e11">2e31c5e</a>)</li>
<li>Prevent triggers without quoted trigger name or table name from failing to be parsed (alexanderglueck) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3028076b45a78766f7ce6856267335ddc243363b">3028076</a>)</li>
<li>Convert usages of UnicodeString to String, in jsonregistry unit, and fix handling of Chinese characters - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/39df33999f59b917269a7656d56b5f1651df5289">39df339</a>)</li>
<li>Broken integers and floats after locale formatting on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fa1db7663a3aa0e226df826f61815bcf47b42b32">fa1db76</a>)</li>
<li>Crash in file-picker with Windows path within Linux - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7f8dc30628b16a9c9d106bbf6f18f5627943cc5d">7f8dc30</a>)</li>
<li>Some more compiler warnings and hints - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3b247070729b18d5af75a88ca9a67ad5927257bc">3b24707</a>)</li>
<li>Missing top anchor control for new terminal edit box - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/427104065c3768913b27c920e5ff20a5d42a4b92">4271040</a>)</li>
<li>Missing SSHPASS environment variable when starting tunnel with sshpass -e - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6ce846b47bfafc58234473beb8bb86c50bd51d25">6ce846b</a>)</li>
<li>Non working MySQL command line launcher, for all platforms - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d9b6f877acfe084b5b8b43833fc9abc4d7523937">d9b6f87</a>)</li>
<li>A few more compiler hints and warnings - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e18b3dbc7e79d9c6e1cc71dce00d21bb1446076e">e18b3db</a>)</li>
<li>Crash at right-click on data grid header - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f88405bfd63def648094a4b5a998317db98ed81a">f88405b</a>)</li>
<li>Add missing dlls and MySQL plugin dlls for use on Windows, remove unused macOS dylibs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/287abde28625d0e1f0708ba06b85c2e0932c4f36">287abde</a>)</li>
<li>Non working "Insert row" actions and its friends - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d1faf6b3617f490474a71005857abdddd1a72fee">d1faf6b</a>)</li>
<li>Stretched preview image, and image metadata label too small - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/20aded3ead77f3ed315032239f275711e25d5733">20aded3</a>)</li>
<li>Ban Windows API code used in OnAdvancedHeaderDraw for painting column headers with sort chars - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/485fb7ddc1b4da56daf961dcb4398b11879ae458">485fb7d</a>)</li>
<li>Broken sort arrows in grid column header - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/377d4023042ee0689b69c1c582a13d9aba7c25b6">377d402</a>)</li>
<li>Fails to run netstat or netstat.exe on Windows, try a cross-platform socket approach - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/633ee44ff2a594f6ed3509f6f0cec4ff24a6ca70">633ee44</a>)</li>
<li>Fix various compiler hints and warnings - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f1ac6dce5ba6673295d2e0ef61c03513f66a7239">f1ac6dc</a>)</li>
<li>Crash when switching between tables - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c054884b51afc63e7d3a48d08e0dc479a35f3718">c054884</a>)</li>
<li>Bad anchors on edit-variable dialog, overlapping/hiding radio buttons - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3e77c0df1c82b1d6b24ae6994cabc990546f2b00">3e77c0d</a>)</li>
<li>Conflicting grid edit shortcuts - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ad52dd31e2b8961a22239de1798e18babf51f798">ad52dd3</a>)</li>
<li>Crash in grid initializing, likely due to a wrong node height - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4c6204a0c59da3f4662de62594f76118a16beb2a">4c6204a</a>)</li>
<li>Compile error on Linux due to "identifier not found: LoadStringW" - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7a7376938bb87e5730d3d0c3893a9e982897782e">7a73769</a>)</li>
<li>Translate button captions on TTaskDialog using LoadStringW on Windows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/97232100404bb21f88d8307f396392ab7d6e8a2a">9723210</a>)</li>
<li>Set MySQL plugins folder like in the classic branch - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eccf7b22b6f3ec83edc0efba64c28cc951d5a45a">eccf7b2</a>)</li>
<li>No locale influence and no scientific notation in JSON reformatter - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/825447f472a0244fc8b884d02cd809761cb227d7">825447f</a>)</li>
<li>Bad anchors on "start" tab of session manager, plus add an info label for portable users - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a140b199d5a476bdb7a3002adf5b1c7281991662">a140b19</a>)</li>
<li>Set Screen.HintFont globally to what the editors use - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2b7d31b54861163b3dd7b01e6166d134da5887f2">2b7d31b</a>)</li>
<li>Do not show ugly/solid grid lines on macOS and Linux - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c35a35cf79637893d2f628956f60d64919fd2ab5">c35a35c</a>)</li>
<li>Prevent host sub-tabs from getting disabled on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6f5a2d1da2808f695389c138e67ee97f06134182">6f5a2d1</a>)</li>
<li>Missing control anchors on create-database dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d26f1282406b81b78344d9ea2ef561e74aaa61a3">d26f128</a>)</li>
<li>Prevent editors from getting an empty font name - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/74abc1666cfebf861e56e9e2f6c38718c5418d87">74abc16</a>)</li>
<li>Show file modification time in about dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/50b6864864ff817673aefb0c3788a2e9024c0326">50b6864</a>)</li>
<li>Skip harmless error when PG has no COLLATION_NAME in IS.COLUMNS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb3937ac04eaab4b48748214d57ca9b3867b76b9">eb3937a</a>)</li>
<li>Broken compiler conditionals - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/556e4fbf9a016d2792d1af88a4ac32457e51963c">556e4fb</a>)</li>
<li>Missing control anchors on copy-table dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6cc530ba5f62602db1b3979aa4d134ce0b77187e">6cc530b</a>)</li>
<li>Set runtime search path for linker, so openssl finds libssl.1.1.dylib and we can access https pages now - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/230ac8d1b1a54b08cc6576b08861336103ce720c">230ac8d</a>)</li>
<li>Missing control anchors on search/replace dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c07b15504b74a7f3154fb1f362ed64a00a379ac4">c07b155</a>)</li>
<li>Missing control anchors and tab order on column selector - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f72156d2adf1b46d549f9727136ecc3ff45bf30d">f72156d</a>)</li>
<li>Wrong button positioning on macOS caused by differences of TButton/TBitBtn - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ba9442b296826a1836a1db12b988827269af7e9e">ba9442b</a>)</li>
<li>Search for translation files in the right folder within macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/52b065a44eddd159b68158e31b5095532f068dee">52b065a</a>)</li>
<li>Prefer TBitBtn over TSpeedButton for native look on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bee61ec929e84db6fdfcea873a525240b8ca7bd5">bee61ec</a>)</li>
<li>Assign no Syn highlighter by default and call it "Text", in texteditor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/446d78c295dd42085040ffdf24e7265905520051">446d78c</a>)</li>
<li>Anchoring in about box - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3605706bea66dda3ecc92b3fe4c54f35fbd010cd">3605706</a>)</li>
<li>Copy functions-*.ini files to the right folder, add iconset - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2f92db27ebd4f533e6aae239fd1cad9afb658772">2f92db2</a>)</li>
<li>Sign and notarize exe file and dylibs on macOS, fix ini filenames - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c34bde312d5b97cca52d5f244ba77c9e8e09c9a1">c34bde3</a>)</li>
<li>Load libs from ../Frameworks on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8f6ba688cbcdc8d258d577e32671993ecdcbdf02">8f6ba68</a>)</li>
<li>Remove dead code - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5f39a44fe4528313315b074142dcc8859c736f5e">5f39a44</a>)</li>
</ul>
<h3>🚜 Refactor</h3>
<ul>
<li>Move grid null colors away from data types array to the new color scheme - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2bc36b47e6e773a7c2ace3a11fd6478b0f825656">2bc36b4</a>)</li>
<li>Rename TSynEditHelper.TextIsEmpty to HasText - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ac095e46cdfe929cdff0d761f736afc6f5f8df39">ac095e4</a>)</li>
<li>Move macOS build to Makefile - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f41a6ffdee8445c7b11c09f0985f6e979ecae0e8">f41a6ff</a>)</li>
</ul>
<h3>🎨 Styling</h3>
<ul>
<li>Remove no longer needed and partly dead code for DpiChange detection - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/23148e91491f6eff3275f1200115a782519e0507">23148e9</a>)</li>
<li>Remove dead code which is unlikely to get re-enabled in the future - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb4a0b41324d98c91e90ea628a09373eda072f2d">eb4a0b4</a>)</li>
<li>Remove non working context help button on session manager, we have a "general help" menu item in the "more" menu already - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b1122c50a0c04a240028c211a38376f1f70443e8">b1122c5</a>)</li>
<li>Reduce borders around controls - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ff065ea7edfec506047e9a3ef97f1855bb5ed1e3">ff065ea</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bump version to 12.15.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cb03bec0c62b4b167c4f9cb57b80f1aa1d992577">cb03bec</a>)</li>
<li>Revert to using include-packages, now that it checks LazCompatibility to exclude outdated/incompatible package files from installation - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fcd45be2acaeed4fb10653edbd8292620c84f973">fcd45be</a>)</li>
<li>Attempt to fix compilation of unwanted and outdated package files - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/04bee7259c6a8553730d4e37c0163aa70f919324">04bee72</a>)</li>
<li>Attempt to fix broken dependency, use correct case of the package's DisplayName - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/45e596c4dd00ef70a5826fc32678347e2b114f80">45e596c</a>)</li>
<li>Mention current Lazarus version in readme file, mention usage for macOS builds and plans for v13 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93fdf7704012763bfe804375dc25719792974cd3">93fdf77</a>)</li>
<li>Remove "Linux" from the Github release name, so I can have one release for all OS packages - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ab46fc57961bcf388f1a7eb174791f630956919c">ab46fc5</a>)</li>
<li>Move translation source file from master to lazarus branch - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b211b44eb03407f9a0ac6f6b49e389ca4326d7bb">b211b44</a>)</li>
<li>Remove unused file extensions and add some others - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0b5ab2599282c349ed6014777ebf78ab11fe4b9a">0b5ab25</a>)</li>
<li>Set release compiler option -WM10.15 identically to debug, relevant for macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6144df2b204c74bdfebe10edb45ce1f7baa5c195">6144df2</a>)</li>
<li>Using the correct <code>lazbuild</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c9c6be097074d8d474de2386aa7db575be30626f">c9c6be0</a>)</li>
<li>And I had to forget one more, right?!?! - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fc49d22f286294c34612ca2b8f1e682c83f34820">fc49d22</a>)</li>
<li>Windows executables have <code>.exe</code> extension!!! - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/35d2ebdbe332c2312c0a6452f3cdb0c4ee4c3d73">35d2ebd</a>)</li>
<li>Add Windows build to the matrix - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/10776d69def131b8c37c2e5a7578ed961390167d">10776d6</a>)</li>
<li>Switch back to upstream setup-lazarus - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b2c049bafeafc7b75b1cc01b0451b49351f80a09">b2c049b</a>)</li>
<li>Add macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6377e1110f5c94e71c8a56e34d610184a04b27fa">6377e11</a>)</li>
<li>Test switching to forked setup-lazarus action - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dcdac1b763190ac7c5e4dab6c0ed6c91cfb202a9">dcdac1b</a>)</li>
<li>Debugging missing columns from IS.COLUMNS on PG v16 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f65bd15d026bbd8e7937a30a8a310ccb77f6c1c1">f65bd15</a>)</li>
<li>Remove dead code and calls: HasSizeGrip, FixControls, TranslateComponent, ConfirmIcon - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1527d355356e65ab5408269e4d2756d2e4d5cd10">1527d35</a>)</li>
<li>Adding support for QT6 CI/CD - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c9d05e891457084199b8794dc038fec91602bb4b">c9d05e8</a>)</li>
<li>Dealing with end of line shenanigans - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d3fa0af0ebceec6f7c1881c176103a9fb90eba0a">d3fa0af</a>)</li>
<li>Remove Transifex integration, prefer precompiled .mo files in extra/locale/ - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4e5504fb80ba287bdfe418cc252a63c7b1ab14f1">4e5504f</a>)</li>
<li>Remove Wine hacks, now that we provide native Linux builds - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/95df174f0c2db1e65a649fe9af8f00058db3e2a0">95df174</a>)</li>
<li>Remove notification for no longer created build updates - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5e2c8b5e72db5c668d79769a9aac1a574b7fd787">5e2c8b5</a>)</li>
<li>Remove dead code - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fa4a14ac149a6c9f3247de010b92a908ffc9e6da">fa4a14a</a>)</li>
<li>Set linker rpath for <em>all</em> build modes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/df80dbfbd9fefdfb545ca71ac7cff49c09dee2e5">df80dbf</a>)</li>
<li>Notarize macOS bundle only with --notarize argument, include team id - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/887a6cf48335ba24778bfbb422a5575f75ff0081">887a6cf</a>)</li>
<li>Apply trivial change to remaining units complaining about CR/LF mixup - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/64cec90d7ca6cc4ffe42177309133d21537daabb">64cec90</a>)</li>
</ul>
<h2>Contributors</h2>
<ul>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a></li>
<li><a href="https://github.com/gcarreno">@gcarreno</a></li>
</ul>
<h2>New Contributors ❤️</h2>
<ul>
<li><a href="https://github.com/D3SOX">@D3SOX</a> made their first contribution in <a href="https://github.com/HeidiSQL/HeidiSQL/pull/2356" data-hovercard-type="pull_request" data-hovercard-url="/HeidiSQL/HeidiSQL/pull/2356/hovercard">#2356</a></li>
</ul>
<h2><a href="https://github.com/HeidiSQL/HeidiSQL/compare/v12.13.1.1..v12.14.1.1">12.14.1.1</a> - 2025-12-11</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Shell script for creating macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/af24108493cb76c42a87977151a260620f63a4e8">af24108</a>)</li>
<li>Support XML formatting in grid popup text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/913fc9dcded9aa75b4fd53a74e611757850cf888">913fc9d</a>)</li>
<li>Switch to grayscale icons on inactive query tabs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/917e04624eaa94074491fe98e38d17c253b6c697">917e046</a>)</li>
<li>Support SSH tunnel configuration per commandline - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/35a52251984b48beadc46b7a4dec1e1c11f66207">35a5225</a>)</li>
<li>Display some known file type icons in file open/save dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b4c0566635fe88df05de8f04f975caee5ffe2253">b4c0566</a>)</li>
<li>Finalize keyboard shortcut customization in preferences - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/637d2d6578fe483b2855644447a30a398edeca3e">637d2d6</a>)</li>
<li>Add new keyboard shortcut editors on preferences dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cc4e6f17d43f61fcb465e7b6817a2a74dae2780a">cc4e6f1</a>)</li>
<li>Keep time fractions intact for CSV exports - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/06322de926b95f0ca7347f03bf05a8e8a3b49c86">06322de</a>)</li>
<li>Use custom folder icons in tree on file dialogs, in non-Windows mode - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3094d79c524603e22e68819cd5afb53694b90bfe">3094d79</a>)</li>
<li>Show NULL values in system variables listing - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/06b44eb483d99c164e4ced3c52185bf032ef77f6">06b44eb</a>)</li>
<li>Highlight same text in grids based on all selected rows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/afc9d8c24fba99b41a11daaee2d8bfdc8d0856ca">afc9d8c</a>)</li>
<li>Support fractional UNIX timestamps in grids - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/65c14727d50f88028799c22999c59eea70292efa">65c1472</a>)</li>
<li>Add "source table: xyz" hint to query result column headers - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2863a80b68ec8fd84e3e6360ab58d2d87ee79280">2863a80</a>)</li>
<li>Support click on path parts on top label of file dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/98b796b6889a3e5ad83e36bcdc29b0fea55402fb">98b796b</a>)</li>
<li>Convert all save/open dialogs to the new custom one - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4a8c53c4e034e38866fa731ab3225a5d83448f04">4a8c53c</a>)</li>
<li>Create file-save dialog with linebreaks selector - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d5d34add5f707b71ce77c7a64868791044535463">d5d34ad</a>)</li>
<li>Recreate basic TExtFileOpenDialog without OS owned dialog and room for customization - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bac0d7a5856c2be98b03d3823f77e016f2d4513b">bac0d7a</a>)</li>
<li>Full support for different icon packs, Silk and Icons8 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dbca69d2b09021960ce49e2feabbd3d4a3c19e9a">dbca69d</a>)</li>
<li>Add 206 Silk icons into new TImageList - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/769afa51950078e46f09ba27ee86cc9525459935">769afa5</a>)</li>
<li>Require libsybdb5 in DEB package - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e1781f96dcbc8a01abaad32b8b7159203b8d529e">e1781f9</a>)</li>
<li>Mark MS SQL protocols like named pipe as unsupported, advise the user to change to TCP/IP - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b20f12146605d48c71f46823b0de0de0dd4b5bcd">b20f121</a>)</li>
<li>Dirty and basic support for MS SQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3df3673a50f43009c5ce55e308a322e6fa72b432">3df3673</a>)</li>
<li>Show more detailed backtrace in crash dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bc0a7dec67a60cef7902124631c155a25db38263">bc0a7de</a>)</li>
<li>Support SSH passwords via sshpass - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f2b2dc371c58585d0e674c5daf7aa48799a9ab03">f2b2dc3</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Position session manager centered over main form, ignore position set by user - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/571c671be3f0511c9ed6e511a79ed7e070e3233e">571c671</a>)</li>
<li>Align bottom buttons on session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ca7aad68a4889c783fdc07ac3f1fa8586946754f">ca7aad6</a>)</li>
<li>Set font style and color of size column in tree - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f987c81cae43aa27d1850a1a42db15970d0df415">f987c81</a>)</li>
<li>Move RightEdge on SQL editors out of sight - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2a23e26f8101294feb4ba673106b013e024c6739">2a23e26</a>)</li>
<li>Light text color instead of ghosted/ugly icon for unseen tree nodes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/76aefb351caed61023cd6a03da70c630e17b6efb">76aefb3</a>)</li>
<li>Disable tree option asDoubleClickInsertsNodeText by default - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1c9321c825e523f1a1e75c1994bc6f50ee03eb07">1c9321c</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>Connect MS SQL query to session transaction, run .ExecSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/59191da66bf1a7758a2576d66a560a1542009adb">59191da</a>)</li>
<li>Prevent SQL delimiter being set to PostgreSQL quotes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a3acc047e83f14d0cde52ce94a89106652dd865f">a3acc04</a>)</li>
<li>Crash when grid-exporting without required key - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ff6050ff1e636a4aa90ed2d3862028badc16d82f">ff6050f</a>)</li>
<li>Delete CLI-created session settings from registry after disconnect - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8778d404d7e65112906cd6281faaa17a06dac5ce">8778d40</a>)</li>
<li>Another broken thousand separator - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/24f3e36d58054f0c1d9db0c88348029a7fd1f155">24f3e36</a>)</li>
<li>New attempt to hide SynEdit caret when unfocused - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/03f4a5f073d4a55502bfd3ed76849af1122bc1ce">03f4a5f</a>)</li>
<li>A TSpeedButton connected to a TAction, and a TMenuItem were not auto-checking - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/42abf46ae3a951763cfda83a242962928e1fecdb">42abf46</a>)</li>
<li>Database icon in Icons8 list too small - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dda44be05c82fd77ae9938ddd0e1e7279a22d2a7">dda44be</a>)</li>
<li>Cannot save new table when added column was removed - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1fe709a8d6e857c4f1fe9f5ecb27976600d2a250">1fe709a</a>)</li>
<li>Compile without MS SQL support on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9a4d841028e7840270798c4553a1aa86c4a0cc5c">9a4d841</a>)</li>
<li>Query batch stops at second last query if it has errors but StopOnErrors is off - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6e40c6270ffc7d83d7a90b492c1b727585dfd37d">6e40c62</a>)</li>
<li>Drag'n drop on Linux requires VT.DragType = dtVCL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4fd646c829269cf625af84212e850e7ac2dac437">4fd646c</a>)</li>
<li>Enable drag'n drop in table editor and session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9afc60f087dd46353f6a407a3acea1381a99779f">9afc60f</a>)</li>
<li>Detected empty text DEFAULT value for table columns - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4c0617d0a83efdec4b9e0f58247b281a6b502154">4c0617d</a>)</li>
<li>Append quick filter without linebreak - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8ea3b9444ec160675039a517251e13ec2518b634">8ea3b94</a>)</li>
<li>Wrong icon sizes, disable right-click select for column list so selection is kept - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a145fc57f076e883131f883192ecd1b60c3200ed">a145fc5</a>)</li>
<li>Remove dead code, fix some compiler hints - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79bcd1d4867d71059dea4e34b5e5fef5ef1a7c26">79bcd1d</a>)</li>
<li>Bad position of TEdit on TInplaceEditorLink - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8d119a011a21c20d8ad20bba8d4eba76e95bb293">8d119a0</a>)</li>
<li>Quick filter &gt; "more values" submenu not created/shown - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8696e61127e2577dddf289e14565cf086fb42421">8696e61</a>)</li>
<li>Empty KeyStrokes list on text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/db00c836651443bec7fbdfdcbba885bbf9da8de3">db00c83</a>)</li>
<li>Broken caption on inline text edit button - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1730956488251dcd6ebdb674e1e3074309d70b37">1730956</a>)</li>
<li>User queries not showing up in log panel - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/222a386039560ae4e0304b9fb8f28048cf35e358">222a386</a>)</li>
<li>Do not edit grid cell on right-click, and set HotCursor on DBtree - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0257867dff7798de701d7b9e6d72731ff23ee8ba">0257867</a>)</li>
<li>Flashing main form in background after cancel session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0563b4d683180a7baa7f15d9f53a062b236bc1e4">0563b4d</a>)</li>
<li>Work around empty space artifact in ShellListView - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cf9ed85900c0cde27ab4f0911a3c573f310af3fd">cf9ed85</a>)</li>
<li>Move all Application event assignments to .lpr file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/64919d6aa6dfc92204607ec34da8411bc3ee1285">64919d6</a>)</li>
<li>Confusion with (selected) folder icons - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b488ca23aeea42d93cf72fbd1f7d9d24bf2a5e18">b488ca2</a>)</li>
<li>Tree with keyboard actions shows wrong captions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5e20c53e21d0c96a56abda53e490602bd555b57a">5e20c53</a>)</li>
<li>Binary result values displayed as 000... - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4322372c3008087ea1f88f0731d77952802fac82">4322372</a>)</li>
<li>TMySQLQuery.TableName() returns wrong string, and introduce apphelpers.GetAppDir - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bb517d79e2cfd606ed061b95a72018815315dad0">bb517d7</a>)</li>
<li>Crash in AnyGridPaintText with no query result - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/59659f074113cd83bda8640b70496cf5a178dbc9">59659f0</a>)</li>
<li>Error: (4004) Variable identifier expected - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/13a0127d69cf2384a4df785d201e2ce94cfe9b45">13a0127</a>)</li>
<li>Crash in printer dialog with 0 printers available - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6eecdd8a5fe4f0b67fb330fb3a8155e10ca4f52a">6eecdd8</a>)</li>
<li>Missing file for previous commit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/857cca865ccef1f207a771bcf7080405b386f967">857cca8</a>)</li>
<li>Some remaining issues in the new file-open/save dialogs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/34e3f32a07bc83af8b2b8ccd83e5ddaf9005b4ed">34e3f32</a>)</li>
<li>Work around out-of-view item in left tree after FormShow - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ec4c237caecfe0633bcb6d08fe261f77358903a5">ec4c237</a>)</li>
<li>Navigate to directory of currently loaded file when user opens dialog for loading another file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/251f632a2ada8d7951e0c47971f474285a15ef66">251f632</a>)</li>
<li>Broken support for non UTF-8 encoding - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fe652313abcc2d5516cf081b1074377fae2f6791">fe65231</a>)</li>
<li>Prompt to overwrite only if file exists - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/91de2fc30d05fadcd92314851b25962302c4cbb8">91de2fc</a>)</li>
<li>Add encoding selector to file-open dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/56b783d8292b0acb72d45e1a2aed6546cb71fcbe">56b783d</a>)</li>
<li>Crash when app exits, with deleted TSynGutterSeparator - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/00627ae2846a56c1f5dceec223d20a8931f000c5">00627ae</a>)</li>
<li>Optical stuff, add bookmark icons for SynEdit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/29d1abc23c6ea5a524931efe62e98078f69532d6">29d1abc</a>)</li>
<li>Use GetApplicationName in InitMoFile as well, plus documentation - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93bf989ac704c5931342de969d95f12bec04a32a">93bf989</a>)</li>
<li>Make LCLTranslator independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0469dd9f51edb341ab05aad9c4e3db1cc80546d9">0469dd9</a>)</li>
<li>Make GetAppConfigDir independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9e2611e54d954a4f87b7c8dc25a38038b85c9d2b">9e2611e</a>)</li>
<li>Make translation filename independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5d487bb352679b8bfc1805328c760291036325ad">5d487bb</a>)</li>
<li>More painting related crashes on QT, this time in OperationRunning() - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fbe32db87594e6b3bba78a8d5fc91bb74f9911c3">fbe32db</a>)</li>
<li>Compiler warnings, re-enable active line background - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a1c84ae578ef3bca71e39f26033b5c2560e71bb3">a1c84ae</a>)</li>
<li>Two crashes in QT caused by aggressive control repainting - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7650efe74056513e3a481785bbfaebd5f7107dc5">7650efe</a>)</li>
<li>Hide library files which ldconfig shows up but don't exist - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/85cf23029993f5702cebde631219a88cda045843">85cf230</a>)</li>
<li>Provide at least one libmysql for macOS, plus its dependencies - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1fbc2aba11bc23b8f7372fbd35e21b73d5c2e964">1fbc2ab</a>)</li>
<li>Fix compiler errors on macOS, set DYLD_LIBRARY_PATH run param to fix wrong path for libssl - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/58b210af469ade5b43d56478aabe815a4252beb5">58b210a</a>)</li>
<li>Wrong integer size/type for ClientFlag in mysql_real_connect - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3213fe94460af85fa8076036381dc772fbb8856c">3213fe9</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bump version to 12.14.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1a2f1f37723be894a1d70cfc109bad66d7963bd3">1a2f1f3</a>)</li>
<li>Use Lazarus logo in readme - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/aa49736545d452b9dfd82a896d489a2acd819776">aa49736</a>)</li>
<li>Remove now unused doc, written for converting to Lazarus - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b01e732a10a1c89a1634be22ba6ef300e1d1b17e">b01e732</a>)</li>
<li>Fix generation of <code>.deb</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e95aca86d6a39ae3e38ef036b9b1fe27ee3b6c08">e95aca8</a>)</li>
<li>Fix missing <code>Package</code> variable - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/13c55ce2ee5895f1e3fdc6b13972bdb98d775c3c">13c55ce</a>)</li>
<li>Using <code>v4</code> of <code>git-cliff-action</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/81d613b08b2ec97c1898a29cb87de614163ecf60">81d613b</a>)</li>
</ul>
<h2>Contributors</h2>
<ul>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a></li>
<li><a href="https://github.com/gcarreno">@gcarreno</a></li>
</ul>
<h2>[12.13.1.1] - 2025-11-03</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Sort session folders at top per setting - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93dc93680327beb4e24422e7cae9c97b71a9ba24">93dc936</a>)</li>
<li>Filter box in user manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b57b76443bfc6c31dd81ea50d7c0238278f78301">b57b764</a>)</li>
<li>Add checkbox "Open file after creation" to grid export dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/613f4d8a23f80fe9542b90724a1cab5e6e9f96b6">613f4d8</a>)</li>
<li>Allow sorting columns in table designer - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8541eb404de942a0b3e976201430cbc65964887a">8541eb4</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Make file exit action OS friendly - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1f19d004905a39a6a1d49df698bd4194735aa29c">1f19d00</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>List procedures in PostgreSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/db902f7da1133c05bcaf67ca92e273582328fdf3">db902f7</a>)</li>
<li>Missing DELETE HISTORY privilege on MariaDB - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f7b80dbb51f802e166528308f35106ada0ae0883">f7b80db</a>)</li>
<li>Prevent crash in auto-refresh action - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2c25e04baf90d3912749421fadac798b7d1db786">2c25e04</a>)</li>
<li>Bad message with no library selected - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f9a486b40352da9426f2575579271d25ffb16ec5">f9a486b</a>)</li>
<li>Generate missing values for geometry columns - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb1b5eac59100605b0a5b749037a6297ff9d6fb7">eb1b5ea</a>)</li>
<li>Allow modify length of index with binary column - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/173efeb6aa4f920c14c961aa3458cfe2fbddf2fd">173efeb</a>)</li>
<li>End global "edit function" mode for grid editing early - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5cac85089a58dcc8e11c540e1499e001df76d69a">5cac850</a>)</li>
<li>Take care for escaped ENUM definitions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/328fb7287b6597a663c465bcece8c05218753f13">328fb72</a>)</li>
<li>Support return data type of stored function containing white spaces - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d7b1faa637869472ffbdabd28d5885caa3a33dc9">d7b1faa</a>)</li>
<li>Safety replacement for folder separator when renaming a session or folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/18a21ef9e4f1f450391b40a1cb8ee3aef036fa36">18a21ef</a>)</li>
<li>Leave away schema when double-click table for inserting into query editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b72f2595c55644daf55b76086ab38f99fa3d93ce">b72f259</a>)</li>
<li>Sticky empty-password warning after setting a non-empty one - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f2028e135e4e3ded46612d30b4687db413c2bb0f">f2028e1</a>)</li>
<li>Support double dollar quotes on PostgreSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/caeae88f25d7b7118836f22c7223a24523a0ba2d">caeae88</a>)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li><em>(CHANGELOG)</em> Proper changelog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79bb279a15998756d040ad3830b7e7bb5f27f8cc">79bb279</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bumping version to 12.13.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bf23332cc1731f521330a61e7fb5cebff87687c3">bf23332</a>)</li>
<li>Using correct target of <code>build-*</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/16a54a57aa6974c819801c3e304367fab7ec07af">16a54a5</a>)</li>
<li>Fixing some blantant mistakes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/76dfa98217d4eabaf30e96a938fb982fdabb221d">76dfa98</a>)</li>
<li>New category: Enhancements - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dd1ad34317215a16178fc6bf5de04146358e29aa">dd1ad34</a>)</li>
<li>Removing unnecessary <code>tx-push</code> recipe - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d293d648d8cc933d01e269619cc041f2833b6a3f">d293d64</a>)</li>
<li>Forgot to copy <code>.ini</code> files on <code>run-*</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c513e535d916d414312481828bdc5a241047a7db">c513e53</a>)</li>
<li>Completing <code>run-gtk2</code>, <code>run-qt5</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/04650d93a7c0a24e8c53b800791b9511d6a1bb30">04650d9</a>)</li>
<li>Adding empty <code>tx-push</code> to <code>Makefile</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3ceed3936c24f3b9034b558a16c490f826c90b34">3ceed39</a>)</li>
<li>Adjusting workflow to skip secrets detection - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/14dd9ce9a590e9e1a768f32db1dcb6412c857eab">14dd9ce</a>)</li>
<li>Adding usage of <code>secrets.mk</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/123a2e7d36f0478cd8e9ce24b6c25ed85386517b">123a2e7</a>)</li>
<li>Forgot to change the output folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/78f1415c210c9bea2fdb0edf27cfa1dd89909f15">78f1415</a>)</li>
<li>First batch of changes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2bee126353676a3387cfd10ae4f348a2488e5938">2bee126</a>)</li>
</ul>
<h2>New Contributors ❤️</h2>
<ul>
<li><a href="https://github.com/gcarreno">@gcarreno</a> made their first contribution</li>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a> made their first contribution</li>
<li><a href="https://github.com/">@</a> made their first contribution</li>
</ul>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p>
<p>For a list of all the changes up to date, please read <a href="https://github.com/HeidiSQL/HeidiSQL/blob/lazarus/CHANGELOG.md">CHANGELOG.md</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HeidiSQL 12.17]]></title>
<description><![CDATA[12.17 - 2026-04-12
⛰️  Features

(packaging) Add libqt6pas dependency - (a3e6d0b)
(packaging) Ship qt6 build in deb package, enhance control file fields - (992b673)
(ui) Turn all TEdit's with NumbersOnly into TSpinEditEx - (96bb466)
Select just created table copy - (18e9431)
Add toolbar button fo...]]></description>
<link>https://tsecurity.de/de/3461044/downloads/heidisql-1217/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461044/downloads/heidisql-1217/</guid>
<pubDate>Fri, 24 Apr 2026 12:46:26 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/HeidiSQL/HeidiSQL/compare/v12.16...12.17">12.17</a> - 2026-04-12</h2>
<h3>⛰️  Features</h3>
<ul>
<li><em>(packaging)</em> Add libqt6pas dependency - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a3e6d0b6041fd61c8d82d76d7ef6fb8b2ea93be9">a3e6d0b</a>)</li>
<li><em>(packaging)</em> Ship qt6 build in deb package, enhance control file fields - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/992b6739a60f251d49096c9adff088499e70040b">992b673</a>)</li>
<li><em>(ui)</em> Turn all TEdit's with NumbersOnly into TSpinEditEx - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/96bb46650f70ad4c89bd57fa0daa725a44dbf213">96bb466</a>)</li>
<li>Select just created table copy - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/18e943155df8a5ff102405bd0e89644c82db6a05">18e9431</a>)</li>
<li>Add toolbar button for toggling reverse foreign key listing, so the user has the chance to disable its potentially long during query - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/938f303bda7bcb1809f456a9fc29734eaf885194">938f303</a>)</li>
<li>Reverse foreign keys on "Foreign keys" tab in table editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ca483435a6ad67e76d7e32bb49121c8cd097327e">ca48343</a>)</li>
<li>Add menu item Edit &gt; Copy column names - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ce9393167f7a5d8f8819bffa4cf31108ed705e3a">ce93931</a>)</li>
<li>Prevent loading an SQL file multiple times into an editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/153e61d6549d69e62c6dfa0d3a976ef43a24212f">153e61d</a>)</li>
<li>Add sshpass.exe v1.0.6 for Windows, and refactor Windows installer script - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d79d462d172da51ea1cb350bb7954a54258bcd11">d79d462</a>)</li>
<li>Inject app name and version into potentially long during SQL queries for the SQL export - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93e1b39f943280aef6efd11c00ea1a87e1c6f2ca">93e1b39</a>)</li>
<li>Run user startup script in DoAfterConnect call, which includes reconnects - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1b27b1d1ef5bf112b10bf5b48f33e93fc6fd4be9">1b27b1d</a>)</li>
<li>Add "Display" main menu, move some spread items there, and add two items for toggling log panel and tree filters - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c0fbcff3ef454ef8035439ded2a0fa7e092268c3">c0fbcff</a>)</li>
<li>Support BOOLEAN column type in MySQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e796ad1d55a4f62c5e4b63ea320d9b065f7dda67">e796ad1</a>)</li>
<li>Re-enable clickable "Analyze query" label on host &gt; processes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/678c7b8a3703e3cb916478a35882108c4e25fec2">678c7b8</a>)</li>
<li>Create SQL export option for wrapping DML commands in a BEGIN/COMMIT transaction - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5560454f1b9aeb50b323dc3950770079e1109dd1">5560454</a>)</li>
<li>Display approximate row count of tables in database tab on MS SQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/146044fcee5d01fbbe3edb70845df01c9d188074">146044f</a>)</li>
<li>Support full table status option in SQLite, showing "Rows" from COUNT(*) for each table - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/422935a3adfb833e8777196df15733ee0d8e6158">422935a</a>)</li>
<li>Add security policy for supported versions and reporting - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7ce4a23e59462604e9deec57d257ff85235d73ab">7ce4a23</a>)</li>
<li>Prefer KILL QUERY over KILL on MySQL and MariaDB, when using the "Kill process" menu item in Host &gt; processlist - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b3743d85b59daa42c9694bd31c02579a598ddac7">b3743d8</a>)</li>
<li>New attempt to leave the main window invisible behind the session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/be5322c69d11d7fbe976e0050ad4e576278292c9">be5322c</a>)</li>
<li>Show virtual, stored and hidden columns in SQLite - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0a87a7360f8dbbba7214c58fbd07dd9c4ebbd36b">0a87a73</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Move color scheme submenu from Tools to Display menu - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f7f90e8f418db4a8901eeb0f62ad330140bcb167">f7f90e8</a>)</li>
<li>Export tables which are hidden through the table filter - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/42e5277be92252f027d406b93c343c49c347c6a1">42e5277</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>Crash on macOS, due to running Connection.ShowWarnings directly in the TQueryThread - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d62807a2ceeec8170d356459630edd80847fec6f">d62807a</a>)</li>
<li>Less aggressive debug compile mode, made the app unresponsive when trying to close - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8d480994e500f459d2018fe77498ad9bba0b189f">8d48099</a>)</li>
<li>Two more exception causes found in uploaded reports - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e33ea1d1fb9e1ba559260c9c642cad7009cda9e0">e33ea1d</a>)</li>
<li>Sporadic "no database selected" when updating grid header with row details - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c9eb76525603ef5d7012e12cb85e44ff06941cd2">c9eb765</a>)</li>
<li>Wrong use of Copy(), which is one-based not zero-based, and remove translated appendix to snipped log message which may use critical chars and confuse SynEdit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e3fc3f5ff6ef928fd6fb6aeadc5d7fe4d5f2517b">e3fc3f5</a>)</li>
<li>Various crash causes, reported in uploaded bug reports - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6215d19ff59cb54b8c33f825d70bab615f7de117">6215d19</a>)</li>
<li>Missing required package LazControls for TSpinEditEx - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/519a84a11ffe763c9a92dd02ff69cef6893a7203">519a84a</a>)</li>
<li>Remove default keystrokes from query editor: 2x ecRedo and 1x ecDeleteLine - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2bc9d78f88c02d2d80c4b4e3a7d37c72abf2ce2d">2bc9d78</a>)</li>
<li>Wrong SQL on MS SQL when renaming table per table editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a763fd1d472cd680fe63e74b32aeaa79672fb7ee">a763fd1</a>)</li>
<li>Use default brew path to sshpass on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b7c3d07ebb867d82956fb3ff90f510b7dd1da735">b7c3d07</a>)</li>
<li>Status bar text gets written into the panel right besides the current one, on Linux/macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dfb86d5ae38b23a1942b710d578bf22b1571ef61">dfb86d5</a>)</li>
<li>Several crash causes Host subtabs when connection is lost externally - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1029657e9cda2bf0545eef8a2aeeb72d03d48030">1029657</a>)</li>
<li>Non stored global setting for "sort alphabetically" checkbox in column selection - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0ccb1acf35e42664c70cc1d873880144c0de8780">0ccb1ac</a>)</li>
<li>High CPU load and unresponsiveness through SynEdit highlighter when starting to edit large text in popup editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/676fcd793f5e01eb2d72d45d1f5c586f3daa6d75">676fcd7</a>)</li>
<li>Crash when enabling TShellListView.MultiSelect in OnFormShow, now sets options per setter method, before FormShow - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2acce3520684df44616bb98b63ffca0e49b517dd">2acce35</a>)</li>
<li>Crash on right-click in empty area of query result grid - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/630930542529c58ac3b557c8ebd718dc8b717dcb">6309305</a>)</li>
<li>Data grid context menu not opening after click in empty area - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/10fc1177d86d7e9b180a8a9bd81de37fa568529e">10fc117</a>)</li>
<li>Repaint columns list after move up/down a column - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6a0cbe3fbfe4b3809797ffab4aac2783f2d553f9">6a0cbe3</a>)</li>
<li>Out-of-memory error in call to sqlite3_open() on a non-existent SQLite database file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e93924f604f6dbe338c88b4cc5797a999bf5bacf">e93924f</a>)</li>
<li>Font bold + italic setting not stored in settings - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cc5b8116c09b17a2cdce9beab35a322a1c560689">cc5b811</a>)</li>
<li>Potentially crashing typecast in LoadRecentFilter - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/da075910453c192b28836f87f23c495a48577ac2">da07591</a>)</li>
<li>Non-themed white area on TTabControl, fix from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3903234039" data-permission-text="Title is private" data-url="https://github.com/zamtmn/metadarkstyle/issues/75" data-hovercard-type="issue" data-hovercard-url="/zamtmn/metadarkstyle/issues/75/hovercard" href="https://github.com/zamtmn/metadarkstyle/issues/75">zamtmn/metadarkstyle#75</a> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7554364151ff8a582060088b8333c4691f7b33e0">7554364</a>)</li>
<li>Forgotten files in <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/HeidiSQL/HeidiSQL/commit/c01a439ce5f3bd4b4ec748937175e6045e8d935e/hovercard" href="https://github.com/HeidiSQL/HeidiSQL/commit/c01a439ce5f3bd4b4ec748937175e6045e8d935e"><tt>c01a439</tt></a> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8098296ea32d8f3fa253866c0d81c74e0095c3f7">8098296</a>)</li>
<li>Initial FK names assigned in TfrmTableEditor.listForeignKeysNewText() were lacking the referencing table's table name in case the referencing table was not created yet (pr from Jochen Neubeck) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d8cd61c08db35588035c0d63a744f2a633572a39">d8cd61c</a>)</li>
<li>Wrong schema queries in SQLite, always shows columns and indexes of first database file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7072986d630dde6c3eefc2d239ea972df510a1f7">7072986</a>)</li>
<li>BIT values in MS SQL grid queries prefixed with MySQL b'' style - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7456c38ae60ca57df41a8cce4637dbbc43cc513e">7456c38</a>)</li>
<li>Random crash in dodgy typecast TEdit/TEditButton - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/37add0fd5bfbaacc6303548d48ecb12ce71f2ded">37add0f</a>)</li>
<li>Crash when moving added column to very bottom - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b739799d3c98b9658dd1d6a166b72a63b03ec9d4">b739799</a>)</li>
<li>Load any foreign keys, anyway if the user owns them, on PostgreSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dbab4cb0d7989eac40e158bbace4dba084609967">dbab4cb</a>)</li>
<li>Wrong captions on quick filter actions shown in preferences &gt; shortcuts - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3e0bf91fccc64598d5dfd004ba3830edbf1d2759">3e0bf91</a>)</li>
<li>Crash in OpenTextFile, for a 0-bytes file - override the encoding to one without BOM - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/27e26a68153f2388b5c24c8fd8620052e791e196">27e26a6</a>)</li>
<li>Keep column default value in table editor, when user changes its datatype to one in the same category as before (int =&gt; bigint) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3c518adb8eb61068f02937c0d13ae236c0fd020f">3c518ad</a>)</li>
<li>Trim away spaces around name of routine parameter silently - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b681ebfff33b15cd5c8379aeb406d4a6c38b64ca">b681ebf</a>)</li>
<li>Re-enable dropping sql files on main form - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/314db47302a4e4ebcbfc91ab31a095b101295643">314db47</a>)</li>
<li>Missing translations, and rephrase the "themes not supported" text - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7dfad025e8e276626f7f88d1032ec5cf17b3bdb1">7dfad02</a>)</li>
<li>TDBQuery.TableName always returned an empty string on MS SQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/520a90c4be1f92a808a3ed8125735279aae80710">520a90c</a>)</li>
<li>TDBQuery.Col() crashes with "Column not available" on certain locales - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a01acd12a7798ec1248d6f6b942f9a87bee76d85">a01acd1</a>)</li>
<li>Reset DesignTimePPI in all forms from 120 to the default 96, let the IDE scale controls down and move or add some defaults like LCLVersion. - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e635ae557f7cb2192e4f8872505ca083d7d909c7">e635ae5</a>)</li>
<li>Allow $$ as delimiter again on non-PostgreSQL connections, and ` on non-MySQL connections - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/71bb25b2fd01893584fb02545463587f3e576d4f">71bb25b</a>)</li>
</ul>
<h3>🚜 Refactor</h3>
<ul>
<li>Migration from Array[TSQLSpecifityId] to TSqlProvider - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/31ba8bf33943eec6b8b2d6ae8e3bbbfdedc4585c">31ba8bf</a>)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li><em>(ui)</em> Mark VCL styles as deprecated - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1ce80eafe8a6ba46055ce42194adc7af37693a0f">1ce80ea</a>)</li>
</ul>
<h3>🎨 Styling</h3>
<ul>
<li><em>(ui)</em> Remove border around reverse foreign key list - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6ed145ef6761b0738b468168d0da2ce6064cc86f">6ed145e</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bump version for v12.16 release - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d141124e9e6552e4f98e30e86dae270394a9772d">d141124</a>)</li>
<li>Move OpenSSL license file out of the dll folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5772d09550b0235078c4aaf3b3d6cac55e5ed348">5772d09</a>)</li>
<li>Add Wine deprecation note used in the Windows builds - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5e34fa994f53f3779291200f433f4f7639b41de5">5e34fa9</a>)</li>
</ul>
<h3>Localize</h3>
<ul>
<li>Update compiled translation files from Transifex - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a5f1a19a0d7c13fb4ad46b16ce73549ed389e5f5">a5f1a19</a>)</li>
</ul>
<h3>Ui</h3>
<ul>
<li>Hint the user in which path we are going to look for sshpass (macOS and Windows) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/86a96bd5b2877c3b7d4236cbaf6b45dd31d613f6">86a96bd</a>)</li>
</ul>
<h2>Contributors</h2>
<ul>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a></li>
</ul>
<h2><a href="https://github.com/HeidiSQL/HeidiSQL/compare/v12.14.1.1..v12.15.1.1">12.15.1.1</a> - 2026-01-30</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Add a few items to the top of the grid's header context menu - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb9cd8b57bd5de0c70b6432fdab9513578fae690">eb9cd8b</a>)</li>
<li>Add a newer FreetTDS library for Windows, from the last successful VS 2022 build on <a href="https://ci.appveyor.com/project/FreeTDS/freetds" rel="nofollow">https://ci.appveyor.com/project/FreeTDS/freetds</a> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93bfda0acc29355ab6646f6e360b549618410ae1">93bfda0</a>)</li>
<li>Make grid-highlight-same-text-color part of the predefined color schemes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7854157fccdcc32f98d130a17b06ef1bcdcb0eaf">7854157</a>)</li>
<li>Switch color scheme from Tools main menu - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c8c3b23eaebc0433c21aaf8d4805a10a301b14e1">c8c3b23</a>)</li>
<li>Introduce global AppColorSchemes for managing SQL and grid colors, and sync both with the app's dark mode (still only on Windows) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d313a596b30fba50f6f42499decc1e35f1afbf0e">d313a59</a>)</li>
<li>Sync active line color and brace highlight with the app's dark or light mode - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/351072849a18e089d3437edc48ae2cc075444c37">3510728</a>)</li>
<li>Auto-switch to dark or light SQL colors in sync with the app's dark mode - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8a08e77afd4f5d1566e79db82436258ae465a7df">8a08e77</a>)</li>
<li>Support dark mode, using MetaDarkStyle from OPM, and provide the 3 known custom settings: automatic, light and dark - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3f9e867dd5647a3803c784c611064f151fa31f99">3f9e867</a>)</li>
<li>Re-enable dropping files from file manager to "insert files to BLOB" dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/23fc9c09875cb8ea1a2947a3b0cdff901a2dbef2">23fc9c0</a>)</li>
<li>Upgrade DPI awareness to Per-Monitor v2, add TMainForm.FormChangeBounds as a replacement for the missing OnAfter/OnBeforeMonitorDpiChanged events - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9eab28ea642b1efe232eb5256163f0516f6f9082">9eab28e</a>)</li>
<li>Re-enable menu item on list header context menu: "Toggle visibility of all columns" - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/41169f773de71534062e88699fdb164fb385340c">41169f7</a>)</li>
<li>Support European umlauts/accents as \w (word char) in some regular expression areas - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/304cd26a05b438fb6f5519504d83ab41417ae609">304cd26</a>)</li>
<li>Auto-uppercase keywords, data types and functions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/62cda84bed0caccd484276ce13cbb1463f838ffe">62cda84</a>)</li>
<li>Recreate previous state of trigger after realizing the user edited code has errors - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e7e5e11cb45bf324e25d1d781cbe2af9dffd4a71">e7e5e11</a>)</li>
<li>Create a TSynEditMarkup descendant and use it for highlighting selected text occurrences - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8a667f297a4e732f4252813147108ce6cae61c6b">8a667f2</a>)</li>
<li>Create custom setting so the user may define a terminal app himself, and auto-detect terminal app if the setting is yet empty - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/613e207b726122a26667bb6f2e210e1820c75516">613e207</a>)</li>
<li>Enable InnoSetup script for creating Windows installer - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/317edcd529bb0a31e24f61e1cb759c48c040df43">317edcd</a>)</li>
<li>Re-enable codepage =&gt; charset mapping using GetACP from DelphiCompat unit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79e4654fc072646cd34d85fc553cf2dbd4953782">79e4654</a>)</li>
<li>Re-enable ValidFilename function with platform specific lists of disallowed characters - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f3a0594a4628470b406ee9f6cf359a57d7f9a3b6">f3a0594</a>)</li>
<li>Re-enable support for hyperlinks in message dialogues, and use TTaskDialog again for simple messages on Windows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/15eb52b1d98f20fb229730de80c3da80043b1158">15eb52b</a>)</li>
<li>Support portable mode with a portable.lock file in the app folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c528c5de3baa685be7491c4bdad3ae9f393d6033">c528c5d</a>)</li>
<li>Re-enable hints on query result tabs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/88115acea27029192d0a117ee95dbbe1c3f639e0">88115ac</a>)</li>
<li>Show connection details as a hint over status bar - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e1ad5c3ab5f8f650cdfd8895df2d6fc81f2ae29a">e1ad5c3</a>)</li>
<li>Add missing LCL translations, compiled to .mo files with msgfmt from Poedit with support for msgctxt - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/505e3ec141491b86a70e76f39a584be11a7dc927">505e3ec</a>)</li>
<li>Use the more native MessageDlg on all platforms when we don't need additional dialog features - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8c0e61f372bfdd774123e1aedaa155693b1f22fc">8c0e61f</a>)</li>
<li>Show only mono-space fonts in SQL font selector - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3388d9f543afe601fe106fbed82600d50a322fd1">3388d9f</a>)</li>
<li>Support compilation and usage on FreeBSD - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/425d099dc12692655c0884c680c461546c318cd2">425d099</a>)</li>
<li>Include libssl 1.1 in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f51d2a9662de23b2cbff5e3938aa7f33259e32ae">f51d2a9</a>)</li>
<li>Include libmysql plugins in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/85a15f839ae16581ea6825eef2e181dc0a9ad76d">85a15f8</a>)</li>
<li>Provide libmariadb plugins in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2967ad28b4e3172e302cb8d487c0d3a5c752b3fe">2967ad2</a>)</li>
<li>Assign OK button to Enter and Cancel button to Esc - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3ea4a903d488960a8a975211dcf6c09bade7184c">3ea4a90</a>)</li>
<li>Add translation files to macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/08735bc11adbe33cca9a95d00ff74a058463670d">08735bc</a>)</li>
<li>Provide libmariadb in macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2a1c7259e75c5cf5bfb9774341b35e19dbf90369">2a1c725</a>)</li>
<li>Support SynEdit hints when mouse is over function names, tables etc - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/82ef10e5a0c7f562de7e10347e751fbec26955e2">82ef10e</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Turn two more TButtons into TBitBtn with icon - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9300cbc67b19c8f9cf0ef5782a07433d35a0311d">9300cbc</a>)</li>
<li>Immediately show new log lines on heavy operations, enhancing user experience - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b100479b7ee609bf6b03c54dd708a1e2ddebdcab">b100479</a>)</li>
<li>Turn export options button into TBitBtn and give it an arrow-down icon - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4864900c658112973d517e94ae38013f597e0769">4864900</a>)</li>
<li>Indicate drop-down menu through arrow-down image on buttons - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/288b346f1aea68ea5f1c0dfc19fd44a15cf527f6">288b346</a>)</li>
<li>Reduce width of left gutter in popup text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4215aeeaaf347f9bd25c8024c2a280dcf8afd969">4215aee</a>)</li>
<li>Hide grid cell border lines in most VirtualStringTree's - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b31f78acd0c16f05baf9a89bde220f386879f159">b31f78a</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li><em>(ci)</em> Get libqt6pas on ubuntu via 3rd party repo - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4205774ae3a7a4be8bce06ba33cd9141a13cfa5a">4205774</a>)</li>
<li>Remove MetaDarkStyle from the required packages, instead add a latest snapshot of the relevant files from <a href="https://github.com/zamtmn/metadarkstyle/">https://github.com/zamtmn/metadarkstyle/</a> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9f9cde005c6fd6a18fb9fc99103ead9e84bf02a7">9f9cde0</a>)</li>
<li>ERangeError when editing text grid values which allow more than 2^31 chars, e.g. LONGTEXT - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/42b5d52fbbb77c38b27ba41485ff41c8e6cb4db8">42b5d52</a>)</li>
<li>Set default value for ThemeIsDark for cases where AppleInterfaceStyle does not exist (= light mode) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/26ca75e8f458b5bb2b1d64e5a2365bcb2c67a93e">26ca75e</a>)</li>
<li>Reload color scheme after auto-apply, reintroduce ThemeIsDark with a detection for Windows and macOS, use MetaDarkStyle units only on Windows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b4afc3af279c776f6424d53f1232a8b975f7ce1f">b4afc3a</a>)</li>
<li>Invalid typecast in List.Add(BaseForm.Components[i]), when running debug builds - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/38faf5787d04fea1043ebd33517baa81827b73f0">38faf57</a>)</li>
<li>Wrong length of text detected (always 0) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/930a815d6ab9bec2b8cdb8f7c3f4dbfe43f84df2">930a815</a>)</li>
<li>Crash in data grid when switching to an empty table on ArchLinux - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e9b6835e47bd34fdd5933fbb98ba7029d58523ab">e9b6835</a>)</li>
<li>Next attempt to fix ERangeError crash in TBaseVirtualTree.UpdateVerticalRange - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c8e8beddbf397af9fcd0c169dd4319f09dd2ec97">c8e8bed</a>)</li>
<li>Wrong ModalResult on "Replace all" button - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2367ac681f12804f50ee62f861f6ba3e0535260c">2367ac6</a>)</li>
<li>Increase too tight node height - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/60ad998715bb5da9ba57d59f144ed3c3ad2399cb">60ad998</a>)</li>
<li>Auto fit columns in search-on-server results, taking the header caption into account - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4ce827b3583abec94aeaf308783ceed5241aa499">4ce827b</a>)</li>
<li>Remove space eating gutter from SynEdit in search text dialog, disable scrollbars as long as not required - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7423aa356110d33394ce78e62ddd00f160b69507">7423aa3</a>)</li>
<li>Form dimensions reset to default values each time, and wrong check for empty SynEdit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dab1cda93e0af7a0a88aca3c792a62033fb0819d">dab1cda</a>)</li>
<li>Confusion about modified default setting for DoubleClickInsertsNodeText, reset to old value - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f8dc7963e836ad15c21dfde22c95050a50200a48">f8dc796</a>)</li>
<li>Wrong BOM characters written to grid export files, when encoding is set to "UTF-8 BOM" for instance - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f951b78c0e831bec296b06e9cdd2054b404135ae">f951b78</a>)</li>
<li>Auto-uppercase when pressing Enter immediately after a keyword - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d34be7f7b4881e1c51f29cae5e7b1550ef4db40b">d34be7f</a>)</li>
<li>Missing selection highlighting and auto-uppercasing in data tab filter editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2e31c5e0eca476ea90952bfa8c883d515b579e11">2e31c5e</a>)</li>
<li>Prevent triggers without quoted trigger name or table name from failing to be parsed (alexanderglueck) - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3028076b45a78766f7ce6856267335ddc243363b">3028076</a>)</li>
<li>Convert usages of UnicodeString to String, in jsonregistry unit, and fix handling of Chinese characters - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/39df33999f59b917269a7656d56b5f1651df5289">39df339</a>)</li>
<li>Broken integers and floats after locale formatting on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fa1db7663a3aa0e226df826f61815bcf47b42b32">fa1db76</a>)</li>
<li>Crash in file-picker with Windows path within Linux - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7f8dc30628b16a9c9d106bbf6f18f5627943cc5d">7f8dc30</a>)</li>
<li>Some more compiler warnings and hints - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3b247070729b18d5af75a88ca9a67ad5927257bc">3b24707</a>)</li>
<li>Missing top anchor control for new terminal edit box - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/427104065c3768913b27c920e5ff20a5d42a4b92">4271040</a>)</li>
<li>Missing SSHPASS environment variable when starting tunnel with sshpass -e - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6ce846b47bfafc58234473beb8bb86c50bd51d25">6ce846b</a>)</li>
<li>Non working MySQL command line launcher, for all platforms - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d9b6f877acfe084b5b8b43833fc9abc4d7523937">d9b6f87</a>)</li>
<li>A few more compiler hints and warnings - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e18b3dbc7e79d9c6e1cc71dce00d21bb1446076e">e18b3db</a>)</li>
<li>Crash at right-click on data grid header - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f88405bfd63def648094a4b5a998317db98ed81a">f88405b</a>)</li>
<li>Add missing dlls and MySQL plugin dlls for use on Windows, remove unused macOS dylibs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/287abde28625d0e1f0708ba06b85c2e0932c4f36">287abde</a>)</li>
<li>Non working "Insert row" actions and its friends - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d1faf6b3617f490474a71005857abdddd1a72fee">d1faf6b</a>)</li>
<li>Stretched preview image, and image metadata label too small - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/20aded3ead77f3ed315032239f275711e25d5733">20aded3</a>)</li>
<li>Ban Windows API code used in OnAdvancedHeaderDraw for painting column headers with sort chars - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/485fb7ddc1b4da56daf961dcb4398b11879ae458">485fb7d</a>)</li>
<li>Broken sort arrows in grid column header - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/377d4023042ee0689b69c1c582a13d9aba7c25b6">377d402</a>)</li>
<li>Fails to run netstat or netstat.exe on Windows, try a cross-platform socket approach - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/633ee44ff2a594f6ed3509f6f0cec4ff24a6ca70">633ee44</a>)</li>
<li>Fix various compiler hints and warnings - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f1ac6dce5ba6673295d2e0ef61c03513f66a7239">f1ac6dc</a>)</li>
<li>Crash when switching between tables - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c054884b51afc63e7d3a48d08e0dc479a35f3718">c054884</a>)</li>
<li>Bad anchors on edit-variable dialog, overlapping/hiding radio buttons - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3e77c0df1c82b1d6b24ae6994cabc990546f2b00">3e77c0d</a>)</li>
<li>Conflicting grid edit shortcuts - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ad52dd31e2b8961a22239de1798e18babf51f798">ad52dd3</a>)</li>
<li>Crash in grid initializing, likely due to a wrong node height - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4c6204a0c59da3f4662de62594f76118a16beb2a">4c6204a</a>)</li>
<li>Compile error on Linux due to "identifier not found: LoadStringW" - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7a7376938bb87e5730d3d0c3893a9e982897782e">7a73769</a>)</li>
<li>Translate button captions on TTaskDialog using LoadStringW on Windows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/97232100404bb21f88d8307f396392ab7d6e8a2a">9723210</a>)</li>
<li>Set MySQL plugins folder like in the classic branch - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eccf7b22b6f3ec83edc0efba64c28cc951d5a45a">eccf7b2</a>)</li>
<li>No locale influence and no scientific notation in JSON reformatter - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/825447f472a0244fc8b884d02cd809761cb227d7">825447f</a>)</li>
<li>Bad anchors on "start" tab of session manager, plus add an info label for portable users - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a140b199d5a476bdb7a3002adf5b1c7281991662">a140b19</a>)</li>
<li>Set Screen.HintFont globally to what the editors use - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2b7d31b54861163b3dd7b01e6166d134da5887f2">2b7d31b</a>)</li>
<li>Do not show ugly/solid grid lines on macOS and Linux - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c35a35cf79637893d2f628956f60d64919fd2ab5">c35a35c</a>)</li>
<li>Prevent host sub-tabs from getting disabled on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6f5a2d1da2808f695389c138e67ee97f06134182">6f5a2d1</a>)</li>
<li>Missing control anchors on create-database dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d26f1282406b81b78344d9ea2ef561e74aaa61a3">d26f128</a>)</li>
<li>Prevent editors from getting an empty font name - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/74abc1666cfebf861e56e9e2f6c38718c5418d87">74abc16</a>)</li>
<li>Show file modification time in about dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/50b6864864ff817673aefb0c3788a2e9024c0326">50b6864</a>)</li>
<li>Skip harmless error when PG has no COLLATION_NAME in IS.COLUMNS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb3937ac04eaab4b48748214d57ca9b3867b76b9">eb3937a</a>)</li>
<li>Broken compiler conditionals - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/556e4fbf9a016d2792d1af88a4ac32457e51963c">556e4fb</a>)</li>
<li>Missing control anchors on copy-table dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6cc530ba5f62602db1b3979aa4d134ce0b77187e">6cc530b</a>)</li>
<li>Set runtime search path for linker, so openssl finds libssl.1.1.dylib and we can access https pages now - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/230ac8d1b1a54b08cc6576b08861336103ce720c">230ac8d</a>)</li>
<li>Missing control anchors on search/replace dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c07b15504b74a7f3154fb1f362ed64a00a379ac4">c07b155</a>)</li>
<li>Missing control anchors and tab order on column selector - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f72156d2adf1b46d549f9727136ecc3ff45bf30d">f72156d</a>)</li>
<li>Wrong button positioning on macOS caused by differences of TButton/TBitBtn - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ba9442b296826a1836a1db12b988827269af7e9e">ba9442b</a>)</li>
<li>Search for translation files in the right folder within macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/52b065a44eddd159b68158e31b5095532f068dee">52b065a</a>)</li>
<li>Prefer TBitBtn over TSpeedButton for native look on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bee61ec929e84db6fdfcea873a525240b8ca7bd5">bee61ec</a>)</li>
<li>Assign no Syn highlighter by default and call it "Text", in texteditor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/446d78c295dd42085040ffdf24e7265905520051">446d78c</a>)</li>
<li>Anchoring in about box - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3605706bea66dda3ecc92b3fe4c54f35fbd010cd">3605706</a>)</li>
<li>Copy functions-*.ini files to the right folder, add iconset - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2f92db27ebd4f533e6aae239fd1cad9afb658772">2f92db2</a>)</li>
<li>Sign and notarize exe file and dylibs on macOS, fix ini filenames - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c34bde312d5b97cca52d5f244ba77c9e8e09c9a1">c34bde3</a>)</li>
<li>Load libs from ../Frameworks on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8f6ba688cbcdc8d258d577e32671993ecdcbdf02">8f6ba68</a>)</li>
<li>Remove dead code - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5f39a44fe4528313315b074142dcc8859c736f5e">5f39a44</a>)</li>
</ul>
<h3>🚜 Refactor</h3>
<ul>
<li>Move grid null colors away from data types array to the new color scheme - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2bc36b47e6e773a7c2ace3a11fd6478b0f825656">2bc36b4</a>)</li>
<li>Rename TSynEditHelper.TextIsEmpty to HasText - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ac095e46cdfe929cdff0d761f736afc6f5f8df39">ac095e4</a>)</li>
<li>Move macOS build to Makefile - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f41a6ffdee8445c7b11c09f0985f6e979ecae0e8">f41a6ff</a>)</li>
</ul>
<h3>🎨 Styling</h3>
<ul>
<li>Remove no longer needed and partly dead code for DpiChange detection - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/23148e91491f6eff3275f1200115a782519e0507">23148e9</a>)</li>
<li>Remove dead code which is unlikely to get re-enabled in the future - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb4a0b41324d98c91e90ea628a09373eda072f2d">eb4a0b4</a>)</li>
<li>Remove non working context help button on session manager, we have a "general help" menu item in the "more" menu already - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b1122c50a0c04a240028c211a38376f1f70443e8">b1122c5</a>)</li>
<li>Reduce borders around controls - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ff065ea7edfec506047e9a3ef97f1855bb5ed1e3">ff065ea</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bump version to 12.15.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cb03bec0c62b4b167c4f9cb57b80f1aa1d992577">cb03bec</a>)</li>
<li>Revert to using include-packages, now that it checks LazCompatibility to exclude outdated/incompatible package files from installation - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fcd45be2acaeed4fb10653edbd8292620c84f973">fcd45be</a>)</li>
<li>Attempt to fix compilation of unwanted and outdated package files - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/04bee7259c6a8553730d4e37c0163aa70f919324">04bee72</a>)</li>
<li>Attempt to fix broken dependency, use correct case of the package's DisplayName - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/45e596c4dd00ef70a5826fc32678347e2b114f80">45e596c</a>)</li>
<li>Mention current Lazarus version in readme file, mention usage for macOS builds and plans for v13 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93fdf7704012763bfe804375dc25719792974cd3">93fdf77</a>)</li>
<li>Remove "Linux" from the Github release name, so I can have one release for all OS packages - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ab46fc57961bcf388f1a7eb174791f630956919c">ab46fc5</a>)</li>
<li>Move translation source file from master to lazarus branch - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b211b44eb03407f9a0ac6f6b49e389ca4326d7bb">b211b44</a>)</li>
<li>Remove unused file extensions and add some others - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0b5ab2599282c349ed6014777ebf78ab11fe4b9a">0b5ab25</a>)</li>
<li>Set release compiler option -WM10.15 identically to debug, relevant for macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6144df2b204c74bdfebe10edb45ce1f7baa5c195">6144df2</a>)</li>
<li>Using the correct <code>lazbuild</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c9c6be097074d8d474de2386aa7db575be30626f">c9c6be0</a>)</li>
<li>And I had to forget one more, right?!?! - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fc49d22f286294c34612ca2b8f1e682c83f34820">fc49d22</a>)</li>
<li>Windows executables have <code>.exe</code> extension!!! - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/35d2ebdbe332c2312c0a6452f3cdb0c4ee4c3d73">35d2ebd</a>)</li>
<li>Add Windows build to the matrix - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/10776d69def131b8c37c2e5a7578ed961390167d">10776d6</a>)</li>
<li>Switch back to upstream setup-lazarus - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b2c049bafeafc7b75b1cc01b0451b49351f80a09">b2c049b</a>)</li>
<li>Add macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6377e1110f5c94e71c8a56e34d610184a04b27fa">6377e11</a>)</li>
<li>Test switching to forked setup-lazarus action - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dcdac1b763190ac7c5e4dab6c0ed6c91cfb202a9">dcdac1b</a>)</li>
<li>Debugging missing columns from IS.COLUMNS on PG v16 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f65bd15d026bbd8e7937a30a8a310ccb77f6c1c1">f65bd15</a>)</li>
<li>Remove dead code and calls: HasSizeGrip, FixControls, TranslateComponent, ConfirmIcon - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1527d355356e65ab5408269e4d2756d2e4d5cd10">1527d35</a>)</li>
<li>Adding support for QT6 CI/CD - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c9d05e891457084199b8794dc038fec91602bb4b">c9d05e8</a>)</li>
<li>Dealing with end of line shenanigans - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d3fa0af0ebceec6f7c1881c176103a9fb90eba0a">d3fa0af</a>)</li>
<li>Remove Transifex integration, prefer precompiled .mo files in extra/locale/ - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4e5504fb80ba287bdfe418cc252a63c7b1ab14f1">4e5504f</a>)</li>
<li>Remove Wine hacks, now that we provide native Linux builds - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/95df174f0c2db1e65a649fe9af8f00058db3e2a0">95df174</a>)</li>
<li>Remove notification for no longer created build updates - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5e2c8b5e72db5c668d79769a9aac1a574b7fd787">5e2c8b5</a>)</li>
<li>Remove dead code - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fa4a14ac149a6c9f3247de010b92a908ffc9e6da">fa4a14a</a>)</li>
<li>Set linker rpath for <em>all</em> build modes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/df80dbfbd9fefdfb545ca71ac7cff49c09dee2e5">df80dbf</a>)</li>
<li>Notarize macOS bundle only with --notarize argument, include team id - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/887a6cf48335ba24778bfbb422a5575f75ff0081">887a6cf</a>)</li>
<li>Apply trivial change to remaining units complaining about CR/LF mixup - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/64cec90d7ca6cc4ffe42177309133d21537daabb">64cec90</a>)</li>
</ul>
<h2>Contributors</h2>
<ul>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a></li>
<li><a href="https://github.com/gcarreno">@gcarreno</a></li>
</ul>
<h2>New Contributors ❤️</h2>
<ul>
<li><a href="https://github.com/D3SOX">@D3SOX</a> made their first contribution in <a href="https://github.com/HeidiSQL/HeidiSQL/pull/2356" data-hovercard-type="pull_request" data-hovercard-url="/HeidiSQL/HeidiSQL/pull/2356/hovercard">#2356</a></li>
</ul>
<h2><a href="https://github.com/HeidiSQL/HeidiSQL/compare/v12.13.1.1..v12.14.1.1">12.14.1.1</a> - 2025-12-11</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Shell script for creating macOS app bundle - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/af24108493cb76c42a87977151a260620f63a4e8">af24108</a>)</li>
<li>Support XML formatting in grid popup text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/913fc9dcded9aa75b4fd53a74e611757850cf888">913fc9d</a>)</li>
<li>Switch to grayscale icons on inactive query tabs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/917e04624eaa94074491fe98e38d17c253b6c697">917e046</a>)</li>
<li>Support SSH tunnel configuration per commandline - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/35a52251984b48beadc46b7a4dec1e1c11f66207">35a5225</a>)</li>
<li>Display some known file type icons in file open/save dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b4c0566635fe88df05de8f04f975caee5ffe2253">b4c0566</a>)</li>
<li>Finalize keyboard shortcut customization in preferences - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/637d2d6578fe483b2855644447a30a398edeca3e">637d2d6</a>)</li>
<li>Add new keyboard shortcut editors on preferences dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cc4e6f17d43f61fcb465e7b6817a2a74dae2780a">cc4e6f1</a>)</li>
<li>Keep time fractions intact for CSV exports - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/06322de926b95f0ca7347f03bf05a8e8a3b49c86">06322de</a>)</li>
<li>Use custom folder icons in tree on file dialogs, in non-Windows mode - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3094d79c524603e22e68819cd5afb53694b90bfe">3094d79</a>)</li>
<li>Show NULL values in system variables listing - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/06b44eb483d99c164e4ced3c52185bf032ef77f6">06b44eb</a>)</li>
<li>Highlight same text in grids based on all selected rows - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/afc9d8c24fba99b41a11daaee2d8bfdc8d0856ca">afc9d8c</a>)</li>
<li>Support fractional UNIX timestamps in grids - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/65c14727d50f88028799c22999c59eea70292efa">65c1472</a>)</li>
<li>Add "source table: xyz" hint to query result column headers - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2863a80b68ec8fd84e3e6360ab58d2d87ee79280">2863a80</a>)</li>
<li>Support click on path parts on top label of file dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/98b796b6889a3e5ad83e36bcdc29b0fea55402fb">98b796b</a>)</li>
<li>Convert all save/open dialogs to the new custom one - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4a8c53c4e034e38866fa731ab3225a5d83448f04">4a8c53c</a>)</li>
<li>Create file-save dialog with linebreaks selector - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d5d34add5f707b71ce77c7a64868791044535463">d5d34ad</a>)</li>
<li>Recreate basic TExtFileOpenDialog without OS owned dialog and room for customization - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bac0d7a5856c2be98b03d3823f77e016f2d4513b">bac0d7a</a>)</li>
<li>Full support for different icon packs, Silk and Icons8 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dbca69d2b09021960ce49e2feabbd3d4a3c19e9a">dbca69d</a>)</li>
<li>Add 206 Silk icons into new TImageList - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/769afa51950078e46f09ba27ee86cc9525459935">769afa5</a>)</li>
<li>Require libsybdb5 in DEB package - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e1781f96dcbc8a01abaad32b8b7159203b8d529e">e1781f9</a>)</li>
<li>Mark MS SQL protocols like named pipe as unsupported, advise the user to change to TCP/IP - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b20f12146605d48c71f46823b0de0de0dd4b5bcd">b20f121</a>)</li>
<li>Dirty and basic support for MS SQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3df3673a50f43009c5ce55e308a322e6fa72b432">3df3673</a>)</li>
<li>Show more detailed backtrace in crash dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bc0a7dec67a60cef7902124631c155a25db38263">bc0a7de</a>)</li>
<li>Support SSH passwords via sshpass - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f2b2dc371c58585d0e674c5daf7aa48799a9ab03">f2b2dc3</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Position session manager centered over main form, ignore position set by user - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/571c671be3f0511c9ed6e511a79ed7e070e3233e">571c671</a>)</li>
<li>Align bottom buttons on session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ca7aad68a4889c783fdc07ac3f1fa8586946754f">ca7aad6</a>)</li>
<li>Set font style and color of size column in tree - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f987c81cae43aa27d1850a1a42db15970d0df415">f987c81</a>)</li>
<li>Move RightEdge on SQL editors out of sight - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2a23e26f8101294feb4ba673106b013e024c6739">2a23e26</a>)</li>
<li>Light text color instead of ghosted/ugly icon for unseen tree nodes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/76aefb351caed61023cd6a03da70c630e17b6efb">76aefb3</a>)</li>
<li>Disable tree option asDoubleClickInsertsNodeText by default - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1c9321c825e523f1a1e75c1994bc6f50ee03eb07">1c9321c</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>Connect MS SQL query to session transaction, run .ExecSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/59191da66bf1a7758a2576d66a560a1542009adb">59191da</a>)</li>
<li>Prevent SQL delimiter being set to PostgreSQL quotes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a3acc047e83f14d0cde52ce94a89106652dd865f">a3acc04</a>)</li>
<li>Crash when grid-exporting without required key - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ff6050ff1e636a4aa90ed2d3862028badc16d82f">ff6050f</a>)</li>
<li>Delete CLI-created session settings from registry after disconnect - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8778d404d7e65112906cd6281faaa17a06dac5ce">8778d40</a>)</li>
<li>Another broken thousand separator - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/24f3e36d58054f0c1d9db0c88348029a7fd1f155">24f3e36</a>)</li>
<li>New attempt to hide SynEdit caret when unfocused - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/03f4a5f073d4a55502bfd3ed76849af1122bc1ce">03f4a5f</a>)</li>
<li>A TSpeedButton connected to a TAction, and a TMenuItem were not auto-checking - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/42abf46ae3a951763cfda83a242962928e1fecdb">42abf46</a>)</li>
<li>Database icon in Icons8 list too small - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dda44be05c82fd77ae9938ddd0e1e7279a22d2a7">dda44be</a>)</li>
<li>Cannot save new table when added column was removed - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1fe709a8d6e857c4f1fe9f5ecb27976600d2a250">1fe709a</a>)</li>
<li>Compile without MS SQL support on macOS - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9a4d841028e7840270798c4553a1aa86c4a0cc5c">9a4d841</a>)</li>
<li>Query batch stops at second last query if it has errors but StopOnErrors is off - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6e40c6270ffc7d83d7a90b492c1b727585dfd37d">6e40c62</a>)</li>
<li>Drag'n drop on Linux requires VT.DragType = dtVCL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4fd646c829269cf625af84212e850e7ac2dac437">4fd646c</a>)</li>
<li>Enable drag'n drop in table editor and session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9afc60f087dd46353f6a407a3acea1381a99779f">9afc60f</a>)</li>
<li>Detected empty text DEFAULT value for table columns - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4c0617d0a83efdec4b9e0f58247b281a6b502154">4c0617d</a>)</li>
<li>Append quick filter without linebreak - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8ea3b9444ec160675039a517251e13ec2518b634">8ea3b94</a>)</li>
<li>Wrong icon sizes, disable right-click select for column list so selection is kept - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a145fc57f076e883131f883192ecd1b60c3200ed">a145fc5</a>)</li>
<li>Remove dead code, fix some compiler hints - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79bcd1d4867d71059dea4e34b5e5fef5ef1a7c26">79bcd1d</a>)</li>
<li>Bad position of TEdit on TInplaceEditorLink - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8d119a011a21c20d8ad20bba8d4eba76e95bb293">8d119a0</a>)</li>
<li>Quick filter &gt; "more values" submenu not created/shown - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8696e61127e2577dddf289e14565cf086fb42421">8696e61</a>)</li>
<li>Empty KeyStrokes list on text editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/db00c836651443bec7fbdfdcbba885bbf9da8de3">db00c83</a>)</li>
<li>Broken caption on inline text edit button - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1730956488251dcd6ebdb674e1e3074309d70b37">1730956</a>)</li>
<li>User queries not showing up in log panel - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/222a386039560ae4e0304b9fb8f28048cf35e358">222a386</a>)</li>
<li>Do not edit grid cell on right-click, and set HotCursor on DBtree - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0257867dff7798de701d7b9e6d72731ff23ee8ba">0257867</a>)</li>
<li>Flashing main form in background after cancel session manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0563b4d683180a7baa7f15d9f53a062b236bc1e4">0563b4d</a>)</li>
<li>Work around empty space artifact in ShellListView - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/cf9ed85900c0cde27ab4f0911a3c573f310af3fd">cf9ed85</a>)</li>
<li>Move all Application event assignments to .lpr file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/64919d6aa6dfc92204607ec34da8411bc3ee1285">64919d6</a>)</li>
<li>Confusion with (selected) folder icons - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b488ca23aeea42d93cf72fbd1f7d9d24bf2a5e18">b488ca2</a>)</li>
<li>Tree with keyboard actions shows wrong captions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5e20c53e21d0c96a56abda53e490602bd555b57a">5e20c53</a>)</li>
<li>Binary result values displayed as 000... - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/4322372c3008087ea1f88f0731d77952802fac82">4322372</a>)</li>
<li>TMySQLQuery.TableName() returns wrong string, and introduce apphelpers.GetAppDir - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bb517d79e2cfd606ed061b95a72018815315dad0">bb517d7</a>)</li>
<li>Crash in AnyGridPaintText with no query result - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/59659f074113cd83bda8640b70496cf5a178dbc9">59659f0</a>)</li>
<li>Error: (4004) Variable identifier expected - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/13a0127d69cf2384a4df785d201e2ce94cfe9b45">13a0127</a>)</li>
<li>Crash in printer dialog with 0 printers available - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/6eecdd8a5fe4f0b67fb330fb3a8155e10ca4f52a">6eecdd8</a>)</li>
<li>Missing file for previous commit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/857cca865ccef1f207a771bcf7080405b386f967">857cca8</a>)</li>
<li>Some remaining issues in the new file-open/save dialogs - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/34e3f32a07bc83af8b2b8ccd83e5ddaf9005b4ed">34e3f32</a>)</li>
<li>Work around out-of-view item in left tree after FormShow - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/ec4c237caecfe0633bcb6d08fe261f77358903a5">ec4c237</a>)</li>
<li>Navigate to directory of currently loaded file when user opens dialog for loading another file - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/251f632a2ada8d7951e0c47971f474285a15ef66">251f632</a>)</li>
<li>Broken support for non UTF-8 encoding - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fe652313abcc2d5516cf081b1074377fae2f6791">fe65231</a>)</li>
<li>Prompt to overwrite only if file exists - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/91de2fc30d05fadcd92314851b25962302c4cbb8">91de2fc</a>)</li>
<li>Add encoding selector to file-open dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/56b783d8292b0acb72d45e1a2aed6546cb71fcbe">56b783d</a>)</li>
<li>Crash when app exits, with deleted TSynGutterSeparator - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/00627ae2846a56c1f5dceec223d20a8931f000c5">00627ae</a>)</li>
<li>Optical stuff, add bookmark icons for SynEdit - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/29d1abc23c6ea5a524931efe62e98078f69532d6">29d1abc</a>)</li>
<li>Use GetApplicationName in InitMoFile as well, plus documentation - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93bf989ac704c5931342de969d95f12bec04a32a">93bf989</a>)</li>
<li>Make LCLTranslator independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/0469dd9f51edb341ab05aad9c4e3db1cc80546d9">0469dd9</a>)</li>
<li>Make GetAppConfigDir independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/9e2611e54d954a4f87b7c8dc25a38038b85c9d2b">9e2611e</a>)</li>
<li>Make translation filename independent of executable filename - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5d487bb352679b8bfc1805328c760291036325ad">5d487bb</a>)</li>
<li>More painting related crashes on QT, this time in OperationRunning() - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/fbe32db87594e6b3bba78a8d5fc91bb74f9911c3">fbe32db</a>)</li>
<li>Compiler warnings, re-enable active line background - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/a1c84ae578ef3bca71e39f26033b5c2560e71bb3">a1c84ae</a>)</li>
<li>Two crashes in QT caused by aggressive control repainting - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/7650efe74056513e3a481785bbfaebd5f7107dc5">7650efe</a>)</li>
<li>Hide library files which ldconfig shows up but don't exist - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/85cf23029993f5702cebde631219a88cda045843">85cf230</a>)</li>
<li>Provide at least one libmysql for macOS, plus its dependencies - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1fbc2aba11bc23b8f7372fbd35e21b73d5c2e964">1fbc2ab</a>)</li>
<li>Fix compiler errors on macOS, set DYLD_LIBRARY_PATH run param to fix wrong path for libssl - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/58b210af469ade5b43d56478aabe815a4252beb5">58b210a</a>)</li>
<li>Wrong integer size/type for ClientFlag in mysql_real_connect - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3213fe94460af85fa8076036381dc772fbb8856c">3213fe9</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bump version to 12.14.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1a2f1f37723be894a1d70cfc109bad66d7963bd3">1a2f1f3</a>)</li>
<li>Use Lazarus logo in readme - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/aa49736545d452b9dfd82a896d489a2acd819776">aa49736</a>)</li>
<li>Remove now unused doc, written for converting to Lazarus - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b01e732a10a1c89a1634be22ba6ef300e1d1b17e">b01e732</a>)</li>
<li>Fix generation of <code>.deb</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/e95aca86d6a39ae3e38ef036b9b1fe27ee3b6c08">e95aca8</a>)</li>
<li>Fix missing <code>Package</code> variable - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/13c55ce2ee5895f1e3fdc6b13972bdb98d775c3c">13c55ce</a>)</li>
<li>Using <code>v4</code> of <code>git-cliff-action</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/81d613b08b2ec97c1898a29cb87de614163ecf60">81d613b</a>)</li>
</ul>
<h2>Contributors</h2>
<ul>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a></li>
<li><a href="https://github.com/gcarreno">@gcarreno</a></li>
</ul>
<h2>[12.13.1.1] - 2025-11-03</h2>
<h3>⛰️  Features</h3>
<ul>
<li>Sort session folders at top per setting - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/93dc93680327beb4e24422e7cae9c97b71a9ba24">93dc936</a>)</li>
<li>Filter box in user manager - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b57b76443bfc6c31dd81ea50d7c0238278f78301">b57b764</a>)</li>
<li>Add checkbox "Open file after creation" to grid export dialog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/613f4d8a23f80fe9542b90724a1cab5e6e9f96b6">613f4d8</a>)</li>
<li>Allow sorting columns in table designer - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/8541eb404de942a0b3e976201430cbc65964887a">8541eb4</a>)</li>
</ul>
<h3>🚀  Enhancements</h3>
<ul>
<li>Make file exit action OS friendly - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/1f19d004905a39a6a1d49df698bd4194735aa29c">1f19d00</a>)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>List procedures in PostgreSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/db902f7da1133c05bcaf67ca92e273582328fdf3">db902f7</a>)</li>
<li>Missing DELETE HISTORY privilege on MariaDB - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f7b80dbb51f802e166528308f35106ada0ae0883">f7b80db</a>)</li>
<li>Prevent crash in auto-refresh action - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2c25e04baf90d3912749421fadac798b7d1db786">2c25e04</a>)</li>
<li>Bad message with no library selected - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f9a486b40352da9426f2575579271d25ffb16ec5">f9a486b</a>)</li>
<li>Generate missing values for geometry columns - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/eb1b5eac59100605b0a5b749037a6297ff9d6fb7">eb1b5ea</a>)</li>
<li>Allow modify length of index with binary column - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/173efeb6aa4f920c14c961aa3458cfe2fbddf2fd">173efeb</a>)</li>
<li>End global "edit function" mode for grid editing early - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/5cac85089a58dcc8e11c540e1499e001df76d69a">5cac850</a>)</li>
<li>Take care for escaped ENUM definitions - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/328fb7287b6597a663c465bcece8c05218753f13">328fb72</a>)</li>
<li>Support return data type of stored function containing white spaces - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d7b1faa637869472ffbdabd28d5885caa3a33dc9">d7b1faa</a>)</li>
<li>Safety replacement for folder separator when renaming a session or folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/18a21ef9e4f1f450391b40a1cb8ee3aef036fa36">18a21ef</a>)</li>
<li>Leave away schema when double-click table for inserting into query editor - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/b72f2595c55644daf55b76086ab38f99fa3d93ce">b72f259</a>)</li>
<li>Sticky empty-password warning after setting a non-empty one - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/f2028e135e4e3ded46612d30b4687db413c2bb0f">f2028e1</a>)</li>
<li>Support double dollar quotes on PostgreSQL - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/caeae88f25d7b7118836f22c7223a24523a0ba2d">caeae88</a>)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li><em>(CHANGELOG)</em> Proper changelog - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/79bb279a15998756d040ad3830b7e7bb5f27f8cc">79bb279</a>)</li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bumping version to 12.13.1.1 - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/bf23332cc1731f521330a61e7fb5cebff87687c3">bf23332</a>)</li>
<li>Using correct target of <code>build-*</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/16a54a57aa6974c819801c3e304367fab7ec07af">16a54a5</a>)</li>
<li>Fixing some blantant mistakes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/76dfa98217d4eabaf30e96a938fb982fdabb221d">76dfa98</a>)</li>
<li>New category: Enhancements - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/dd1ad34317215a16178fc6bf5de04146358e29aa">dd1ad34</a>)</li>
<li>Removing unnecessary <code>tx-push</code> recipe - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/d293d648d8cc933d01e269619cc041f2833b6a3f">d293d64</a>)</li>
<li>Forgot to copy <code>.ini</code> files on <code>run-*</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/c513e535d916d414312481828bdc5a241047a7db">c513e53</a>)</li>
<li>Completing <code>run-gtk2</code>, <code>run-qt5</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/04650d93a7c0a24e8c53b800791b9511d6a1bb30">04650d9</a>)</li>
<li>Adding empty <code>tx-push</code> to <code>Makefile</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/3ceed3936c24f3b9034b558a16c490f826c90b34">3ceed39</a>)</li>
<li>Adjusting workflow to skip secrets detection - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/14dd9ce9a590e9e1a768f32db1dcb6412c857eab">14dd9ce</a>)</li>
<li>Adding usage of <code>secrets.mk</code> - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/123a2e7d36f0478cd8e9ce24b6c25ed85386517b">123a2e7</a>)</li>
<li>Forgot to change the output folder - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/78f1415c210c9bea2fdb0edf27cfa1dd89909f15">78f1415</a>)</li>
<li>First batch of changes - (<a href="https://github.com/HeidiSQL/HeidiSQL/commit/2bee126353676a3387cfd10ae4f348a2488e5938">2bee126</a>)</li>
</ul>
<h2>New Contributors ❤️</h2>
<ul>
<li><a href="https://github.com/gcarreno">@gcarreno</a> made their first contribution</li>
<li><a href="https://github.com/ansgarbecker">@ansgarbecker</a> made their first contribution</li>
<li><a href="https://github.com/">@</a> made their first contribution</li>
</ul>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p>
<p>For a list of all the changes up to date, please read <a href="https://github.com/HeidiSQL/HeidiSQL/blob/lazarus/CHANGELOG.md">CHANGELOG.md</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Democrats want to ban ICE from turning warehouses into detention centers]]></title>
<description><![CDATA[A bill introduced by Rep. Rashida Tlaib (D-MI) would prohibit the Department of Homeland Security from converting warehouses and similar buildings into immigrant detention centers, an attempt to slow President Donald Trump's mass deportations campaign. The Ban Warehouse Detention Act would also f...]]></description>
<link>https://tsecurity.de/de/3459138/it-nachrichten/democrats-want-to-ban-ice-from-turning-warehouses-into-detention-centers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459138/it-nachrichten/democrats-want-to-ban-ice-from-turning-warehouses-into-detention-centers/</guid>
<pubDate>Thu, 23 Apr 2026 20:45:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A bill introduced by Rep. Rashida Tlaib (D-MI) would prohibit the Department of Homeland Security from converting warehouses and similar buildings into immigrant detention centers, an attempt to slow President Donald Trump's mass deportations campaign. The Ban Warehouse Detention Act would also forbid Immigration and Customs Enforcement from developing other "non-traditional" detention facilities. "ICE and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta will record employees’ keystrokes and use it to train its AI models]]></title>
<description><![CDATA[Meta says that it has a new internal tool that is converting mouse movements and button clicks into data that can train its AI models.]]></description>
<link>https://tsecurity.de/de/3453134/it-nachrichten/meta-will-record-employees-keystrokes-and-use-it-to-train-its-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3453134/it-nachrichten/meta-will-record-employees-keystrokes-and-use-it-to-train-its-ai-models/</guid>
<pubDate>Wed, 22 Apr 2026 01:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta says that it has a new internal tool that is converting mouse movements and button clicks into data that can train its AI models.]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Images 2.0 is better at rendering non-Latin text]]></title>
<description><![CDATA[A little more than a year after OpenAI gave ChatGPT users the option to create images and designs directly from its chatbot, it's now releasing ChatGPT Images 2.0. OpenAI describes the new system as a “step change” for image generation models, particularly when it comes to the tool’s ability to f...]]></description>
<link>https://tsecurity.de/de/3452738/it-nachrichten/chatgpt-images-20-is-better-at-rendering-non-latin-text/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452738/it-nachrichten/chatgpt-images-20-is-better-at-rendering-non-latin-text/</guid>
<pubDate>Tue, 21 Apr 2026 21:16:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A little more than a year after OpenAI gave ChatGPT users the option to create images and designs <a target="_blank" class="link" href="https://www.engadget.com/ai/now-you-can-generate-images-directly-from-chatgpt-and-sora-180047905.html" data-i13n="cpos:1;pos:1">directly from its chatbot</a>, it's now releasing ChatGPT Images 2.0. OpenAI describes the new system as a “step change” for image generation models, particularly when it comes to the tool’s ability to follow instructions in detail, render dense text and place and relate objects in a scene. For the first time, OpenAI has also built an image model with reasoning capabilities, giving the system the ability to do things like search the web and verify its outputs. According to the company, those capabilities should translate to a tool that's more reliable when accuracy, consistency and visual cohesion are essential. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/imagegen_call_000_image_000_2978.png" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/imagegen_call_000_image_000_2978.png" alt="An example of ChatGPT's new non-Latin rendering abilities. " data-uuid="20b5589b-3fa0-43e5-8afb-eeb07a4f017c"><figcaption>An example of ChatGPT's new non-Latin rendering abilities. </figcaption><div class="photo-credit">OpenAI</div></figure><p>OpenAI says it has also put in a lot of work to make Images 2.0 better at understanding and rendering non-Latin text, with "significant gains" when it comes to the model's ability to handle Japanese, Korean, Chinese, Hindi and Bengali. At the same time, the company claims the new model is better at faithfully recreating the specific characteristics of different visual languages. On this point, OpenAI says that makes Images 2.0 more useful for tasks like game prototyping and storyboarding. Outside of those features, the new model is more flexible when it comes to aspect ratios, allowing it to generate images that are as wide as 3:1 and as tall as 1:3. It can also produce designs at resolutions of up to 2K, and even generate up to eight outputs in one go. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/chatgpt_image_apr_21%2C_2026%2C_02_39_32_pm_8401.png" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/chatgpt_image_apr_21%2C_2026%2C_02_39_32_pm_8401.png" alt="A tortoiseshell cat in the style of Pokemon's third generation of games. " data-uuid="a1f565b8-aae0-42b7-ab75-442d982f03b8"><figcaption>A tortoiseshell cat in the style of Pokemon's third generation of games. </figcaption><div class="photo-credit">ChatGPT</div></figure><p>I got a chance to preview Images 2.0 ahead of its public release. For my first prompt, I asked ChatGPT to generate an image of a tortoiseshell cat in the pixel art style of Pokémon's third generation. I thought this would be a good test because AI models typically struggle with pixel art, and the Game Boy Advance Pokémon games are iconic for their art style, so much so that if ChatGPT merely approximated that style, it wouldn't do. The result is the image you see above, and I think ChatGPT did a commendable job there. I then tasked the new model with converting that image into a transparent PNG. For one last test, I asked ChatGPT to create a four-page manga about my cat enjoying a sunny day by an idyllic city stream. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/chatgpt_image_apr_21%2C_2026%2C_12_02_14_pm_4197.png" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/chatgpt_image_apr_21%2C_2026%2C_12_02_14_pm_4197.png" alt="Notice how the cat isn't render exactly like the one above it. " data-uuid="68f40bac-ea36-4ac3-820b-99adfc3b52f4"><figcaption>Notice how the cat isn't render exactly like the one above it. </figcaption><div class="photo-credit">ChatGPT</div></figure><p>Of those three tests, ChatGPT spent the most time on the second one and the output there was slightly different from the first image it generated, which I felt deviated from my prompt. Still, it managed to generate a proper transparent image, which is something other image models can struggle to do properly. Once more people have a chance to put the model through its paces, we’ll have a better idea of how it compares to Google’s <a target="_blank" class="link" href="https://www.engadget.com/ai/googles-nano-banana-2-is-a-faster-version-of-nano-banana-pro-160000695.html" data-i13n="cpos:2;pos:1">Nano Banana 2</a>, and where OpenAI can make additional improvements. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/chatgpt_image_apr_21%2C_2026%2C_12_53_48_pm_5068.png" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/chatgpt_image_apr_21%2C_2026%2C_12_53_48_pm_5068.png" alt="A manga generated by ChatGPT about a cat enjoying a sunny day. " data-uuid="b033bd0d-ed54-4fb0-a75e-c2e229af4246"><figcaption>A manga generated by ChatGPT about a cat enjoying a sunny day. </figcaption><div class="photo-credit">ChatGPT</div></figure><p>Images 2.0 is available starting today for all ChatGPT users, including those on the company's Free and <a target="_blank" class="link" href="https://www.engadget.com/ai/openai-is-bringing-ads-to-chatgpt-192831449.html" data-i13n="cpos:3;pos:1">Go tiers</a>. Plus and Pro subscribers get access to more advanced outputs. OpenAI is also making the model available through its API service and <a target="_blank" class="link" href="https://www.engadget.com/ai/openai-brings-its-codex-coding-app-to-mac-with-new-multi-agent-abilities-included-183103262.html" data-i13n="cpos:4;pos:1">Codex coding app</a>, which just last week it updated to offer built-in <a target="_blank" class="link" href="https://www.engadget.com/ai/openais-latest-codex-update-builds-the-groundwork-for-its-upcoming-super-app-170000019.html" data-i13n="cpos:5;pos:1">image generation</a>. Notably, Images 2.0 arrives just days after Anthropic waded into the visual design market with its <a target="_blank" class="link" href="https://www.engadget.com/ai/anthropic-now-has-a-design-assistant-too-150000903.html" data-i13n="cpos:6;pos:1">own design assistant</a>.  </p>This article originally appeared on Engadget at https://www.engadget.com/ai/chatgpt-images-20-is-better-at-rendering-non-latin-text-190000153.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Prompt injection turned Google’s Antigravity file search into RCE]]></title>
<description><![CDATA[Security researchers have revealed a prompt injection flaw in Google’s Antigravity IDE that could be weaponized to bypass its sandbox protections and achieve remote code execution (RCE).



The issue came from Antigravity’s ability to allow AI agents to invoke native functions, like searching fil...]]></description>
<link>https://tsecurity.de/de/3451414/it-security-nachrichten/prompt-injection-turned-googles-antigravity-file-search-into-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3451414/it-security-nachrichten/prompt-injection-turned-googles-antigravity-file-search-into-rce/</guid>
<pubDate>Tue, 21 Apr 2026 14:29:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Security researchers have revealed a prompt injection flaw in Google’s Antigravity IDE that could be weaponized to bypass its sandbox protections and achieve remote code execution (RCE).</p>



<p>The issue came from Antigravity’s ability to allow AI agents to invoke native functions, like searching files, on behalf of the user. Designed to kill complexity, the feature could allow attackers to inject malicious input into a tool parameter.</p>



<p>According to Pillar Security researchers, the vulnerability could bypass Antigravity’s “most restrictive security configuration,” Secure Mode.</p>



<p>The flaw was reported to Google in January, which acknowledged and fixed the issue internally, awarding Pillar Security a bounty through its Vulnerability Reward Program (VRP) for AI-specific categories. Google did not immediately respond to CSO’s request for comments.</p>



<h2 class="wp-block-heading"><a></a>File search could be turned into code execution</h2>



<p>Pillar’s prompt injection vector relied on Antigravity’s “find_my_name” tool and an “fd” utility within. find_my_name is one of Antigravity’s built-in agent tools that allows the AI to search for files and directories in the project workspace using the fd command line.</p>



<p>What was happening is that any string beginning with “-” was being interpreted by fd as a flag rather than a search pattern, allowing execution of binaries within files matching a “-Xsh” pattern. “The technique exploits insufficient input sanitization of the find_by_name tool’s Pattern parameter, allowing attackers to inject command-line flags into the underlying fd utility, converting a file search operation into arbitrary code execution,” the researchers said in a blog <a href="https://www.pillar.security/blog/prompt-injection-leads-to-rce-and-sandbox-escape-in-antigravity">post</a>.</p>



<p>Essentially, instead of just locating files, “fd” could be tricked into executing attacker-supplied binaries across those files using a crafted prompt that manipulates the “Pattern” parameter. The researchers demonstrated this by creating a file in the local directory with the malicious prompt to exploit the “pattern” injected. Antigravity picked up the file, ran its intended tasks (like launching Calculator), and also launched the search tool, now primed to execute “-Xsh” patterns.</p>



<p>This could also be turned into remote code execution via <a href="https://www.csoonline.com/article/4080154/copilot-diagrams-could-leak-corporate-emails-via-indirect-prompt-injection.html">indirect prompt injection</a>. “A user pulls a benign-looking source file from an untrusted origin, such as a public repository, containing attacker-controlled comments that instruct the agent to stage and trigger the exploit,” the researchers explained.</p>



<p>The worst part was that it was unstoppable with the existing protection.</p>



<h2 class="wp-block-heading"><a></a>Google’s sandbox never got a chance</h2>



<p>Antigravity’s Secure Mode, which is designed to restrict network access, prevent out-of-workspace writes, and ensure all command operations run strictly under a sandbox context, could not flag or quarantine this technique. This is because the find_my_name tool is called much before Secure Mode restrictions are evaluated.</p>



<p>“The agent treats it as a native tool invocation, not a shell command, so it never reaches the security boundary that Secure Mode enforces,“ the researchers noted.</p>



<p>The issue was trimmed down to a twofold root cause. A “No <a href="https://www.csoonline.com/article/4151814/langchain-path-traversal-bug-adds-to-input-validation-woes-in-ai-pipelines.html">input validation</a>” at the Pattern parameter, which accepts arbitrary strings without checking for legitimate search pattern characters. The second was “no argument termination,” which refers to fd’s inability to distinguish between flags and search terms. Google has already fixed the flaw internally, and Antigravity users need not do anything else to remain protected. However, the flaw’s ability to bypass Secure Mode, Pillar researchers point out, underlines that security controls focused on shell commands are insufficient. “The industry must move beyond sanitization-based controls toward execution isolation,” they said. “Every native tool parameter that reaches a shell command is a potential injection point.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the CIO is uniquely positioned to lead the digital workforce]]></title>
<description><![CDATA[In March, OpenAI’s GPT-5.4 achieved a new state-of-the-art, matching or exceeding industry professionals in 83.0% of comparisons on GDPval, a benchmark spanning 44 occupations. In February, Anthropic’s Claude Opus 4.6 signaled a similar advance, pairing that performance with stronger coding, bett...]]></description>
<link>https://tsecurity.de/de/3451042/it-security-nachrichten/why-the-cio-is-uniquely-positioned-to-lead-the-digital-workforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3451042/it-security-nachrichten/why-the-cio-is-uniquely-positioned-to-lead-the-digital-workforce/</guid>
<pubDate>Tue, 21 Apr 2026 12:06:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In March, OpenAI’s GPT-5.4 achieved a new state-of-the-art, matching or exceeding industry professionals in 83.0% of comparisons on GDPval, a benchmark spanning 44 occupations. In February, Anthropic’s Claude Opus 4.6 signaled a similar advance, pairing that performance with stronger coding, better debugging, and longer task execution for agents. This progress has changed the enterprise conversation because AI is now doing much more than generating answers. It’s at a point where it can complete meaningful pieces of work.</p>



<p>In sharp contrast, the previous two years were defined by hesitation across the C-Suite. In early 2024, IBM found that 42% of enterprise-scale companies had actively deployed AI, while another 40% were still exploring or experimenting. In 2025, IBM reported that <a href="https://newsroom.ibm.com/2024-01-10-Data-Suggests-Growth-in-Enterprise-Adoption-of-AI-is-Due-to-Widespread-Deployment-by-Early-Adopters" rel="nofollow">only 25% of AI initiatives</a> had delivered expected ROI and only 16% had scaled enterprise-wide. McKinsey’s 2025 survey showed the same pattern at a broader level: nearly nine in ten organizations were using AI in at least one function, yet most remained in piloting or early scaling, and only 39% reported any business impact. The mood across 2024 and 2025 was distinctly shaped by curiosity and pilot activity with persistent questions about payoff.</p>



<h2 class="wp-block-heading">From pilots to production</h2>



<p>Against that backdrop, 2026 has ushered in a new era of workflow accuracy with strong gains in places where enterprises can see immediate value: spreadsheets, document-heavy analysis and software development. For example, OpenAI’s GPT-5.4 released in March 2026 is 33% less likely to be false than GPT-5.2 on a set of real-world prompts. Anthropic positioned Opus 4.6 as a model that plans more carefully and sustains longer-running work. At the same time, Deloitte reported that workforce access to sanctioned AI tools had risen from fewer than 40% to around 60% in one year, and that <a href="https://www.deloitte.com/us/en/about/press-room/state-of-ai-report-2026.html">85% of companies</a> expect to customize autonomous agents for their own businesses.</p>



<p>Markets have picked up the implications quickly. By the first week of February, stocks had lost about $1 trillion in market value as investors worried that fast-advancing AI tools could upend the sector. Part of the shock came from how directly the new systems were moving into core business workflows. Reuters reported that <a href="https://www.reuters.com/business/finance/anthropic-touts-new-ai-tools-weeks-after-legal-plug-in-spurred-market-rout-2026-02-24/" rel="nofollow">Anthropic launched plug-ins</a> for legal, sales, marketing and data-analysis tasks, then added more plug-ins for investment banking, wealth management, HR, private equity, engineering and design. OpenAI, meanwhile, <a href="https://www.reuters.com/business/openai-deepens-partnerships-with-consulting-giants-push-enterprise-ai-beyond-2026-02-23/" rel="nofollow">formed an alliance with BCG, McKinsey, Accenture and Capgemini</a> to give AI pilots greater legitimacy and a clearer path to scale through consulting firms that enterprises already trust to guide major transformation efforts. Investors were reacting to a simple idea: software was beginning to perform work that had once lived inside teams and SaaS products.</p>



<h2 class="wp-block-heading">The CIO becomes steward of digital labor</h2>



<p>As AI takes on more structured cognitive work, enterprises gain a new layer of digital labor. Someone must decide where that labor fits, how it connects to core systems and data, how its output is measured, where human oversight remains essential and how risk and accountability are managed. Those responsibilities sit naturally with the CIO because they span the very domains the role already oversees: enterprise platforms, security, governance, integration, operating workflows and the architecture that links technology to business execution. The CIO is also one of the few leaders with visibility across functions, which makes the role especially well-suited to determining where digital labor can scale, where it needs guardrails and how it should reshape the way work gets done. The mandate now extends beyond running systems. It includes stewarding systems that increasingly execute work.</p>



<p>This pushes the CIO deeper into business strategy. Now that AI is accurate enough to redesign workflows, the challenge has become operational, economic and organizational. Which tasks should move to agents first? Where does human judgment create the most value? Which functions benefit most from faster analysis and machine-assisted execution? The answers shape speed, margins, customer experience and competitive differentiation. In this environment, the CIO becomes one of the executives most responsible for translating technical progress into business-model advantage.</p>



<p>The next source of advantage will come from converting company-specific judgment into executable systems. Frontier models are spreading quickly across the market, which brings up a different question: whose policies, pricing logic, approval paths, customer context and exception rules are being encoded into workflows that agents can execute with confidence? Much of a company’s edge lives inside those decisions. The CIO stands at the center of that conversion because turning institutional know-how into reliable machine action requires data access, process redesign, system integration and governance working together.</p>



<p>As AI access broadens and use becomes routine, the CIO’s role increasingly includes leading cultural change. Teams need training, new operating norms, trusted guardrails and clear accountability for outputs shaped by AI. Roles are beginning to shift toward judgment, exception handling, taste and decision-making. The most effective CIOs will treat this as work redesign rather than a tool rollout. They will build a blended workforce in which people and digital workers are orchestrated together with intention.</p>



<h2 class="wp-block-heading"><a></a>Turning AI capability into operating advantage</h2>



<p>AI’s promise is growing faster than most enterprises’ ability to capture its value. Yet <a href="https://www.pwc.com/gx/en/ceo-survey/2026/pwc-ceo-survey-2026.pdf" rel="nofollow">only 12%</a> of CEOs report higher revenues from AI. Given the CIO’s role as an execution leader, the gap between what the technology can do and what the business realizes is exactly where CIO leadership matters most. The enterprise needs someone who can turn AI from enthusiasm into operating discipline by selecting workflows with measurable upside, embedding governance into deployment, managing vendors and models coherently and proving that digital labor can scale safely inside the business. This is where CIOs can truly shine. The organizations that win this phase will treat AI as a managed workforce layer with standards, accountability and clear ownership.</p>



<p>The next management discipline will look like workforce management fused with managerial accounting. Leading CIOs will track digital labor through business metrics: cost per accepted outcome, cycle-time, error and rework levels, escalation patterns and the share of output that still requires human repair. Those measures show where AI is compounding value and where it is creating hidden friction to find where human oversight continues to carry the greatest economic return. The enterprises that build this measurement layer early will scale AI with evidence, steer investment with far more precision and learn faster than competitors how to allocate work across people and machines.</p>



<p>AI is making the next chapter of IT leadership bigger than infrastructure and more consequential than another round of digital transformation rhetoric. As software begins to perform meaningful work, the CIO becomes the steward of the digital workforce. The role now extends into strategy, growth, talent, culture and operating model design. In 2024 and 2025, enterprises were asking whether AI would ever justify itself. In 2026, the more urgent question is where AI can reshape workflow economics first. CIOs will be the executives who answer it.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Project Glasswing and the Next Challenge for Defenders: Turning Faster Discovery into Faster Action]]></title>
<description><![CDATA[Anthropic’s Project Glasswing has sparked plenty of discussion about what AI might soon do for vulnerability discovery, but the more useful question for most security teams is how to prepare for, and more importantly seize the opportunity of, what comes next. As we wrote in our earlier blog, What...]]></description>
<link>https://tsecurity.de/de/3449046/it-security-nachrichten/project-glasswing-and-the-next-challenge-for-defenders-turning-faster-discovery-into-faster-action/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3449046/it-security-nachrichten/project-glasswing-and-the-next-challenge-for-defenders-turning-faster-discovery-into-faster-action/</guid>
<pubDate>Mon, 20 Apr 2026 18:51:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Anthropic’s </span><a href="https://www.anthropic.com/glasswing" target="_blank"><span>Project Glasswing</span></a><span> has sparked plenty of discussion about what AI might soon do for vulnerability discovery, but the more useful question for most security teams is how to prepare for, and more importantly seize the opportunity of, what comes next.</span></p><p><span> As we wrote in our earlier blog,</span><a href="https://www.rapid7.com/blog/post/ai-what-project-glasswing-means-for-security-leaders" target="_blank"><span> What Project Glasswing Means for Security Leaders</span></a><span>, AI is becoming more capable of finding software flaws. The pressure that follows lands on the teams responsible for deciding what matters, validating risk, assigning ownership, and getting remediation moving across environments that were already hard to manage. We believe that the organizations that will benefit most from the next wave of AI will be the ones that understand their environment well enough to use </span>these emerging AI models<span> with intent, rather than layering them onto immature processes and hoping that speed alone will solve the backlog.</span></p><h2>What this moment means for security teams</h2><p><span>The number of publicly tracked software vulnerabilities has broken records almost every year over the last decade, while supply chain risk has continued to rise. Most teams were already feeling the strain of more findings than they could process cleanly. The Common Vulnerabilities and Exposures (CVE) program, the standard system for identifying and tracking known vulnerabilities, recorded 48,185 disclosures in 2025, a 20% increase over 2024, with roughly 40% of those disclosed vulnerabilities rated high or critical. </span></p><p><span>The pace in 2026 was already working out to hundreds of new CVEs per day when those figures were cited. That tells you something important about the current environment: the challenge has not necessarily been  a lack of findings, but instead converting a growing stream of findings into measurable risk reduction.</span></p><p><span>The reality is that very few organizations are going to hand a model free rein over their most sensitive environments the minute those capabilities become more widely available. Trust will be built in stages: early adoption is much more likely to focus on backlog reduction, triage support, patch testing, and repetitive lower-tier remediation work that consumes time without carrying the same level of operational risk as the most critical systems in the business. That is a more realistic starting point, and it leads to a more useful question. Before teams apply AI more broadly, they need to understand their environment well enough to use it intentionally.</span></p><h2>Establish the foundation before layering in AI</h2><p><span>The promise from Project Glasswing and almost every other AI-powered security initiative is quite similar: leverage AI to identify patterns, summarize risk, suggest fixes, and speed up repetitive work. Regardless of technology, success  still depends on how well an organization understands its environment, the context around each finding, and the process used to act on it. </span></p><p><span>A model can generate more output than a team ever could on its own, but that output becomes noise if the organization cannot answer basic questions about scope, ownership, criticality, and exposure. Teams need a clear, continuously updated picture of the environment before they can decide where AI should be applied, what should remain human-led, and which parts of the backlog are safe to push through more automated workflows.</span></p><p><span>The AI landscape is already shifting fast, and it will keep shifting, which is why this moment should prompt a more preemptive and resilient strategy rather than another round of tooling hype. Chasing each new capability as it arrives will inevitably force teams to keep reorganizing around the latest announcement. A stronger path is to get the foundation right first - understand the environment, the attack paths, and the assets that matter most; but most importantly, establishing the process and the people behind making these decisions. Then use AI where it meaningfully improves speed, consistency, and focus.</span></p><h2>Why Attack Surface Management should be part of that foundation</h2><p><span>A strong foundation starts with visibility. Security teams need a live picture of what exists in the environment, what is exposed, how assets connect to one another, and which systems carry the greatest business impact if something goes wrong. That is where</span><a href="https://www.rapid7.com/products/command/attack-surface-management-asm/" target="_blank"><span> Attack Surface Management</span></a><span> becomes central. Rapid7’s approach through Surface Command is built around a continuous view of the attack surface across the digital estate, which helps teams understand where exposures sit and how they relate to internet-facing, business-critical, or otherwise high-impact systems.</span></p><p><span>That matters for AI adoption just as much as it matters for day-to-day security operations. Teams cannot apply AI strategically if they are guessing about which parts of the environment are lower priority, which assets belong to which owners, or where a newly disclosed flaw could create real business risk. A better view of the attack surface gives organizations the context they need to segment the problem properly. That makes it far easier to start with the right use cases, whether that is backlog reduction in lower-impact systems, targeted prioritization of exposed assets, or faster triage where the risk picture is already well understood.</span></p><p><span>Ownership is part of that foundation too. Remediation slows down when no one can quickly identify who owns the affected application, environment, or workflow. Security teams already lose time there today, and AI will only make that bottleneck more visible if it starts surfacing issues faster than organizations can assign them. Attack Surface Management helps turn that ambiguity into something more actionable by tying exposure to environment context and likely ownership.</span></p><h2>How Vulnerability and Exposure Management turns visibility into action</h2><p><span>Once the environment is understood, teams still need a way to move from findings to outcomes. That is where</span><a href="https://www.rapid7.com/solutions/vulnerability-management/" target="_blank"><span> Vulnerability and Exposure Management</span></a><span> becomes the operating layer that keeps the work grounded.</span></p><p><span>The biggest value here is not simply collecting more vulnerability data. It is targeted prioritization and validation. When a disclosure lands, teams need to know whether the issue affects an exposed asset, whether there is evidence of exploitation or attacker interest, whether the impacted system is business-critical, and whether existing controls already reduce some of the risk. That is the kind of context that helps organizations decide what deserves immediate attention and what can be handled through a normal remediation cycle.</span></p><p><span>This is where artificial intelligence can help move remediation forward faster. Instead of asking teams to manually connect exploit signals, asset criticality, and vulnerability intelligence on their own,</span><a href="https://www.rapid7.com/blog/post/pt-remediate-vulnerabilities-faster-with-ai-generated-risk-intelligence/" target="_blank"><span> AI can distill that context directly in the remediation workflow</span></a><span>. That makes it easier to understand why an issue matters, what the likely impact is, and what to do next, which shortens the gap between discovery and a confident decision on how to respond.</span></p><p><span>We expect most organizations to use AI to assist with, or in some cases take over, lower-tier triage, backlog cleanup, summary generation, and patch support in areas where the workflow is already established and the blast radius is more manageable. Human experts still stay closest to the most critical business logic, the most sensitive environments, and the most complex remediation paths. That is a practical adoption model, and it only works when the organization already has enough structure in place to know where those boundaries are.</span></p><h2>Curated vulnerability intelligence changes the quality of decisions</h2><p><span>That kind of deliberate adoption only works when teams can make better decisions, faster. Security teams need more than severity scores and a long list of CVEs. They need enough context to understand what matters, what can wait, and where action will reduce real risk fastest. As Rapid7 outlined in</span><a href="https://www.rapid7.com/blog/post/pt-the-power-of-curated-vulnerability-intelligence/" target="_blank"><span> The Power of Curated Vulnerability Intelligence</span></a><span>, the goal is to identify the vulnerabilities that actually matter and give teams enough context to act with confidence.</span></p><p><span>That intelligence provides a form of validation that most teams need badly as disclosure volume rises. It helps answer whether a finding is tied to active attacker interest, whether proof-of-concept activity is public, whether the asset is exposed, and whether delaying a patch creates unacceptable risk. It also supports the decisions that happen in the gap between discovery and full remediation. When a patch is delayed because of change controls, testing constraints, or lack of a vendor fix, teams still need to reduce exposure. Curated intelligence helps them decide whether to use segmentation, access restrictions, configuration changes, added monitoring, or virtual patching while the longer-term fix is being worked through.</span></p><p><span>That is one of the clearest ways Rapid7 helps customers move from data to outcomes. Intelligence is fused into the workflow so teams can prioritize with more precision and validate their actions against real threat context, not just generalized scores.</span></p><h2>How runtime and remediation fit into the broader AI story</h2><p><span>There is another part of this story that matters as organizations think more seriously about AI-driven security operations. As AI shapes the way teams handle exposures earlier in the lifecycle, context of application at runtime matters more too.</span></p><p><span>To make that foundation complete, organizations need to look beyond static posture and bring runtime validation into the picture. When teams can identify which vulnerabilities and misconfigurations are actively exploitable in production, and map sensitive data and identity access to real-world attack paths, they get a much clearer view of actual risk. Security teams need to understand what is vulnerable, how systems behave when live, and where unusual activity may suggest a problem is moving toward exploitation. With that runtime context in place, teams can spend less time chasing theoretical vulnerabilities and more time focusing on the exposures that are actively creating risk in live environments. </span></p><p><span>That connection between exposure, intelligence, remediation, and runtime behavior is where AI starts to become genuinely useful rather than simply impressive. It supports a more intentional model of security decision-making, one that narrows the gap between what is found, what matters, and what happens next.</span></p><h2>What security leaders should do now</h2><p><span>This is a good time for security leaders to step back and ask a more disciplined set of questions.</span></p><ul><li><p><span>Do we understand our environment well enough to direct AI toward the right problems? </span></p></li><li><p><span>Can we clearly separate higher-risk, higher-impact assets from the parts of the backlog that are mostly operational drag? </span></p></li><li><p><span>Is threat intelligence embedded in how we interpret findings, or are we still depending too heavily on raw severity? </span></p></li><li><p><span>Can we identify ownership fast enough for AI-assisted triage to result in meaningful action? </span></p></li><li><p><span>Are compensating controls part of the plan when remediation cannot happen immediately?</span></p></li></ul><p><span>Those questions shape the quality of everything that follows.</span></p><p><span>Glasswing creates a real opportunity for security teams that are ready to use AI with more intention. AI can move work forward faster, reduce manual drag, and absorb classes of issues that currently consume time without improving outcomes. The teams that benefit most will not be the ones that rush to apply new models everywhere. They will be the ones that understand their environment, have a clear view of their attack surface, have mature enough workflows to apply AI where it makes sense, and can measure whether the actions taken actually reduced exposure.</span></p><p><span>Rapid7’s approach to building resilience is grounded in those same needs. Attack Surface Management provides the environmental foundation, Vulnerability Management drives prioritization and action, curated vulnerability intelligence strengthens validation and decision-making, AI-generated remediation insights compress the time from discovery to the next step, and runtime security adds context where live behavior matters. Together, those pieces help customers build a security program that is ready for AI rather than constantly reacting to it.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PicoCTF Writeup — AutoRev 1]]></title>
<description><![CDATA[Write-up for the 2026 picoCTF challenge, AutoRev 1.About:Challenge InstanceIntroduction:In this challenge, we were given a remote service that repeatedly sends binary data and asks for a “secret” value hidden inside it. Instead of manually reversing each instance, we can automate the entire proce...]]></description>
<link>https://tsecurity.de/de/3445357/hacking/picoctf-writeup-autorev-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445357/hacking/picoctf-writeup-autorev-1/</guid>
<pubDate>Sun, 19 Apr 2026 05:19:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Write-up for the 2026 picoCTF challenge, AutoRev 1.</h4><p><strong>About:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*sQ2PkXSKTUnlKRGK7ixKPw.png"><figcaption>Challenge Instance</figcaption></figure><h4><strong>Introduction:</strong></h4><p>In this challenge, we were given a remote service that repeatedly sends binary data and asks for a “secret” value hidden inside it. Instead of manually reversing each instance, we can automate the entire process using Python and the pwntools library.</p><p>This writeup demonstrates how to solve the challenge by identifying a <strong>consistent byte pattern</strong> and extracting the secret directly from raw binary data. This can be done <strong>without using disassemblers</strong> such as Ghidra or Binary Ninja.</p><p>The challenge itself is one outside the box whereas many reverse engineering challenges rely on tools like disassemblers. It shows how sometimes <strong>pattern recognition alone is enough</strong>. If a binary repeatedly follows the same structure, we can exploit that structure instead of fully reversing it every time.</p><p>In many real-world scenarios, analysts often look for signatures or repeating structures rather than fully understanding every instruction.</p><h4><strong>Main Idea:</strong></h4><p>Each binary blob contains a recognizable <strong>x86 instruction pattern</strong>:</p><pre>c7 45 fc XX XX XX XX</pre><p>The four bytes <strong>immediately following the pattern</strong> represent the secret, which we can extract, convert, and send down the pipeline.</p><p>This byte pattern corresponds to an x86 instruction that moves a value into a local stack variable. It is important to know that the <strong>value being assigned is stored directly in those 4 bytes</strong>, making it easy to extract once we recognize the pattern.</p><p>The opcode c7 45 fc is commonly used in x86 assembly for instructions such as:</p><pre>mov DWORD PTR [ebp-0x4], &lt;value&gt;</pre><p>This means the program is assigning a constant value into a variable on the stack. That constant value is the secret and is what we want.</p><p>Let’s connect to the program and take a look at its response.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qOszGykecMVQc3XcoXfYzA.png"><figcaption>Binary Search</figcaption></figure><p>Over here, we see that the binary is given, 1547565313. When we enter it, it says that we were too slow.</p><p>As we know now, speed is the problem in this challenge, meaning <strong>manual solving will fail</strong> due to time constraints. Therefore we must create a python script which:</p><ul><li>connects to the program.</li><li>gets the binary (shown after the machine instruction).</li><li>responds to the program with the binary within the time limit.</li></ul><p>Following is the script Max Huddleston created to solve the challenge. For it to work, we must make sure pwntools is installed. If not, we can install it with the command $pip3 install pwntools.</p><pre>from pwn import *<br>import re<br><br>HOST = "mysterious-sea.picoctf.net"<br>PORT = [YOUR PORT]<br><br>r = remote(HOST, PORT)<br><br>for i in range(20):<br>    <br>    r.recvuntil(b"Here's the next binary in bytes:\n")<br>    hex_blob = r.recvline().strip()<br><br>    binary = bytes.fromhex(hex_blob.decode())<br><br>    sig = b"\xc7\x45\xfc"<br><br>    idx = binary.find(sig)<br>    if idx == -1:<br>        log.failure("Signature not found")<br>        exit()<br><br>    secret_bytes = binary[idx+3:idx+7]<br>    secret = u32(secret_bytes)<br><br>    log.success(f"Secret {i+1}: {secret}")<br><br>    r.recvuntil(b"What's the secret?")<br>    r.sendline(str(secret).encode())<br><br>print(r.recvall().decode())</pre><h4><strong>Line-by-line breakdown of the script:</strong></h4><pre>from pwn import *<br>import re</pre><ol><li><strong>Import Functions and Modules</strong></li></ol><p>The first line imports all functions from the pwntools library. The second line imports the module re, which stands for regular expressions (RegEx). It is useful for pattern identification and text manipulation.</p><pre>HOST = "mysterious-sea.picoctf.net"<br>PORT = [YOUR PORT]</pre><p>2. <strong>Assigning Variables </strong><strong>HOST and </strong><strong>PORT</strong></p><p>The third line defines the host/target server, mysterious-sea.picoctf.net. The fourth line assigns the port, which you will replace with your individual port given in the challenge instance.</p><pre>for i in range(20):<br>    <br>    r.recvuntil(b"Here's the next binary in bytes:\n")<br>    hex_blob = r.recvline().strip()</pre><p>3. <strong>Looping, Assigning Variables, and Calling Functions</strong></p><p>The line for i in range(20): creates a loop that repeats a block of code 20 times, as there are 20 questions in the challenge. It assigns each iteration an integer from 0 to 19.</p><p>The next two lines skip over the machine instructions until they reach "Here's the next binary in bytes". The program listens and captures all output until the next newline character \n.</p><p>hex_blob is a variable that stores the binary data. The function r.recvline() reads everything from its current position up to the next newline (\n) character. This newline character is removed using .strip(), which removes leading and trailing whitespace.</p><pre>binary = bytes.fromhex(hex_blob.decode())</pre><p>4. <strong>Hex Encoding and Assigning Variables.</strong></p><p>This line converts a hexadecimal-encoded string received as bytes into raw binary data. The variable binary stores this raw binary data.</p><pre>sig = b"\xc7\x45\xfc"<br><br>    idx = binary.find(sig)</pre><p>5. <strong>Creating a bytes literal</strong></p><p>The line sig = b"\xc7\x45\xfc" defines a bytes object with three raw hex values to search for. It represents the first three bytes of an x86 assembly instruction, commonly used to initialize local variables on the stack.</p><p>The next line searches for this exact byte sequence in the binary variable and stores the result in the variable idx.</p><pre>if idx == -1:<br>        log.failure("Signature not found")<br>        exit()</pre><p>6. <strong>“Not Found” Error Handling</strong></p><p>In Python, .find() returns -1 if the pattern is not found. Therefore, in the following lines, we display a failure message ("Signature not found") and exit.</p><pre>secret_bytes = binary[idx+3:idx+7]<br>    secret = u32(secret_bytes)</pre><p>7. <strong>Extracting a 4-byte Slice and Converting to a 32-bit Unsigned Integer</strong></p><p>The first line slices 4 bytes from the binary variable, starting at the offset idx. It captures bytes from idx+3 to idx+7 (not including idx+7).</p><p>The next line interprets these 4 bytes as a 32-bit unsigned integer.</p><p>For data storage, pwntools universally uses little-endian format, where the smallest byte is stored first in the memory. Misinterpreting little-endian format for big-endian or others would result in incorrect values.</p><p>This is the formula the computer uses to convert:</p><p><strong>Int = B₀+2⁸B₁+2¹⁶B₂+2²⁴B₃</strong></p><pre>log.success(f"Secret {i+1}: {secret}")</pre><p>8. <strong>Formatting and Matching</strong></p><p>This line formats the secret using an f-string (f"") and matches it to the correct question. i + 1 is used because the loop starts at 0, but the questions start from 1. Additionally, it helps track progress while the script is running.</p><p>Using log.success() from pwntools is helpful because it provides clean and readable output.</p><pre>r.recvuntil(b"What's the secret?")<br>    r.sendline(str(secret).encode())<br><br>print(r.recvall().decode())</pre><p>9. <strong>Encoding the Secret, Decoding Binary Data, and Printing Output</strong></p><p>The next few lines read input until they reach the string "What's the secret?".</p><p>They then encode the secret and send it to the program.</p><p>The final line receives the binary data and decodes it into a human-readable string, then prints it to the console.</p><h4><strong>Testing the Script:</strong></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wRSIVt-Qr-ofqYZOlkzDZA.png"><figcaption>Python File for Script in GNU nano (text editor)</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Y9RK_trL4ceQ-Vg90NNsgQ.png"><figcaption>Testing the Script with python3</figcaption></figure><p>Here, we have run the script and can see that all 20 secrets have been revealed, giving us the flag.</p><p><strong>Final Flag: picoCTF{4u7o_r3v_g0_brrr_78c345aa}</strong></p><h4><strong>Key Takeaways:</strong></h4><ul><li>pwntools library usage</li><li>Binary parsing without disassemblers (Ghidra, Binary Ninja, objdump, etc.), showing that patterns can sometimes be enough to solve a challenge.</li><li>Python Variables and Functions</li><li>x86 assembly (how compilers store local variables and recognize stack-based assignments)</li><li>Pattern matching in raw binary data (Regex, .find(), malware pattern detection)</li><li>Hex-Encoded Data</li><li>Unsigned Integers</li><li>Little-endian format (CPU architecture and the importance of memory layout) + formula</li><li>Writing Python scripts using GNU Nano</li><li>Automation speed (handling interactive remote services)</li></ul><h4><strong>Final Thoughts:</strong></h4><ul><li>The challenge does a good job of showing how automation and low-level knowledge can sometimes surpass modern reverse engineering processes.</li><li>Additionally, instead of relying solely on tools, training yourself to spot repeatable binary patterns (such as in this challenge) can speed up your CTF-solving process.</li></ul><p>Thank you for reading this writeup. If you have any questions, feel free to reach out to me at amanbarolia110@gmail.com.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=180a9f350d8f" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/picoctf-writeup-autorev-1-180a9f350d8f">PicoCTF Writeup — AutoRev 1</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How poor data foundations can undermine AI success]]></title>
<description><![CDATA[The promise of AI is immense, but poor-quality data undermines every attempt to derive any value from it. Without the right inputs, AI produces unreliable, incomplete, and even misleading outcomes.



For the average enterprise, data exists in many forms across many systems, says Brian Sathianath...]]></description>
<link>https://tsecurity.de/de/3441530/it-security-nachrichten/how-poor-data-foundations-can-undermine-ai-success/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441530/it-security-nachrichten/how-poor-data-foundations-can-undermine-ai-success/</guid>
<pubDate>Fri, 17 Apr 2026 12:07:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The promise of AI is immense, but <a href="https://www.cio.com/article/4145131/the-ai-data-dilemma-every-cio-must-address.html?utm=hybrid_search">poor-quality data</a> undermines every attempt to derive any value from it. Without the right inputs, AI produces unreliable, incomplete, and even misleading outcomes.</p>



<p>For the average enterprise, data exists in many forms across many systems, says Brian Sathianathan, CTO at Iterate.ai, and integrating structured and unstructured data is harder than most AI pilots account for. “Structured data from operational systems is rarely as tidy as teams are assuming, and unstructured data, like scanned documents and forms, requires a different preparation process before it can be matched and used effectively,” he says, adding this might explain why businesses hit a wall when trying to move beyond POC.</p>



<p>Organizations with impressive <a href="https://www.cio.com/article/4126383/how-the-growing-ai-workforce-is-changing-the-cio-role.html?utm=hybrid_search">POCs</a> typically succeed because they rely on curated datasets, manual workarounds, and tightly controlled environments, says Rhian Letts, head of group technology strategy at Investec. The real challenge lies in converting pilots into reliable, production-grade implementations. Scaling, she adds, requires resilient pipelines, consistent definitions, operational support, and integration into real workflows. It also raises the bar for governance.</p>



<p>“Many <a href="https://www.cio.com/article/4128980/the-struggle-for-good-ai-governance-is-real.html?utm=hybrid_search">data governance frameworks</a> were designed for human-paced consumption,” she says. “AI significantly increases both the speed and volume of data demand and introduces non-human consumers. Governance, therefore, needs to evolve to become more automated, real-time, and explicit about provenance and permissions.”</p>



<p>For Daniel Acton, CTO at technology firm ADG, too many organizations rush to do something with AI without properly analyzing what they actually want to do with it. “AI can be useful, but if you feed AI data that’s incomplete and inaccurate, or if it doesn’t have the data needed to teach the machine to do what you want it to do, the results will be underwhelming,” he says.</p>



<p>Another core issue is a lack of standardized, high-fidelity metadata. “The quality of metadata is the hardest challenge to overcome,” says Brett Pollak, executive director for workplace technology and infrastructure services at UC San Diego. “Metadata is the essential connective tissue that allows an AI agent to interpret a user’s prompt and map it correctly to the intersection of specific columns and rows. Most organizations have unique, institution-specific interpretations of data that are rarely documented properly or kept current.” This creates a translation gap where an agent might have access to the data but lacks the context to understand what a specific field represents in a business context.</p>



<h2 class="wp-block-heading">Data, data everywhere</h2>



<p>Just because obstacles exist, though, doesn’t mean progress needs to pause. “AI use should be aligned to current maturity,” says Letts. “Rather than treating imperfect data as a constraint, organizations can ask how AI might help improve and better connect the data they already have.” Sathianathan agrees, adding that within the new LLM world, even small amounts of accurate data can have significant value. “With traditional machine learning just a few years ago, you needed a lot of data to train models,” he says. “Today, since most LLMs come with highly pre-packaged knowledge, all you need is sufficient amounts of the right data to get it ready for your domain.”</p>



<p>For organizations that have already deployed structured data warehousing, the new barrier is the transition from human-centric storage to machine-actionable delivery, says Pollak. “Readiness now means ensuring your data is wrapped in specific metadata, exposed via modern protocols like MCP servers, and governed by a selective exposure strategy that ensures agents only act on what’s governed,” he says.</p>



<h2 class="wp-block-heading">Shift your mindset around data</h2>



<p>Today, many organizations want to quickly move from data disorder to being data-driven. But if that’s the end goal, CIOs and tech leaders need to be mindful of treating data like a first-class citizen within your organization. As part of this shift, data can no longer be seen as a by-product of business systems, but rather as a core output that should be managed with the same level of care as any other product or service. When this happens, business leaders can unlock insights and value they didn’t know existed.</p>



<p>Also, according to Letts, a use-case-led approach is critical. Trying to fix every dataset across an organization is neither practical nor necessary. Meaningful value can be unlocked even where data is imperfect by focusing on the right use cases. By prioritizing five to 10 high-value use cases and mapping the data required to deliver them in production, it’s easier to focus efforts. Foundations can then be strengthened to serve those priorities.</p>



<p>With AI, the threshold for what’s good enough has lowered for many use cases, particularly those focused on productivity and knowledge work, she adds. AI models can extract value from context and connect dots, even where data isn’t perfectly structured. But higher-stakes use cases demand higher quality and stronger controls. “The key is to be explicit about purpose, risk, and operational dependency,” she says. “Lower-risk use cases can move faster with well-described and well-governed context, while higher-risk applications require tighter thresholds.”</p>



<h2 class="wp-block-heading">Prioritize ownership, governance, and security</h2>



<p>All governance frameworks, policies, standards and procedures should be reviewed with AI in mind, adds Letts. Many were designed for human-paced consumption, whereas AI increases speed, scale, and integration across both structured and unstructured data. So validating ownership of critical data elements and establishing a shared business understanding of their meaning is essential to progress. Standardized definitions and metadata should also ensure questions like what it means and where did it come from can always be answered. “AI access must be secure by default,” she adds. “This means having least privilege, audit trails, handling of sensitive data, and strong controls around retrieval. It should always be demonstrable what a model can and cannot access.”</p>



<p>Additionally, organizations must be mindful of <a href="https://www.cio.com/article/4000132/8-steps-to-ensure-data-privacy-compliance-across-borders.html?utm=hybrid_search">data privacy</a> when using AI, too. “Agentic AI systems require a different level of data access than traditional enterprise apps,” says Sathianathan. “Data needs to be analyzed, not just queried, at scale. That’s a big change to privilege models, and IT and security leaders need to think carefully about where all that data is going and what access the AI system really requires.” The same is true, he adds, if the LLM processing that data is running within or outside an organization’s four walls, and such decisions should be considered before deployment, not after. </p>



<h2 class="wp-block-heading">Use AI to fill in the gaps</h2>



<p>In areas where the business might be falling short, consider using AI to draft and update your organization-specific data definitions, suggests Pollak. “Prioritize establishing a rigorous <a href="https://www.cio.com/article/4157466/cios-reimagine-business-processes-to-reap-ai-benefits.html?utm=hybrid_search">human-in-the-loop</a> process to ensure this connective tissue is accurate and current.” Additionally, it’s possible to use LLMs and smaller language models to clean up data in certain areas with restrictive prompts, adds Sathianathan. This way, you can process data efficiently and avoid wasting resources by pumping massive amounts of data into large cloud-based LLMs.</p>



<p>Being AI-ready isn’t a one-time milestone, says Letts. AI capabilities are evolving quickly, which means the threshold for readiness shifts over time. It’s essential to improve end-to-end lineage, build shared semantics and ontology so data is consistently understood, increase interoperability across platforms and domains, and tighten how AI systems access data so it remains secure, auditable, and fit for purpose. “Thresholds change as use cases evolve,” she says, “so data readiness must be treated as an ongoing discipline rather than a completed task.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build a Voice-Enabled Telegram Bot with the Gemini Interactions API]]></title>
<description><![CDATA[Author: Google for Developers - Bewertung: 23x - Views:185 Thor from Google DeepMind walks through how to build a Telegram bot that receives voice messages, reasons over them with Gemini 3.1 Flash, and responds with generated speech in a custom accent, all built with Antigravity and deployed to C...]]></description>
<link>https://tsecurity.de/de/3439504/videos/build-a-voice-enabled-telegram-bot-with-the-gemini-interactions-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439504/videos/build-a-voice-enabled-telegram-bot-with-the-gemini-interactions-api/</guid>
<pubDate>Thu, 16 Apr 2026 18:18:17 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Google for Developers - Bewertung: 23x - Views:185 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/J716eJOAnqE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Thor from Google DeepMind walks through how to build a Telegram bot that receives voice messages, reasons over them with Gemini 3.1 Flash, and responds with generated speech in a custom accent, all built with Antigravity and deployed to Cloud Run without writing the code manually.<br />
What's covered: Setting up a Telegram bot with BotFather, using Gemini Flash for reasoning and Gemini TTS for voice responses, handling OGG audio from Telegram and converting output with FFmpeg, building agent, transcription, and translation modes, deploying to Google Cloud Run with Docker and Secret Manager, and using the Gemini Interactions API coding skill to accelerate the build.<br />
<br />
Grab your Gemini API key at Google AI Studio and your bot token from BotFather on Telegram to get started. Full code and tutorial linked below.<br />
<br />
Resources:<br />
Find the tutorial → https://goo.gle/4cdOpJa <br />
Find the code → https://goo.gle/3Q8prCo <br />
<br />
What are you building with Gemini? Drop it in the comments.<br />
<br />
Chapters<br />
0:00 - Intro and Telegram voice bot demo<br />
1:17 - Technical Setup and Prerequisites<br />
1:48 - Deploying to Google Cloud Run<br />
2:27 - AI-Assisted Coding with Antigravity<br />
4:08 - Using Gemini 3.1 Flash Lite and TTS<br />
4:51 - Bot Modes: Agent, Transcription, and Translation<br />
6:32 - Voice Message Flow and Audio Conversion<br />
8:31 - GitHub Repo and Next Steps<br />
<br />
Subscribe to Google for Developers → https://goo.gle/developers<br />
<br />
Speaker: Thor Schaeff<br />
Products Mentioned:  Google AI, Gemini<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI traffic to US retailers rose 393% in Q1, and it’s boosting their revenue too]]></title>
<description><![CDATA[Adobe says AI traffic to U.S. retail sites also jumped 269% in March, with visitors converting better and generating more revenue than non-AI shoppers.]]></description>
<link>https://tsecurity.de/de/3439487/it-nachrichten/ai-traffic-to-us-retailers-rose-393-in-q1-and-its-boosting-their-revenue-too/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439487/it-nachrichten/ai-traffic-to-us-retailers-rose-393-in-q1-and-its-boosting-their-revenue-too/</guid>
<pubDate>Thu, 16 Apr 2026 18:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Adobe says AI traffic to U.S. retail sites also jumped 269% in March, with visitors converting better and generating more revenue than non-AI shoppers.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Mirax Android RAT Turns Infected Phones Into Residential Proxy Nodes]]></title>
<description><![CDATA[A newly discovered Android malware called Mirax has been quietly circulating in underground criminal forums since late 2025, posing a growing threat to mobile users across Europe and beyond. What sets it apart from typical banking trojans is its dual purpose: it steals banking credentials while s...]]></description>
<link>https://tsecurity.de/de/3432215/it-security-nachrichten/new-mirax-android-rat-turns-infected-phones-into-residential-proxy-nodes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3432215/it-security-nachrichten/new-mirax-android-rat-turns-infected-phones-into-residential-proxy-nodes/</guid>
<pubDate>Tue, 14 Apr 2026 15:51:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered Android malware called Mirax has been quietly circulating in underground criminal forums since late 2025, posing a growing threat to mobile users across Europe and beyond. What sets it apart from typical banking trojans is its dual purpose: it steals banking credentials while simultaneously converting infected phones into residential proxy nodes, giving […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-mirax-android-rat-turns-infected-phones/">New Mirax Android RAT Turns Infected Phones Into Residential Proxy Nodes</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI says Elon Musk is orchestrating a last-minute 'legal ambush' before trial]]></title>
<description><![CDATA[The feud between Elon Musk and OpenAI is getting even more contentious as the two sides get ready for trial later this month. The latest development in the legal back-and-forth saw OpenAI accuse Elon Musk and his latest proposals as a "legal ambush," as first reported by Bloomberg. OpenAI filed i...]]></description>
<link>https://tsecurity.de/de/3426710/it-nachrichten/openai-says-elon-musk-is-orchestrating-a-last-minute-legal-ambush-before-trial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3426710/it-nachrichten/openai-says-elon-musk-is-orchestrating-a-last-minute-legal-ambush-before-trial/</guid>
<pubDate>Sun, 12 Apr 2026 20:40:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The <a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:1;pos:1" class="no-affiliate-link" href="https://www.engadget.com/openai-says-elon-musks-lawsuit-allegations-are-incoherent-070056403.html">feud</a> between Elon Musk and OpenAI is getting even more contentious as the two sides get ready for trial later this month. The latest development in the legal back-and-forth saw OpenAI accuse Elon Musk and his latest proposals as a "legal ambush," as first reported by <a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:2;pos:1" class="no-affiliate-link" href="https://www.bloomberg.com/news/articles/2026-04-11/openai-accuses-musk-of-ambush-as-100-billion-plus-trial-looms"><em>Bloomberg</em></a>. OpenAI filed its response on Friday, which detailed that Musk was "sandbagging the defendants and injecting chaos into the proceedings, while trying to recast his public narrative about his lawsuit."</p>
<p>The <a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:3;pos:1" class="no-affiliate-link" href="https://www.engadget.com/elon-musk-drags-openai-into-federal-court-152709507.html">lawsuit</a> dates back to 2024 when Elon Musk sued both OpenAI and Microsoft, accusing the AI giant of ditching its original mission of being a non-profit and instead converting into a for-profit business after receiving financial backing and forming a partnership with Microsoft. Prior to OpenAI's latest filing, <a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:4;pos:1" class="no-affiliate-link" href="https://www.engadget.com/ai/elon-musk-wants-any-damages-from-his-openai-lawsuit-given-to-the-ai-companys-nonprofit-arm-223337225.html">Musk amended</a> his original complaint to instead award any damages received to OpenAI's nonprofit arm instead. Musk's amendment, which was filed earlier this month, also sought to oust Altman from his role as OpenAI's CEO and board member. In OpenAI's Friday filing, the AI company claimed that Musk's last-minute changes were "legally improper and factually unsupported."</p>
<span></span><p>There's a lot at stake with this lawsuit since Musk is reportedly seeking anywhere between $79 billion and $134 billion in "<a data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:5;pos:1" class="no-affiliate-link" href="https://www.engadget.com/big-tech/elon-musk-is-looking-for-a-134-billion-payout-from-openai-and-microsoft-171824945.html">wrongful gains</a>." With both OpenAI and Microsoft denying any wrongdoing, according to <em>Bloomberg</em>, the trial is still set to kick off on April 27.</p>This article originally appeared on Engadget at https://www.engadget.com/ai/openai-says-elon-musk-is-orchestrating-a-last-minute-legal-ambush-before-trial-163248345.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Rethinking Angular forms: A state-first perspective]]></title>
<description><![CDATA[Forms remain one of the most important interaction surfaces in modern web applications. Nearly every product relies on them to capture user input, validate data, and coordinate workflows between users and back-end systems. Yet despite their importance, forms are also one of the areas where front-...]]></description>
<link>https://tsecurity.de/de/3419896/ai-nachrichten/rethinking-angular-forms-a-state-first-perspective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3419896/ai-nachrichten/rethinking-angular-forms-a-state-first-perspective/</guid>
<pubDate>Thu, 09 Apr 2026 11:51:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Forms remain one of the most important interaction surfaces in modern web applications. Nearly every product relies on them to capture user input, validate data, and coordinate workflows between users and back-end systems. Yet despite their importance, forms are also one of the areas where front-end complexity tends to accumulate quietly over time.</p>



<p>For simple scenarios, Angular forms feel straightforward to work with. A handful of controls, a few validators, and a submission handler can be implemented quickly and confidently. But the situation changes as applications grow. Nested form groups, dynamic controls, conditional validation, and cross-field dependencies gradually introduce layers of behavior that are difficult to visualize as a single coherent system.</p>



<p>Developers often reach a point where a form technically works but becomes difficult to explain. Adding a new rule or modifying a validation condition can require tracing through observables, validators, and control states that are spread across multiple components. The challenge is rarely a missing feature. Instead, it is the growing difficulty of reasoning about how the system behaves as a whole.</p>



<p>This is not a criticism of Angular forms themselves. The framework has evolved powerful abstractions that solve real problems: keeping view and model synchronized, enforcing validation rules, coordinating asynchronous operations, and maintaining accessibility. These capabilities are essential for production-scale applications.</p>



<p>The more interesting question is architectural rather than technical. What mental model should developers use when reasoning about form behavior in modern Angular applications?</p>



<p>In this article, we step away from specific APIs and instead examine forms from first principles. By looking at forms primarily as state systems rather than event pipelines, we can better understand where complexity originates and why newer reactive primitives such as <a href="https://angular.dev/guide/signals">Angular Signals</a> align naturally with the underlying structure of form logic.</p>



<p>Over the past decade, Angular forms have been shaped primarily by event-driven abstractions and observable streams. As the framework evolves toward signal-based reactivity, it is worth reconsidering whether forms should continue to be modeled primarily around events at all.</p>



<p>Forms are not fundamentally event systems. They are state systems that happen to receive events. This distinction becomes clearer as front-end systems grow larger and validation logic becomes increasingly intertwined with application state.</p>



<p>Many front-end systems have gradually adopted an event-centric mental model, where application behavior is primarily expressed through chains of reactions and emissions. As discussed in my recent InfoWorld article, “<a href="https://www.infoworld.com/article/4145032/we-mistook-event-handling-for-architecture.html">We mistook event handling for architecture</a>”, this approach can blur the distinction between reacting to change and representing the underlying state of an application. Forms are one of the areas where that distinction becomes particularly visible.</p>



<h2 class="wp-block-heading">Why forms became complicated (and why that was reasonable)</h2>



<p>To understand why a signal-first approach matters, it is worth briefly revisiting how Angular forms evolved and why complexity was an unavoidable outcome.</p>



<p>Early Angular forms were primarily about synchronization. Input elements need to remain synchronized with the model, and updates must flow in both directions. Template-driven forms relied heavily on two-way binding to achieve this. For small forms, this approach felt intuitive and productive. However, as forms grew larger and more complex, the need for structure became apparent. Validation rules, cross-field dependencies, conditional UI logic, and testability all pushed developers toward a more explicit model.</p>



<p>Reactive forms addressed this need by modeling forms as trees of controls. Each control encapsulated its own value, validation state, and metadata. <a href="https://rxjs.dev/guide/overview">RxJS observables</a> provided a declarative way to respond to changes over time. Validators, both synchronous and asynchronous, could be attached to controls, and Angular automatically tracked interaction state, such as whether a control was dirty, touched, or pending.</p>



<p>This architecture solved many real problems. It also shifted the dominant mental model from state to events. That shift was reasonable at the time, but it also encouraged developers to think of form behavior primarily as a sequence of reactions rather than as a system defined by state. Developers began reasoning about forms in terms of streams: when a value emits, when a status changes, when a validator runs, and when subscriptions are triggered. In simple cases, this was manageable. In larger forms, it often became difficult to trace why a particular piece of logic executed or why a control entered a specific state.</p>



<p>The deeper issue is not that reactive forms rely on RxJS, but that they often conflate state with coordination. RxJS excels at coordinating asynchronous workflows and reacting to events. It is less well-suited to serve as a primary representation of the state. Forms, however, are overwhelmingly state-driven. At any given moment, a form has a well-defined set of values, validation rules, derived errors, and UI flags. Much of this information can be computed deterministically, without reference to time or event ordering.</p>



<p>As form logic grows, the cost of mixing state representation with event coordination increases. Debugging requires tracing emissions across multiple observables. Understanding behavior requires knowing not only what the state is but also how it arrived at that state. This is the context in which Angular Signals becomes interesting, not as a replacement for RxJS, but as a better fit for modeling form state itself.</p>



<h2 class="wp-block-heading">Defining form state from first principles</h2>



<p>Before introducing any APIs or framework constructs, it is useful to strip the problem down to its essentials and ask a basic question: what is form state?</p>



<p>At its core, a form exists to collect data. This data is typically represented as a plain object composed of strings, numbers, booleans, or nested structures. These values form the canonical source of truth for everything else the form does. Without values, there is no form.</p>



<p>Validation rules operate on those values. They define constraints such as whether a field is required, whether a value conforms to a particular format, or whether multiple fields satisfy a cross-field condition. Importantly, validation rules do not store state. Given the same input values, they always produce the same outcome. They are pure functions of state, not state themselves.</p>



<p>From values and validation rules, we derive validity and error information. A field is either valid or invalid, and specific error messages may apply. At the form level, validity is typically derived by aggregating field-level results. This information is deterministic and can be recalculated at any time from the underlying values.</p>



<p>Forms also track interaction metadata. Whether a field has been touched or modified influences when feedback is shown to the user, but it does not affect the correctness of the data. This metadata exists to improve user experience, not to define business logic.</p>



<p>Finally, there are side effects. Submitting data to a server, persisting drafts, performing asynchronous validation, or navigating to another view are all reactions to state changes. These actions matter, but they are not the state. They are consequences of the state.</p>



<p>Seen through this lens, most of what we consider “form complexity” is not inherent complexity. It is organizational complexity. Derived information is often stored as a mutable state. Validation logic is scattered across imperative callbacks. UI flags are toggled in response to events rather than derived from underlying conditions.</p>



<p>Signals encourage a different organization. They make it natural to treat values as the only mutable input, to express validity and UI state as derived data, and to isolate side effects as explicit reactions. This separation does not introduce new ideas, but it makes existing best practices easier to apply consistently.</p>



<p>Understanding this distinction is essential before adopting any signal-based form API. Without it, signals risk becoming just another abstraction layered on top of existing complexity. With it, they become a tool for simplifying how form behavior is expressed and understood.</p>



<h2 class="wp-block-heading">The cost of treating the state as events</h2>



<p>As reactive forms evolved, the complexity in form logic related to  event coordination soared. Value changes emitted events. Validation status emitted events. Asynchronous validators emitted events. Subscriptions responded to these emissions, producing additional side effects. This model is powerful, but it subtly shifts how developers reason about form behavior.</p>



<p>When form logic is expressed primarily through events, understanding behavior requires temporal reasoning. Developers must ask not only what the current state of the form is, but also how the form arrived at that state. Questions such as “Which emission triggered this validator?” or “Why did this error appear now?” become common. The answers often depend on subscription order, life-cycle timing, or intermediate states that no longer exist.</p>



<p>This event orientation creates an asymmetry in how form behavior can be inspected. Current state, values, errors, and validity can be logged or displayed. The sequence of events that produced that state cannot. Once an emission has passed, it leaves no trace beyond its effects. Debugging becomes an exercise in reconstruction rather than observation.</p>



<p>Over time, the focus on events leads to a common anti-pattern: derived information is promoted to a mutable state. Validation results are stored rather than computed. UI flags are toggled imperatively rather than derived from underlying conditions. These shortcuts reduce immediate friction but increase long-term complexity. The form begins to carry not only its current state but also the historical residue of its manipulation.</p>



<p>The problem becomes more pronounced as forms grow. Cross-field validation introduces dependencies that span multiple controls. Conditional logic ties UI behaviour to combinations of values and interaction states. At this scale, the cost of reasoning in terms of events compounds. Understanding behavior requires tracing emissions across multiple observables, each representing a partial view of the system.</p>



<p>This is not a failure of RxJS or reactive forms. RxJS excels at coordinating asynchronous workflows and reacting to external data streams. The issue arises when event-driven coordination is used as the primary representation of state. Forms, by their nature, are overwhelmingly state-driven. At any given moment, a form has a well-defined configuration of values, rules, and derived outcomes.</p>



<p>Recognizing this mismatch is an important step. It allows us to separate coordination concerns from state representation, and to ask whether some of the complexity we experience is inherent or simply a consequence of the mental model we apply.</p>



<h2 class="wp-block-heading">Gaining a state-first perspective</h2>



<p>Many of the challenges developers encounter when building complex forms are not the result of missing framework features. They arise from how form behavior is structured and reasoned about. When validation rules, UI state, and side effects are coordinated primarily through event flows, understanding the system often requires reconstructing the sequence of events that produced the current state.</p>



<p>A state-first perspective approaches the problem differently. Form values become the central source of truth. Validation rules operate deterministically on that state. Error messages, validity flags, and UI behavior emerge as derived information rather than independently managed pieces of mutable state.</p>



<p>This shift does not invalidate existing Angular Forms patterns, nor does it diminish the usefulness of RxJS where coordination of asynchronous workflows is required. Instead, it clarifies the distinction between two different concerns: representing the state and reacting to events.</p>



<p>Teams that model forms explicitly around state tend to build systems that are easier to inspect, easier to refactor, and easier to reason about as they grow. Angular’s evolving reactivity model opens the door to expressing these ideas more directly.</p>



<p>In the next article in this series, we will examine Angular Signals themselves—what they are, how they differ from observable-driven reactivity, and why their design aligns naturally with the way form state behaves in real applications. From there, the series will explore how signal-driven models can simplify validation, derived state, and large-scale form architecture.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Ripping CDs and converting audio with fre:ac]]></title>
<description><![CDATA[It has been a little while since LWN last surveyed tools for managing a digital
music collection. In the intervening decades, many Linux users have moved on to
music streaming services, found them wanting, and are looking to curate their own
collection once again. There are plenty of choices when...]]></description>
<link>https://tsecurity.de/de/3417945/linux-tipps/ripping-cds-and-converting-audio-with-freac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3417945/linux-tipps/ripping-cds-and-converting-audio-with-freac/</guid>
<pubDate>Wed, 08 Apr 2026 17:53:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It has been a little while since LWN last <a href="https://lwn.net/Articles/160704/">surveyed tools for managing a digital
music collection</a>. In the intervening decades, many Linux users have moved on to
music streaming services, found them wanting, and are looking to curate their own
collection once again. There are plenty of choices when it comes to
ripping, managing, and playing digital audio; so many, in fact, that it can be a
bit daunting. After years of tinkering, I've found a few tools that work well for
managing my digital library: the first I'd like to cover is the <a href="https://www.freac.org/">fre:ac</a> free audio encoder for ripping music from
CDs and converting between audio formats.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ComfyUI Servers Hijacked for Cryptomining, Proxy Botnet Ops]]></title>
<description><![CDATA[Hackers are aggressively hijacking Internet-exposed ComfyUI servers and converting them into high‑value cryptomining rigs and proxy botnet nodes, abusing weakly secured AI image-generation setups for long‑term monetization. More than 1,000 ComfyUI servers are currently reachable on the public Int...]]></description>
<link>https://tsecurity.de/de/3416171/it-security-nachrichten/comfyui-servers-hijacked-for-cryptomining-proxy-botnet-ops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3416171/it-security-nachrichten/comfyui-servers-hijacked-for-cryptomining-proxy-botnet-ops/</guid>
<pubDate>Wed, 08 Apr 2026 07:36:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers are aggressively hijacking Internet-exposed ComfyUI servers and converting them into high‑value cryptomining rigs and proxy botnet nodes, abusing weakly secured AI image-generation setups for long‑term monetization. More than 1,000 ComfyUI servers are currently reachable on the public Internet, even after filtering out honeypots, giving attackers a small but lucrative attack surface concentrated on GPU‑rich […]</p>
<p>The post <a href="https://gbhackers.com/comfyui-servers-hijacked/">ComfyUI Servers Hijacked for Cryptomining, Proxy Botnet Ops</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ComfyUI Servers Hijacked for Cryptomining, Proxy Botnet Ops]]></title>
<description><![CDATA[Hackers are aggressively hijacking Internet-exposed ComfyUI servers and converting them into high‑value cryptomining rigs and proxy botnet nodes, abusing weakly secured AI image-generation setups for long‑term monetization. More than 1,000 ComfyUI servers are currently reachable on the public Int...]]></description>
<link>https://tsecurity.de/de/3416167/it-security-nachrichten/comfyui-servers-hijacked-for-cryptomining-proxy-botnet-ops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3416167/it-security-nachrichten/comfyui-servers-hijacked-for-cryptomining-proxy-botnet-ops/</guid>
<pubDate>Wed, 08 Apr 2026 07:36:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers are aggressively hijacking Internet-exposed ComfyUI servers and converting them into high‑value cryptomining rigs and proxy botnet nodes, abusing weakly secured AI image-generation setups for long‑term monetization. More than 1,000 ComfyUI servers are currently reachable on the public Internet, even…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/comfyui-servers-hijacked-for-cryptomining-proxy-botnet-ops/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/comfyui-servers-hijacked-for-cryptomining-proxy-botnet-ops/">ComfyUI Servers Hijacked for Cryptomining, Proxy Botnet Ops</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LLM-referred traffic converts at 30-40% — and most enterprises aren't optimizing for it]]></title>
<description><![CDATA[For more than two decades, digital discovery has operated on a simple model: search, scan, click, decide. That worked when humans were the ones doing the web searching; but with the advent of AI agents, the primary consumer of information is no longer always human.This is giving rise to a new par...]]></description>
<link>https://tsecurity.de/de/3414997/it-nachrichten/llm-referred-traffic-converts-at-30-40-and-most-enterprises-arent-optimizing-for-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3414997/it-nachrichten/llm-referred-traffic-converts-at-30-40-and-most-enterprises-arent-optimizing-for-it/</guid>
<pubDate>Tue, 07 Apr 2026 19:46:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For more than two decades, digital discovery has operated on a simple model: search, scan, click, decide. </p><p>That worked when humans were the ones doing the web searching; but with the advent of AI agents, the primary consumer of information is no longer always human.</p><p>This is giving rise to a new paradigm: Answer engine optimization (AEO), also referred to as generative engine optimization (GEO). Because agents look at data much differently than humans do, success is no longer defined by rankings and clicks, but whether content is understood, selected, and cited by AI systems.</p><p>The SEO model that the web was built on simply isn’t going to cut it anymore, and enterprises need to prepare now.</p><h2>How LLMs interpret web content</h2><p>Traditional SEO is built around keywords, rankings, page-level optimization, and click-through rates. Users manually search across multiple sources and click around to get what they need. Simple, but sometimes frustrating and a definite time suck.</p><p>But AEO operates on a whole different level. Agents are increasingly taking over users’ workflows: Claude Code, OpenClaw, CrewAI, Microsoft Copilot, AutoGen, LangChain, Agent Bricks, Agentforce, Google Vertex, Perplexity’s web interface, and whatever else comes along.</p><p>These agents do not “browse” the web the way humans do. They analyze user intent based not just on phrasing, but persistent memory and context from past sessions (rather than simple autocomplete). They require materials that are concise, structured, and to the point. </p><p>What’s more, agents are moving beyond browsing to delegation, handling more downstream work. What started as “search, read, decide,” evolves to “agent retrieves, agent summarizes, human decides” (and, beyond that, “agent acts → human validates”). </p><p>“In practice, AEO begins where SEO stops,” said Dustin Engel, founder of consultancy company <a href="https://www.elegantdisruption.com/">Elegant Disruption</a>. “AEO is the next layer of discovery,” or “zero-click discovery.”</p><p>In this new world where agents synthesize answers, users may never even see an enterprise’s website, click-through rates decline, and attribution and citability (rather than pure visibility, or showing up at the top of a list of blue links) become critical. </p><p>“The new default is closer to a citation map: Where the model is pulling from, how often you show up, and how you are described,” Engel said. </p><p>Some, like Adam Yang of Q&amp;A platform <a href="https://www.quora.com/">Quora</a>, argue that AEO is already becoming the default over SEO.  </p><p>This is for “a certain class of queries,” Yang notes. Any question where the user wants a synthesized answer — "what's the best approach to X," "compare these two options," "what do I need to know about Y" — is increasingly resolved by an AI without a click. </p><p>Google's own AI Overviews are already accelerating this on the consumer side, many analysts note. “SEO isn't dead,” Yang said. “But the optimization target has shifted from ‘rank on page 1’ to ‘get cited in the answer.’”</p><h2>How devs are already using AI agents </h2><p>Are there scenarios where regular search/Googling is still the best option? </p><p>“Absolutely,” said analyst Wyatt Mayham of <a href="https://nwai.co/">Northwest AI Consulting</a>.  Notably, for personal tasks like finding nearby restaurants or local service providers. The interface is “just better” in those cases because it integrates maps, reviews, and photos. “That experience is hard to beat right now,” he said.</p><p>For work-related research, though, he says he’s “barely” using traditional search anymore, and it’s getting “closer to zero” every month. </p><p>“When I need to understand a company or a person professionally, agents do it faster and give me a more useful output than a page of blue links ever did,” he said. </p><p>His firm uses autonomous agents “heavily,” and built a Claude Skills function that powers its sales operation. Before a discovery call with a prospect, team members can trigger a skill that pulls the contact’s LinkedIn profile, scrapes their company website, grabs relevant info from sources like ZoomInfo, and crafts a clear picture of their revenue, team size, tech stack, and pain points. </p><p>“By the time I get on a call, I have a tailored research brief ready to go without spending 30 to 45 minutes manually Googling around,” Mayham said. </p><p>The big advantage is that these tools run in the background, he noted. You don’t have to sit clicking through browser tabs: You just tell the agent what you need, it does it, and you get a structured output that’s actually useful. </p><p>“It's collapsed what used to be a full hour of sales prep into a few minutes,” Mayham said. </p><p>Carlos Dutra, data science manager at fintech company <a href="https://www.trustly.com/">Trustly</a>, said Claude Code has “genuinely changed” his daily workflow. He uses it for most of his coding work, and what surprised him wasn't the speed, but the fact that he didn’t need to open and keep track of browser tabs. 

“Not because I'm lazy, but because the answers are better,” he said. He still uses Google for some tasks: Pricing pages, recent news, anything that needs to be current. 

“But for technical reasoning? Agents have mostly replaced search for me personally,” he said. 

Quora’s Yang has had a similar experience. He’s been using Claude Code daily for the past few months, primarily for content strategy, knowledge management, and competitive research. Workflows that used to take him half a day now take 30 minutes.

But what’s been most advantageous is that he can now run research and synthesis tasks in parallel that he previously had to do sequentially. Also helpful is that agents’ context retention across sessions is “meaningfully better” than web-based tools.

When he needs to understand a concept, map a competitive landscape, or synthesize industry trends, Claude or Perplexity are the go-to before opening a browser tab. “I've started treating agent search as my first stop, not Google. Traditional search is now where I verify, not where I discover.” 

The kinks are real, though. Mayham pointed out that LinkedIn, in particular, is “aggressive” about blocking automated access, and many other sites have (or are implementing) similar protections. Users will hit walls when agents can't get through, so a fallback plan is important for those relying on agents. 

“The reliability isn't 100% yet, and that's probably the biggest thing holding broader adoption back,” he said. 

Mayham’s advice for other devs: Stop chasing shiny objects. A new AI tool launches “practically every day,” and many (experienced devs included) are jumping from platform to platform without ever going deep with any of them.

“Pick a model, go deep, build real workflows on it,” he emphasized. “You'll get more value from mastery of one platform than surface-level experimentation across five.”</p><h2>How enterprises can compete in an AEO-driven world </h2><p>When AI agents do the searching, the rules change. The question is no longer whether your content ranks on the first page, it's whether the model selects you as the source when generating an answer.</p><p>Structure matters much more than it used to. Content should:</p><ul><li><p>Be organized around conversational intent, provide direct answers, and mirror real user questions and follow-ups;</p></li><li><p>Be authoritative and reflect strong expertise;</p></li><li><p>Be fresh (and, when necessary, regularly refreshed);</p></li><li><p>Have clear headers and established FAQ schema. </p></li></ul><p>Another must is maintaining a strong brand presence across the forums and platforms — Wikipedia, Reddit, LinkedIn, industry publications — that models are trained on. Enterprises might also consider investing in original data, like research.</p><p>In Mayham’s experience, when a business gets recommended by an LLM during a search-style query, the conversion rate is “dramatically higher” than traditional channels. For his company, LLM-referred traffic is converting at 30 to 40%, which “blows away what we see from SEO or paid social.”</p><p>“The intent signal is just different when someone is having a conversation with an AI and it recommends you by name.” </p><p>Discoverability inside LLMs will matter as much as Google rankings, “maybe more,” Mayham said. “It's a whole new surface for customer acquisition that most businesses aren't even thinking about yet.”</p><p>Trustly’s Dutra agreed that the “uncomfortable truth” is that most enterprise content is becoming “basically invisible” in agent-driven queries. “AEO is about whether your content survives being chunked, embedded, and semantically retrieved,” he said. </p><p>The companies getting ahead aren’t doing anything “exotic,” he noted. They have clean, declarative content that doesn’t require context to understand. Those still writing copy stuffed with keywords are going to fall behind because LLMs care about semantic clarity.</p><p>A quick test he gives clients: Ask an LLM a question your page is supposed to answer, without giving it the URL. “If it can't construct the answer from your content, you have a problem.” </p><p>Jeff Oxford of SEO agency <a href="https://visibilitylabs.ai/">Visibility Labs</a> offers valuable step-by-step advice: </p><ol><li><p>Engage in conversations on Reddit, which is one of the most-cited domains in AI search. Enterprises should establish a positive reputation on Reddit, and engage on any relevant threads where customers are asking for recommendations.</p></li><li><p>Build a strong YouTube presence. According to Ahrefs, which tracks internet behavior, YouTube mentions have the “strongest correlation” with AI visibility across ChatGPT, AI Mode, and AI Overviews. “This makes sense, since both Google and OpenAI have trained their models on YouTube transcripts,” Oxford said, “and YouTube is the most-cited domain in Google's AI products.” </p></li><li><p>Invest in digital PR and brand mentions; the latter is the second-highest correlated factor with AI visibility. “Brands need to improve their digital presence by being in as many places as possible,” Oxford said. </p></li><li><p>Create content aligned with AI citation patterns. Enterprises should audit the prompts and topics where AI search engines are surfacing competitors, then create authoritative content on those same topics.</p></li></ol><p>“The goal is to become a source that AI models consider worth citing,” he noted. </p><p>Still, there may be a lot of unnecessary hype around how drastically enterprises need to change, <!-- -->said Shashi Bellamkonda, principal research director at consultancy firm <a href="https://www.infotech.com/">Info-Tech Research Group</a>. 

Those following best practices of producing content that their audience actually needs, written by experts and showcasing expert opinion, are in a good position to be cited in AI-powered search.

He pointed out that Google developed an EEAT framework (experience, expertise, authority, and trust) to evaluate content quality and helpfulness and help algorithms identify reliable, high-quality information. 

To stand out, enterprises should use structured data and schema to signal the context: Is this an article, a research study, a product overview? “Original long-form content will be valued by AI-powered answer engines,” Bellamkonda said. “Copycat strategies or trying to game the system are taboo in this era.”

Experts should also share their thoughts across several channels, and "About Us" pages must be “robust” and include bios highlighting thought leaders’ expertise.</p><p>“Ultimately, the reputation of AI-powered search is in making sure the user likes the search rather than what you think they should read,” Bellamkonda said. “So a good focus on the end user is a great way to succeed.”</p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choosing Ten Image Animation Platforms With Less Guesswork]]></title>
<description><![CDATA[In this post, we will be choosing ten image animation platforms with less guesswork. A still image often carries more creative value than people admit. It holds framing, subject hierarchy, lighting, and emotional direction before any motion is added. The real challenge is not always inventing a v...]]></description>
<link>https://tsecurity.de/de/3411230/it-security-nachrichten/choosing-ten-image-animation-platforms-with-less-guesswork/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411230/it-security-nachrichten/choosing-ten-image-animation-platforms-with-less-guesswork/</guid>
<pubDate>Mon, 06 Apr 2026 15:38:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, we will be choosing ten image animation platforms with less guesswork. A still image often carries more creative value than people admit. It holds framing, subject hierarchy, lighting, and emotional direction before any motion is added. The real challenge is not always inventing a video from nothing. It is converting a finished […]</p>
<p>The post <a href="https://secureblitz.com/image-animation-platforms/">Choosing Ten Image Animation Platforms With Less Guesswork</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OCSF explained: The shared data language security teams have been missing]]></title>
<description><![CDATA[The security industry has spent the last year talking about models, copilots, and agents, but a quieter shift is happening one layer below all of that: Vendors are lining up around a shared way to describe security data. The Open Cybersecurity Schema Framework (OCSF), is emerging as one of the st...]]></description>
<link>https://tsecurity.de/de/3408148/it-nachrichten/ocsf-explained-the-shared-data-language-security-teams-have-been-missing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3408148/it-nachrichten/ocsf-explained-the-shared-data-language-security-teams-have-been-missing/</guid>
<pubDate>Sat, 04 Apr 2026 22:01:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The security industry has spent the last year talking about models, copilots, and agents, but a quieter shift is happening one layer below all of that: Vendors are lining up around a shared way to describe security data. The Open Cybersecurity Schema Framework<i> (</i>OCSF), is emerging as one of the strongest candidates for that job.</p><p>It gives vendors, enterprises, and practitioners a common way to represent <a href="https://venturebeat.com/security/claude-code-512000-line-source-leak-attack-paths-audit-security-leaders?_gl=1*1bnj2g2*_up*MQ..*_ga*MjA4NDYxMTU5MS4xNzc1MjYyMDM1*_ga_SCH1J7LNKY*czE3NzUyNjIwMzMkbzEkZzAkdDE3NzUyNjIwMzMkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3NzUyNjIwMzQkbzEkZzAkdDE3NzUyNjIwMzQkajYwJGwwJGgw">security events</a>, findings, objects, and context. That means less time rewriting field names and custom parsers and more time correlating detections, running analytics, and building workflows that can work across products. In a market where every security team is stitching together endpoint, identity, cloud, SaaS, and AI telemetry, a common infrastructure long felt like a pipe dream, and OCSF now puts it within reach.</p><h2>OCSF in plain language</h2><p>OCSF is an open-source framework for cybersecurity schemas. It’s vendor neutral by design and deliberately agnostic to storage format, data collection, and ETL choices. In practical terms, it gives application teams and data engineers a shared structure for events so analysts can work with a more consistent language for threat detection and investigation.</p><p>That sounds dry until you look at the daily work inside a <a href="https://venturebeat.com/security/axios-npm-supply-chain-attack-rat-maintainer-token-2026?_gl=1*18t0sen*_up*MQ..*_ga*MjA4NDYxMTU5MS4xNzc1MjYyMDM1*_ga_SCH1J7LNKY*czE3NzUyNjIwMzMkbzEkZzAkdDE3NzUyNjIwMzMkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3NzUyNjIwMzQkbzEkZzAkdDE3NzUyNjIwMzQkajYwJGwwJGgw">security operations center</a> (SOC). Security teams have to spend a lot of effort normalizing data from different tools so that they can correlate events. For example, detecting an employee logging in from San Francisco at 10 a.m. on their laptop, then accessing a cloud resource from New York at 10:02 a.m. could reveal a leaked credential. </p><p>Setting up a system that can correlate those events, however, is no easy task: Different tools describe the same idea with different fields, nesting structures, and assumptions. OCSF was built to lower this tax. It helps vendors map their own schemas into a common model and helps customers move data through lakes, pipelines, security incident and event management (SIEM) tools without requiring time consuming translation at every hop.</p><h2>The last two years have been unusually fast</h2><p>Most of OCSF’s visible acceleration has happened in the last two years. The project was <a href="https://venturebeat.com/security/black-hat-2022-reveals-enterprise-security-trends">announced in August 2022</a> by Amazon AWS and Splunk, building on worked contributed by Symantec, Broadcom, and other well known infrastructure giants Cloudflare, CrowdStrike, IBM, Okta, Palo Alto Networks, Rapid7, Salesforce, Securonix, Sumo Logic, Tanium, Trend Micro, and Zscaler.</p><p><i>The OCSF community has kept up a steady cadence of releases over the last two years</i></p><p>The community has grown quickly. AWS said in August 2024 that OCSF had expanded from a 17-company initiative into a community with more than 200 participating organizations and 800 contributors, which expanded to 900 wen OCSF joined the Linux Foundation in November 2024. </p><h2>OCSF is showing up across the industry</h2><p>In the observability and security space, OCSF is everywhere. AWS Security Lake converts natively supported AWS logs and events into OCSF and stores them in Parquet. AWS AppFabric can output OCSF — normalized audit data. AWS Security Hub findings use OCSF, and AWS publishes an extension for cloud-specific resource details. </p><p>Splunk can translate incoming data into OCSF with edge processor and ingest processor. Cribl supports seamless converting streaming data into OCSF and compatible formats.</p><p>Palo Alto Networks can forward Strata sogging Service data into Amazon Security Lake in OCSF. CrowdStrike positions itself on both sides of the OCSF pipe, with Falcon data translated into OCSF for Security Lake and Falcon Next-Gen SIEM positioned to ingest and parse OCSF-formatted data. OCSF is one of those rare standards that has crossed the chasm from an abstract standard into standard operational plumbing across the industry.</p><h2>AI is giving the OCSF story fresh urgency</h2><p>When enterprises deploy AI infrastructure, large language models (LLMs) sit at the core, surrounded by complex distributed systems such as model gateways, agent runtimes, vector stores, tool calls, retrieval systems, and policy engines. These components generate new forms of telemetry, much of which spans product boundaries. Security teams across the SOC are increasingly focused on capturing and analyzing this data. The central question often becomes what an agentic AI system actually did, rather than only the text it produced, and whether its actions led to any security breaches.</p><p>That puts more pressure on the underlying data model. An AI assistant that calls the wrong tool, retrieves the wrong data, or chains together a risky sequence of actions creates a security event that needs to be understood across systems. A shared security schema becomes more valuable in that world, especially when AI is also being used on the analytics side to correlate more data, faster.</p><h2>For OCSF, 2025 was all about AI</h2><p>Imagine a company uses an AI assistant to help employees look up internal documents and trigger tools like ticketing systems or code repositories. One day, the assistant starts pulling the wrong files, calling tools it should not use, and exposing sensitive information in its responses. </p><p>Updates in OCSF versions 1.5.0, 1.6.0, and 1.7.0 help security teams piece together what happened by flagging unusual behavior, showing who had access to the connected systems, and tracing the assistant’s tool calls step by step. Instead of only seeing the final answer the AI gave, the team can investigate the full chain of actions that led to the problem.</p><h2>What's on the horizon</h2><p>Imagine a company uses an AI customer support bot, and one day the bot begins giving long, detailed answers that include internal troubleshooting guidance meant only for staff. With the kinds of changes being developed for OCSF 1.8.0, the security team could see which model handled the exchange, which provider supplied it, what role each message played, and how the token counts changed across the conversation. </p><p>A sudden spike in prompt or completion tokens could signal that the bot was fed an unusually large hidden prompt, pulled in too much background data from a vector database, or generated an overly long response that increased the chance of sensitive information leaking. That gives investigators a practical clue about where the interaction went off course, instead of leaving them with only the final answer.</p><h2>Why this matters to the broader market</h2><p>The bigger story is that OCSF has moved quickly from being a community effort to becoming a real standard that security products use every day. Over the past two years, it has gained stronger governance, frequent releases, and practical support across data lakes, ingest pipelines, SIEM workflows, and partner ecosystems. </p><p>In a world where AI expands the security landscape through scams, abuse, and new attack paths, security teams rely on OCSF to connect data from many systems without losing context along the way to keep your data safe. </p><p><i>Nikhil Mungel has been building distributed systems and AI teams at SaaS companies for more than 15 years.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[North Korea-Related Campaign Abuses GitHub as C2 in New LNK Phishing Attacks]]></title>
<description><![CDATA[A newly identified campaign linked to North Korean state-sponsored threat actors is using Windows shortcut files, known as LNK files, to launch targeted phishing attacks against organizations in South Korea. What makes this campaign alarming is how attackers conceal their operations inside GitHub...]]></description>
<link>https://tsecurity.de/de/3404633/it-security-nachrichten/north-korea-related-campaign-abuses-github-as-c2-in-new-lnk-phishing-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404633/it-security-nachrichten/north-korea-related-campaign-abuses-github-as-c2-in-new-lnk-phishing-attacks/</guid>
<pubDate>Fri, 03 Apr 2026 08:05:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly identified campaign linked to North Korean state-sponsored threat actors is using Windows shortcut files, known as LNK files, to launch targeted phishing attacks against organizations in South Korea. What makes this campaign alarming is how attackers conceal their operations inside GitHub, one of the most trusted platforms on the internet, converting it into […]</p>
<p>The post <a href="https://cybersecuritynews.com/north-korea-related-campaign-abuses-github/">North Korea-Related Campaign Abuses GitHub as C2 in New LNK Phishing Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft launches 3 new AI models in direct shot at OpenAI and Google]]></title>
<description><![CDATA[Microsoft on Wednesday launched three new foundational AI models it built entirely in-house — a state-of-the-art speech transcription system, a voice generation engine, and an upgraded image creator — marking the most concrete evidence yet that the $3 trillion software giant intends to compete di...]]></description>
<link>https://tsecurity.de/de/3402527/it-nachrichten/microsoft-launches-3-new-ai-models-in-direct-shot-at-openai-and-google/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3402527/it-nachrichten/microsoft-launches-3-new-ai-models-in-direct-shot-at-openai-and-google/</guid>
<pubDate>Thu, 02 Apr 2026 14:03:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.microsoft.com/en-us">Microsoft</a> on Wednesday launched <a href="https://microsoft.ai/news/today-were-announcing-3-new-world-class-mai-models-available-in-foundry/">three new foundational AI models</a> it built entirely in-house — a state-of-the-art speech transcription system, a voice generation engine, and an upgraded image creator — marking the most concrete evidence yet that the $3 trillion software giant intends to compete directly with <a href="https://openai.com/">OpenAI</a>, <a href="https://www.google.com/">Google</a>, and other frontier labs on model development, not just distribution.</p><p>The trio of models — <a href="https://microsoft.ai/news/state-of-the-art-speech-recognition-with-mai-transcribe-1/">MAI-Transcribe-1</a>, <a href="https://microsoft.ai/news/today-were-announcing-3-new-world-class-mai-models-available-in-foundry/">MAI-Voice-1</a>, and <a href="https://msi-playground.microsoft.com/chat">MAI-Image-2</a> — are available immediately through <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a> and a new <a href="https://msi-playground.microsoft.com/chat">MAI Playground</a>. They span three of the most commercially valuable modalities in enterprise AI: converting speech to text, generating realistic human voice, and creating images. Together, they represent the opening salvo from Microsoft's <a href="https://microsoft.ai/">superintelligence team</a>, which Suleyman formed just six months ago to pursue what he calls "<a href="https://www.mitsloanme.com/article/microsoft-moves-toward-ai-self-sufficiency-amid-evolving-openai-ties/">AI self-sufficiency</a>."</p><p>"I'm very excited that we've now got the first models out, which are the very best in the world for transcription," Suleyman told VentureBeat in an exclusive interview ahead of the launch. "Not only that, we're able to deliver the model with half the GPUs of the state-of-the-art competition."</p><p>The announcement lands at a precarious moment for Microsoft. The company's stock just closed its <a href="https://www.cnbc.com/2026/03/31/microsofts-stock-closes-worst-quarter-since-2008-financial-crisis.html">worst quarter since the 2008 financial crisis</a>, as investors increasingly demand proof that hundreds of billions of dollars in AI infrastructure spending will translate into revenue. These models — priced aggressively and positioned to reduce Microsoft's own cost of goods sold — are Suleyman's first answer to that pressure.</p><h2><b>Microsoft's new transcription model claims best-in-class accuracy across 25 languages</b></h2><p><a href="https://microsoft.ai/news/state-of-the-art-speech-recognition-with-mai-transcribe-1/">MAI-Transcribe-1</a> is the headline release. The speech-to-text model achieves the lowest average Word Error Rate on the <a href="https://arxiv.org/abs/2205.12446">FLEURS benchmark</a> — the industry-standard multilingual test — across the top 25 languages by Microsoft product usage, averaging 3.8% WER. According to Microsoft's benchmarks, it beats OpenAI's <a href="https://huggingface.co/openai/whisper-large-v3">Whisper-large-v3</a> on all 25 languages, Google's <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-flash-lite/">Gemini 3.1 Flash</a> on 22 of 25, and ElevenLabs' <a href="https://elevenlabs.io/blog/introducing-scribe-v2">Scribe v2</a> and OpenAI's <a href="https://developers.openai.com/api/docs/models/gpt-4o-transcribe">GPT-Transcribe</a> on 15 of 25 each.</p><p>The model uses a transformer-based text decoder with a bi-directional audio encoder. It accepts MP3, WAV, and FLAC files up to 200MB, and Microsoft says its batch transcription speed is 2.5 times faster than the existing Microsoft Azure Fast offering. Diarization, contextual biasing, and streaming are listed as "coming soon." Microsoft is already testing <a href="https://microsoft.ai/news/state-of-the-art-speech-recognition-with-mai-transcribe-1/">MAI-Transcribe-1</a> inside <a href="https://www.microsoft.com/en-us/microsoft-copilot/for-individuals/do-more-with-ai/general-ai/what-is-copilot-voice?form=MA13PW">Copilot's Voice mode</a> and <a href="https://www.microsoft.com/en-us/microsoft-teams/group-chat-software">Microsoft Teams</a> for conversation transcription — a detail that underscores how quickly the company intends to replace third-party or older internal models with its own.</p><p>Alongside it, <a href="https://microsoft.ai/news/today-were-announcing-3-new-world-class-mai-models-available-in-foundry/">MAI-Voice-1</a> is Microsoft's text-to-speech model, capable of generating 60 seconds of natural-sounding audio in a single second. The model preserves speaker identity across long-form content and now supports custom voice creation from just a few seconds of audio through Microsoft Foundry. Microsoft is pricing it at $22 per 1 million characters. <a href="https://msi-playground.microsoft.com/chat">MAI-Image-2</a>, meanwhile, debuted as a top-three model family on the <a href="http://arena.ai/">Arena.ai leaderboard</a> and now delivers at least 2x faster generation times on Foundry and Copilot compared to its predecessor. Microsoft is rolling it out across <a href="https://www.bing.com/">Bing</a> and <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a>, pricing it at $5 per 1 million tokens for text input and $33 per 1 million tokens for image output. <a href="https://www.wpp.com/en-us">WPP</a>, one of the world's largest advertising holding companies, is among the first enterprise partners building with MAI-Image-2 at scale.</p><h2><b>The contract renegotiation with OpenAI that made Microsoft's model ambitions possible</b></h2><p>To understand why these models matter, you have to understand the contractual tectonic shift that made them possible. Until October 2025, Microsoft was <a href="https://www.wired.com/story/openai-five-levels-agi-paper-microsoft-negotiations/">contractually prohibited</a> from independently pursuing artificial general intelligence. The original deal with OpenAI, signed in 2019, gave <a href="https://news.microsoft.com/source/2019/07/22/openai-forms-exclusive-computing-partnership-with-microsoft-to-build-new-azure-ai-supercomputing-technologies/">Microsoft a license to OpenAI's models</a> in exchange for building the cloud infrastructure OpenAI needed. But when OpenAI sought to expand its compute footprint beyond Microsoft — striking deals with SoftBank and others — Microsoft renegotiated. As Suleyman explained in a December 2025 interview with <a href="https://www.bloomberg.com/features/2025-mustafa-suleyman-weekend-interview/">Bloomberg</a>, the revised agreement meant that "up until a few weeks ago, Microsoft was not allowed — by contract — to pursue artificial general intelligence or superintelligence independently." The new terms freed Microsoft to build its own frontier models while retaining license rights to everything OpenAI builds through 2032.</p><p>Suleyman described the dynamic to VentureBeat in characteristically blunt terms. "Back in September of last year, we renegotiated the contract with OpenAI, and that enabled us to independently pursue our own superintelligence," he said. "Since then, we've been convening the compute and the team and buying up the data that we need."</p><p>He was quick to emphasize that the <a href="https://blogs.microsoft.com/blog/2025/10/28/the-next-chapter-of-the-microsoft-openai-partnership/">OpenAI partnership remains intact</a>. "Nothing's changing with the OpenAI partnership. We will be in partnership with them at least until 2032 and hopefully a lot longer," Suleyman said. "They have been a phenomenal partner to us." He also highlighted that Microsoft provides access to Anthropic's <a href="https://claude.ai/">Claude</a> through its <a href="https://learn.microsoft.com/en-us/rest/api/aifoundry/">Foundry API</a>, framing the company as "a platform of platforms." But the subtext is unmistakable: Microsoft is building the capability to stand on its own. In March, as <a href="https://www.businessinsider.com/microsoft-combines-copilot-teams-and-mustafa-suleyman-superintelligence-memos-2026-3">Business Insider first reported</a>, Suleyman wrote in an internal memo that his goal is to "focus all my energy on our Superintelligence efforts and be able to deliver world class models for Microsoft over the next 5 years." <a href="https://www.cnbc.com/2026/03/17/microsoft-copilot-ai-suleyman.html">CNBC reported</a> that the structural shift freed Suleyman from day-to-day Copilot product responsibilities, with former Snap executive Jacob Andreou taking over as EVP of the combined consumer and commercial Copilot experience.</p><h2><b>How teams of fewer than 10 engineers built models that rival Big Tech's best</b></h2><p>Perhaps the most striking detail Suleyman shared with VentureBeat is how small the teams behind these models actually are. "The audio model was built by 10 people, and the vast majority of the speed, efficiency and accuracy gains come from the model architecture and the data that we have used," Suleyman said. "My philosophy has always been that we need fewer people who are more empowered. So we operate an extremely flat structure." He added: "Our image team, equally, is less than 10 people. So this is all about model and data innovation, which has delivered state of the art performance."</p><p>This matters for two reasons. First, it challenges the prevailing industry narrative that frontier AI development requires thousands of researchers and billions in headcount costs. <a href="https://www.meta.com/">Meta</a>, by contrast, has pursued what Suleyman described in his Bloomberg interview as a strategy of "<a href="https://www.bloomberg.com/features/2025-mustafa-suleyman-weekend-interview/">hiring a lot of individuals, rather than maybe creating a team</a>" — including reported compensation packages of $100 million to $200 million for top researchers. Second, small teams producing state-of-the-art results dramatically improve the economics. If Microsoft can build best-in-class transcription with 10 engineers and half the GPUs of competitors, the margin structure of its AI business looks fundamentally different from companies burning through cash to achieve similar benchmarks.</p><p>The lean-team philosophy also echoes Suleyman's broader views on how AI is already reshaping the work of building AI itself. When asked by VentureBeat how his own team works, Suleyman described an environment that resembles a startup trading floor more than a traditional Microsoft engineering org. "There are groups of people around round tables, circular tables, not traditional desks, on laptops instead of big screens," he said. "They're basically vibe coding, side by side all day, morning till night, in rooms of 50 or 60 people."</p><h2><b>Why Suleyman's "humanist AI" pitch is aimed squarely at enterprise buyers</b></h2><p>Suleyman has been steadily building a philosophical brand around Microsoft's AI efforts that he calls "<a href="https://microsoft.ai/">humanist AI</a>" — a term that appeared prominently in the blog post he authored for the launch and that he elaborated on in our interview. "I think that the motivation of a humanist super intelligence is to create something that is truly in service of humanity," he told VentureBeat. "Humans will remain in control at the top of the food chain, and they will be always aligned to human interests."</p><p>The framing serves multiple purposes. It differentiates Microsoft from the more acceleration-oriented rhetoric coming from <a href="https://openai.com/">OpenAI</a> and <a href="https://www.meta.ai/">Meta</a>. It resonates with enterprise buyers who need governance, compliance, and safety assurances before deploying AI in regulated industries. And it provides a narrative hedge: if something goes wrong in the broader AI ecosystem, Microsoft can point to its stated commitment to human control. In his December Bloomberg interview, Suleyman went further, describing containment and alignment as "<a href="https://www.bloomberg.com/features/2025-mustafa-suleyman-weekend-interview/">red lines</a>" and arguing that no one should release a superintelligence tool until they are "confident it can be controlled."</p><p>Suleyman also stressed data provenance as a competitive advantage, describing a conversation with CEO Satya Nadella about developing "a clean lineage of models where the data is extremely clean." He drew an implicit contrast with open-source alternatives, noting that "many of the open-source models have been trained on data in, let's say, inappropriate ways. And there are potentially security issues with that." For enterprise customers evaluating AI vendors amid a thicket of copyright lawsuits across the industry, that is a meaningful commercial argument — if Microsoft can credibly claim that its training data was acquired through properly licensed channels, it reduces the legal and reputational risk of deploying these models in production.</p><h2><b>Microsoft's aggressive pricing puts pressure on Amazon, Google, and the AI startup ecosystem</b></h2><p>Today’s launch positions Microsoft on three competitive fronts simultaneously. <a href="https://microsoft.ai/news/state-of-the-art-speech-recognition-with-mai-transcribe-1/">MAI-Transcribe-1 </a>directly targets the transcription workloads that OpenAI's <a href="https://openai.com/index/whisper/">Whisper models</a> have dominated in the open-source community, with Microsoft claiming superior accuracy on all 25 benchmarked languages. The FLEURS results also show it winning against Google's Gemini 3.1 Flash Lite on 22 of 25 languages — a direct challenge as Google aggressively pushes Gemini across its own product suite. And <a href="https://microsoft.ai/news/today-were-announcing-3-new-world-class-mai-models-available-in-foundry/">MAI-Voice-1</a>'s ability to clone voices from seconds of audio and generate speech at 60x real-time puts it in competition with <a href="https://elevenlabs.io/">ElevenLabs</a>, <a href="https://www.resemble.ai/">Resemble AI</a>, and the growing ecosystem of voice AI startups, with Microsoft's distribution advantage — any Foundry developer can now access these capabilities through the same API they use for GPT-4 and Claude — acting as a powerful moat.</p><p>Suleyman framed the competitive position confidently: "We're now a top three lab just under OpenAI and Gemini," he told VentureBeat. The pricing strategy — <a href="https://microsoft.ai/news/today-were-announcing-3-new-world-class-mai-models-available-in-foundry/">MAI-Voice-1</a> at $22 per million characters, <a href="https://msi-playground.microsoft.com/chat">MAI-Image-2</a> at $5 per million input tokens — reflects a deliberate decision to compete on cost. "We're pricing them to be the very best of any hyperscaler. So there will be the cheapest of any of the hyperscalers out there, Amazon. And obviously Google," Suleyman said. "And that's a very conscious decision."</p><p>This makes strategic sense for Microsoft, which can amortize model development costs across its enormous installed base of enterprise customers. But it also speaks to the question investors have been asking with increasing urgency: when does AI spending start generating returns? <a href="https://www.cnbc.com/2026/03/31/microsofts-stock-closes-worst-quarter-since-2008-financial-crisis.html">Microsoft's stock has fallen roughly 17% year-to-date</a>, according to CNBC, part of a broader selloff in software stocks. By building models that run on half the GPUs of competitors, Microsoft reduces its own infrastructure costs for internal products — <a href="http://teams.microsoft.com/v2/">Teams</a>, <a href="https://copilot.microsoft.com/">Copilot</a>, <a href="https://www.bing.com/">Bing</a>, <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a> — while offering developers pricing designed to undercut the rest of the market. In his March memo, <a href="https://blogs.microsoft.com/blog/2026/03/17/announcing-copilot-leadership-update/">Suleyman wrote</a> that his models would "enable us to deliver the COGS efficiencies necessary to be able to serve AI workloads at the immense scale required in the coming years." These three models are the first tangible delivery on that promise.</p><h2><b>Suleyman says a frontier large language model is coming — and Microsoft plans to be "completely independent"</b></h2><p>Suleyman made clear that transcription, voice, and image generation are just the beginning. When asked whether Microsoft would build a large language model to compete directly with GPT at the frontier level, he was unequivocal. "We absolutely are going to be delivering state of the art models across all modalities," he said. "Our mission is to make sure that if Microsoft ever needs it, we will be able to provide state of the art at the best efficiency, the cheapest price, and be completely independent."</p><p>He described a multi-year roadmap to "set up the GPU clusters at the appropriate scale," noting that the superintelligence team was formally stood up only in October 2025. Suleyman spoke to VentureBeat from Miami, where the full team was convening for one of its regular week-long in-person sessions. He described Nadella flying in for the gathering to lay out "the roadmap of everything that we need to achieve for our AI self-sufficiency mission over the next 2, 3, 4 years, and all the compute roadmap that that would involve."</p><p>Building a competitive frontier LLM, of course, is a different order of magnitude in complexity, data requirements, and compute cost from what Microsoft demonstrated Wednesday. The models launched today are specialized — they handle audio and images, not the general reasoning and text generation that underpin products like ChatGPT or Copilot's core intelligence. Suleyman has the organizational mandate, Nadella's public backing, and the contractual freedom. What he doesn't yet have is a track record at Microsoft of delivering on the hardest problem in AI.</p><p>But consider what he does have: three models that are best-in-class or near it in their respective domains, built by teams smaller than most seed-stage startups, running on half the industry-standard GPU footprint, and priced below every major cloud competitor. Two years ago, Suleyman proposed in MIT Technology Review what he called the "Modern Turing Test" — not whether AI could fool a human in conversation, but whether it could go out into the world and accomplish real economic tasks with minimal oversight. On Wednesday, his own models took a step toward that vision. The question now is whether Microsoft's superintelligence team can repeat the trick at the scale that actually matters — and whether they can do it before the market's patience runs out.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Warns of AVrecon Malware Targeting Network Devices Across 163 Countries]]></title>
<description><![CDATA[The router sitting in your home office or small business did not need to be hacked by a skilled operator to end up serving as infrastructure for banking fraud, password attacks, and digital marketplace scams. All it needed was an unpatched vulnerability and a malware dubbed "AVrecon" to infect an...]]></description>
<link>https://tsecurity.de/de/3401954/it-security-nachrichten/fbi-warns-of-avrecon-malware-targeting-network-devices-across-163-countries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3401954/it-security-nachrichten/fbi-warns-of-avrecon-malware-targeting-network-devices-across-163-countries/</guid>
<pubDate>Thu, 02 Apr 2026 10:50:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="535" src="https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="AVrecon, AVrecon Malware, Home Router, FBI, SocksEscort, Proxy Network" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers.webp 800w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-300x201.webp 300w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-768x514.webp 768w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-600x401.webp 600w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-750x502.webp 750w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers.webp 800w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-300x201.webp 300w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-768x514.webp 768w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-600x401.webp 600w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/AVrecon-Malware-on-Home-Routers-750x502.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="FBI Warns of AVrecon Malware Targeting Network Devices Across 163 Countries 3"></p>The router sitting in your home office or small business did not need to be hacked by a skilled operator to end up serving as infrastructure for banking fraud, password attacks, and digital marketplace scams. All it needed was an unpatched vulnerability and a malware dubbed "AVrecon" to infect and sell access to it within minutes.

Last month, FBI alongside several international law enforcement agencies <a href="https://www.justice.gov/usao-edca/pr/authorities-dismantle-global-malicious-proxy-service-deployed-malware-and-defrauded" target="_blank" rel="nofollow noopener">took down</a> SocksEscort residential proxy service. In a follow-up of that investigation, the agency has found a <a class="wpil_keyword_link" title="malware" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="27440">malware</a> called AVrecon, that was used in the targeting of scores of network devices worldwide.
<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>How AVrecon Works</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">AVrecon spreads by scanning the <a class="wpil_keyword_link" title="internet" href="https://thecyberexpress.com/what-is-internet/" data-wpil-keyword-link="linked" data-wpil-monitor-id="27444">internet</a> for devices with exposed vulnerable services. The SocksEscort operators exploited Remote Code Execution <a class="wpil_keyword_link" title="vulnerabilities" href="https://thecyberexpress.com/what-are-vulnerabilities/" data-wpil-keyword-link="linked" data-wpil-monitor-id="27441">vulnerabilities</a> and command injection flaws, as well as weaknesses in exposed SOAP interfaces — a web services protocol found in many consumer router management panels.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The malware's command-and-control framework is modular by design, meaning new <a class="wpil_keyword_link" title="exploit" href="https://cyble.com/exploit/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="27443">exploit</a> modules can be added as new vulnerabilities are discovered, continuously expanding the range of vulnerable device models it can infect. The FBI identified approximately 1,200 targeted device models from Cisco, D-Link, Hikvision, MikroTik, Netgear, TP-Link, and Zyxel.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Beyond converting infected devices into proxy nodes, AVrecon can also update its own stored configuration, establish a remote shell directly to an attacker-controlled server, and act as a loader that downloads and executes entirely separate payloads onto the device.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Once inside a router, the <a class="wpil_keyword_link" title="malware" href="https://thecyberexpress.com/what-is-malware/" data-wpil-keyword-link="linked" data-wpil-monitor-id="27445">malware</a> beacons to its command-and-control server every 60 seconds using a PING/PONG communication loop. When the C2 has a command ready, it interrupts that loop to direct the infected router to open a traffic tunnel to a SocksEscort relay server.</p>

<h5>Also read: <a href="https://thecyberexpress.com/fcc-blocked-new-foreign-made-router-from-us/">The FCC Just Blocked Every New Foreign-Made Router from the U.S. Market</a></h5>
<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>The Persistence Problem</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The persistence mechanism AVrecon uses on some device models makes remediation particularly difficult. On vulnerable targets, the attackers use the device's own built-in firmware update feature to flash a custom firmware image that contains a hardcoded copy of AVrecon and silently disables the device's future update and re-flashing functionality.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The FBI <a href="https://www.ic3.gov/CSA/2026/260312.pdf" target="_blank" rel="nofollow noopener">notes</a> these devices are essentially permanently infected — a factory reset cannot help if the reset itself has been disabled, and an end-of-life device has no manufacturer patches to address the underlying vulnerability regardless.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">On devices where firmware modification is not used, a simple power cycle can clear the infection. However, in at least one documented case, AVrecon C2 servers detected the loss of an infected device and automatically re-infected it using the same vulnerabilities used in the original compromise. Meaning, rebooting alone does not guarantee lasting protection if the underlying <a class="wpil_keyword_link" title="vulnerability" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" data-wpil-keyword-link="linked" data-wpil-monitor-id="27438">vulnerability</a> remains unpatched.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>What SocksEscort Built and Sold</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">SocksEscort operated a commercial criminal service that sold paying customers the ability to tunnel their internet traffic through compromised home and small-office routers in 163 countries, including the United States. The tunneling protocol used — SOCKS — is a legitimate networking standard that proxies traffic through an intermediate host. In criminal use, it makes the attacker's activity appear to originate from the victim's home IP address rather than from any infrastructure that could be blocked or attributed.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The FBI estimates SocksEscort compromised and sold access to approximately 369,000 devices since 2020. The malware enabling all of this is was AVrecon — written in the C programming language and designed to target devices running on MIPS and ARM architectures, the processor types that dominate the consumer router market.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>What the Proxy Network Enabled</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The FBI and partners observed SocksEscort's infrastructure used to conduct ad <a class="wpil_keyword_link" title="fraud" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="27442">fraud</a>, attempt website vulnerability exploitation, password spraying, digital marketplace fraud, banking fraud, and romance fraud, among other malicious activity. By routing attacks through residential IP addresses, SocksEscort customers dramatically increased their chances of bypassing corporate <a class="wpil_keyword_link" title="security" href="https://thecyberexpress.com/" data-wpil-keyword-link="linked" data-wpil-monitor-id="27436">security</a> filters and block lists that flag traffic from known commercial or cloud hosting providers.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The FBI's advisory specifically notes that while lateral movement into internal networks was not directly observed in the AVrecon case, malware targeting edge devices like routers is frequently used as a staging point for exactly that — moving from the compromised device into the broader corporate or home network it protects, potentially enabling data exfiltration or <a class="wpil_keyword_link" title="ransomware" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="27439">ransomware</a> deployment.</p>

<h3 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>Remediation for Network Defenders</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">The FBI recommends applying firmware updates to all SOHO routers and IoT devices immediately, as many do not apply patches automatically and require manual interaction with the device administration panel. Devices classified as End-of-Life that no longer receive security updates should be replaced entirely.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Remote administration features should be disabled or access-restricted via <a class="wpil_keyword_link" title="firewall" href="https://cyble.com/knowledge-hub/what-is-firewall/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="27437">firewall</a> rules, and all default passwords should be changed.</p>
<p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Network defenders should monitor for traffic to the C2 domains and IP addresses published in the advisory and watch for the malware filenames "x" (loader) and "dnssmasq" (malware) on network-connected devices.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Robosen Soundwave review: A childhood dream made real]]></title>
<description><![CDATA[There's just something magical about a robot that can convert into a car, tank or plane. It seems that Hollywood agrees as there are several major franchises based around that concept. As someone who grew up in the 80s and 90s, Transformers hold a special place in my heart, despite Michael Bay's ...]]></description>
<link>https://tsecurity.de/de/3399217/it-nachrichten/robosen-soundwave-review-a-childhood-dream-made-real/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3399217/it-nachrichten/robosen-soundwave-review-a-childhood-dream-made-real/</guid>
<pubDate>Wed, 01 Apr 2026 14:02:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>There's just something magical about a robot that can convert into a car, tank or plane. It seems that Hollywood agrees as there are several major franchises based around that concept. As someone who grew up in the 80s and 90s, <a target="_blank" class="link" href="https://www.engadget.com/entertainment/were-living-through-a-golden-age-of-transformers-toys-170000428.html" data-i13n="cpos:1;pos:1">Transformers</a> hold a special place in my heart, despite Michael Bay's best efforts at tarnishing its legacy. I spent countless hours as a kid playing with Hasbro and Takara's plastic figures, but there was one type of toy I always wanted but never got: a robot that could transform on its own just like the ones I watched on TV. That changed a few years ago when <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=f1f1596b-9071-47be-adae-e45d17d94dfa&amp;featureId=text-link&amp;linkText=Robosen&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3VzLnJvYm9zZW4uY29tLyIsImNvbnRlbnRVdWlkIjoiZjFmMTU5NmItOTA3MS00N2JlLWFkYWUtZTQ1ZDE3ZDk0ZGZhIiwib3JpZ2luYWxVcmwiOiJodHRwczovL3VzLnJvYm9zZW4uY29tLyJ9&amp;signature=AQAAARfV4G9jG1z9NgD7oVKmJjXfN-S9KN-J3IrXHalYyH7S&amp;gcReferrer=https%3A%2F%2Fus.robosen.com%2F" data-i13n="elm:affiliate_link;sellerN:;elmt:;cpos:2;pos:1" data-original-link="https://us.robosen.com/">Robosen</a> <a target="_blank" class="link" href="https://www.engadget.com/robosen-robotics-optimus-prime-collectible-hasbro-153031747.html" data-i13n="cpos:3;pos:1">launched</a> its line of officially licensed auto-converting models, and from what I've seen, its latest release featuring <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=f1f1596b-9071-47be-adae-e45d17d94dfa&amp;featureId=text-link&amp;linkText=Soundwave&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3VzLnJvYm9zZW4uY29tL3Byb2R1Y3RzL2ZsYWdzaGlwLXNvdW5kd2F2ZSIsImNvbnRlbnRVdWlkIjoiZjFmMTU5NmItOTA3MS00N2JlLWFkYWUtZTQ1ZDE3ZDk0ZGZhIiwib3JpZ2luYWxVcmwiOiJodHRwczovL3VzLnJvYm9zZW4uY29tL3Byb2R1Y3RzL2ZsYWdzaGlwLXNvdW5kd2F2ZSJ9&amp;signature=AQAAAWecKYbP9fNLNVmCtsaAG-J2mpmNhmnqSvow7PMT7J4M&amp;gcReferrer=https%3A%2F%2Fus.robosen.com%2Fproducts%2Fflagship-soundwave" data-i13n="elm:affiliate_link;sellerN:;elmt:;cpos:4;pos:1" data-original-link="https://us.robosen.com/products/flagship-soundwave">Soundwave</a> might be its best yet. </p>
<p>
 <core-commerce data-type="product-list" data-original-url="https://us.robosen.com/products/flagship-soundwave"></core-commerce></p>
<h2>Design: More than meets the eye</h2>
<p>As a follow-up to previous bots featuring Optimus Prime, Megatron, Bumblebee, Grimlock and others, Soundwave was a <a target="_blank" class="link" href="https://www.youtube.com/watch?v=NkbySu0cRxc" data-i13n="cpos:5;pos:1">superior</a> choice, and Robosen has done a more than respectable job of bringing him to life. Not only can he spit out classic lines performed by original voice actor <a target="_blank" class="link" href="https://en.wikipedia.org/wiki/Frank_Welker#Transformers" data-i13n="cpos:6;pos:1">Frank Welker</a>, both his robot and <a target="_blank" class="link" href="https://tfwiki.net/wiki/Alternate_mode" data-i13n="cpos:7;pos:1">alt modes</a> are a vision straight out of the first-generation (G1) cartoon. Everywhere you look, there are a ton of lovingly crafted details like the working eject button for the cassette slot and all sorts of lights. Robosen's head sculpt is spot on, and it even includes additional LEDs for his eyes and shoulder cannon. Granted, there is a bit of <a target="_blank" class="link" href="https://tfwiki.net/wiki/Kibble" data-i13n="cpos:8;pos:1">kibble</a> (aka what fans call out of place parts leftover from transformation), like hands that don't properly fold away when Soundwave turns into a boombox, but that's really nitpicking. Between his incredibly accurate design, vocoder-powered vocals and an imposing stature that stands at around 14 inches tall, there's no way you can call this rendition of Soundwave <a target="_blank" class="link" href="https://youtu.be/V8-_DjQc0sA?t=10" data-i13n="cpos:9;pos:1">uncharismatic</a>. </p>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-head_2920.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-head_2920.jpg" alt="" data-uuid="8cc26289-3b0d-42fc-8ba5-a1b0d21f3331">
 <figcaption>
  A simply superior head sculpt.
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>However, the real magic happens when you turn him on (there's a little button on his back) and say "Hey, Soundwave." From here, you can use more than 50 different voice commands to boss him around like you're the <a target="_blank" class="link" href="https://youtu.be/SaIUjUJwL_E?t=12" data-i13n="cpos:10;pos:1">leader of the Decepticons</a>. This includes asking him to say iconic lines, respond to an Autobot attack or just wishing someone a happy birthday. Naturally, the most impressive request is asking him to transform, at which point 28 high-precision servo motors and multiple motion sensors coordinate. This allows Soundwave to convert from boombox mode to robot and back again, complete with the required sound effects. Even as a jaded adult, there's still something incredibly enchanting about watching a Transformer actually transform on its own. But that pales in comparison to the one-of-a-kind reaction my four-year-old son gave me when I repeated the process for him. There was a joy in his face I'm not sure a grown-up can truly express, as he gets to experience this without knowing this bot costs a cool $1,400. </p>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/robosen-app_7335.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/robosen-app_7335.jpg" alt="" data-uuid="c98d40ed-7767-4f48-8fa9-77d91c42c3a7">
 <figcaption>
  Robosen's free mobile app features a D-pad so you can easily tell the robot where to walk. 
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>While testing Soundwave's various commands, I did notice that his voice recognition can be somewhat hit or miss. I found that even a little background noise can cause issues. To be consistently heard, you have to speak louder than you think you should. The real key is being very deliberate with a sharp "Hi" or "Hey" to activate Soundwave's wake phrase properly. Alternatively, if you prefer not to yell at your robots, there's also a free companion app that allows you to send commands by simply pressing a button, which was super easy to set up and quickly became my preferred control scheme. </p>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-size-comp_7585.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-size-comp_7585.jpg" alt="" data-uuid="d1961d1a-10d5-46dc-bd87-d7b0b58efcc1">
 <figcaption>
  Here is Robosen's version of Soundwave (right) compared to the Studio Series 86 figure (left). 
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>In addition to making it easier to get Soundwave to walk around (it's much more fun to use a virtual D-pad than yell "Walk forward" all the time), the app also provides a more straightforward way of discovering what he can do while reducing the ambiguity of voice commands. There are handy buttons for all his voice lines and poses, plus there’s a toolkit for creating some of your own. You can also download more from the app, though there weren't any for me to test out because Soundwave wasn't officially out yet at the time of writing. There's even a Mini Theatre mode that allows the bot to perform short skits, and if you're lucky enough to own some of Robosen's other Transformers toys, like Megatron, some of these scenes can even be performed in tandem. </p>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-vs-jazz-2_2768.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-vs-jazz-2_2768.jpg" alt="" data-uuid="d9464220-9c77-4da3-88d2-a047c64aff1e">
 <figcaption>
  I don't think any Autobots have a chance against a Soundwave this big. 
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>One awkward thing about Roboen's more sophisticated approach to toy robots is that Soundwave loses some of his structural integrity when his motors are off. For example, when you power him down in robot mode, he bends over backwards and gets stuck halfway between his humanoid and boombox forms. I assume this is to prevent him from falling over, which is a good thing; it just looks kind of weird. On the flip side, if you pick him up while in stereo mode, his limbs tend to droop. However, perhaps the biggest downside to Soundwave is one inherent to his design. Because his alt mode is a boombox instead of a vehicle like Optimus, Bumblebee and others, he can't pull double duty as a remote control car. But what Soundwave lacks in mobility, he makes up for with his signature acoustic skills.</p>
<h2>Audio: Not just a bot, he's a real boombox too</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-boombox_0916.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-boombox_0916.jpg" alt="" data-uuid="4c9897fa-ab13-45f2-a7c7-69f9bbe935ed">
 <figcaption>
  From the front, Soundwave's boombox alt mode looks damn near perfect. 
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>Soundwave turning into a boombox that can't play music just wouldn't make sense. Thankfully, that's not an issue as this bot's buttons aren't just for show. Hitting Play lets you listen to original tracks from the G1 cartoon, complete with the ability to pause or skip to the next track. You can also hold the record button to save a personal message for later, though I found this feature has a bit of a learning curve as Soundwave tends to cut out one or two seconds from the beginning and end of a clip. </p>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/robosen-app-commands_6162.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/robosen-app-commands_6162.jpg" alt="" data-uuid="8ac92282-6800-4787-a563-6f93c676548e">
 <figcaption>
  Inside the app, there's also a big list for all of Soundwave's voice lines and poses. 
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>Most importantly, if you want Soundwave to play other tunes, you can pair it with your phone or pretty much any other mobile device and use him just like a typical Bluetooth speaker. Now it probably won't be a surprise when I say that Soundwave's audio quality is mediocre at best. With all the various sensors, motors and moving parts, there probably isn't a ton of room for fancy drivers, so things sound tinny and flat. But in a way, that's kind of endearing because the vast majority of portable speakers back in the 80s didn't sound great either. The one thing I wish Robosen had included was a proper cassette player to really capitalize on Soundwave's classic audio capabilities. That said, even though I still have stacks of CDs and DVDs in my house, I don't have any tapes (<a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=da022f9a-4814-44de-b5e9-ea4e197a791c&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=f1f1596b-9071-47be-adae-e45d17d94dfa&amp;featureId=text-link&amp;merchantName=AARP&amp;linkText=despite+their+resurgence&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5hYXJwLm9yZy9lbnRlcnRhaW5tZW50L211c2ljL2Nhc3NldHRlLXRhcGVzLW1ha2luZy1hLWNvbWViYWNrLyIsImNvbnRlbnRVdWlkIjoiZjFmMTU5NmItOTA3MS00N2JlLWFkYWUtZTQ1ZDE3ZDk0ZGZhIiwib3JpZ2luYWxVcmwiOiJodHRwczovL3d3dy5hYXJwLm9yZy9lbnRlcnRhaW5tZW50L211c2ljL2Nhc3NldHRlLXRhcGVzLW1ha2luZy1hLWNvbWViYWNrLyJ9&amp;signature=AQAAAQ40nG88xV2wWR6g-f2SM6Ylh655J90Na6FeTtScYY9v&amp;gcReferrer=https%3A%2F%2Fwww.aarp.org%2Fentertainment%2Fmusic%2Fcassette-tapes-making-a-comeback%2F" data-i13n="elm:affiliate_link;sellerN:AARP;elmt:;cpos:11;pos:1" data-original-link="https://www.aarp.org/entertainment/music/cassette-tapes-making-a-comeback/">despite their resurgence</a>), so I get why that feature didn't make it. </p>
<h2>Battery life</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-back_0970.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-back_0970.jpg" alt="" data-uuid="20bdf686-d709-424b-b112-a632b9b6ec4c">
 <figcaption>
  It may not be period accurate, but the addition of a USB-C port around back for power is a really nice touch. 
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>Soundwave comes with a built-in 1,650mAh battery which takes about 120 minutes to charge from dead to full while offering a standby time of around 60 minutes. During my testing, I found you can get a solid 20 to 30 minutes of playtime out of him, which felt like plenty. Of course,that depends a ton on how much moving around you tell him to do. And while it certainly isn't period authentic, I really appreciate the inclusion of a USB-C port for charging. </p>
<h2>Wrap-up</h2>
<p>The funny thing about Robosen's Soundwave is that a toy like this would have been priceless to me as a child. But now that I'm older and I have to attach a value that goes beyond its basic price, things are a lot trickier. </p>
<p>I love Robosen's attention to detail. The figure looks incredible and getting voice lines from the original actor shows there's more than meets the eye to the robot’s design. But most importantly, seeing Soundwave transform on his own and stomp around like he does in the show will never get old. </p>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-box_0504.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/soundwave-box_0504.jpg" alt="" data-uuid="15e324d1-1ea7-43c4-89aa-4bb0a9f8707f">
 <figcaption>
  As you'd expect from a toy this expensive, Robosen's packaging is excellent. 
 </figcaption>
 <div class="photo-credit">
  Sam Rutherford for Engadget
 </div>
</figure>
<p>On the other hand, $1,400 can buy the whole family a nice three-day vacation or more than two dozen regular Transformers toys. That kind of math makes it difficult to add this Cybertronian to the household register. But for anyone who has a budget similar to a Michael Bay movie, this take on Soundwave really does feel like a dream come true. Aside from some of Robosen's other products, this robot is certainly made of <a target="_blank" class="link" href="https://youtu.be/bVzf6_wUtlg?t=193" data-i13n="cpos:12;pos:1">sterner stuff</a>. </p>
<p></p>This article originally appeared on Engadget at https://www.engadget.com/general/robosen-soundwave-review-a-childhood-dream-made-real-120000804.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4608: Simple Podcasting - Episode 1 - Preparation and Recording]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.

Simple-Podcasting



01 Introduction

This is the first episode in a four part series  on a simple way to create your own HPR podcast episode.



02

If it sounds contradictory to have four episodes on a simple subject, you only actua...]]></description>
<link>https://tsecurity.de/de/3397751/podcasts/hpr4608-simple-podcasting-episode-1-preparation-and-recording/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397751/podcasts/hpr4608-simple-podcasting-episode-1-preparation-and-recording/</guid>
<pubDate>Wed, 01 Apr 2026 02:17:25 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<p>
Simple-Podcasting</p>


<p>
01 Introduction</p>
<p>
This is the first episode in a four part series  on a simple way to create your own HPR podcast episode.</p>


<p>
02</p>
<p>
If it sounds contradictory to have four episodes on a simple subject, you only actually need the first episode to see how to create podcasts. </p>
<p>
The remaining episodes are on steadily more complex subjects, with the later ones being more in the realm of gratuitous hackery for the fun of it.</p>


<p>
03</p>
<p>
I am fairly new to podcasting. I have done an HPR episode on Oathtool, another on the UCSD P-System, and an 8 part series on nuclear power.</p>
<p>
Prior to this I have never done a podcast before.</p>
<p>
Despite that, a number of people wrote into HPR to say that they really liked what I did.</p>
<p>
This means that you too can make a first podcast and have other people find it very interesting.</p>


<p>
04</p>
<p>
Since I am fairly new to this, I thought I would document how I went about it for the benefit of anyone who wants to do the same. </p>
<p>
This describes things from the perspective of someone who is very new to this sort of thing.</p>


<p>
Later on I will get into some more advanced topics and then finish off with some blatant gratuitous hackery like how to use Libre Office Calc or GNU Octave in place of an audio editor for some things. </p>


<hr>


<p>
05 Initial Hurdles</p>
<p>
There were several hurdles to get over before I could record an episode though.</p>
<p>
The most obvious one to me was that I'm not the sort of person who can simply babble into a microphone. </p>
<p>
That meant that I needed to have a way of recording things that would let me exclude pauses and repeat sentences that I had messed up.</p>


<p>
06</p>
<p>
However, since I was new to podcasting, I didn't know how to use an audio editor such as Audacity.</p>
<p>
After a bit of thinking though I came up with a very simple solution to that which I will get into a bit later in this episode. </p>


<hr>


<p>
07 Picking a Topic</p>
<p>
With the recording process solved, the next thing to do was to find something to talk about.</p>
<p>
The key to this is to have some place to keep notes.</p>
<p>
I use a note taking program for this, called Zim.</p>


<p>
08</p>
<p>
There are other programs which do something similar, but Zim is the one that I use.</p>
<p>
Whenever I came up with an idea of a topic, I would add a note for it.</p>
<p>
Whenever I came across any information relevant to one of the topics, I added it to the note. </p>


<p>
09</p>
<p>
You might think that you don't know of anything interesting, but the fact is that a lot of the rest of us are fairly sad individuals who are just as boring as you are and so find things like verbal tours through obsolete and obscure operating systems to be quite fascinating.</p>


<p>
10</p>
<p>
I am sure that you too know something obscure but equally interesting.</p>


<hr>


<p>
11 Writing a Script</p>
<p>
Once you have a topic, the next thing is to write a script.</p>
<p>
If you are good at talking off the cuff, then all you may need is an outline.</p>
<p>
If you are like me however, then you will need to write down exactly what you are going to say in a way which you can read back later.</p>


<p>
12</p>
<p>
In this case, start with an outline and fill in the detail after the outline is written.</p>
<p>
Again, I use Zim for writing my scripts.</p>
<p>
It provides a simple way of organizing my scripts as I am putting them together.</p>
<p>
It also provides character and word counts so I can estimate how many minutes of material that I have.</p>
<p>
When I started I decided that I should target about 10 to 20 minutes for the length of an episode.</p>
<p>
That's a personal decision and not something you need to follow for yourself, but it gives me a guideline to work to.</p>


<p>
13</p>
<p>
As a rule of thumb I find that if I multiply the character count by 0.0011, that gives me the approximate number of minutes of audio when recorded.</p>
<p>
Your own number may differ from this, but it's a good starting point to work from.</p>
<p>
If you think the episode is getting too long, don't worry. You can split it up into multiple episodes. </p>


<p>
14</p>
<p>
Once you have the script written and have, if necessary, split it into separate episodes, start numbering the paragraphs.</p>


<p>
This is related to the recording method, which I will go into more detail later.</p>


<p>
15</p>
<p>
Each paragraph or section should be equivalent to 30 seconds to a minute of audio. </p>
<p>
If you are just starting out in podcasting, this may be roughly how much you are comfortable with recording without pausing to collect your thoughts or stumbling over what you are saying.</p>
<p>
We will knit these sections together with a very simple bit of software later.</p>


<hr>


<p>
16 Recording Equipment</p>
<p>
You will need some sort of recording equipment.</p>
<p>
While some people may talk about using a phone or an MP3 player with record function, or something like that, I'll stick with recording onto a PC.</p>


<p>
17</p>
<p>
My recording equipment consists of a Maxwell headset with headphones, boom mic, and USB connection.</p>
<p>
There is no part number on it and can't identify it further than that.</p>
<p>
The cost was probably around $20.</p>
<p>
Similar ones sell for $5 to $35, depending on where you buy it.</p>
<p>
I already had this, so I didn't have to go out and buy it when I decided to make a podcast. </p>


<p>
18</p>
<p>
A boom mic, that is a microphone that is on an arm attached to the headset, is good because it keeps the microphone at a consistent distance from your mouth without any effort.</p>


<p>
19</p>
<p>
The disadvantage of the particular model that I have is that there is noise in the signal, which you can hear in my first two podcast episodes.</p>
<p>
Despite the noise, people still liked the episodes so don't get too hung up on audio quality.</p>
<p>
I will talk later about how to fix noise issues like this by filtering.</p>
<p>
However at this point I am just going to stick to the basics.</p>


<hr>




<p>
20 Recording Software</p>
<p>
For recording software, I used Gnome Record on Ubuntu.</p>
<p>
This is licensed under GPLv2 or later.</p>


<p>
21</p>
<p>
Is very basic</p>
<p>
The only options are to select the file format, and select stereo or mono</p>
<p>
The sample rate for flac is fixed at 44.10 kHz, which is what HPR wants.</p>


<p>
22</p>
<p>
If you are using different software, possibly on another operating system, the principles are the same.</p>
<p>
There are probably equivalents which you can find if you look for them.</p>
<p>
Perhaps you or other listeners could make an HPR episode recommending one.</p>


<p>
23</p>
<p>
When using Gnome Record, use the menu located in the upper right of the window bar, which has three small horizontal lines as an icon.</p>
<p>
Set the preferred format to FLAC.</p>
<p>
Set the audio channel to mono.</p>


<p>
24 Recording</p>
<p>
Get comfortable at your desk.</p>
<p>
Get a cup of tea ready as your throat may get dry.</p>
<p>
Set up the hardware.</p>


<p>
25</p>
<p>
If using a boom mic on a headset, adjust the mic so that it is roughly at chin level. </p>
<p>
Avoid putting a boom microphone directly in front of your mouth. You should speak over the top of the boom microphone, not directly at it. This  will prevent you from breathing on the microphone, causing noise problems.</p>


<p>
26</p>
<p>
If you have a different type of microphone, you may have to experiment a bit using short test recordings to find the optimal position. </p>


<p>
27</p>
<p>
Using your recording software, make a test recording and listen to it.</p>
<p>
If it is too quiet and the input volume is already up all the way, we can adjust this later with software. </p>


<p>
28</p>
<p>
If the test recording sounds OK though, then you are ready to start.</p>


<hr>


<p>
29 Recording using Gnome Sound Recorder</p>
<p>
I will now describe how to use Gnome Sound Recorder.</p>
<p>
If you are using different software the details may be different, but the basic principles should be similar.</p>
<p>
Using the mouse, click on the "Record" button. </p>
<p>
It will start recording, showing the waveform of the recording as it goes.</p>


<p>
30</p>
<p>
To stop recording, click on the square "stop" icon that appeared at the bottom.</p>
<p>
Give the recording a name, using a numbering system starting at 01.</p>
<p>
To accept the recording, click on the check mark button on the right.</p>
<p>
To save the recording, click on the down pointing arrow on the right.</p>
<p>
31</p>
<p>
The file name will default to the name of the recording which we just gave it.</p>
<p>
The numbers should match the paragraph numbers in your script.</p>
<p>
The recording will be saved as a flac file in your home directory. there is no option to save it anywhere else and you will need to move it to your preferred destination manually. </p>
<p>
32</p>
<p>
You can now delete the copy of the recording which Sound Recorder keeps by clicking on the garbage can on the left. This does not affect the copy on your disk. You will want to delete these extra copies as you go along, as there's no easy way to do this later and an extra copy of the recordings will accumulate in a dot directory somewhere and take up space.</p>
<p>
33</p>
<p>
If you make a mistake or are otherwise dissatisfied with that paragraph, just delete the file and record it again. </p>
<p>
Keep the pauses at the start and end of each audio segment equivalent to normal pauses between words. This is actually fairly easy to do. </p>
<p>
When you are done you may have anywhere between  2 and 4 dozen separate flac files. </p>




<p>
34 Using the keyboard shortcuts with Gnome Sound Recorder</p>
<p>
Here are the two most useful keyboard shortcuts for Gnome Sound Recorder.</p>
<p>
Press Ctrl - R to start recording.</p>
<p>
Press "S" to stop recording.</p>
<p>
35</p>
<p>
You still need to use the mouse to click on the check mark button to accept the recording.</p>
<p>
There are supposedly keyboard shortcuts to save the recording to disk and to delete the recording, but these don't seem to work, at least not in version 43.beta on Ubuntu 24.04</p>
<p>
Starting and stopping via keyboard shortcuts is still useful however.</p>


<p>
36</p>
<p>
You can use other software, and I will talk later in another episode about using command line software such as ffmpeg to record.</p>


<hr>


<p>
37 Tips on Recording</p>
<p>
If you are new to podcasting or just are not good at making long speeches, keep each recording segment short, a minute or less being a good target.</p>
<p>
If you stumble over what you are trying to say, don't worry, just repeat the recording for that section. </p>
<p>
38</p>
<p>
Talk clearly in even, measured tones at a reasonably constant volume.</p>
<p>
Remember who your audience are.</p>
<p>
They are people who are listening to your podcast while they are doing housework, or gardening, or driving a car, or walking down a street, or taking some exercise.</p>
<p>
Very few will be sitting at a desk in a quiet room like you are when you are recording.</p>
<p>
39</p>
<p>
Try to make sure that what you are saying comes across clearly.</p>
<p>
If the loudness of your voice varies too much, they won't be able to hear you in the quiet parts.</p>
<p>
The worst thing to do is to trail off into an imperceptible mumble at the end of each sentence. </p>
<p>
Listeners will not be able to follow you if you do that and may give up trying to listen to your episode.</p>




<hr>


<p>
40 HPR Audio File Requirements</p>


<p>
HPR episodes are mono, not stereo.</p>
<p>
If you send in a stereo file, they will convert to mono.</p>
<p>
However, you may wish to convert to mono yourself for the purposes of better duplicating the final result when you review your own work.</p>


<p>
41</p>
<p>
The easiest way to create a mono recording is to record it as mono in the first place, if your recording software has this option.</p>
<p>
If you are using Gnome Sound Recorder, there is a setting for this.</p>
<p>
I described how to set Gnome Sound Recorder to mono just a few moments ago.</p>


<p>
42</p>
<p>
If your software doesn't have a mono option, or if you have already recorded it and now wish to convert to mono, you can use ffmpeg to do the conversion.</p>


<p>
ffmpeg -i stereosample.flac  -ac 1 monofile.flac</p>


<hr>


<p>
43 Alternatives to Gnome Sound Recorder</p>


<p>
An alternative to Gnome Sound Recorder is KDE Recorder.</p>
<p>
This is also available as a snap on Ubuntu.</p>
<p>
The license is GPL-2.0-or-later.</p>


<p>
44</p>
<p>
However, I found it to be a bit more difficult to use than Gnome Sound Recorder.</p>
<p>
Selecting the microphone source was difficult.</p>
<p>
It shows several sources rather than just taking what the OS says is standard.</p>
<p>
45</p>
<p>
This may be because it is a KDE app running on Gnome. Perhaps this is easier if you are using KDE.</p>
<p>
Every time I unplugged my headset and plugged it back in, it added more audio sources to its list.</p>
<p>
None of them worked however until I selected the correct one, exited the program, and then started it back up.</p>
<p>
46</p>
<p>
All files are saved to the Music directory, there is no choice offered.</p>
<p>
Audio format selection is more difficult, it being a two step process.</p>
<p>
There was no option for mono recordings, only stereo.</p>
<p>
Flac recordings were 48 kHz rather than HPR's preferred 44.1 kHz. Converting this would require more post-processing using audio software to change it. </p>
<p>
47</p>
<p>
It seems to offer no advantages over Gnome Sound Recorder on Ubuntu, while making selecting sound sources more difficult.</p>
<p>
If you are using a Gnome desktop you are better off with Gnome Sound Recorder.</p>
<p>
However, it is all a matter of personal preference, and if you find that you like KDE Recorder better, then go ahead and use it. </p>


<p>
48 Other Alternatives</p>
<p>
There are of course still other alternatives.</p>
<p>
Many people recommend using Audacity to record.</p>
<p>
However, I don't know how to do that, and the premise of this podcast episode is that you have something you would like to make an HPR episode but are put off by the difficulty of learning how to do so.</p>
<p>
49</p>
<p>
However, Audacity is a very capable audio program and I have nothing against it.</p>
<p>
I will describe how to use a feature in Audacity to help overcome an audio problem that I encountered,  but I will save that for another episode.</p>


<p>
50</p>
<p>
As well as GUI programs, there are also programs which allow you to record audio from the command line.</p>
<p>
I will describe a couple of these in another episode.</p>
<p>
If you are wondering why you may want to use a command line program for this purpose, one of the advantages of this is that it lets us write scripts which automate the recording process and eliminate some of the manual steps that I outlined above. </p>


<hr>


<p>
51 Combining the Segments into a Single Audio File</p>


<p>
At this point you will have recorded your podcast episode as a series of several dozen flac files.</p>
<p>
We will now stitch the separate flac files into a single file.</p>
<p>
We do this using either ffmpeg or sox. </p>


<p>
52 FFMPEG and Sox</p>
<p>
FFMPEG is a set of command line programs for converting and manipulating audio and video files.</p>
<p>
Various parts are licensed under the LGPL V 2.1 or later, and GPL v 2 or later.</p>


<p>
53</p>
<p>
Sox is also a set of command line programs, but for audio only.</p>
<p>
Sox stands for Sound Exchange.</p>
<p>
Sox is licensed under similar terms as FFMPEG.</p>
<p>
In fact Sox actually uses FFMPEG for certain operations.</p>


<p>
54</p>
<p>
For our purposes here, with one exception you can do everything audio related with either FFMPEG or Sox, except for one thing which I will get to in another episode. That one is related to doing some gratuitous hackery when analyzing audio files, so it may be irrelevant to anything you need to do.</p>


<p>
Since the two are more or less equivalent for our purposes, I will provide examples using both.</p>


<p>
55 Combining Audio Segments</p>
<p>
The best way to combine multiple audio segments is with a simple shell script. </p>
<p>
A copy of this will be in the show notes.</p>


<p>
56 Using FFMPEG</p>
<p>
Doing this with FFMPEG requires just two lines.</p>


<p>
# First create the list file.</p>
<p>
printf "file '%s'\n" [0-9][0-9].flac &gt; podseglist.txt</p>


<p>
57</p>
<p>
This first line creates a file called "podseglist.txt" which contains a list of all the two digit numbered flac files in the current directory, together with some other necessary text.</p>
<p>
I have assumed you wish to give these files two digits. Add more digits out if you feel this is necessary.</p>
<p>
The file name "podseglist.txt" is purely arbitrary and you can use whatever name you wish.</p>


<p>
58</p>
<p>
Now we need to concatenate the files.</p>
<p>
# Now concatenate them</p>
<p>
ffmpeg -f concat -safe 0 -i podseglist.txt fullpod.flac</p>


<p>
The second line calls ffmpeg, tells it to perform a concatenation operation, turning the multiple files listed in "podseglist.txt" into one and saving it in a file called "fullpod.flac".</p>


<p>
59 Using Sox</p>
<p>
The Sox version is simpler.</p>


<p>
sox [0-9][0-9].flac fullpod.flac</p>


<p>
60</p>
<p>
This will concatenate all the two digit numbered flac files in the current directory into one file called  "fullpod.flac".</p>




<hr>


<p>
61 Review the Combined Audio File</p>
<p>
Next you need to review your combined audio file.</p>
<p>
Listen to the resulting file.</p>
<p>
If you are satisfied with it, you are done recording and are ready to upload.</p>
<p>
If you are unhappy about some part of it, you can re-record just that section and run the combining script again. The numbers in your script will help you find the appropriate file. </p>
<p>
62</p>
<p>
The people running HPR will worry about adding the introductory and concluding music, converting it to mono if it is currently stereo, and adjusting the output level to make the volume consistent with other HPR episodes.</p>
<p>
If there are noise problems that you want to try to correct I will cover that in another episode in this series.</p>


<hr>


<p>
63 Prepare the Show Notes</p>
<p>
You will need to have a few things ready when you go to upload your episode.</p>
<p>
These are the title, summary, tags, and show notes.</p>
<p>
The title should be something short but descriptive. </p>
<p>
If this episode is part of a series, you probably want to use a consistent title and include an episode number.</p>
<p>
64</p>
<p>
Next, you need a summary. This is a brief description of what the episode is about. Try to be clear about what it is you will be talking about.</p>
<p>
However, there are limits on the length of the summary. The limit was 100 characters at the time that I was writing this.</p>
<p>
65</p>
<p>
The title and summary will be automatically added by HPR to the beginning of your episode, so put some thought into what you write here.</p>
<p>
The title and summary are read out by a text to speech program, so avoid difficult abbreviations or words that the software may not know how to pronounce. </p>
<p>
66</p>
<p>
Next you will need to pick some tags. These are used for search purposes. I will let someone else recommend how you should pick tags.</p>
<p>
67</p>
<p>
Next, you need to have show notes. </p>
<p>
If you have written a script, you can simply copy-paste the whole thing into the show notes.</p>
<p>
68</p>
<p>
At one time there was a limit on the size of the show notes, but that limit was removed recently. </p>


<hr>


<p>
69 Uploading the Episode</p>
<p>
I will let someone else describe the process of uploading the audio file and associated title, summary, and show notes.</p>
<p>
However, you will need to have an email address ready to use as part of that process, so if you have multiple email accounts you need to settle on which one will be used as your HPR contact address.</p>


<hr>


<p>
70 Conclusion</p>
<p>
The preceding is how I created my first two podcast episodes, which were on Oathtool and the UCSD P-System operating system. </p>
<p>
Plenty of people wrote in to say that they liked them.</p>
<p>
Nobody complained about the quality of my narration or the technical quality of the audio. </p>
<p>
You should be able to do the same.</p>


<hr>


<p>
71 Further Episodes in this Series</p>
<p>
I have covered the basics, but there is more that we can do to improve the audio quality if you are so inclined or if you encounter an audio problem. In further episodes in this series I will cover the following:</p>
<p>
72</p>
<p>
Basic filtering with FFMPEG and Sox to cover general cases. It's a good idea to use this sort of basic filtering on  your audio whether you notice any problems or not.</p>
<p>
73</p>
<p>
"De-essing" to improve perceived voice quality slightly in order to overcome sound artifacts inherent to using at least some microphones. </p>
<p>
74</p>
<p>
Normalizing audio to adjust the sound levels for easier reviewing.</p>
<p>
75</p>
<p>
Analyzing the audio signal with Audacity to discover the characteristics of any noise problems that you may hear.</p>
<p>
76</p>
<p>
Advanced filtering with with FFMPEG and Sox so solve specific problems such as I had with my headset or which you may have with environmental noise such as fans. </p>
<p>
77</p>
<p>
Command line recording and playing of audio using FFMPEG and Sox. This can help automate the process by automatically numbering the small audio files which are part of the recording process which I have described.</p>
<p>
78</p>
<p>
I promised some gratuitous hackery, and I will provide it in the form of describing how to do audio spectrum analysis using Libre Office Calc spreadsheets and GNU Octave mathematical software in place of Audacity when troubleshooting audio problems. </p>


<p>
79</p>
<p>
This concludes the first episode in a four part series on simple podcasting.</p>


<hr>
<p>
Scripts for this episode.</p>


<pre>
<code>
#!/bin/bash
# First create the list file.
printf "file '%s'\n" [0-9][0-9].flac &gt; podseglist.txt
ffmpeg -f concat -safe 0 -i podseglist.txt fullpod.flac
</code>
</pre>
<hr>
<pre>
<code>
#!/bin/bash
sox [0-9][0-9].flac fullpod.flac
</code>
</pre>
<hr>

<p><a href="https://hackerpublicradio.org/eps/hpr4608/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Usage pricing leaving software vendors guessing what lands on the invoice]]></title>
<description><![CDATA['Converting AI capability into sustainable, auditable revenue remains a challenge' says PwC survey Software companies are leaving money on the table because their core financial systems haven't kept pace with the way they sell pay-per-use services, which often now incorporate AI capabilities.…]]></description>
<link>https://tsecurity.de/de/3395785/it-nachrichten/usage-pricing-leaving-software-vendors-guessing-what-lands-on-the-invoice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395785/it-nachrichten/usage-pricing-leaving-software-vendors-guessing-what-lands-on-the-invoice/</guid>
<pubDate>Tue, 31 Mar 2026 13:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>'Converting AI capability into sustainable, auditable revenue remains a challenge' says PwC survey</h4> <p>Software companies are leaving money on the table because their core financial systems haven't kept pace with the way they sell pay-per-use services, which often now incorporate AI capabilities.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays]]></title>
<description><![CDATA[A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3395372/it-security-nachrichten/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395372/it-security-nachrichten/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays/</guid>
<pubDate>Tue, 31 Mar 2026 10:37:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays/">Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays]]></title>
<description><![CDATA[A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers a reliable and sile...]]></description>
<link>https://tsecurity.de/de/3395298/it-security-nachrichten/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395298/it-security-nachrichten/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays/</guid>
<pubDate>Tue, 31 Mar 2026 10:07:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers a reliable and silent path deeper into a network after initial compromise. That narrow focus […]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-deploy-roadk1ll-pivoting-malware/">Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GhostSocks Hijacks Devices as Proxy Network for Stealthy Cyberattacks]]></title>
<description><![CDATA[A newly emerging malware known as GhostSocks is quietly reshaping how attackers evade detection by converting compromised systems into residential proxy nodes. Modern cyberattacks rely heavily on blending into normal network traffic. Residential proxies allow attackers to route malicious activity...]]></description>
<link>https://tsecurity.de/de/3394998/it-security-nachrichten/ghostsocks-hijacks-devices-as-proxy-network-for-stealthy-cyberattacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394998/it-security-nachrichten/ghostsocks-hijacks-devices-as-proxy-network-for-stealthy-cyberattacks/</guid>
<pubDate>Tue, 31 Mar 2026 07:36:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly emerging malware known as GhostSocks is quietly reshaping how attackers evade detection by converting compromised systems into residential proxy nodes. Modern cyberattacks rely heavily on blending into normal network traffic. Residential proxies allow attackers to route malicious activity…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ghostsocks-hijacks-devices-as-proxy-network-for-stealthy-cyberattacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ghostsocks-hijacks-devices-as-proxy-network-for-stealthy-cyberattacks/">GhostSocks Hijacks Devices as Proxy Network for Stealthy Cyberattacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GhostSocks Hijacks Devices as Proxy Network for Stealthy Cyberattacks]]></title>
<description><![CDATA[A newly emerging malware known as GhostSocks is quietly reshaping how attackers evade detection by converting compromised systems into residential proxy nodes. Modern cyberattacks rely heavily on blending into normal network traffic. Residential proxies allow attackers to route malicious activity...]]></description>
<link>https://tsecurity.de/de/3394971/it-security-nachrichten/ghostsocks-hijacks-devices-as-proxy-network-for-stealthy-cyberattacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394971/it-security-nachrichten/ghostsocks-hijacks-devices-as-proxy-network-for-stealthy-cyberattacks/</guid>
<pubDate>Tue, 31 Mar 2026 07:22:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly emerging malware known as GhostSocks is quietly reshaping how attackers evade detection by converting compromised systems into residential proxy nodes. Modern cyberattacks rely heavily on blending into normal network traffic. Residential proxies allow attackers to route malicious activity through legitimate home IP addresses, making it appear as if traffic originates from ordinary users […]</p>
<p>The post <a href="https://gbhackers.com/ghostsocks-hijacks-devices/">GhostSocks Hijacks Devices as Proxy Network for Stealthy Cyberattacks</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to embed AI into business processes without breaking the business]]></title>
<description><![CDATA[Playtime is over. The pressure is on business leaders to deliver tangible results from artificial intelligence (AI) projects, even amid statistics that show how difficult that may be. Organizations that can solve one of AI’s most vexing puzzles — how to embed AI into existing business processes —...]]></description>
<link>https://tsecurity.de/de/3393974/it-security-nachrichten/how-to-embed-ai-into-business-processes-without-breaking-the-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393974/it-security-nachrichten/how-to-embed-ai-into-business-processes-without-breaking-the-business/</guid>
<pubDate>Mon, 30 Mar 2026 19:36:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Playtime is over. The pressure is on business leaders to deliver tangible results from artificial intelligence (AI) projects, even amid statistics that show how difficult that may be. Organizations that can solve one of AI’s most vexing puzzles — how to embed AI into existing business processes — will likely be on the road to success.</p>



<p>By now you’ve likely seen the MIT report that found that 95% of AI projects “are getting zero return.” Based on an analysis of more than 300 implementations, MIT researchers found that only 5% of custom or vendor-sold AI tools reached production. “Most fail due to brittle workflows, lack of contextual learning, and misalignment with day-to-day operations,” MIT reports.<a href="https://www.cio.com/article/4151905/how-to-embed-ai-into-business-processes-without-breaking-the-business.html#_edn1"><sup>[i]</sup></a></p>



<p>Those findings speak to an issue that is likely familiar to any company that has experimented with AI: how to achieve enterprise AI integration that aligns with day-to-day <a href="https://www.flowfinity.com/?utm_source=foundry&amp;utm_medium=magazine&amp;utm_campaign=it-leader?" rel="sponsored">operations</a> without breaking the existing workflows where work actually happens.<br><br>AI provides value when it’s useful, reliable, and safe. But how is that achieved?<br><br></p>



<p><strong>The power of no-code</strong></p>



<p>An answer may lie in no-code workflow automation platforms such as Flowfinity. No-code has long enabled frontline employees to create applications and workflows that help them do their job more efficiently. It stands to reason that those same frontline employees will understand better than anyone else where and how to best employ AI to help them do their job more effectively.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“You shouldn’t need to reimagine existing processes to see value from AI,” says Alex Puttonen, senior marketing manager at <a href="https://www.flowfinity.com/?utm_source=foundry&amp;utm_medium=magazine&amp;utm_campaign=it-leader" rel="sponsored">Flowfinity</a>, provider of a no-code <a href="https://www.flowfinity.com/apps/?utm_source=foundry&amp;utm_medium=magazine&amp;utm_campaign=it-leader" rel="sponsored">business process improvement platform</a>. “With the right no-code workflow automation tools, you can embed AI directly into your current processes to help users perform their work more effectively without disrupting daily operations.”</p>
</blockquote>



<p>AI tools offer a range of valuable use cases for an organization, including automating repetitive data entry tasks, summarizing long documents, finding key nuggets of data to inform decision-making, converting speech to text, and more.</p>



<p><strong>Embedding AI into existing processes</strong></p>



<p>Until now, employees wanting to use AI had to seek out external assistants that might not be approved by IT; help wasn’t embedded into their native workflows. No-code platforms enable organizations to shape AI around how they actually operate, with built-in guardrails for safe use.<br><br></p>



<p>One example might be a field technician at a job site performing an inspection of malfunctioning equipment, Puttonen says. As the technician completes a repair workflow on their mobile device, Flowfinity can invoke AI assistance as needed, such as:</p>



<ul class="wp-block-list">
<li>Checking past service history and summarizing inspection records for machinery and similar assets to help with troubleshooting</li>



<li>Offering up potential solutions in context to the problem at hand, with links to repair instructions and potential next steps</li>



<li>Compiling all the relevant form entries and voice notes to convert them into a clean customer-facing report with custom formatting</li>
</ul>



<p>What makes this successful is that the technician is using a field service reporting tool configured to support the organization’s business processes and that AI capabilities are introduced only when they are most useful. AI assistance can help the technician identify the problem and complete the job more quickly and reliably. Finally, AI tools help create reports for both the customer’s and the company’s own use — likely sparing the tech one of the least-favorite parts of their job.</p>



<p>Importantly, the entire process is handled within the Flowfinity Platform, ensuring that your company maintains control over AI use and your data is safely contained.</p>



<p>Multiply that example by any number of scenarios in fields such as engineering, utilities, facilities management, manufacturing, and more, and you can get a sense of how to successfully embed AI into numerous business processes — without breaking them.</p>



<p>For more than 25 years, Flowfinity has been helping leading organizations innovate and grow. Learn more about the Flowfinity no-code <a href="https://www.flowfinity.com/apps/?utm_source=foundry&amp;utm_medium=magazine&amp;utm_campaign=it-leader" rel="sponsored">business process improvement platform</a>, designed to make it easier to deliver useful, reliable, and safe AI-enhanced workflow automation solutions efficiently and effectively.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a href="https://www.cio.com/article/4151905/how-to-embed-ai-into-business-processes-without-breaking-the-business.html#_ednref1"><sup>[i]</sup></a> <a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf" rel="sponsored">“The GenAI Divide: STATE OF AI IN BUSINESS 2025,”</a> July 2025, MIT NANDA.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Edge clouds and local data centers reshape IT]]></title>
<description><![CDATA[For more than 10 years, enterprise cloud strategy has relied on centralizing as much as possible—shifting workloads from data centers, consolidating operations on hyperscale platforms, and leveraging economies of scale. This approach has reduced infrastructure sprawl, accelerated deployment, and ...]]></description>
<link>https://tsecurity.de/de/3385864/ai-nachrichten/edge-clouds-and-local-data-centers-reshape-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3385864/ai-nachrichten/edge-clouds-and-local-data-centers-reshape-it/</guid>
<pubDate>Fri, 27 Mar 2026 10:32:58 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For more than 10 years, enterprise cloud strategy has relied on centralizing as much as possible—shifting workloads from data centers, consolidating operations on hyperscale platforms, and leveraging economies of scale. This approach has reduced infrastructure sprawl, accelerated deployment, and provided nearly unlimited compute and storage. However, the next generation of digital systems increasingly interacts with regional regulations, real-time decision loops, and the physical world in general. These factors do not tolerate distance well. Smart traffic systems can’t wait for a round-trip to distant cloud regions. Industrial control systems can’t halt operations because a wide-area link is congested. AI-driven video analytics becomes costly and inefficient when every frame must be sent back to a centralized platform for inference. In these environments, it matters where the data is created and processed and where decisions are made.</p>



<p>The future of cloud computing is neither more nor less centralized. It is selectively distributed, with edge cloud and localized data centers becoming essential in situations where latency, sovereignty, and physical-world responsiveness matter most.</p>



<p>That is the real story behind the rise of edge cloud. It’s not hype, a complete reversal of cloud adoption, or a nostalgic return to on-premises infrastructure. Instead, what’s emerging is more practical dual architecture: a centralized cloud for aggregation, model training, cross-region coordination, and platform services; with local infrastructure for time-sensitive processing, regional independence, and compliance-driven workloads.</p>



<h2 class="wp-block-heading">Use cases for edge clouds</h2>



<p>Edge cloud involves deploying compute, storage, and networking resources closer to users, devices, and data sources. It looks like telecom facilities at the metro edge, or micro data centers in hospitals, retail outlets, factories, or municipal centers. These localized data centers support workloads that benefit from proximity, embodying the regional computing principle of placing workloads where they are most operationally and economically effective.</p>



<p>The trend is accelerating because multiple forces are converging at once. Low-latency applications are moving from pilot projects to full production. AI is transitioning from centralized training to distributed inference. Data residency laws are becoming more specific and easier to enforce. Enterprises are also realizing that bandwidth is limited, and transmitting massive amounts of sensor, video, and telemetry data to a central cloud can often be a poor design choice hidden behind architectural simplicity.</p>



<p>Consider smart cities. Municipal systems are no longer limited to back-office software and basic public websites. City systems now include connected traffic lights, intelligent surveillance, environmental sensors, safety systems, transit monitoring, and energy efficiency platforms, all generating continuous streams of local data that require immediate responses. Detecting congestion, hazards, or emergency vehicle routes at intersections demands quick action. Relying on distant cloud analysis can delay responses, risking public safety.</p>



<p>The same logic applies in industrial settings. Connected factories increasingly use machine vision, predictive maintenance models, robotics, telemetry, and digital twins to boost throughput and minimize downtime. Much of that data has local value first and global value second. A detection model for defects running alongside a production line can stop defective output in real time. A centralized system can still gather data for fleet-wide analytics, training, and optimization, but it should not be on the critical path of every local decision. This is where edge cloud delivers tangible business value as a way to keep local operations fast, resilient, and cost-effective.</p>



<p>Healthcare can’t rely solely on a centralized cloud system. Regional setups depend on imaging, monitoring, connected devices, and patient-facing services. Some workloads must remain local because of privacy concerns, network limitations, or response time requirements. Hospitals need local computing for imaging, decision support, and operations that can’t risk WAN failures. At the same time, they require centralized platforms for <a href="https://www.infoworld.com/article/2255434/what-is-big-data-analytics-fast-answers-from-diverse-data-sets.html">analytics</a>, model development, and data integration. Hybrid is the best operating model.</p>



<p>Retail demonstrates another vital aspect of edge: local processing for personalization, inventory, checkout, and analytics. Pushing all transactions to a central platform is costly, especially when business value is immediate and local. Stores that adapt staffing, promotions, or fulfillment in real time gain an edge. This doesn’t mean abandoning centralized platforms but rather extending them with localized execution.</p>



<p>Telecom providers, colocation operators, and cloud vendors recognize this opportunity. Telecom companies aim to monetize network proximity by converting metro infrastructure into application platforms. Colocation providers position regional facilities as neutral points for latency-sensitive workloads, data exchange, and multi-cloud interconnection. Hyperscale cloud vendors respond by expanding managed services through local zones, distributed appliances, and edge-specific platforms. Everyone strives to control the plane in a world where compute becomes increasingly decentralized.</p>



<h2 class="wp-block-heading">When hype outruns architecture</h2>



<p>Deploying edge infrastructure is easy to celebrate in strategy decks because it sounds modern and inevitable. However, operating it at scale is much less glamorous. Managing a centralized cloud region is already challenging, but having hundreds of distributed sites with hardware limitations, physical exposure, inconsistent connectivity, and varying operational maturity presents a completely different set of problems. The issue isn’t just deploying small clusters across many locations. It involves life-cycle management, security hardening, observability, orchestration, failover, and governance within an inherently fragmented estate.</p>



<p>Security complexity rises as each distributed site increases the attack surface. Remote, diverse infrastructure makes patching harder. <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">Identity</a>, certificates, and policies must be consistent across locations with varying staffing and controls. Many underestimate the operational burden, thinking edge is just cloud with shorter networks.</p>



<p><a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">Observability </a>remains a significant gap. Distributed systems fail in distributed ways, which rapidly multiplies blind spots. If enterprises cannot monitor what is happening across thousands of nodes, local clusters, gateways, and data pipelines, they are not truly operating at the edge—they are building up technical debt in smaller units.</p>



<p>Interoperability also remains underdeveloped. Despite vendor claims, many edge solutions are still too tightly linked to specific hardware stacks, connectivity methods, or cloud ecosystems. This creates lock-in risks exactly when enterprises seek greater architectural flexibility.</p>



<p>Edge advocates stress lower latency and better bandwidth, both of which provide real benefits. However, local infrastructure costs include capital, staffing, remote management, and maintenance. The case is strong if the workload genuinely needs local processing but weak if it’s adopted just because it sounds strategic. Running workloads at the edge without real-time capabilities, sovereignty, or resilience is often just expensive infrastructure rather than true innovation.</p>



<p>That is why enterprise leaders should resist the temptation to frame edge as the next universal destination for workloads. It is not. Some apps fit in centralized cloud regions, some belong in data centers, and others in localized facilities. The aim isn’t architectural purity but placement discipline. A helpful way to think about edge adoption in the next three to five years is to start with three questions:</p>



<ol class="wp-block-list">
<li>What decisions need to be made locally because of latency, safety, or user experience?</li>



<li>What data should remain local because regulation, privacy, or economics make centralization a poor option?</li>



<li>What operations must keep going even when connectivity to a centralized cloud is limited?</li>
</ol>



<p>If a workload clearly benefits from one or more of those criteria, edge deserves serious consideration. If not, it probably fits better in a more centralized setup.</p>



<p>CIOs and architects should also avoid treating edge as a disconnected side project. The preferred model remains the integrated <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid cloud</a>. Centralized platforms are still ideal for data aggregation, long-term storage, model training, enterprisewide policies, and shared digital services. Edge is where execution occurs close to the source of interaction. More mature organizations will treat these as coordinated layers within one architecture, rather than opposing camps in an infrastructure debate.</p>



<p>The cloud market is evolving beyond the one-size-fits-all centralization model that characterized its early days. This is the cloud maturing. Smart cities, industrial systems, healthcare networks, telecom infrastructure, and low-latency digital services all point to the same truth: Proximity has become a crucial architectural factor that can no longer be overlooked.</p>



<p>Enterprises don’t need edge computing everywhere. They need a strategy for where it truly matters. The next stage of cloud architecture will reward organizations that recognize a simple truth: The most effective cloud is the one that intentionally distributes intelligence.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Basic and advanced Java serialization]]></title>
<description><![CDATA[Serialization is the process of converting a Java object into a sequence of bytes so they can be written to disk, sent over a network, or stored outside of memory. Later, the Java virtual machine (JVM) reads those bytes and reconstructs the original object. This process is called deserialization....]]></description>
<link>https://tsecurity.de/de/3382596/ai-nachrichten/basic-and-advanced-java-serialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3382596/ai-nachrichten/basic-and-advanced-java-serialization/</guid>
<pubDate>Thu, 26 Mar 2026 10:02:44 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Serialization</em> is the process of converting a <a href="https://www.infoworld.com/article/4050993/jdk-26-the-new-features-in-java-26.html">Java</a> object into a sequence of bytes so they can be written to disk, sent over a network, or stored outside of memory. Later, the <a href="https://www.infoworld.com/article/2269370/what-is-the-jvm-introducing-the-java-virtual-machine.html">Java virtual machine (JVM)</a> reads those bytes and reconstructs the original object. This process is called <em>deserialization</em>.</p>



<p>Under normal circumstances, objects exist only in memory and disappear when a program terminates. Serialization allows an object’s state to outlive the program that created it, or to be transferred between different execution contexts.</p>



<aside class="sidebar large">
<h3>Get the code</h3>
<p>To follow along with the examples in this article, you can download the accompanying source code <a href="https://github.com/rafadelnero/javaworld-challengers/tree/master/src/main/java/com/javaworld/javachallengers/serialization">here</a>. All examples were written and tested using Java 25 or later.</p>
</aside>




<h2 class="wp-block-heading">The Serializable interface</h2>



<p>Java does not allow every object to be serialized. A class must explicitly opt in by implementing the <code>Serializable</code> interface, as shown here:</p>



<pre class="wp-block-code"><code>public class Challenger implements Serializable {

    private Long id;
    private String name;

    public Challenger(Long id, String name) {
        this.id = id;
        this.name = name;
    }
}</code></pre>



<p><code>Serializable</code> (<code>java.io.Serializable</code>) is a <em>marker interface</em>, meaning that it does not define any methods. By implementing it, the class signals to the JVM that its instances may be converted into bytes. If Java attempts to serialize an object whose class does not implement the <code>Serializable</code> interface, it fails at runtime with a <code>NotSerializableException</code>. There is no compile‑time warning.</p>



<p>Serialization traverses the entire object graph. Every non‑transient field must refer to an object that is itself serializable. If any referenced object cannot be serialized, the entire operation fails. All primitive wrapper types (<code>Integer</code>, <code>Long</code>, <code>Boolean</code>, and others), as well as <code>String</code>, implement <code>Serializable</code>, which is why they can be safely used in serialized object graphs.</p>



<h2 class="wp-block-heading">Limits of Java serialization</h2>



<p>Serialization stores instance state and preserves reference identity within the object graph (shared references and cycles). It does not preserve behavior or JVM identity across runs. Remember the following guidelines when using serialization:</p>



<ul class="wp-block-list">
<li>Instance fields are written to the byte stream.</li>



<li>Behavior is not serialized.</li>



<li>Static fields are not serialized.</li>



<li>Object identity is preserved.</li>
</ul>



<p>Also note: If two fields reference the same object before serialization, that relationship is preserved after deserialization.</p>



<h2 class="wp-block-heading">A Java serialization example</h2>



<p>As an example of serialization, consider the following example, a <em>Java Challengers</em> player:</p>



<pre class="wp-block-code"><code>Challenger duke = new Challenger(1L, "Duke");</code></pre>



<p>What do you notice? Let’s unpack it.</p>



<h3 class="wp-block-heading">1. Writing the object</h3>



<p>First, Java verifies that the class implements <code>Serializable</code>, converts the object’s field values into bytes, and writes them to the file:</p>



<pre class="wp-block-code"><code>try (ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("duke.ser"))) {
    out.writeObject(duke);
}</code></pre>



<h3 class="wp-block-heading">2. Reading the object back</h3>



<p>During deserialization, the serializable class’s own constructor is not called. The JVM creates the object through an internal mechanism and assigns field values directly from the serialized data. However, if the class extends a nonserializable superclass, that superclass’s no‑argument constructor <em>will</em> run:</p>



<pre class="wp-block-code"><code>try (ObjectInputStream in = new ObjectInputStream(new FileInputStream("duke.ser"))) {
    Challenger duke = (Challenger) in.readObject();
}</code></pre>



<p>This behavior often surprises developers the first time they debug a deserialized object, as the invariants are silently broken. This distinction is also important in class hierarchies, which we’ll discuss later in the article.</p>



<h2 class="wp-block-heading">Serialization callbacks</h2>



<p>Because the JVM controls object creation and field restoration during serialization, it also provides hooks that allow a class to customize how its state is written and restored. A class can define two private methods with exact signatures:</p>



<pre class="wp-block-code"><code>private void writeObject(ObjectOutputStream out) throws IOException
private void readObject(ObjectInputStream in) throws IOException, ClassNotFoundException</code></pre>



<p>These methods are not called directly by application code. They are JVM callbacks invoked automatically during serialization and deserialization. Calling them manually results in a <code>NotActiveException</code>, because they require an active serialization context managed by the JVM:</p>



<pre class="wp-block-code"><code>import java.io.*;

public class OrderSensitiveExample implements Serializable {
    private static final long serialVersionUID = 1L;

    void main() throws IOException, ClassNotFoundException {
        OrderSensitiveExample example = new OrderSensitiveExample();

        // Serialization: triggers writeObject(...)
        try (ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("example.ser"))) {
            out.writeObject(example);
        }

        // Deserialization: triggers readObject(...)
        try (ObjectInputStream in = new ObjectInputStream(new FileInputStream("example.ser"))) {
            in.readObject();
        }
    }

    private void writeObject(ObjectOutputStream out) throws IOException {
        out.defaultWriteObject();
        out.writeObject("Duke");
        out.writeObject("Juggy");
    }

    private void readObject(ObjectInputStream in) throws IOException, ClassNotFoundException {
        in.defaultReadObject();
        String first = (String) in.readObject();
        String second = (String) in.readObject();

        System.out.println(first + " " + second);
    }
}</code></pre>



<p>Meanwhile, <code>writeObject</code> and <code>readObject</code> are invoked by the JVM. This is done via <a href="https://www.infoworld.com/article/3489879/better-than-reflection-using-method-handles-and-variable-handles-in-java.html">Java reflection</a>, as part of <code>ObjectOutputStream.writeObject</code> and <code>ObjectInputStream.readObject</code>, and cannot be meaningfully called by application code.</p>



<h2 class="wp-block-heading">Using serialVersionUID for version control</h2>



<p>Every serializable class has a version identifier called <code>serialVersionUID</code>. This value is written into the serialized data. During deserialization, the JVM compares the value stored in the serialized data with the value declared in the current version of the class. If they differ, deserialization fails with an <code>InvalidClassException</code>.</p>



<p>If you do not declare a <code>serialVersionUID</code>, Java generates one automatically based on the given class structure. Adding a field, removing a method, or even recompiling the class can change it and break compatibility. This is why  relying on the generated value is usually a mistake.</p>



<h3 class="wp-block-heading">Choosing a serialVersionUID</h3>



<p>For new classes, it is common and correct to start with the following declaration:</p>



<pre class="wp-block-code"><code>private static final long serialVersionUID = 1L;</code></pre>



<p>IDEs often suggest long, generated values that mirror the JVM’s default computation. While technically correct, those values are frequently misunderstood. They do not distinguish objects, prevent name collisions, or identify individual instances. All objects of the same class share the same <code>serialVersionUID</code>.</p>



<p>The purpose of this value is to identify the class definition, not the object. It acts as a compatibility check during deserialization, ensuring that the class structure matches the one used when the data was written. This usually becomes a problem only after data has already been serialized and deployed.</p>



<p>The number itself has no special meaning; Java does not treat 1L differently from any other value. What matters is that the value is explicit, stable, and changed intentionally.</p>



<h3 class="wp-block-heading">When to change serialVersionUID</h3>



<p>You should change <code>serialVersionUID</code> when a class change causes previously serialized field values to have a different meaning for the current code.</p>



<p>Typical reasons include removing or renaming a serialized field, changing the type of a serialized field, changing the meaning of stored values such as status codes, introducing new constraints that old data may violate, or changing the class hierarchy or custom serialization logic.</p>



<p>In these cases, deserialization may still succeed, but the resulting object would represent an incorrect logical state. Changing the <code>serialVersionUID</code> ensures such data is rejected instead of silently misused.</p>



<p>If changes only add behavior or optional data, such as adding new fields or methods, the value usually does not need to change.</p>



<h2 class="wp-block-heading">Excluding fields with transient</h2>



<p>Some fields should not be serialized, such as passwords, cached values, or temporary data. In these cases, you can use the <code>transient</code> keyword:</p>



<pre class="wp-block-code"><code>public class ChallengerAccount implements Serializable {

    private static final long serialVersionUID = 1L;

    private String username;
    private transient String password;

    public ChallengerAccount(String username, String password) {
        this.username = username;
        this.password = password;
    }
}</code></pre>



<p>A field marked <code>transient</code> is skipped during serialization. When the object is deserialized, the field is set to its default value, which is usually null.</p>



<h2 class="wp-block-heading">Serialization and inheritance</h2>



<p>Serialization works across class hierarchies, but there are strict rules.</p>



<p>If a superclass does not implement <code>Serializable</code>, its fields are not serialized, and it must provide a no‑argument constructor. This failure tends to surface late, often after a seemingly harmless refactor of a base class:</p>



<pre class="wp-block-code"><code>class Person {
    String name;
    public Person() { this.name = "unknown"; }
}

class RankedChallenger extends Person implements Serializable {
    private static final long serialVersionUID = 1L;
    int ranking;
}</code></pre>



<p>During deserialization, the superclass constructor runs and initializes its fields, while only the subclass fields are restored from the serialized data. If the no‑argument constructor is missing, deserialization fails at runtime.</p>



<h2 class="wp-block-heading">Custom serialization with sensitive data</h2>



<p>Revisiting the <code>ChallengerAccount</code> example we looked at earlier, the password field was marked as <code>transient</code>, so it is not included in default serialization and will be null after deserialization. In controlled environments, this behavior can be overridden by defining custom serialization logic.</p>



<p>In the example below, the <code>writeObject</code> and <code>readObject</code> methods are shown inline for clarity, but they must be declared as private methods inside the serializable class. Here’s what happens during deserialization:</p>



<pre class="wp-block-code"><code>private void writeObject(ObjectOutputStream out) throws IOException {
    out.defaultWriteObject();
    out.writeObject(password);
}

private void readObject(ObjectInputStream in) throws IOException, ClassNotFoundException {
    in.defaultReadObject();
    this.password = (String) in.readObject();
}</code></pre>



<p>This is considered <em>custom serialization</em> because the class explicitly writes and reads part of its state instead of relying entirely on the JVM’s default mechanism. The call to <code>readObject()</code> does not read a field by name. Java serialization is a linear byte stream, not a keyed structure.</p>



<p>The value returned here is simply the next object in the stream, which happens to be the password because it was written immediately after the default object data. For this reason, values must be read in the exact order they were written. Changing that order will corrupt the stream or cause deserialization to fail.</p>



<h2 class="wp-block-heading">Transforming data during serialization</h2>



<p>Custom serialization can also transform data before writing it. This is useful for derived values, normalization, or compact representations:</p>



<pre class="wp-block-code"><code>public class ChallengerProfile implements Serializable {

    private static final long serialVersionUID = 1L;

    private String username;
    private transient LocalDate joinDate;

    public ChallengerProfile(String username, LocalDate joinDate) {
        this.username = username;
        this.joinDate = joinDate;
    }
}</code></pre>



<p>The <code>joinDate</code> field is marked as transient, so it is not serialized by default. Although <code>LocalDate</code> is itself <code>Serializable</code>, marking it as transient and writing it as a single long demonstrates how custom serialization can transform a field into a different representation:</p>



<pre class="wp-block-code"><code>private void writeObject(ObjectOutputStream out) throws IOException {
    out.defaultWriteObject();
    out.writeLong(joinDate.toEpochDay());
}</code></pre>



<p>During deserialization, the epoch day is converted back into a <code>LocalDate</code>:</p>



<pre class="wp-block-code"><code>private void readObject(ObjectInputStream in)throws IOException, ClassNotFoundException {
    in.defaultReadObject();
    this.joinDate = LocalDate.ofEpochDay(in.readLong());
}</code></pre>



<p>The important point is not the specific transformation, but that <code>writeObject</code> and <code>readObject</code> must apply inverse transformations and read values in the exact order they were written. Here, <code>toEpochDay</code> and <code>ofEpochDay</code> are natural inverses: One converts a date to a number, and the other converts it back.</p>



<h2 class="wp-block-heading">Restoring derived fields</h2>



<p>Some fields are derived from others and should not be serialized:</p>



<pre class="wp-block-code"><code>public class ChallengerStats implements Serializable {

    private static final long serialVersionUID = 1L;

    private int wins;
    private int losses;

    private transient int score;

    public ChallengerStats(int wins, int losses) {
        this.wins = wins;
        this.losses = losses;
        this.score = calculateScore();
    }

    private int calculateScore() {
        return wins * 3 - losses;
    }
}</code></pre>



<p>After deserialization, <code>score</code> will be zero. It can be restored as follows:</p>



<pre class="wp-block-code"><code>private void readObject(ObjectInputStream in)  throws IOException, ClassNotFoundException {
    in.defaultReadObject();
    this.score = calculateScore();
}</code></pre>



<h2 class="wp-block-heading">Why order matters in custom serialization logic</h2>



<p>When writing custom serialization logic, the order in which values are written must exactly match the order in which they are read:</p>



<pre class="wp-block-code"><code>private void writeObject(ObjectOutputStream out) throws IOException {
    out.defaultWriteObject();
    out.writeInt(42);
    out.writeUTF("Duke");
    out.writeLong(1_000_000L);
}
private void readObject(ObjectInputStream in) throws IOException, ClassNotFoundException {
    in.defaultReadObject();
    int level = in.readInt();
    String name = in.readUTF();
    long score = in.readLong();
}</code></pre>



<p>Because the stream is not keyed by field name, each <code>read</code> call simply consumes the next value in sequence. If <code>readUTF</code> were called before <code>readInt</code>, the stream would attempt to interpret the bytes of an integer as a UTF string, resulting in corrupted data or a deserialization failure. This is one of the main reasons custom serialization should be used sparingly. A useful mental model is to think of serialization as a tape recorder: Deserialization must replay the tape in exactly the order it was recorded.</p>



<h2 class="wp-block-heading">Why serialization is risky</h2>



<p>Serialization is fragile when classes change. Even small modifications can make previously stored data unreadable.</p>



<p>Deserializing untrusted data is particularly dangerous. Deserialization can trigger unexpected code paths on attacker‑controlled object graphs, and this has been the source of real‑world security vulnerabilities.</p>



<p>For these reasons, Java serialization should be used only in controlled environments.</p>



<h2 class="wp-block-heading">When serialization makes sense</h2>



<p>Java serialization is suitable only for a narrow set of use cases where class versions and trust boundaries are tightly controlled.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Use case</strong></td><td><strong>Recommendation</strong></td></tr><tr><td>Internal caching</td><td>Java serialization works well when data is short-lived and controlled by the same application.</td></tr><tr><td>Session storage</td><td>Acceptable with care, provided all participating systems run compatible class versions.</td></tr><tr><td>Long-term storage</td><td>Risky: Even small class changes can make old data unreadable.</td></tr><tr><td>Public APIs</td><td>Use JSON. It is language-agnostic, stable across versions, and widely supported. Java serialization exposes implementation details and is fragile.</td></tr><tr><td>System-to-system communication</td><td>Prefer JSON or schema-based formats such as Protocol Buffers or Avro.</td></tr><tr><td>Cross-language communication</td><td>Avoid Java serialization entirely. It is Java-specific and not interoperable with other platforms.</td></tr></tbody></table> </div></figure>



<p><strong>Rule of thumb</strong>: If the data must survive class evolution, cross trust boundaries, or be consumed by non‑Java systems, prefer JSON or a schema‑based format over Java serialization.</p>



<h2 class="wp-block-heading">Advanced serialization techniques</h2>



<p>The mechanisms we’ve covered so far handle most practical scenarios, but Java serialization has a few additional tools for solving problems that default serialization cannot.</p>



<h3 class="wp-block-heading">Preserving singletons with readResolve</h3>



<p>Deserialization creates a new object. For classes that enforce a single instance, this breaks the guarantee silently:</p>



<pre class="wp-block-code"><code>public class GameConfig implements Serializable {

    private static final long serialVersionUID = 1L;
    private static final GameConfig INSTANCE = new GameConfig();

    private GameConfig() {}

    public static GameConfig getInstance() {
        return INSTANCE;
    }

    private Object readResolve() throws ObjectStreamException {
        return INSTANCE;
    }
}</code></pre>



<p>Without <code>readResolve</code>, deserializing a <code>GameConfig</code> would produce a second instance, and any identity check using <code>==</code> would fail. The method intercepts the deserialized object and substitutes the canonical one. The deserialized copy is discarded.</p>



<h3 class="wp-block-heading">Substituting objects with writeReplace</h3>



<p>Whereas <code>readResolve</code> controls what comes <em>out</em> of deserialization, <code>writeReplace</code> controls what goes <em>into</em> serialization. A class can define this method to substitute a different object before any bytes are written.</p>



<p>The two methods are often used together to implement a <em>serialization proxy</em>. One class represents the object’s runtime form, while another represents its serialized form.</p>



<p>In this example,<code>ChallengerWriteReplace</code> plays the role of the “real” object, while <code>ChallengerProxy</code> represents its serialized form:</p>



<pre class="wp-block-code"><code>public class ChallengerProxy implements Serializable {

    private static final long serialVersionUID = 1L;

    private final long id;
    private final String name;

    public ChallengerProxy(long id, String name) {
        this.id = id;
        this.name = name;
    }

    private Object readResolve() throws ObjectStreamException {
        return new ChallengerWriteReplace(id, name);
    }
}

class ChallengerWriteReplace implements Serializable {

    private static final long serialVersionUID = 1L;

    private long id;
    private String name;

    public ChallengerWriteReplace(long id, String name) {
        this.id = id;
        this.name = name;
    }

    private Object writeReplace() throws ObjectStreamException {
        return new ChallengerProxy(id, name);
    }
}</code></pre>



<p>When a <code>ChallengerWriteReplace</code> instance is serialized, its <code>writeReplace</code> method substitutes it with a lightweight <code>ChallengerProxy</code>. The proxy is the only object that is actually written to the byte stream.</p>



<p>During deserialization, the proxy’s <code>readResolve</code> method reconstructs a new <code>ChallengerWriteReplace</code> instance, and the proxy itself is discarded. The application never observes the proxy object directly.</p>



<p>This technique keeps the serialized form decoupled from the internal structure of <code>ChallengerWriteReplace</code>. As long as the proxy remains stable, the main class can evolve freely without breaking previously serialized data. It also provides a controlled point where invariants can be enforced during reconstruction.</p>



<h3 class="wp-block-heading">Filtering deserialized classes with ObjectInputFilter</h3>



<p>I have explained why deserializing untrusted data is dangerous. Introduced in Java 9, the <code>ObjectInputFilter</code> API gives applications a way to restrict which classes are allowed during deserialization:</p>



<pre class="wp-block-code"><code>ObjectInputFilter filter = ObjectInputFilter.Config.createFilter(
        "com.example.model.*;!*"
);

try (ObjectInputStream in = new ObjectInputStream(new FileInputStream("data.ser"))) {
    in.setObjectInputFilter(filter); // must be set before readObject()
    Object obj = in.readObject();
}</code></pre>



<p>This filter allows only classes under <code>com.example.model</code> and rejects everything else. The pattern syntax supports <code>allowlisting</code> by package, as well as setting limits on array sizes, object graph depth, and total object count.</p>



<p>Java 9 made it possible to set a process-wide filter via <code>ObjectInputFilter.Config.setSerialFilter</code> or the <code>jdk.serialFilter</code> system property, ensuring that no <code>ObjectInputStream</code> would be left unprotected by default. Java 17 extended this further by introducing <em>filter factories</em> (<code>ObjectInputFilter.Config.setSerialFilterFactory</code>), which allow context‑specific filters to be applied per stream rather than relying on a single global policy. If your application deserializes data that crosses a trust boundary, an input filter is not optional; it is the minimum viable defense.</p>



<h3 class="wp-block-heading">Java records and serialization</h3>



<p><a href="https://www.infoworld.com/article/4058874/introduction-to-java-records-simplified-data-centric-programming-in-java.html">Java records</a> can implement <code>Serializable</code>, but they behave differently from ordinary classes in one critical way: During deserialization, the record’s canonical constructor is called. This means any validation logic in the constructor runs on deserialized data, which is a significant safety advantage:</p>



<pre class="wp-block-code"><code>public record ChallengerRecord(Long id, String name) implements Serializable {
    public ChallengerRecord {
        if (id == null || name == null) {
            throw new IllegalArgumentException(
                    "id and name must not be null");
        }
    }
}</code></pre>



<p>With a traditional <code>Serializable</code> class, a corrupted or malicious stream could inject null values into fields that the constructor would normally reject. With a record, the constructor acts as a gatekeeper even during deserialization.</p>



<p>Records do not support <code>writeObject</code>, <code>readObject</code>, or <code>serialPersistentFields</code>. Their serialized form is derived entirely from their components, a design decision that intentionally favors predictability and safety over customization.</p>



<h2 class="wp-block-heading">Alternatives to Java serialization</h2>



<p>The <code>Externalizable</code> interface is an alternative to <code>Serializable</code> that gives the class complete control over the byte format. A class that implements <code>Externalizable</code> must define <code>writeExternal</code> and <code>readExternal</code>, and must provide a public no‑argument constructor:</p>



<pre class="wp-block-code"><code>public class ChallengerExt implements Externalizable {

    private long id;
    private String name;

    public ChallengerExt() {} // required

    public ChallengerExt(long id, String name) {
        this.id = id;
        this.name = name;
    }

    @Override
    public void writeExternal(ObjectOutput out) throws IOException {
        out.writeLong(id);
        out.writeUTF(name);
    }

    @Override
    public void readExternal(ObjectInput in) throws IOException {
        this.id = in.readLong();
        this.name = in.readUTF();
    }
}</code></pre>



<p>Unlike <code>Serializable</code>, no field metadata or field values are written automatically. The class descriptor (class name and <code>serialVersionUID</code>) is still written, but the developer is fully responsible for writing and reading all instance state.</p>



<p>Because <code>writeExternal</code> and <code>readExternal</code> work directly with primitives and raw values, fields should use primitive types where possible. Using a wrapper type such as <code>Long</code> with <code>writeLong</code> would throw a <code>NullPointerException</code> if the value were null, since auto‑unboxing cannot handle that case.</p>



<p>This approach can produce more compact output, but the developer is fully responsible for versioning, field ordering, and backward compatibility.</p>



<p>In practice, <code>Externalizable</code> is rarely used in modern Java. When a full control over-the-wire format is needed, most teams choose <a href="https://protobuf.dev/">Protocol Buffers</a>, <a href="https://avro.apache.org/">Avro</a>, or similar schema‑based formats instead.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Java serialization is a low-level JVM mechanism for saving and restoring object state. Known for being powerful but unforgiving, serialization bypasses constructors, assumes stable class definitions, and provides no automatic safety guarantees. Used deliberately in tightly controlled systems, it can be effective. Used casually, it introduces subtle bugs and serious security vulnerabilities. Understanding the trade-offs discussed in this article will help you use serialization correctly and avoid accidental misuse.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RedLine Infostealer Network’s Second Defendant Now Faces a U.S. Court]]></title>
<description><![CDATA[Seventeen months after international law enforcement dismantled one of the world's most damaging infostealing malware networks, a second defendant has arrived in a U.S. federal courtroom — this time extradited from Armenia — as the prosecution of the RedLine infostealer operation continues to wor...]]></description>
<link>https://tsecurity.de/de/3382303/it-security-nachrichten/redline-infostealer-networks-second-defendant-now-faces-a-us-court/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3382303/it-security-nachrichten/redline-infostealer-networks-second-defendant-now-faces-a-us-court/</guid>
<pubDate>Thu, 26 Mar 2026 08:06:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="RedLine Infostealer, infostealer Operator, Armenia, Infostealer Operator Armenia, US Extradition, FBI, Hambardzum Minasyan, Minasyan" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia.webp 800w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia.webp 800w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/RedLine-Infostealer-Operator-Armenia-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="RedLine Infostealer Network's Second Defendant Now Faces a U.S. Court 1"></p>Seventeen months after international law enforcement dismantled one of the world's most damaging infostealing malware networks, a second defendant has arrived in a U.S. federal courtroom — this time extradited from Armenia — as the prosecution of the RedLine infostealer operation continues to work through the criminal network that built and sustained it.

Hambardzum Minasyan, an Armenian national, appeared in an Austin federal court after being extradited to the United States to face charges related to his alleged role in the RedLine infostealer scheme. The Justice Department's Office of International Affairs secured Minasyan's arrest and extradition on March 23, 2026, with significant assistance from Eurojust's ICHIP attorney adviser based at The Hague.

Minasyan faces three counts: conspiracy to commit access device <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="27269">fraud</a>, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. If convicted, he faces up to 10 years in prison on the access device fraud charge and up to 20 years each on the remaining two counts.

An infostealer is <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="27270">malware</a> designed to silently harvest credentials, browser cookies, saved passwords, financial data, and cryptocurrency wallet information from an infected device, then transmit that data to attackers — often in seconds, without any visible sign of compromise.

The indictment alleges that Minasyan and his co-conspirators maintained digital infrastructure, including command-and-control servers and administrative panels, to deploy the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="27273">malware</a> and collected payments from affiliates using RedLine against victims.

Minasyan specifically registered two virtual private servers and two <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="27275">internet</a> domains to support the RedLine scheme, created repositories on an online file-sharing site to distribute RedLine to affiliates, and registered a cryptocurrency account in November 2021 to receive payments.

RedLine operated on a Malware-as-a-Service model. It is a criminal franchise structure where the core developers build and maintain the malware platform, then license it to affiliates who run their own infection campaigns in exchange for a fee. Affiliates distributed RedLine to victims using malvertising, <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="27268">phishing</a> emails, fraudulent software downloads, and malicious software sideloading, with various ruses — including COVID-19 and Windows update lures — used to trick victims into downloading the malware.

RedLine and its derivative Meta <a class="wpil_keyword_link" href="https://cyble.com/malware/infostealer/" target="_blank" rel="noopener" title="infostealer" data-wpil-keyword-link="linked" data-wpil-monitor-id="27274">infostealer</a> could also enable cybercriminals to bypass multifactor authentication through the theft of authentication cookies and session tokens. Multifactor authentication is a <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="27272">security</a> layer requiring users to verify their identity through a second method beyond a password; stealing session cookies allows attackers to impersonate an already-authenticated user and render that protection useless.

The Lapsus$ threat group used RedLine to obtain passwords and cookies from an employee account at a major technology company and subsequently used that access to obtain and leak limited source code. RedLine also infected hundreds of systems belonging to U.S. Department of Defense personnel, and authorities have described its victim count in the millions globally.

Minasyan's extradition represents the second defendant charged in connection with Operation Magnus, the joint international takedown announced in October 2024.
<h5>Read: <a href="https://thecyberexpress.com/operation-magnus-redline-and-meta-infostealer/" target="_blank" rel="noopener">Law Enforcement Puts a Damning Dent in RedLine and Meta Infostealer Operations</a></h5>
Operation Magnus — a Joint <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="Cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="27271">Cybercrime</a> Action Taskforce operation supported by Europol — resulted in Dutch authorities seizing three servers running the malware, Belgian authorities seizing communication channels and Telegram accounts used by the operators, and the recovery of a database of thousands of RedLine and Meta clients. That client database gave investigators a roadmap for follow-on prosecutions that continues to generate results.

The first defendant charged, Russian national Maxim Rudometov, was identified as a developer and administrator of RedLine and unsealed in the Western District of Texas in October 2024. Rudometov, believed to reside in Krasnodar, Russia, is not expected to face extradition given his location.
<h5>Read: <a href="https://thecyberexpress.com/u-s-charges-man-redline-infostealer-operations/" target="_blank" rel="noopener">U.S. Charges Man Behind RedLine Infostealer that Infected U.S. DoD Personnel Systems</a></h5>
Minasyan's extradition from Armenia, by contrast, demonstrates the value of maintaining extradition treaty relationships and Eurojust cooperation frameworks that can reach defendants outside of jurisdictions beyond U.S. reach.

The investigation is a <a href="https://www.justice.gov/usao-wdtx/pr/armenian-man-extradited-us-faces-charges-role-infostealing-malware-scheme" target="_blank" rel="nofollow noopener">joint effort</a> by the FBI Austin Cyber Task Force, which includes the Naval Criminal Investigative Service, IRS Criminal Investigation, the Department of Defense Office of Inspector General's Defense Criminal Investigative Service, and the Army Criminal Investigation Division.

The case demonstrates a sustained prosecution strategy, where rather than treating Operation Magnus as a one-time disruption event, the DOJ has continued converting the intelligence gained from seized infrastructure and client databases into individual criminal referrals across multiple jurisdictions.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare’s new Dynamic Workers ditch containers to run AI agent code 100x faster]]></title>
<description><![CDATA[Web infrastructure giant Cloudlflare is seeking to transform the way enterprises deploy AI agents with the open beta release of Dynamic Workers, a new lightweight, isolate-based sandboxing system that it says starts in milliseconds, uses only a few megabytes of memory, and can run on the same mac...]]></description>
<link>https://tsecurity.de/de/3377948/it-nachrichten/cloudflares-new-dynamic-workers-ditch-containers-to-run-ai-agent-code-100x-faster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377948/it-nachrichten/cloudflares-new-dynamic-workers-ditch-containers-to-run-ai-agent-code-100x-faster/</guid>
<pubDate>Tue, 24 Mar 2026 20:31:17 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Web infrastructure giant Cloudlflare is seeking to transform the way enterprises deploy AI agents with<a href="https://blog.cloudflare.com/dynamic-workers"> the open beta release of Dynamic Workers,</a> a new lightweight, isolate-based sandboxing system that it says starts in milliseconds, uses only a few megabytes of memory, and can run on the same machine — even the same thread — as the request that created it. </p><p>Compared with traditional Linux containers, the company says that makes Dynamic Workers roughly 100x faster to start and between 10x and 100x more memory efficient.</p><p>Cloudflare has spent months pushing what it calls “Code Mode,” the idea that large language models often perform better when they are given an API and asked to write code against it, rather than being forced into one tool call after another. </p><p>The company says converting an MCP server into a TypeScript API can cut token usage by 81%, and it is now positioning Dynamic Workers as the secure execution layer that makes that approach practical at scale.</p><p>For enterprise technical decision makers, that is the bigger story. Cloudflare is trying to turn sandboxing itself into a strategic layer in the AI stack. If agents increasingly generate small pieces of code on the fly to retrieve data, transform files, call services or automate workflows, then the economics and safety of the runtime matter almost as much as the capabilities of the model. Cloudflare’s pitch is that containers and microVMs remain useful, but they are too heavy for a future where millions of users may each have one or more agents writing and executing code constantly.</p><h2><b>The history of modern isolated runtime environments</b></h2><p>To understand why Cloudflare is doing this, it helps to look at the longer arc of secure code execution. Modern sandboxing has evolved through three main models, each trying to build a better digital box: smaller, faster and more specialized than the one before it.</p><p>The first model is the isolate. Google introduced the <code>v8::Isolate</code> API in 2011 so the V8 JavaScript engine could run many separate execution contexts efficiently inside the same process. In effect, a single running program could spin up many small, tightly separated compartments, each with its own code and variables. </p><p>In 2017, Cloudflare adapted that browser-born idea for the cloud with Workers, betting that the traditional cloud stack was too slow for instant, globally distributed web tasks. The result was a runtime that could start code in milliseconds and pack many environments onto a single machine. The trade-off is that isolates are not full computers. They are strongest with JavaScript, TypeScript and WebAssembly, and less natural for workloads that expect a traditional machine environment.</p><p>The second model is the container. Containers had been technically possible for years through Linux kernel features, but the company <a href="https://www.docker.com/">Docker</a> turned them into the default software packaging model when it popularized them in 2013.</p><p>Containers solved a huge portability problem by letting developers package code, libraries and settings into a predictable unit that could run consistently across systems. That made them foundational to modern cloud infrastructure. But they are relatively heavy for the sort of short-lived tasks Cloudflare is talking about here. The company says containers generally take hundreds of milliseconds to boot and hundreds of megabytes of memory to run, which becomes costly and slow when an AI-generated task only needs to execute for a moment.</p><p>The third model is the microVM. Popularized by AWS Firecracker in 2018, microVMs were designed to offer stronger machine-like isolation than containers without the full bulk of a traditional virtual machine. They are attractive for running untrusted code, which is why they have started to show up in newer AI-agent systems such as Docker Sandboxes. But they still sit between the other two models: stronger isolation and more flexibility than an isolate, but slower and heavier as well.</p><p>That is the backdrop for Cloudflare’s pitch. The company is not claiming containers disappear, or that microVMs stop mattering. It is claiming that for a growing class of web-scale, short-lived AI-agent workloads, the default box has been too heavy, and the isolate may now be the better fit.</p><h2><b>Cloudflare’s case against the container bottleneck</b></h2><p>Cloudflare’s argument is blunt: for “consumer-scale” agents, containers are too slow and too expensive. In the company’s framing, a container is fine when a workload persists, but it is a bad fit when an agent needs to run one small computation, return a result and disappear. Developers either keep containers warm, which costs money, or tolerate cold-start delay, which hurts responsiveness. They may also be tempted to reuse a live sandbox across multiple tasks, which weakens isolation.</p><p><a href="https://developers.cloudflare.com/dynamic-workers/">Dynamic Worker Loader is Cloudflare’s answer.</a> The API allows one Worker to instantiate another Worker at runtime with code provided on the fly, usually by a language model. Because these dynamic Workers are built on isolates, Cloudflare says they can be created on demand, run one snippet of code, and then be thrown away immediately afterward. In many cases, they run on the same machine and even the same thread as the Worker that created them, which removes the need to hunt for a warm sandbox somewhere else on the network.</p><p>The company is also pushing hard on scale. It says many container-based sandbox providers limit concurrent sandboxes or the rate at which they can be created, while Dynamic Workers inherit the same platform characteristics that already let Workers scale to millions of requests per second. In Cloudflare’s telling, that makes it possible to imagine a world where every user-facing AI request gets its own fresh, isolated execution environment without collapsing under startup overhead.</p><h2><b>Security remains the hardest part</b></h2><p>Cloudflare does not pretend this is easy to secure. In fact, the company explicitly says hardening an isolate-based sandbox is trickier than relying on hardware virtual machines, and notes that security bugs in V8 are more common than those in typical hypervisors. That is an important admission, because the entire thesis depends on convincing developers that an ultra-fast software sandbox can also be safe enough for AI-generated code.</p><p>Cloudflare’s response is that it has nearly a decade of experience doing exactly that. The company points to automatic rollout of V8 security patches within hours, a custom second-layer sandbox, dynamic cordoning of tenants based on risk, extensions to the V8 sandbox using hardware features like MPK, and research into defenses against Spectre-style side-channel attacks. It also says it scans code for malicious patterns and can block or further sandbox suspicious workloads automatically. Dynamic Workers inherit that broader Workers security model.</p><p>That matters because without the security story, the speed story sounds risky. With it, Cloudflare is effectively arguing that it has already spent years making isolate-based multi-tenancy safe enough for the public web, and can now reuse that work for the age of AI agents.</p><h2><b>Code Mode: from tool orchestration to generated logic</b></h2><p>The release makes the most sense in the context of Cloudflare’s larger Code Mode strategy. The idea is simple: instead of giving an agent a long list of tools and asking it to call them one by one, give it a programming surface and let it write a short TypeScript function that performs the logic itself. That means the model can chain calls together, filter data, manipulate files and return only the final result, rather than filling the context window with every intermediate step. Cloudflare says that cuts both latency and token usage, and improves outcomes especially when the tool surface is large.</p><p>The company points to its own Cloudflare MCP server as proof of concept. Rather than exposing the full Cloudflare API as hundreds of individual tools, it says the server exposes the entire API through two tools — search and execute — in under 1,000 tokens because the model writes code against a typed API instead of navigating a long tool catalog.</p><p>That is a meaningful architectural shift. It moves the center of gravity from tool orchestration toward code execution. And it makes the execution layer itself far more important.</p><h2><b>Why Cloudflare thinks TypeScript beats HTTP for agents</b></h2><p>One of the more interesting parts of the launch is that Cloudflare is also arguing for a different interface layer. MCP, the company says, defines schemas for flat tool calls but not for programming APIs. OpenAPI can describe REST APIs, but it is verbose both in schema and in usage. TypeScript, by contrast, is concise, widely represented in model training data, and can communicate an API’s shape in far fewer tokens.</p><p>Cloudflare says the Workers runtime can automatically establish a Cap’n Web RPC bridge between the sandbox and the harness code, so a dynamic Worker can call those typed interfaces across the security boundary as if it were using a local library. That lets developers expose only the exact capabilities they want an agent to have, without forcing the model to reason through a sprawling HTTP interface.</p><p>The company is not banning HTTP. In fact, it says Dynamic Workers fully support HTTP APIs. But it clearly sees TypeScript RPC as the cleaner long-term interface for machine-generated code, both because it is cheaper in tokens and because it gives developers a narrower, more intentional security surface.</p><h2><b>Credential injection and tighter control over outbound access</b></h2><p>One of the more practical enterprise features in the release is <code>globalOutbound</code>, which lets developers intercept every outbound HTTP request from a Dynamic Worker. They can inspect it, rewrite it, inject credentials, respond to it directly, or block it entirely. That makes it possible to let an agent reach outside services while never exposing raw secrets to the generated code itself.</p><p>Cloudflare positions that as a safer way to connect agents to third-party services requiring authentication. Instead of trusting the model not to mishandle credentials, the developer can add them on the way out and keep them outside the agent’s visible environment. In enterprise settings, that kind of blast-radius control may matter as much as the performance gains.</p><h2><b>More than a runtime: the helper libraries matter too</b></h2><p>Another reason the announcement lands as more than a low-level runtime primitive is that Cloudflare is shipping a toolkit around it. The <code>@cloudflare/codemode</code> package is designed to simplify running model-generated code against AI tools using Dynamic Workers. At its core is <code>DynamicWorkerExecutor()</code>, which sets up a purpose-built sandbox with code normalization and direct control over outbound fetch behavior. The package also includes utility functions to wrap an MCP server into a single <code>code()</code> tool or generate MCP tooling from an OpenAPI spec.</p><p>The <code>@cloudflare/worker-bundler</code> package handles the fact that Dynamic Workers expect pre-bundled modules. It can resolve npm dependencies, bundle them with <code>esbuild</code>, and return the module map the Worker Loader expects. The <code>@cloudflare/shell</code> package adds a virtual filesystem backed by a durable Workspace using SQLite and R2, with higher-level operations like read, write, search, replace, diff and JSON update, plus transactional batch writes.</p><p>Taken together, those packages make the launch feel much more complete. Cloudflare is not just exposing a fast sandbox API. It is building the surrounding path from model-generated logic to packaged execution to persistent file manipulation.</p><h2><b>Isolates versus microVMs: two different homes for agents</b></h2><p>Cloudflare’s launch also highlights a growing split in the AI-agent market. One side emphasizes fast, disposable, web-scale execution. The other emphasizes deeper, more persistent environments with stronger machine-like boundaries.</p><p><a href="https://docs.docker.com/ai/sandboxes/">Docker Sandboxes</a> is a useful contrast. Rather than using standard containers alone, it uses lightweight microVMs to give each agent its own private Docker daemon, allowing the agent to install packages, run commands and modify files without directly exposing the host system. That is a better fit for persistent, local or developer-style environments. Cloudflare is optimizing for something different: short-lived, high-volume execution on the global web.</p><p>So the trade-off is not simply security versus speed. It is depth versus velocity. MicroVMs offer a sturdier private fortress and broader flexibility. Isolates offer startup speed, density and lower cost at internet scale. That distinction may become one of the main dividing lines in agent infrastructure over the next year.</p><h2><b>Community reaction: hype, rivalry and the JavaScript catch</b></h2><p>The release also drew immediate attention from developers on X, with reactions that captured both excitement and skepticism. </p><p>Brandon Strittmatter, a Cloudflare product lead and founder of Outerbase, <a href="https://x.com/burcs/status/2036435172623622571">called the move</a> “classic Cloudflare,” praising the company for “changing the current paradigm on containers/sandboxes by reinventing them to be lightweight, less expensive, and ridiculously fast.” </p><p><a href="https://x.com/Zackary_Chapple/status/2036442657744957728">Zephyr Cloud CEO Zack Chapple</a> called the release “worth shouting from the mountain tops.”</p><p>But the strongest caveat surfaced quickly too: this system works best when the agent writes JavaScript. Cloudflare says Workers can technically run Python and WebAssembly, but that for small, on-demand snippets, “JavaScript will load and run much faster.” </p><p>That prompted criticism from YouTuber and ThursdAI podcast host <a href="https://x.com/altryne/status/2036442314382651449">Alex Volkov</a>, who wrote that he “got excited... until I got here,” reacting to the language constraint.</p><p>Cloudflare’s defense is pragmatic and a little provocative. Humans have language loyalties, the company argues, but agents do not. In Cloudflare’s words, “AI will write any language you want it to,” and JavaScript is simply well suited to sandboxed execution on the web. That may be true in the narrow sense the company intends, but it also means the platform is most naturally aligned with teams already comfortable in the JavaScript and TypeScript ecosystem.</p><p>The announcement also triggered immediate competitive positioning.<a href="https://x.com/NathanFlurry/status/2036441313424670848"> Nathan Flurry of Rivet</a> used the moment to contrast his Secure Exec product as an open-source alternative that supports a broader range of platforms including Vercel, Railway and Kubernetes rather than being tied closely to Cloudflare’s own stack. </p><p>That reaction is worth noting because it shows how quickly the sandboxing market around agents is already splitting between vertically integrated platforms and more portable approaches.</p><h2><b>Early use cases: AI apps, automations and generated platforms</b></h2><p>Cloudflare is pitching Dynamic Workers for much more than quick code snippets. The company highlights Code Mode, AI-generated applications, fast development previews, custom automations and user platforms where customers upload or generate code that must run in a secure sandbox.</p><p>One example it spotlights is Zite, which Cloudflare says is building an app platform where users interact through chat while the model writes TypeScript behind the scenes to build CRUD apps, connect to services like Stripe, Airtable and Google Calendar, and run backend logic. Cloudflare quotes Zite CTO and co-founder Antony Toron saying Dynamic Workers “hit the mark” on speed, isolation and security, and that the company now handles “millions of execution requests daily” using the system.</p><p>Even allowing for vendor framing, that example gets at the company’s ambition. Cloudflare is not just trying to make agents a bit more efficient. It is trying to make AI-generated execution environments cheap and fast enough to sit underneath full products.</p><h2><b>Pricing and availability</b></h2><p>Dynamic Worker Loader is now in open beta and available to all users on the Workers Paid plan. Cloudflare says dynamically loaded Workers are priced at $0.002 per unique Worker loaded per day, in addition to standard CPU and invocation charges, though that per-Worker fee is waived during the beta period. For one-off code generation use cases, the company says that cost is typically negligible compared with the inference cost of generating the code itself.</p><p>That pricing model reinforces the larger thesis behind the product: that execution should become a small, routine part of the agent loop rather than a costly special case.</p><h2><b>The bigger picture</b></h2><p>Cloudflare’s launch lands at a moment when AI infrastructure is becoming more opinionated. Some vendors are leaning toward long-lived agent environments, persistent memory and machine-like execution. Cloudflare is taking the opposite angle. For many workloads, it argues, the right agent runtime is not a persistent container or a tiny VM, but a fast, disposable isolate that appears instantly, executes one generated program, and vanishes.</p><p>That does not mean containers or microVMs go away. It means the market is starting to split by workload. Some enterprises will want deeper, more persistent environments. Others — especially those building high-volume, web-facing AI systems — may want an execution layer that is as ephemeral as the requests it serves.</p><p>Cloudflare is betting that this second category gets very large, very quickly. And if that happens, Dynamic Workers may prove to be more than just another Workers feature. They may be Cloudflare’s attempt to define what the default execution layer for internet-scale AI agents looks like.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Automating complex finance workflows with multimodal AI]]></title>
<description><![CDATA[Finance leaders are automating their complex workflows by actively adopting powerful new multimodal AI frameworks. Extracting text from unstructured documents presents a frequent headache for developers. Historically, standard optical character recognition systems failed to accurately digitise co...]]></description>
<link>https://tsecurity.de/de/3377600/ai-nachrichten/automating-complex-finance-workflows-with-multimodal-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377600/ai-nachrichten/automating-complex-finance-workflows-with-multimodal-ai/</guid>
<pubDate>Tue, 24 Mar 2026 18:17:39 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Finance leaders are automating their complex workflows by actively adopting powerful new multimodal AI frameworks. Extracting text from unstructured documents presents a frequent headache for developers. Historically, standard optical character recognition systems failed to accurately digitise complex layouts, frequently converting multi-column files, pictures, and layered datasets into an unreadable mess of plain text. The varied […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/automating-complex-finance-workflows-with-multimodal-ai/">Automating complex finance workflows with multimodal AI</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Converting inbound leads into customers at OpenAI]]></title>
<description><![CDATA[Learn how OpenAI used AI to deliver personalized answers at scale, converting inbound leads into customers.]]></description>
<link>https://tsecurity.de/de/3372096/ai-nachrichten/converting-inbound-leads-into-customers-at-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3372096/ai-nachrichten/converting-inbound-leads-into-customers-at-openai/</guid>
<pubDate>Mon, 23 Mar 2026 09:22:49 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn how OpenAI used AI to deliver personalized answers at scale, converting inbound leads into customers.]]></content:encoded>
</item>
<item>
<title><![CDATA[A Foolproof Formula for Air Frying Almost Anything]]></title>
<description><![CDATA[There's almost nothing you can't make in the air fryer, but cooking directions and recipes aren't always a one-to-one match. Here's what you need to know before converting.]]></description>
<link>https://tsecurity.de/de/3367479/it-nachrichten/a-foolproof-formula-for-air-frying-almost-anything/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3367479/it-nachrichten/a-foolproof-formula-for-air-frying-almost-anything/</guid>
<pubDate>Fri, 20 Mar 2026 17:32:01 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[There's almost nothing you can't make in the air fryer, but cooking directions and recipes aren't always a one-to-one match. Here's what you need to know before converting.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why enterprises aren’t seeing AI ROI — and what CIOS can do about it]]></title>
<description><![CDATA[Artificial intelligence is the most transformative technological development, changing the broader global operating environment. AI spending is projected to reach $2.52 trillion, which is a 44 percent year-over-year increase, according to Gartner’s 2026 Trend Report. Enterprises are positioning A...]]></description>
<link>https://tsecurity.de/de/3366313/it-security-nachrichten/why-enterprises-arent-seeing-ai-roi-and-what-cios-can-do-about-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3366313/it-security-nachrichten/why-enterprises-arent-seeing-ai-roi-and-what-cios-can-do-about-it/</guid>
<pubDate>Fri, 20 Mar 2026 11:05:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence is the most transformative technological development, changing the broader global operating environment. AI spending is projected to reach $2.52 trillion, which is a 44 percent year-over-year increase, according to Gartner’s 2026 Trend Report. Enterprises are positioning AI as a primary lever for value creation in response to <a href="https://mkto.deloitte.com/rs/712-CNF-326/images/DI_Tech-trends-2026.pdf" rel="nofollow">emerging trends</a>, aiming to drive revenue growth, margin expansion, productivity gains and scalable operating leverage. Yet, despite considerable investment, many organizations still struggle to translate their Board’s and CEO’s ambitions into verifiable financial outcomes for the CFO, because value is created through disciplined execution embedded in the enterprise operating fabric.</p>



<p>CIOs face a growing disconnect between optimism and outcomes. <a href="https://hbr.org/2026/01/hb-how-executives-are-thinking-about-ai-heading-into-2026" rel="nofollow">Executives</a> remain bullish on AI, continue to increase investment and report pockets of measurable business value. This drive sustains high vendor valuations, expanding infrastructure build-out and broad organizational initiatives centered on AI capabilities. The real challenge for all enterprises is ROAI. ROAI represents the net realization of hard benefits — revenue growth, cost reduction, margin improvement and risk mitigation — verified in financial results, supported by soft benefits such as productivity, decision quality, workforce capacity and resilience that protect and sustain those returns over time. When ROAI stalls, the cause is rarely technical; it stems from gaps in change leadership, workforce readiness and operating-model alignment. Long-term success depends on treating ROAI as an enterprise execution discipline. For today’s CIO, this marks a pivotal shift — from delivering technology to owning enterprise execution, where leadership is measured by sustained ROAI rather than deployment.</p>



<h2 class="wp-block-heading">The board-CEO mandate: Implement enterprise AI capabilities now</h2>



<p>The directive from Boards and CEOs to CIOs is unequivocal: implement enterprise AI capabilities now. In many organizations, however, this mandate arrives without clearly defined financial targets, operating metrics or accountability models.</p>



<p>Boards increasingly expect CIOs to demonstrate a clear linkage between technology investments and business outcomes, such as EBITDA improvement, margin expansion and cost-to-serve reduction. As a result, CIO political capital is increasingly determined by a single measure: ROAI. Traditional indicators of CIO success — system uptime, modernization, cybersecurity and delivery velocity — are essential but no longer sufficient. AI has deeply shifted the evaluation criteria for technology leadership.</p>



<p>Many CIOs have learned a difficult lesson. The speed of deployment does not equal the speed of adoption. Enterprises can quickly implement advanced models, yet adoption stalls when AI is not embedded in their workflows. Employees revert to familiar processes, managers lack confidence in outputs and productivity gains remain theoretical instead of financial. This challenge of moving from experimentation to monetization defines modern CIO leadership. <a href="https://hbr.org/2026/01/hb-how-executives-are-thinking-about-ai-heading-into-2026" rel="nofollow">(Harvard Business Review’s Survey: How Executives Are Thinking About AI in 2026)</a></p>



<p>AI is not failing. Enterprises are failing to operate it. This moment marks the redefinition of the CIO role.</p>



<h2 class="wp-block-heading">CIO addressing the AI execution gap</h2>



<p>The board–CIO relationship is no longer about oversight; it is focused on shared ownership of enterprise outcomes. When directors provide clear economic intent, risk boundaries and visible advocacy, the CIO can shape what happens next rather than report what has already occurred. The CIO–CHRO relationship must evolve from transactional enablement to a workforce-transformation partnership, in which roles, workflows and decision-related authority are deliberately built into the operating model. Likewise, the CIO–CFO relationship must move beyond budget approval, with the CFO validating returns and providing fiscal guidance to move AI outcomes that translate into P&amp;L and balance-sheet performance. As highlighted by the <a href="https://reports.weforum.org/docs/WEF_Four_Futures_for_Jobs_in_the_New_Economy_AI_and_Talent_in_2030_2025.pdf" rel="nofollow">World Economic Forum</a>, the CHRO is central to realizing ROAI by converting AI investments into sustained, measurable productivity and cost gains through workforce readiness, adoption and behavior change — embedding AI into how work is done and redefining the enterprise operating model for durable performance. When these relationships shift from functional handoffs to shared accountability, the CIO can scale execution and convert ambition into concrete ROAI and repeatable enterprise value.</p>



<p>Boards are no longer asking whether AI works; they are asking who owns ROAI. Most enterprises operate without executive ownership, causing AI investments to remain fragmented, value to leak through poor adoption and returns to be impossible to validate. This exposes the core leadership challenge of the AI era: technology implementation alone does not create value. Closing the AI Execution Gap demands organizational alignment and shared accountability across the executive team. Another strategic tactic for high-performing CIOs is to establish a four-member strategic alliance — the Strategic Quad—linking the board, CFO, CHRO and CIO as joint owners of ROAI. Within this model, the CIO ensures technology enablement and reliability; the CHRO drives workforce adoption, skills and behavioral change; the CFO measures, validates and realizes economic outcomes to the balance sheet; and the CEO aligns priorities to enterprise value. Together, the Strategic Quad transforms AI from isolated deployment to sustained, measurable enterprise performance and ROAI advancement.</p>



<p>The Strategic Quad establishes explicit executive ownership of ROAI and aligns technology, workforce, finance and governance to close the AI Execution Gap.</p>



<h2 class="wp-block-heading">Embedding AI where enterprise value is created</h2>



<p>Applying AI solely to customer engagement or revenue initiatives rarely produces a sustained effect. While these use cases generate visibility, they fail to address the core of enterprise performance. Sustainable economic value is created within the organization’s operating fabric. The operating fabric consists of processes, technologies, data, governance structures, decision rights and workforce behaviors that determine how work gets done. When AI is embedded within this fabric, employee adoption cannot be resisted, become optional or episodic. It becomes natural rather than forced.</p>



<p>Core enterprise platforms form the foundation of the operating fabric:</p>



<ul class="wp-block-list">
<li><strong>Human capital management systems</strong> enable workforce productivity, skills alignment and capacity planning.</li>



<li><strong>Productivity and collaboration platforms</strong> shape decision velocity and strengthen execution discipline.</li>



<li><strong>Workflow and process orchestration platforms</strong> standardize and automate enterprise processes.</li>



<li><strong>Enterprise resource planning systems</strong> translate operational activity into financial insight.</li>



<li><strong>Data and analytics platforms</strong> support forecasting, optimization and performance intelligence.</li>



<li><strong>Governance, risk and data trust tools</strong> establish transparency, compliance and Board confidence.</li>
</ul>



<p>Importantly, the operating fabric is not a single technology platform. Its systems, tools. and platforms that affect how employees work across the enterprise, which must be prioritized, sequenced and governed to fully deliver enterprise AI capabilities. Together, these layers create an environment in which AI becomes operational rather than experimental.</p>



<h2 class="wp-block-heading">The enterprise capability roadmap</h2>



<p>Successful CIOs approach enterprise AI enablement using disciplined sequencing aligned to ROAI impact. The roadmap begins with workforce enablement. Without adoption, value cannot materialize. Stanford research reinforces that employee-facing augmentation produces the highest economic return.</p>



<p>The second priority is productivity and collaboration platforms, where time leverage delivers immediate efficiency gains. Workflow orchestration follows, enabling scalability and repeatability across functions.</p>



<p>Only after these foundations are established should AI be deeply embedded in ERP environments, where financial outcomes can be measured, governed and validated. Advanced analytics then enhance forecasting and optimization, while governance frameworks ensure sustainability and compliance.</p>



<p>This sequencing transforms non-experimental, isolated pilots into a scalable enterprise capability.</p>



<p>As AI integrates into operations, organizations can prioritize initiatives based on value, risk and time-to-return, with ongoing monitoring, financial validation and clear accountability. This discipline turns productivity into profit, time savings into leverage and innovation into predictable results.</p>



<h2 class="wp-block-heading">Redefining the CIO as an enterprise value leader</h2>



<p>The CIO role has shifted from managing technology to owning enterprise value, especially as AI becomes essential and risky. Boards now expect CIOs to oversee the entire AI cycle, from funding to governance, elevating their role to enterprise operators with increased influence as trusted partners delivering financial results. Failing to bridge the AI Execution Gap risks reduced strategic relevance, seen as just managing IT.</p>



<p>The AI enterprise capability is a leadership mandate, not a technical deployment, requiring the Strategic Quad to operate as a single, accountable command unit that aligns strategy, workforce transformation and the operating model to convert AI investment into measurable financial impact. This framework guides leaders in translating AI value into measurable financial impact.</p>



<ul class="wp-block-list">
<li>Strategic readiness and use-case prioritization</li>



<li>Workforce productivity transformation</li>



<li>Business and financial impact management</li>



<li>Enterprise operating model and capital governance</li>



<li>Governance, risk and scalable confidence</li>



<li>Board KPI oversight and reporting cadence</li>
</ul>



<p>AI success now hinges on enterprise leadership, not technological deployment or oversight. When the Board sets clear outcomes, the CEO enforces accountability and the CIO operates as the enterprise integrator — aligning workforce adoption, capital governance and execution discipline — AI becomes a measurable driver of productivity, margin expansion and sustained P&amp;L impact. Organizations that unify leadership around this mandate will convert AI investment into enterprise advantage.</p>



<p>The question before enterprise leadership is no longer whether AI can create value, but whether the Board, CEO and CIO are prepared to govern and operationalize it with the same rigor applied to capital, risk and performance. Sustainable returns are achieved only when intelligence is embedded into the daily flow of work — shaping decisions, compounding productivity and making enterprise performance repeatable rather than episodic. For CIOs, this is the defining leadership moment: those who activate the Strategic Quad, own workforce transformation and steward AI as a true enterprise capability will convert AI from promise into performance — and secure their place at the helm of enterprise growth.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[LlamaIndex Releases LiteParse: A CLI and TypeScript-Native Library for Spatial PDF Parsing in AI Agent Workflows]]></title>
<description><![CDATA[In the current landscape of Retrieval-Augmented Generation (RAG), the primary bottleneck for developers is no longer the large language model (LLM) itself, but the data ingestion pipeline. For software developers, converting complex PDFs into a format that an LLM can reason over remains a high-la...]]></description>
<link>https://tsecurity.de/de/3365887/ai-nachrichten/llamaindex-releases-liteparse-a-cli-and-typescript-native-library-for-spatial-pdf-parsing-in-ai-agent-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365887/ai-nachrichten/llamaindex-releases-liteparse-a-cli-and-typescript-native-library-for-spatial-pdf-parsing-in-ai-agent-workflows/</guid>
<pubDate>Fri, 20 Mar 2026 07:47:13 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In the current landscape of Retrieval-Augmented Generation (RAG), the primary bottleneck for developers is no longer the large language model (LLM) itself, but the data ingestion pipeline. For software developers, converting complex PDFs into a format that an LLM can reason over remains a high-latency, often expensive task. LlamaIndex has recently introduced LiteParse, an open-source, […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/03/19/llamaindex-releases-liteparse-a-cli-and-typescript-native-library-for-spatial-pdf-parsing-in-ai-agent-workflows/">LlamaIndex Releases LiteParse: A CLI and TypeScript-Native Library for Spatial PDF Parsing in AI Agent Workflows</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hunting in the Dark Forest: How I Uncovered a Private $25M Simulation Fork via an RPC…]]></title>
<description><![CDATA[Hunting in the Dark Forest: How I Uncovered a Private $25M Simulation Fork via an RPC MisconfigurationBug bounty hunting in Web3 isn’t just about analyzing smart contracts for reentrancy or logic flaws. Sometimes, the biggest vulnerabilities hide in the off-chain infrastructure.In this write-up, ...]]></description>
<link>https://tsecurity.de/de/3365748/hacking/hunting-in-the-dark-forest-how-i-uncovered-a-private-25m-simulation-fork-via-an-rpc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365748/hacking/hunting-in-the-dark-forest-how-i-uncovered-a-private-25m-simulation-fork-via-an-rpc/</guid>
<pubDate>Fri, 20 Mar 2026 06:35:05 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Hunting in the Dark Forest: How I Uncovered a Private $25M Simulation Fork via an RPC Misconfiguration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3uaYt-0ahVtIPP39zNgFew.png"></figure><p><em>Bug bounty hunting in Web3 isn’t just about analyzing smart contracts for reentrancy or logic flaws. Sometimes, the biggest vulnerabilities hide in the off-chain infrastructure.</em></p><p>In this write-up, I’ll share my experience of discovering a highly sensitive infrastructure misconfiguration in a prominent DeFi protocol (let’s call it <strong>TargetX</strong>). What started as a simple API scan escalated into uncovering a private simulation environment containing over $25 Million in manipulated assets, and how I had to prove my case when the triage team initially rejected it.</p><h3>Phase 1: The Initial Recon and the Bypass</h3><p>While analyzing TargetX’s web applications, I noticed they were making requests to a custom RPC endpoint: <a href="https://rpc.target.com./">https://rpc.target.com.</a></p><p>Out of curiosity, I sent a basic POST request to the root endpoint. As expected, it returned a 403 Forbidden / Gateway Error. The developers had clearly put a firewall or reverse proxy in front of it.</p><p>However, in the Web3 world, RPC endpoints often route traffic based on Chain IDs. I decided to fuzz the URL paths by appending standard EVM Chain IDs.</p><p><strong>The Bypass:</strong></p><p>Sending a request to https://rpc.target.com/1 (appending /1 for Ethereum Mainnet) bypassed the 403 restriction entirely! The endpoint responded with a valid 200 OK JSON-RPC response.</p><h3>Phase 2: The $22 Million Discrepancy</h3><p>Now that I had unauthenticated access to their internal node, I wanted to see what state this node was tracking. I targeted one of TargetX’s core vault contracts (0xVaultAddress...) and queried its balance.</p><pre>curl -X POST -H "Content-Type: application/json" \<br>--data '{"jsonrpc":"2.0","method":"eth_getBalance","params":["0xVaultAddress...", "latest"],"id":1}' \<br>https://rpc.target.com/1</pre><p><strong>The Result:</strong> 0x22d68445673d07axxxx</p><p>Converting this hex to decimal revealed a staggering balance of <strong>~10,282 ETH</strong> (worth around $25+ Million at the time).</p><p>But here was the catch: I cross-referenced this exact contract address on the real Ethereum Mainnet via Etherscan. The real balance was only <strong>~2,599 ETH</strong> (around $7.7 Million).</p><p><em>Where did the extra $22 Million come from?</em> ### Phase 3: Fingerprinting the Infrastructure</p><p>The balance mismatch was a massive red flag. Real public nodes mirror the exact state of the blockchain. This node was hallucinating funds. I needed to identify what backend technology TargetX was actually running.</p><p>I used the web3_clientVersion RPC method to fingerprint the node:</p><pre>curl -X POST -H "Content-Type: application/json" \<br>--data '{"jsonrpc":"2.0","method":"web3_clientVersion","params":[],"id":1}' \<br>https://rpc.target.com/1</pre><p><strong>The Response:</strong> {"jsonrpc":"2.0","id":1,"result":"Tenderly/1.0"}</p><p>Bingo! The backend wasn’t a standard Geth or Erigon node. It was a <strong>Tenderly Virtual Fork</strong>. TargetX had accidentally exposed their private, paid simulation and testing environment to the public internet without any API key authentication.</p><h3>Phase 4: The Pushback from Triage</h3><p>I quickly wrote up a detailed report explaining the exposed Tenderly fork, the information disclosure of internal EIP-1967 proxy slots, and the potential for infrastructure quota exhaustion.</p><p>A few hours later, I received a response from the triage team:</p><blockquote>“Closed as Informative. This is just an erpc proxy routing to public nodes. The data you are fetching is public blockchain data. There is no security impact.”</blockquote><p>They completely missed the point. They assumed my results were just public Mainnet data. I needed a “Killer Proof” to demonstrate that this was a manipulatable simulation environment, not a read-only public proxy.</p><h3>Phase 5: The “State Override” Nuke (Proving the Bug)</h3><p>Public RPC proxies (like Infura, Alchemy, or generic public nodes) strictly prohibit unauthorized users from modifying the blockchain state. However, Tenderly simulation forks allow a powerful feature called <strong>State Overrides</strong> via the eth_call method.</p><p>I decided to perform a simulated hijacking of their Proxy Contract. I crafted a request to query the proxy’s implementation address, but I injected a stateDiff parameter to artificially overwrite the EIP-1967 Logic Slot (0x360894...) with a dummy address (0x1111...).</p><pre>curl -X POST -H "Content-Type: application/json" \<br>--data '{<br>  "jsonrpc":"2.0",<br>  "method":"eth_call",<br>  "params":[<br>    {"to":"0xVaultAddress...", "data":"0xd781aaec"}, <br>    "latest", <br>    {<br>      "0xVaultAddress...": {<br>        "stateDiff": {<br>          "0x360894a13ba1a3210667c828492db98dca3e2076cc3735a920a3caxxxxxxxxxx": "0x0000000000000000000000001111111111111111111111111111111111111111"<br>        }<br>      }<br>    }<br>  ],<br>  "id":1<br>}' \<br>https://rpc.target.com/1</pre><p><strong>The Result:</strong> {"jsonrpc":"2.0","id":1,"result":"0x"}</p><p><strong>Checkmate.</strong> Because I overwrote the logic address with a non-existent contract (0x1111...), the call returned 0x. If this had been a true public proxy as the triage team claimed, it would have rejected the stateDiff parameter entirely or returned the actual implementation address. The RPC processed my state override, definitively proving it was an active simulation environment.</p><h3>The Resolution</h3><p>I replied to the triage team with my final evidence:</p><ol><li>The web3_clientVersion proving the Tenderly backend.</li></ol><p>2. The $22M asset mismatch proving an artificial state.</p><p>3. The successful execution of a State Override proving simulation capabilities.</p><p>I politely explained that exposing a private development fork allows attackers to reverse-engineer unreleased protocol logic, perform dark-forest simulations on upcoming deployments, and exhaust their paid infrastructure quotas.</p><p>Shortly after, the team acknowledged the technical proof, reopened the ticket, and validated the vulnerability.</p><h3>Takeaways for Web3 Bug Hunters</h3><ul><li><strong>Always Fingerprint Your Nodes:</strong> Don’t assume an RPC is just a standard Geth node. Use methods like web3_clientVersion to know exactly what you are talking to.</li><li><strong>Look for State Discrepancies:</strong> Compare the data from the target’s RPC against a public block explorer like Etherscan. Inconsistencies often reveal staging environments.</li><li><strong>Don’t Give Up on Triage:</strong> If you know your technical finding is correct, build an irrefutable Proof of Concept. The “State Override” technique is the ultimate way to prove you are inside a simulation fork.</li></ul><p><em>Happy Hunting!</em> 🐺</p><p>#Web3Security #BugBounty #Infosec #EthicalHacking #BlockchainSecurity #Ethereum #EVM #DeFiSecurity #SmartContracts #Tenderly #RPC</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/391/1*G_IA7a0YpxCCE6d_c2H4aQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8bP0VwsPj31ypL4Av43ZVQ.png"></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=4b4193f90ac5" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/hunting-in-the-dark-forest-how-i-uncovered-a-private-25m-simulation-fork-via-an-rpc-4b4193f90ac5">Hunting in the Dark Forest: How I Uncovered a Private $25M Simulation Fork via an RPC…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 ways Gemini supercharges Google Sheets]]></title>
<description><![CDATA[Google’s AI assistant, Gemini, can assist you in several ways in Google Sheets, from analyzing your data to helping you edit your spreadsheet faster. In Google Sheets, you mostly use these genAI tools through the Gemini sidebar. But you can also trigger Gemini to take action through a formula ins...]]></description>
<link>https://tsecurity.de/de/3364219/it-nachrichten/6-ways-gemini-supercharges-google-sheets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3364219/it-nachrichten/6-ways-gemini-supercharges-google-sheets/</guid>
<pubDate>Fri, 20 Mar 2026 04:17:28 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google’s AI assistant, Gemini, can assist you in several ways in Google Sheets, from analyzing your data to helping you edit your spreadsheet faster. In Google Sheets, you mostly use these genAI tools through the Gemini sidebar. But you can also trigger Gemini to take action through a formula inside a cell. It also automatically performs actions in the background to provide suggestions.</p>



<p>To use Gemini within Google Sheets, you need to be subscribed to a Google Workspace <a href="https://workspace.google.com/pricing.html" target="_blank" rel="noreferrer noopener">Business Standard, Business Plus, or Enterprise plan</a> or a <a href="https://one.google.com/about/google-ai-plans/" target="_blank" rel="noreferrer noopener">Google AI plan</a>. Alternatively, you can sign up for <a href="https://workspace.google.com/labs-sign-up/u/0/" target="_blank" rel="noreferrer noopener">Google Workspace Labs</a> with a free Google account.</p>



<p><strong>Note:</strong> If you use Google Workspace at work, your administrator may need to enable permission for Gemini to be used in Google Sheets.</p>



<p>This quick guide will go over the major ways you can use Gemini in Google Sheets. If you’re new to Google Sheets or need a refresher, see our <a href="https://www.computerworld.com/article/1657150/how-to-use-google-sheets.html">Google Sheets cheat sheet</a> first to get up and running.</p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ol class="wp-block-list">
<li>Generate analyses, insights, or summaries</li>



<li>Generate charts, graphs, or other data visualizations</li>



<li>Generate formulas</li>



<li>Quickly edit or format your spreadsheet</li>



<li>Use a formula inside a cell to prompt Gemini</li>



<li>Use Enhanced Smart Fill (or turn it off)</li>
</ol>



<p>As when using any generative AI tool, remember that Gemini can make mistakes or <a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">simply make things up</a>, so you should always check its output for accuracy.</p>



<h2 class="wp-block-heading"><a></a>Start in the Gemini sidebar</h2>



<p>From the <a href="https://www.computerworld.com/article/3845447/google-workspace-how-to-use-gemini-ai-side-panel.html">Gemini sidebar</a>, you can prompt Gemini to take several actions on your spreadsheet, such as adding information to it, providing analysis about it, or even editing it for you.</p>



<p>In the top-right corner of Google Sheets, click the <em>Gemini</em> icon, a nova star located between the Share button and your Google user account pic. The Gemini sidebar will open to the right of your spreadsheet.</p>



<p>Now that you have it opened, you can type prompts inside the text box on the sidebar, triggering Gemini to take actions on your spreadsheet.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?w=1024" alt="spreadsheet in google sheets with gemini sidebar open on right" class="wp-image-4131544" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?quality=50&amp;strip=all 1366w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-01-sidebar.png?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Click the nova star icon at upper right to open the Gemini sidebar.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>As a reminder: You can always enter more prompts to follow up on something that Gemini generated. Examples include:</p>



<ul class="wp-block-list">
<li>Ask a question about something specific in an analysis that it generated.</li>



<li>Tell it to generate a visualization from its analysis.</li>



<li>Tell it to explain how a formula that it generated works.</li>
</ul>



<p><strong>Tip:</strong> Gemini’s responses are often long, but you can drag the left edge of the sidebar to make it wider and reduce the need to scroll.</p>



<p>The first four tips below summarize the major things Gemini can do to your spreadsheet from its sidebar.</p>



<h2 class="wp-block-heading"><a></a>1. Generate analyses, insights, or summaries</h2>



<p>Gemini can extract deep data analyses, insights, or trends from your spreadsheet.</p>



<p>Optionally, select the cells that you want Gemini to analyze. This is suggested so that Gemini can give you a more accurate and faster result, especially if your spreadsheet contains a lot of data. Click a table, column, or row, or highlight a cell range.</p>



<p>Next, enter your prompt. Examples:</p>



<ul class="wp-block-list">
<li><strong>Anomalies or outliers:</strong> <em>Find any anomalies or outliers in the “Inventory Amount” column for “Product A” row.</em></li>



<li><strong>Correlations:</strong> <em>Find any correlation between the “Travel” column and the “Total Revenue” column.</em></li>



<li><strong>Predictions:</strong> <em>Predict the net income for the next quarter based on the data in the “Quarter 2” tab.</em></li>



<li><strong>Summaries or takeaways:</strong> <em>What are the three key takeaways from this survey data?</em></li>
</ul>



<p>Gemini will generate a result that appears in the Gemini sidebar.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?w=1024" alt="gemini sidebar in google sheets with key takeaways generated from spreadsheet data" class="wp-image-4131542" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?quality=50&amp;strip=all 1078w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=300%2C214&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=768%2C547&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=1024%2C730&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=978%2C697&amp;quality=50&amp;strip=all 978w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=236%2C168&amp;quality=50&amp;strip=all 236w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=118%2C84&amp;quality=50&amp;strip=all 118w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=674%2C480&amp;quality=50&amp;strip=all 674w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=505%2C360&amp;quality=50&amp;strip=all 505w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-02-analysis.png?resize=351%2C250&amp;quality=50&amp;strip=all 351w" width="1024" height="730" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can ask Gemini to identify key takeaways from your spreadsheet data.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>Additionally, you can have Gemini generate a summary of related material from a source outside your spreadsheet, such as a document in your Google Drive or an email thread in your Gmail:</p>



<ul class="wp-block-list">
<li><strong>Google Drive document:</strong> <em>Summarize the takeaways from the “Q4 Sales 2026” Google Doc in my Drive.</em></li>



<li><strong>Gmail thread:</strong> <em>List the action items from my recent email thread with Scot Davenport about “New Client Onboarding Steps.”</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?w=1024" alt="gemini sidebar in google sheets showing summary of specified emails" class="wp-image-4131539" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?quality=50&amp;strip=all 1079w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=300%2C213&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=768%2C545&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=1024%2C727&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=982%2C697&amp;quality=50&amp;strip=all 982w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=237%2C168&amp;quality=50&amp;strip=all 237w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=118%2C84&amp;quality=50&amp;strip=all 118w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=676%2C480&amp;quality=50&amp;strip=all 676w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=507%2C360&amp;quality=50&amp;strip=all 507w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-03-gmail-summary.png?resize=352%2C250&amp;quality=50&amp;strip=all 352w" width="1024" height="727" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Gemini can summarize email threads or documents related to your spreadsheet.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h3 class="wp-block-heading"><strong>Adding or saving Gemini’s result</strong></h3>



<p>Click <em>Insert</em> to insert the result on your spreadsheet where your cursor is, <em>Copy</em> to copy the generated text to your PC clipboard, or <em>Export to Docs</em> to save the result as a new document in your Google Drive. You’ll be able to open it in Google Docs.</p>



<p>You can click the <em>Analysis steps</em> link that appears above the result to see the steps Gemini took to arrive at its result. There may also be a <em>Sources</em> link below the result. Clicking this will show you the specific files or email threads Gemini used to generate this result.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png" alt="gemini sidebar in google sheets showing sources used to generate an analysis of the spreadsheet" class="wp-image-4131555" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png?quality=50&amp;strip=all 702w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png?resize=300%2C210&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png?resize=240%2C168&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png?resize=120%2C84&amp;quality=50&amp;strip=all 120w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png?resize=686%2C480&amp;quality=50&amp;strip=all 686w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png?resize=515%2C360&amp;quality=50&amp;strip=all 515w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-04b-analysis-sources.png?resize=357%2C250&amp;quality=50&amp;strip=all 357w" width="702" height="491" sizes="auto, (max-width: 702px) 100vw, 702px"><figcaption class="wp-element-caption"><p>Gemini lists the source(s) it used to generate a result.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>2. Generate charts, graphs, or other data visualizations</h2>



<p>Chart creation works best if the data on your spreadsheet has headers for each column or row, such as “Expenses,” “Month,” “Sales,” etc. (This rule also applies if you use the standard way to create a chart in Google Sheets, by selecting <em>Insert &gt; Chart</em> on the menu bar above your spreadsheet.)</p>



<p>Your prompt should name the type of chart you want (pie chart, bar chart, etc.), as well as the headers of the columns and rows that you want in it. But don’t be afraid to just ask Gemini to generate a chart from your data without naming headers as an experiment to see what the result might be.</p>



<p>Prompt examples:</p>



<ul class="wp-block-list">
<li><strong>Bar chart (comparison chart):</strong> <em>Generate a bar chart that compares Weekly Sales and Product Categories.</em></li>



<li><strong>Complex analysis:</strong> <em>Build a stacked column chart that shows Quarterly Profit by Product Category.</em></li>



<li><strong>Line Chart:</strong> <em>Create a line chart with the Date on the X-axis and Sales on the Y-axis.</em></li>



<li><strong>Pie chart (distribution chart):</strong> <em>Show me a pie chart of the percentage share of Budget by Items.</em></li>



<li><strong>Trend:</strong> <em>Identify the key trends in sales so far this year.</em></li>
</ul>



<p>Gemini will generate a result that appears in the Gemini sidebar.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?w=1024" alt="gemini sidebar in google sheets with generated pie chart" class="wp-image-4131546" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?quality=50&amp;strip=all 1078w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=300%2C213&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=768%2C545&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=1024%2C727&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=982%2C697&amp;quality=50&amp;strip=all 982w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=237%2C168&amp;quality=50&amp;strip=all 237w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=118%2C84&amp;quality=50&amp;strip=all 118w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=676%2C480&amp;quality=50&amp;strip=all 676w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=507%2C360&amp;quality=50&amp;strip=all 507w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-05-pie-chart.png?resize=352%2C250&amp;quality=50&amp;strip=all 352w" width="1024" height="727" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Describe the chart you want Gemini to create, and it will appear in the sidebar.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>You can enter more prompts to trigger Gemini to refine the chart. Examples could include telling it to change the chart type or rename a label in the chart, adding a trend line, or using only the data from certain columns and rows.</p>



<h3 class="wp-block-heading"><strong>Adding or saving Gemini’s result</strong></h3>



<p>Click the <em>Preview</em> button at the bottom of the chart card to see a larger preview of the chart in a panel over your spreadsheet, and if you like what you see, click the panel’s <em>Insert</em> button to add the chart. Or you can skip the preview step and just click <em>Insert</em> below the chart in the sidebar. Either way, a new tab will be added to your spreadsheet with the chart that Gemini generated on it. (For some users, the chart may instead be added to the current tab.)</p>



<h2 class="wp-block-heading"><a></a>3. Generate formulas</h2>



<p>Gemini can generate a formula and insert it into a cell. Prompt examples:</p>



<ul class="wp-block-list">
<li><em>Create a formula that averages the values for columns A2 and A6.</em></li>



<li><em>Generate a formula that adds 7 business days to the dates in the “Deadline” column.</em></li>
</ul>



<p>Gemini will generate a result that appears in its sidebar along with the steps it took to arrive at the result. Sometimes it may even set up a new column or row and insert the formula into the cells; you can undo this action if you want.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?w=1024" alt="google sheets spreadsheet with new column - gemini sidebar is open to right with explanation of steps gemini took to add and fill in the column" class="wp-image-4131540" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?quality=50&amp;strip=all 1078w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=300%2C213&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=768%2C546&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=1024%2C729&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=980%2C697&amp;quality=50&amp;strip=all 980w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=236%2C168&amp;quality=50&amp;strip=all 236w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=118%2C84&amp;quality=50&amp;strip=all 118w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=675%2C480&amp;quality=50&amp;strip=all 675w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=506%2C360&amp;quality=50&amp;strip=all 506w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-06-formula-with-new-column.png?resize=351%2C250&amp;quality=50&amp;strip=all 351w" width="1024" height="729" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Column J contains results based on the generated formula.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>If you don’t understand how a formula works, just ask Gemini to explain it as your next prompt.</p>



<h3 class="wp-block-heading"><strong>Adding or saving Gemini’s result</strong></h3>



<p>Click <em>Insert</em> to set the generated formula or calculated result in the cell where your cursor is, or click <em>Copy</em> to copy it to your clipboard.</p>



<h2 class="wp-block-heading"><a></a>4. Quickly edit or format your spreadsheet</h2>



<p>Gemini can add elements to your spreadsheet or help you edit it. Prompt examples:</p>



<ul class="wp-block-list">
<li><strong>Add columns or rows:</strong><em> Add a new column with the heading “Expenses”.</em></li>



<li><strong>Checkboxes:</strong> <em>Insert checkboxes in the column H1.</em></li>



<li><strong>Conditional formatting:</strong> <em>Highlight all Sellers in red whose Total Sales are less than $200.</em></li>



<li><strong>Convert to title case:</strong> <em>Convert all the text in the column “Job Titles” to title case.</em></li>



<li><a href="https://www.computerworld.com/article/1614498/google-sheets-how-to-use-dropdown-lists.html"><strong>Dropdown lists</strong></a><strong>:</strong> <em>Add a dropdown to the cells in the “Status” column with options: “Awaiting,” “In Progress,” “Done”.</em></li>



<li><strong>Extract:</strong> <em>Extract the ZIP codes from the “Address” column and put them in the “ZIP Codes” column.</em></li>



<li><a href="https://www.computerworld.com/article/1613357/google-sheets-how-to-use-filters-and-slicers.html"><strong>Filter</strong></a><strong>:</strong> <em>Apply a filter to show rows where the “Progress” is “Done”.</em></li>



<li><strong>Freeze rows/columns:</strong><em> Freeze the first four rows and the third and sixth columns.</em></li>



<li><a href="https://www.computerworld.com/article/1617396/google-sheets-how-to-use-pivot-tables.html"><strong>Pivot tables</strong></a><strong>:</strong> <em>Create a pivot table showing the average sale amount by “Person” and “Product.”</em></li>



<li><strong>Remove extra spacing:</strong><em> Remove any extra spacing in this sheet.</em></li>



<li><strong>Sort:</strong> <em>Sort the entire sheet by the “Sales Figures” column, from largest to smallest number.</em></li>



<li><strong>Multi-step command:</strong> <em>Sort the data by “Employee”. Freeze the header row. Highlight the cells in the “Sales” column that are above 100.</em></li>
</ul>



<p>Gemini will immediately apply your requested changes to your spreadsheet, and list in the sidebar the steps it took to do so.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?w=1024" alt="google sheets spreadsheet with conditional formatting - gemini sidebar is open to right with explanation of how gemini applied formatting" class="wp-image-4131541" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?quality=50&amp;strip=all 1366w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=1024%2C576&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=1240%2C697&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=854%2C480&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=640%2C360&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-07-conditional-formatting.png?resize=444%2C250&amp;quality=50&amp;strip=all 444w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Gemini can apply conditional formatting in an instant.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>If the changes do not give you the results that you want, simply click the <em>Undo</em> button in the Gemini sidebar.</p>



<p>For certain actions such as conditional formatting or pivot tables, a <em>Settings</em> button may appear in the Gemini sidebar after the action is applied. Clicking this will open the Google Sheets settings panel for that feature so that you can make adjustments.</p>



<p>Gemini will often suggest additional prompts below the current result, such as creating a chart or asking a question about the data. Click any prompt, and Gemini will generate a response to it.</p>



<h2 class="wp-block-heading"><a></a>5. Use a formula inside a cell to prompt Gemini</h2>



<p>You can use a formula in a cell to trigger Gemini to generate content in that cell that references data in another cell or cell range. You can use this formula to categorize text in cells or even write emails. You can also apply this function across multiple rows.</p>



<p>The format for this formula is:</p>



<pre class="wp-block-preformatted">=AI("<em>YOUR PROMPT</em>", <em>REFERENCE CELL OR CELL RANGE</em>)</pre>



<ul class="wp-block-list">
<li><em>YOUR PROMPT</em> is your prompt telling Gemini what you want it to do.</li>



<li><em>REFERENCE CELL OR CELL RANGE</em> is the cell(s) containing the data you want Gemini to reference with your prompt.</li>
</ul>



<p>Examples:</p>



<ul class="wp-block-list">
<li><strong>Draft emails:</strong> <em>=AI(“Write a concise, professional email opening line to the person in A2, referencing their industry in B2”, A2:B2)</em></li>



<li><strong>Extract data:</strong> <em>=AI(“Extract only the 5-digit zip code from the address”, B2)</em></li>



<li><strong>Fix text:</strong> <em>=AI(“Apply proper capitalization, and remove extra spaces from the name in”, B2)</em></li>



<li><strong>Standardize dates:</strong> <em>=AI(“Standardize the date in B2 to YYYY-MM-DD format”, B2)</em></li>



<li><strong>Categorize information:</strong> <em>=AI(“categorize amount greater than 80 as ‘Glorious’ and below 80 as ‘Must Improve’, H5”)</em></li>
</ul>



<p>When you’ve finished typing your formula, press the Enter key. Gemini will process your prompt and generate a result. The result will be inserted into the cell.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?w=1024" alt="google sheets spreadsheet with ai formula in formula bar and the result of that formula in cell J5" class="wp-image-4131545" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?quality=50&amp;strip=all 1265w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=300%2C132&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=768%2C339&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=1024%2C452&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=1240%2C547&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=150%2C66&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=854%2C377&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=640%2C282&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-08-ai-formula-in-cell.png?resize=444%2C196&amp;quality=50&amp;strip=all 444w" width="1024" height="452" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The rightmost column shows the result of an AI prompt formula (shown in the formula bar at the top).</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>If the data in the reference cell / range is changed, the formula result won’t automatically be updated, but you can select the cell that contains the formula and click the <em>Refresh and insert</em> button that appears to update it.<strong></strong></p>



<h3 class="wp-block-heading"><strong>Applying your Gemini formula to other cells</strong></h3>



<p>You can apply this Gemini formula in the cell to the other cells on the rows below it. First, make sure your spreadsheet data is formatted as a table. If it’s not, select all the cells containing data and click <em>Format &gt; Convert to table</em> from the top menu bar.</p>



<p>Click the cell that contains the formula. Then click on the bottom-right corner of the cell (you may see a + sign appear) and drag down to apply the formula to the cells below. Gemini will automatically run the prompt inside these cells, referencing the data from each row that they’re on.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?w=1024" alt="google sheets spreadsheet with ai formula applied to whole column" class="wp-image-4131548" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?quality=50&amp;strip=all 1266w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=300%2C131&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=768%2C335&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=1024%2C447&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=1240%2C542&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=150%2C66&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=854%2C373&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=640%2C280&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-09-ai-formula-copied-down.png?resize=444%2C194&amp;quality=50&amp;strip=all 444w" width="1024" height="447" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The formula is now copied into all the rows in the rightmost column.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading">6. Use Enhanced Smart Fill (or turn it off)</h2>



<p>The Smart Fill feature in Google Sheets is an automation tool that assists you as you work on your spreadsheet. It’s been enhanced to use Gemini to detect patterns in your data. As you enter data in cells, it may offer to fill out subsequent cells for you.</p>



<p>For example: After you finish entering values into a few rows, Smart Fill may suggest that it automatically add more rows for you, and supply the values for those cells. This suggestion may be triggered after you do the same task to your spreadsheet three or more times.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png" alt="google sheets with autofill suggestion based on gemini analysis" class="wp-image-4131538" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?quality=50&amp;strip=all 828w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?resize=300%2C189&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?resize=768%2C485&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?resize=266%2C168&amp;quality=50&amp;strip=all 266w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?resize=133%2C84&amp;quality=50&amp;strip=all 133w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?resize=760%2C480&amp;quality=50&amp;strip=all 760w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?resize=570%2C360&amp;quality=50&amp;strip=all 570w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-10-enhanced-smart-fill-suggest.png?resize=396%2C250&amp;quality=50&amp;strip=all 396w" width="828" height="523" sizes="auto, (max-width: 828px) 100vw, 828px"><figcaption class="wp-element-caption"><p>Smart Fill can suggest autofill values based on Gemini’s analysis of the data you’ve already entered.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>Other Smart Fill behaviors:</p>



<ul class="wp-block-list">
<li><strong>Categorizing:</strong> Analyzing the text in the cells of a column and filling in the cells of an adjacent column with corresponding category names.</li>



<li><strong>Extracting:</strong> Extracting the ZIP codes from the addresses listed in a column and inserting them into a new column.</li>



<li><strong>Standardizing:</strong> Converting values in a column that have been entered in inconsistent formats. For example, it can offer to convert both “sept 1st, 2026” and “9/6/26” into a uniform “YYYY-MM-DD” format.</li>
</ul>



<p>A Smart Fill suggestion appears as a faded outline or a bubble showing its predicted range of values. If you want to accept the suggestion, click the outline or checkmark on the Auto Fill notice card. If you don’t want to accept, click the X icon on this card.</p>



<h3 class="wp-block-heading"><strong>Turning Enhanced Smart Fill off or on</strong></h3>



<p>If you find that these Smart Fill suggestions get in your way as you work on your spreadsheet, or simply don’t work well for you, you can turn off the feature.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png" alt="google sheets with menu sequence to turn off enhanced smart fill suggestions" class="wp-image-4131543" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?quality=50&amp;strip=all 827w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?resize=300%2C190&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?resize=768%2C486&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?resize=266%2C168&amp;quality=50&amp;strip=all 266w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?resize=133%2C84&amp;quality=50&amp;strip=all 133w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?resize=759%2C480&amp;quality=50&amp;strip=all 759w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?resize=569%2C360&amp;quality=50&amp;strip=all 569w, https://b2b-contenthub.com/wp-content/uploads/2026/02/gemini-sheets-11-turn-off-enhanced-smart-fill.png?resize=395%2C250&amp;quality=50&amp;strip=all 395w" width="827" height="523" sizes="auto, (max-width: 827px) 100vw, 827px"><figcaption class="wp-element-caption"><p>Turning off Enhanced Smart Fill.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>On the menu bar above your spreadsheet, select <em>Tools &gt; Suggestion controls &gt; Enable enhanced Smart Fill suggestions</em> to uncheck it. Select it again to turn it back on (the checkmark reappears).<sup></sup></p>



<p><strong>Note:</strong> Turning off Enhanced Smart Fill does not disable the basic Smart Fill feature, which doesn’t use Gemini. It uses simpler logic to suggest sequential numbering or extracting text.</p>



<h4 class="wp-block-heading"><strong>Related reading:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1657150/how-to-use-google-sheets.html">Google Sheets cheat sheet: How to get started</a></li>



<li><a href="https://www.computerworld.com/article/4030767/quick-tips-for-google-sheets.html">6 quick tips for Google Sheets</a></li>



<li><a href="https://www.computerworld.com/article/3845447/google-workspace-how-to-use-gemini-ai-side-panel.html">Google Workspace: 7 great ways to use the Gemini AI sidebar</a></li>



<li><a href="https://www.computerworld.com/article/1613357/google-sheets-how-to-use-filters-and-slicers.html">Google Sheets power tips: How to use filters and slicers</a></li>



<li><a href="https://www.computerworld.com/article/1617396/google-sheets-how-to-use-pivot-tables.html">Google Sheets power tips: How to use pivot tables</a></li>



<li><a href="https://www.computerworld.com/article/1634828/how-to-use-google-sheets-for-project-management.html">How to use Google Sheets for project management</a></li>



<li><a href="https://www.computerworld.com/article/1631765/how-to-use-smart-chips-in-google-docs-and-sheets.html">How to use smart chips in Google Docs and Sheets</a></li>



<li><a href="https://www.computerworld.com/article/1638670/smart-chips-advanced-tips-google-docs-google-sheets.html">4 advanced ‘smart chip’ tips for Google Docs and Sheets</a></li>



<li><a href="https://www.computerworld.com/article/1611674/google-workspace-productivity-across-apps.html">Google Workspace power tips: Tap into cross-app productivity</a></li>



<li><a href="https://www.computerworld.com/article/1633736/how-to-use-google-workspace-tips-tutorials-cheat-sheets.html">More Google Workspace tips and tutorials</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 Best Encryption Software & Tools in 2026]]></title>
<description><![CDATA[Encryption software protects data by converting it into secure code. Explore the best encryption tools of 2026 to keep your information safe. The post 8 Best Encryption Software & Tools in 2026 appeared first on eSecurity Planet. This article has…
Read more →
The post 8 Best Encryption Software &...]]></description>
<link>https://tsecurity.de/de/3363244/it-security-nachrichten/8-best-encryption-software-tools-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3363244/it-security-nachrichten/8-best-encryption-software-tools-in-2026/</guid>
<pubDate>Fri, 20 Mar 2026 00:35:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Encryption software protects data by converting it into secure code. Explore the best encryption tools of 2026 to keep your information safe. The post 8 Best Encryption Software &amp; Tools in 2026 appeared first on eSecurity Planet. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/8-best-encryption-software-tools-in-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/8-best-encryption-software-tools-in-2026/">8 Best Encryption Software &amp; Tools in 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 Best Encryption Software & Tools in 2026]]></title>
<description><![CDATA[Encryption software protects data by converting it into secure code. Explore the best encryption tools of 2026 to keep your information safe. 
The post 8 Best Encryption Software & Tools in 2026 appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3363226/it-security-nachrichten/8-best-encryption-software-tools-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3363226/it-security-nachrichten/8-best-encryption-software-tools-in-2026/</guid>
<pubDate>Fri, 20 Mar 2026 00:20:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Encryption software protects data by converting it into secure code. Explore the best encryption tools of 2026 to keep your information safe. </p>
<p>The post <a href="https://www.esecurityplanet.com/products/best-encryption-software/">8 Best Encryption Software &amp; Tools in 2026</a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why reinforcement learning is at the heart of AI solving problems]]></title>
<description><![CDATA[The first act of the current AI boom was defined by prediction. LLMs were trained to predict the next word in a sentence, acting as sophisticated statistical mirrors of the internet. But for the enterprise, prediction is rarely the end goal — action is.



We are now entering the second act: the ...]]></description>
<link>https://tsecurity.de/de/3354672/it-security-nachrichten/why-reinforcement-learning-is-at-the-heart-of-ai-solving-problems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3354672/it-security-nachrichten/why-reinforcement-learning-is-at-the-heart-of-ai-solving-problems/</guid>
<pubDate>Tue, 17 Mar 2026 10:04:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The first act of the current AI boom was defined by prediction. LLMs were trained to predict the next word in a sentence, acting as sophisticated statistical mirrors of the internet. But for the enterprise, prediction is rarely the end goal — action is.</p>



<p>We are now entering the second act: the transition from AI that speaks to AI that reasons and acts. At the heart of this transition is reinforcement learning (RL), a field of computer science that has suddenly become the most valuable frontier in Silicon Valley. While supervised learning taught AI to recognize a pattern, RL is teaching AI to solve a problem.</p>



<h2 class="wp-block-heading">Beyond pattern matching: What RL actually is</h2>



<p>To a business executive, the difference between standard machine learning and RL is the difference between a textbook and a flight simulator.</p>



<ul class="wp-block-list">
<li><strong>Supervised learning (the textbook)</strong>: You provide the AI with millions of labeled examples. The AI learns to recognize the pattern.</li>



<li><strong>Reinforcement learning (the simulator):</strong> You provide the AI with a goal and a set of rewards for success. The AI then enters a trial-and-error loop, testing millions of strategies and learning from its own failures.</li>
</ul>



<p>As industry leaders note, RL is about maximizing a reward function — a mathematical representation of what success looks like for your <a href="https://docs.nvidia.com/learning/physical-ai/getting-started-with-isaac-lab/latest/train-your-first-robot-with-isaac-lab/01-what-is-reinforcement-learning.html">specific business</a>. It doesn’t need to be told the right answer; it discovers it through experience. This makes it uniquely suited for the messy multi-step logic of physical industries, where there is no historical perfect dataset to copy.</p>



<h2 class="wp-block-heading">Why everyone is talking about it now: The inference scaling era</h2>



<p>The conversation has shifted from the size of a model to the quality of its reasoning. We have entered the era of inference scaling laws, which prioritize what happens <em>after</em> you hit enter.</p>



<p>In the first wave of AI, intelligence was static — a model either knew the answer or it didn’t. Today, frontier models use RL-driven test-time compute. This allows a model to brainstorm internally, running millions of tiny self-simulations to verify its logic and search for the best path before presenting a solution.</p>



<p>For the CEO, this turns AI into a variable intellectual resource. For high-stakes decisions — like a complex pricing pivot or a supply chain overhaul — you can scale up the inference compute, allowing the model to spend more time to arrive at a reasoned conclusion. The bottleneck is no longer data scarcity, but the clarity of the goal the model is <a href="https://scalingintelligence.stanford.edu/pubs/codemonkeys.pdf">searching</a> for.</p>



<h2 class="wp-block-heading">The economics of the environment: The new strategic moat</h2>



<p>If data was the oil of the first AI wave, “environments” are the refineries of the second. RL requires a sandbox where the AI can fail safely millions of times.</p>



<p>This infrastructure shift is personified by the evolution of industry leaders like Scale AI. Having established their footprint by labeling data for the predictive era, they are now pivoting to build the RL environments required for the <a href="https://scale.com/blog/enterprise-rl-agents">age of action</a>. The industry is graduating from annotating the past to engineering the synthetic arenas where proprietary business logic is codified and refined.</p>



<p>The engineering feat of building these simulations is only half the battle; the real value lies in the subject matter experts who facilitate reinforcement learning from human feedback (RLHF). By grading the AI’s reasoning to codify a reward function, these experts create the critical feedback loop where institutional wisdom directly calibrates the model against real-world business logic. This shift creates a new economic reality: as the models themselves become commoditized, the moat moves to the proprietary rules of the game that only a domain expert can provide.</p>



<h2 class="wp-block-heading">The business mandate: Building the playground</h2>



<p>For some CEOs outside the tech sector, the mandate is not to build AI models, but to build the simulators those models need to learn. In traditional industries, the cost of failure in the real world is too high.</p>



<p>Executives can sponsor the creation of a digital twin — a high-fidelity replica of the business where AI can “practice” safely. By connecting the digital twin (the world) to a reward function (the goal), companies are achieving provable ROI:</p>



<ul class="wp-block-list">
<li><strong>Walmart:</strong> Using digital twins of 4,200 stores, Walmart simulated equipment failures, reducing maintenance costs by 19% and saving $1.4M <a href="https://willowinc.com/customer-stories/walmart-uses-digital-twin-technology-to-optimize-operations">in downtime</a>.</li>



<li><strong>Nestlé:</strong> By converting 10,000 products into digital twins and simulating marketing variations, they’ve reduced production costs and lead times <a href="https://www.microsoft.com/en-us/industry/blog/retail/2025/07/15/the-next-wave-of-ai-for-content-creation-includes-digital-twins/" rel="nofollow">by over 70%</a>.</li>



<li><strong>Starbucks:</strong> Their Deep Brew platform practices inventory management, resulting in a 30% increase in ROI and $410M in <a href="https://www.growthhq.io/our-thinking/how-starbucks-ai-predictive-ordering-is-redefining-customer-loyalty-deep-brew-roi-and-the-future-of-retail-across-north-america-europe-and-a" rel="nofollow">incremental revenue</a>.</li>
</ul>



<h2 class="wp-block-heading">The domain expert as the ultimate architect</h2>



<p>The current interest in RL represents a fundamental shift in leadership. In the era of predictive AI, the advantage belonged to those with the most data. In the era of agentic AI, the advantage belongs to those with the clearest understanding of their own business logic.</p>



<p>The CEO’s specific call to action is to become the architect of the reward function. The machine can solve for any goal it is given, but it cannot decide what winning looks like for a complex organization. The strategic moat of the future is the ability to translate institutional wisdom into the digital rewards that allow AI to further your unique business logic.</p>



<p>The companies that win the next decade won’t be those that outsource their intelligence, but those whose leaders are experts in their own domain.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Driven Phishing Campaign Uses Browser Permissions to Harvest Sensitive Data]]></title>
<description><![CDATA[A new AI-driven phishing campaign, uncovered by Cyble Research & Intelligence Labs (CRIL) demonstrates how attackers are moving beyond traditional credential theft and adopting more invasive, technology-driven tactics. 

According to CRIL, the campaign has been active since early 2026 and relie...]]></description>
<link>https://tsecurity.de/de/3354669/it-security-nachrichten/ai-driven-phishing-campaign-uses-browser-permissions-to-harvest-sensitive-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3354669/it-security-nachrichten/ai-driven-phishing-campaign-uses-browser-permissions-to-harvest-sensitive-data/</guid>
<pubDate>Tue, 17 Mar 2026 10:04:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1500" height="1036" src="https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="AI-driven phishing" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing.webp 1500w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-300x207.webp 300w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-1024x707.webp 1024w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-768x530.webp 768w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-600x414.webp 600w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-150x104.webp 150w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-750x518.webp 750w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-1140x787.webp 1140w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing.webp 1500w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-300x207.webp 300w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-1024x707.webp 1024w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-768x530.webp 768w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-600x414.webp 600w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-150x104.webp 150w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-750x518.webp 750w, https://thecyberexpress.com/wp-content/uploads/AI-driven-phishing-1140x787.webp 1140w" sizes="(max-width: 1500px) 100vw, 1500px" title="AI-Driven Phishing Campaign Uses Browser Permissions to Harvest Sensitive Data 1"></p><span data-contrast="auto">A new AI-driven phishing campaign, uncovered by Cyble Research &amp; Intelligence Labs (CRIL) </span><span data-contrast="auto">demonstrates how attackers are moving beyond traditional credential theft and adopting more invasive, technology-driven tactics.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">According to CRIL, the campaign has been active since early 2026 and relies on a wide range of social engineering lures, including themes like ID scanner, Telegram ID freezing, and “Health Fund AI.” These deceptive entry points are designed to trick users into granting access to hardware features such as cameras and microphones under the guise of verification or account recovery.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Once permissions are granted, the malicious scripts begin collecting extensive <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="26997">data</a>. This includes images, video recordings, microphone audio, device specifications, contact details, and approximate geographic location. The stolen data is then transmitted to attacker-controlled systems via Telegram bots, making exfiltration quick and efficient.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto"><a href="https://cyble.com/blog/ai-assisted-phishing-campaign/" target="_blank" rel="nofollow noopener">Researchers</a> also noted signs of AI-assisted code generation within the campaign’s infrastructure. Structured annotations and unusual emoji-based formatting embedded in the scripts suggest the use of generative AI tools to streamline development and deployment.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Infrastructure and Attack Mechanism</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The campaign primarily uses the edgeone.app platform to host <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="26999">phishing</a> pages, enabling scalable and low-cost deployment. These pages impersonate well-known platforms such as TikTok, Instagram, Telegram, <a href="https://thecyberexpress.com/cve-2026-2441-google-chrome/" target="_blank" rel="noopener">Google Chrome</a>, and even games like Flappy Bird to gain user trust.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

[caption id="" align="aligncenter" width="496"]<img class="" src="https://cyble.com/wp-content/uploads/2026/03/figure-2-723x1024.png" alt="Campaign Overview" width="496" height="702"> Campaign Overview (Source: Cyble)[/caption]

<span data-contrast="auto">Unlike traditional phishing attacks that rely on victims entering credentials, this AI-driven phishing campaign focuses on browser-level permissions. Once a user interacts with a phishing page, <a href="https://thecyberexpress.com/critical-splunk-vulnerabilities/" target="_blank" rel="noopener">JavaScript code triggers</a> permission prompts. If accepted, the script activates the device <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-find-hidden-cameras-using-mobile-phones/" title="camera" data-wpil-keyword-link="linked" data-wpil-monitor-id="27000">camera</a> and begins capturing live data.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

[caption id="" align="aligncenter" width="529"]<img class="" src="https://cyble.com/wp-content/uploads/2026/03/figure-3.png" alt="JavaScript Implementation Used for Browser-Based Photo Capture" width="529" height="267"> JavaScript Implementation Used for Browser-Based Photo Capture (Source: Cyble)[/caption]

<span data-contrast="auto">A key technique involves rendering a frame from a live video stream onto an HTML5 canvas using </span><span data-contrast="auto">ctx.drawImage()</span><span data-contrast="auto">, then converting it into a JPEG file via </span><span data-contrast="auto">canvas.toBlob()</span><span data-contrast="auto">. This file</span><span data-contrast="auto"> is immediately transmitted to attackers through the Telegram Bot API. The same process is used for video and <a href="https://thecyberexpress.com/grigol-liluashvili-arrested/" target="_blank" rel="noopener">audio recordings</a>.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Expanded Data Collection Capabilities</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The phishing framework goes beyond simple media capture. It performs extensive device fingerprinting using browser APIs such as:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<ul>
 	<li><span data-contrast="auto">navigator.userAgent</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">navigator.platform</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">navigator.deviceMemory</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">navigator.hardwareConcurrency</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">navigator.connection</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">navigator.getBattery</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
</ul>
<span data-contrast="auto">Through these methods, attackers gather detailed information about the victim’s device, including operating system, browser version, CPU capacity, RAM, network type, and battery status.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Additionally, the script retrieves the victim’s IP address via external services and enriches it with geolocation data such as country, city, latitude, and longitude. This information is aggregated and sent to attackers before further data collection begins.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

[caption id="" align="aligncenter" width="491"]<img class="" src="https://cyble.com/wp-content/uploads/2026/03/figure-4.png" alt="Script Fetching Victim IP and Geolocation via External APIs" width="491" height="441"> Script Fetching Victim IP and Geolocation via External APIs (Source: Cyble)[/caption]

<span data-contrast="auto">The campaign also attempts to access contact lists using the browser’s Contacts Picker API. If users grant permission, names, phone numbers, and email addresses are extracted and transmitted.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Role of Telegram in Data Exfiltration</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">A notable aspect of this campaign is its reliance on Telegram for command-and-control (C2) operations. By using Telegram bots, attackers eliminate the need for complex backend infrastructure. Data such as images, videos, and audio files are sent directly via <a href="https://thecyberexpress.com/eu-socta-2025/" target="_blank" rel="noopener">API methods</a> like </span><span data-contrast="auto">sendPhoto</span><span data-contrast="auto">, </span><span data-contrast="auto">sendVideo</span><span data-contrast="auto">, and </span><span data-contrast="auto">sendAudio</span><span data-contrast="auto">.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">This approach simplifies operations while providing attackers with immediate access to stolen information.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">User Interface Deception</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">To maintain credibility, phishing pages display realistic status messages such as “Capturing photo,” “Sending to server,” and “Photo sent successfully.” These prompts mimic legitimate verification workflows, reinforcing the illusion of authenticity.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Once the data is captured and transmitted, the script shuts down the camera and resets the interface, leaving minimal visible traces of the attack.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Risks and Business Impact</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The implications of this AI-driven phishing campaign are significant. By collecting biometric and contextual data, attackers gain powerful tools for:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<ul>
 	<li><span data-contrast="auto">Identity theft and account takeover</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">Bypassing video-based verification systems</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">Targeted <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="27002">social engineering</a> attacks</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
 	<li><span data-contrast="auto">Extortion using captured multimedia</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></li>
</ul>
<span data-contrast="auto">For example, images and audio recordings could be used to impersonate victims or bypass <a href="https://thecyberexpress.com/binance-kyc-data-breach-refuted-by-the-company/" target="_blank" rel="noopener">KYC (Know Your Customer) systems</a>. Device and location data allow attackers to craft highly personalized attacks, increasing their success rate.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Organizations face additional <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="27001">risks</a>, including reputational damage, regulatory exposure, and financial losses. The use of impersonated brands further amplifies the threat by eroding trust in legitimate digital services.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">One of the more unusual findings in this campaign is the presence of emojis embedded within the script’s operational logic. While uncommon in manually written <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="26998">malware</a>, such patterns are linked to AI-assisted code generation. This suggests attackers may be leveraging generative AI tools to accelerate development and scale their operations.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data]]></title>
<description><![CDATA[Executive Summary




Cyble Research & Intelligence Labs (CRIL) has identified a widespread, highly active social engineering campaign hosted primarily on edgeone.app infrastructure.


The initial access vectors are diverse — ranging from “ID Scanner,” and “Telegram ID Freezing,” to “Health Fund ...]]></description>
<link>https://tsecurity.de/de/3351982/it-security-nachrichten/ai-assisted-phishing-campaign-exploits-browser-permissions-to-capture-victim-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3351982/it-security-nachrichten/ai-assisted-phishing-campaign-exploits-browser-permissions-to-capture-victim-data/</guid>
<pubDate>Mon, 16 Mar 2026 08:21:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1366" height="768" src="https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="AI-Assisted" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog.png 1366w, https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog-300x169.png 300w, https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog-1024x576.png 1024w, https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog-768x432.png 768w" sizes="(max-width: 1366px) 100vw, 1366px" title="AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) has identified a widespread, highly active social engineering campaign hosted primarily on <strong>edgeone.app</strong> infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The initial access vectors are diverse — ranging from <strong>“ID Scanner,” </strong>and<strong> “Telegram ID Freezing,” </strong>to<strong> “Health Fund AI”</strong>—to trick users into granting browser-level hardware permissions such as camera and microphone access under the pretext of verification or service recovery.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Upon gaining permissions, the underlying JavaScript workflow attempts to capture <strong>live images, video recordings, microphone audio, device information, contact details, and approximate geographic location</strong> from affected devices. This data is subsequently transmitted to attacker-controlled infrastructure, enabling operators to obtain Personally Identifiable Information (PII) and contextually sensitive information. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Further analysis revealed indicators of potential AI-assisted code generation, including structured annotations and emoji-based message formatting embedded within the operational logic. These characteristics reflect a growing trend where <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/cyber-threat-actor-and-types/" target="_blank" rel="noopener" title="What is a Cyber Threat Actor? Types of Threat Actors" data-wpil-keyword-link="linked" data-wpil-monitor-id="29405">threat actors</a> leverage generative AI tools to accelerate the development of phishing frameworks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The breadth of data collected in this campaign extends beyond traditional credential phishing and raises significant security concerns. Harvested multimedia and device telemetry could be leveraged for <strong>identity theft, targeted social engineering, account compromise attempts, or extortion</strong>, posing risks to both individuals and organizations. (Figure 1)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114781,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-1-1024x605.png" alt="Figure 1 – Malicious Web Interfaces Used for Data Collection, AI-Assisted" class="wp-image-114781"><figcaption class="wp-element-caption">Figure 1 – Malicious Web Interfaces Used for Data Collection</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Infrastructure: Extensive use of edgeone.app (EdgeOne Pages) for hosting low-cost, scalable, and highly available phishing landing pages.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Biometric Harvesting: The operation abuses legitimate browser APIs to access cameras, microphones, and device information after user consent.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>C2 Mechanism: Utilization of the Telegram Bot API (api.telegram.org) as a streamlined C2 and data exfiltration channel.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Diverse Lures: Attackers rotate lures, including "ID Scanner" and "Health Fund AI", to target various demographics and bypass regional security filters.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The phishing pages impersonate popular platforms and services, including TikTok, Telegram, Instagram, Chrome/Google Drive, and game-themed lures such as Flappy Bird, to increase victim trust.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Once interaction occurs, the campaign attempts to collect multiple forms of sensitive data, including photographs, video recordings, microphone audio, device information, contact details, and approximate geographic location.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Campaign Start:</strong> Observed since early 2026</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Primary Objective:</strong> Harvesting victim multimedia data and device information</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Primary Infrastructure:</strong> edgeone.app (multiple subdomains)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Impersonated Brands:</strong> TikTok, Telegram, Instagram, Chrome/Google Drive, Flappy Bird</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Key Behavior:</strong> Browser permission prompts used to capture camera images, record audio/video, enumerate device metadata, retrieve geolocation information, and attempt contact list access through browser APIs.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign operates as a web-based phishing framework that captures photographs directly from victims’ devices. The infrastructure hosts multiple phishing templates that impersonate verification systems or service recovery portals. The goal is to socially engineer users into granting browser permission for camera access.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Unlike traditional credential phishing pages, these pages do not primarily collect typed input. Instead, they rely on browser hardware permissions, requesting access to the device’s camera. Once permission is granted, the page silently captures a frame from the live video stream and exfiltrates it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The use of Telegram as a data collection mechanism indicates that the operators prioritize low operational complexity and immediate access to stolen data. Since Telegram bots can receive file uploads through simple HTTP requests, attackers can directly integrate the API into client-side scripts.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Business Impact and Potential Abuse</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The data collected through this campaign provides attackers with <strong>multiple forms of sensitive personal information and contextual intelligence</strong>, thereby significantly increasing the effectiveness of follow-on attacks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>One potential abuse scenario involves <strong>identity fraud and account recovery manipulation</strong>. The campaign captures victim photographs, video recordings, and audio samples that could be used to bypass identity verification workflows used by financial platforms, social media services, or other online services that rely on biometric or video-based verification.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, the collection of device information, location data, and contact details allows attackers to build detailed victim profiles. This information may be used to perform <strong>targeted social engineering attacks</strong>, impersonate victims in communication platforms, or craft convincing fraud attempts against their contacts.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Another concerning use case involves <strong>extortion and intimidation</strong>. Because the campaign captures multimedia data, such as camera images, video recordings, and microphone audio, attackers may pressure victims by threatening to expose the collected material unless a payment is made.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For organizations, the broader business impact includes:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Increased risk of <strong>identity theft and account takeover attempts</strong></li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Potential abuse of stolen biometric and multimedia data in fraud schemes</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Targeted phishing or fraud campaigns against employees and customers</strong></li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Reputational damage if impersonated brand identities are used in malicious campaigns</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign's ability to collect multiple categories of sensitive information from a single interaction significantly amplifies the risk to both individuals and businesses.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Why does this matter?</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This campaign marks a significant evolution in phishing operations, shifting from credential theft to <strong>harvesting biometric and device-level data</strong>. By abusing browser permissions to capture victims' live images, audio, and contextual device information, threat actors can obtain high-quality identity data that is difficult to revoke or replace.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The stolen data can be leveraged to <strong>bypass video-KYC and remote identity verification processes</strong>, enabling fraudulent account creation, synthetic identity fraud, account takeover, and financial scams across banking, fintech, telecom, and digital service platforms. Additionally, high-resolution facial images and audio samples may be weaponized for <strong>AI-driven impersonation and deepfake attacks</strong>, increasing the effectiveness of business email compromise and targeted social engineering campaigns.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For organizations, the campaign introduces elevated risks, including <strong>financial losses, regulatory non-compliance, AML exposure, reputational damage, and erosion of trust in digital onboarding systems</strong>, highlighting the growing need for stronger verification controls and browser-permission abuse detection.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The infection chain, as outlined in Figure 2, shows the stages of the attack.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114782,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-2-723x1024.png" alt="Figure 2: Campaign Overview" class="wp-image-114782"><figcaption class="wp-element-caption">Figure 2: Campaign Overview</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Phishing Page Behaviour</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The phishing page contains embedded JavaScript that leverages browser media APIs to access the victim’s device camera after obtaining user permission. Once access is granted, the script initializes a live video stream and processes its frames.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A capture function then renders a frame from the video feed onto an HTML5 canvas using ctx.drawImage(), effectively converting the live camera input into a static image. (see Figure 3)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The canvas content is subsequently encoded into a JPEG blob via canvas.toBlob(), creating a binary image object that can be transmitted through HTTP requests to attacker-controlled infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114783,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-3.png" alt="Figure 3 – JavaScript Implementation Used for Browser-Based Photo Capture" class="wp-image-114783"><figcaption class="wp-element-caption">Figure 3 – JavaScript Implementation Used for Browser-Based Photo Capture</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Expanded Data Collection Capabilities</strong><strong></strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of the campaign script indicates that the phishing framework performs extensive device fingerprinting and environment enumeration before initiating camera-based verification workflows.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The script collects system metadata using the following browser APIs</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>navigator.userAgent</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.platform</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.deviceMemory</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.hardwareConcurrency</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.connection</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.getBattery</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This allows the attacker to gather detailed information such as operating system type and version, device model indicators, screen resolution and orientation, browser version, available RAM, CPU core count, network type, battery level, and language settings.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114784,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-4.png" alt="Figure 4 – Script Fetching Victim IP and Geolocation via External APIs" class="wp-image-114784"><figcaption class="wp-element-caption">Figure 4 – Script Fetching Victim IP and Geolocation via External APIs</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, the script retrieves the victim’s public IP address using services such as api.ipify.org, then enriches the geolocation using ipapi.co, enabling the collection of country, city, latitude, and longitude data. (see Figure 4)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This telemetry is aggregated and transmitted to the attacker via the Telegram Bot API, providing operators with contextual information about the victim’s device and location prior to further data harvesting.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114785,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-5.png" alt="Figure 5 – Audio Recording Logic Used to Capture Victim Microphone Input" class="wp-image-114785"><figcaption class="wp-element-caption">Figure 5 – Audio Recording Logic Used to Capture Victim Microphone Input</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Beyond system profiling, the script implements multiple routines for collecting multimedia and personal data via browser permission prompts. The campaign captures several still images from both the front-facing and rear-facing cameras, records short video clips using the MediaRecorder API, and performs microphone recordings.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These recordings are packaged as JPEG, WebM video, or WebM audio files and exfiltrated via Telegram API methods such as sendPhoto, sendVideo, and sendAudio. (see Figure 5)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114786,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-6.png" alt="" class="wp-image-114786"><figcaption class="wp-element-caption">Figure 6 – Code Requesting Access to Victim Contacts via the Contacts API</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, the script attempts to access the victim’s contact list through the Contacts Picker API (navigator.contacts.select), requesting attributes such as contact names, phone numbers, and email addresses. If granted, the selected contacts are formatted into structured messages and transmitted to the attacker. (see Figure 6)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>User Interface Manipulation</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The phishing pages include interface elements designed to convince victims that the image capture process is legitimate.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For example, status messages displayed during execution may include:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>“Capturing photo”</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>“Sending to server”</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>“Photo sent successfully”</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>These messages simulate the behavior of legitimate identity verification platforms and help maintain the illusion that the process is part of a valid verification workflow.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the image is successfully transmitted, the script terminates the camera stream and resets the interface after a short delay.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Infrastructure Observations</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of the campaign revealed that the phishing pages are primarily hosted under the edgeone.app domain. Multiple variations of phishing pages were observed using similar JavaScript logic and workflow patterns.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The consistent use of the same infrastructure suggests that attackers may be operating a templated phishing kit capable of generating different themed pages while maintaining the same underlying data-collection logic.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Because the image exfiltration occurs through Telegram infrastructure, the phishing pages themselves do not require backend servers, simplifying deployment and enabling rapid rotation of phishing URLs.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Indicators of Potential Generative AI Use in Script Development</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis of the phishing framework, researchers observed the use of emojis embedded directly within the script’s message formatting logic. These emojis appear in structured status messages that are assembled and transmitted during the data collection workflow. The use of decorative Unicode symbols within operational code is uncommon in manually written malicious scripts but has increasingly been observed in campaigns that use generative AI tools during development. (see Figure 7)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114787,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-7.png" alt="Figure 7 – Script Fragment Suggesting AI-Assisted Development" class="wp-image-114787"><figcaption class="wp-element-caption">Figure 7 – Script Fragment Suggesting AI-Assisted Development</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Targeted Countries and Impersonated Brands</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During infrastructure monitoring and phishing URL telemetry analysis, the campaign's infrastructure appears to be globally accessible. Analysis of the phishing templates used in this campaign reveals that the operators impersonate a range of widely recognized consumer platforms and applications. Observed brand impersonation themes include:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Impersonated Brand</strong><strong></strong></td>
<td><strong>Observed Theme</strong><strong></strong></td>
</tr>
<tr>
<td>TikTok</td>
<td>Free followers/engagement rewards</td>
</tr>
<tr>
<td>Flappy Bird</td>
<td>Game reward or verification workflows</td>
</tr>
<tr>
<td>Telegram</td>
<td>Account freezing or verification alerts</td>
</tr>
<tr>
<td>Instagram</td>
<td>Account recovery or follower reward systems</td>
</tr>
<tr>
<td>Google Chrome / Google Drive</td>
<td>Security verification prompts</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Our deep-dive analysis revealed a sophisticated phishing campaign that extends beyond traditional credential theft by harvesting <strong>multimedia and device-level data</strong> through browser permission abuse.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign attempts to collect <strong>photographs, video recordings, audio recordings from microphones, contact details, device information, and approximate location data</strong> directly from victims. This operation demonstrates a growing trend where attackers leverage <strong>client-side scripting and legitimate web services</strong> to collect and transmit sensitive data without relying on traditional command-and-control infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Indicators in the script also suggest AI-assisted development, reflecting how threat actors may be using generative AI tools to accelerate the creation of phishing frameworks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The breadth of information collected increases the potential for <strong>identity theft, targeted social engineering, account compromise attempts, and extortion</strong>. Organizations should remain cautious about phishing pages that request hardware permissions, such as camera, microphone, or contact access, particularly when originating from untrusted domains.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Cyble’s </strong><a href="https://cyble.com/products/cyble-vision/" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Platforms </strong></a>continuously monitor emerging threats, attacker infrastructure, and malware activity across the <a href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noreferrer noopener">dark web</a>, <a href="https://cyble.com/knowledge-hub/what-is-the-deep-web/" target="_blank" rel="noreferrer noopener">deep web</a>, and open sources. This proactive intelligence empowers organizations with early detection, brand and domain protection, infrastructure mapping, and attribution insights. Altogether, these capabilities provide a critical head start in mitigating and responding to evolving <a href="https://cyble.com/knowledge-hub/what-are-cyber-threats/" target="_blank" rel="noreferrer noopener">cyber threats</a>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Restrict camera permissions for unknown websites</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Monitor outbound traffic to api.telegram.org when originating from browser sessions</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Deploy browser security extensions capable of identifying phishing pages</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Implement domain monitoring for suspicious infrastructure hosting phishing kits</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td><strong>Initial Access</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1566/">T1566 – Phishing</a></td>
<td>Phishing pages used to lure victims to malicious verification workflows.</td>
</tr>
<tr>
<td><strong>Execution</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1059/007/">T1059.007 – JavaScript</a></td>
<td>Malicious JavaScript executed in the victim’s browser.</td>
</tr>
<tr>
<td><strong>Collection</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1125/">T1125 – Video Capture</a></td>
<td>Camera access is used to capture photos and videos of victims.</td>
</tr>
<tr>
<td><strong>Collection</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1123/">T1123 – Audio Capture</a></td>
<td>Microphone access is used to record the victim's audio.</td>
</tr>
<tr>
<td><strong>Collection</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1005/">T1005 – Data from Local System</a></td>
<td>Device information is collected from the browser environment.</td>
</tr>
<tr>
<td><strong>Collection</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1213/">T1213 – Data from Information Repositories</a></td>
<td>Contact details retrieved from the device contact list.</td>
</tr>
<tr>
<td><strong>Discovery</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1082/">T1082 – System Information Discovery</a></td>
<td>Device and browser information enumeration.</td>
</tr>
<tr>
<td><strong>Discovery</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1614/">T1614 – System Location Discovery</a></td>
<td>Victim IP and geographic location collected.</td>
</tr>
<tr>
<td><strong>Exfiltration</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1567/">T1567 – Exfiltration Over Web Services</a></td>
<td>Collected data transmitted to the attacker's infrastructure.</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The IOCs have been added to this <a href="https://github.com/CRIL-ThreatIntelligence/IOCs/tree/main/AI-Assisted%20Phishing%20Uses%20Browser%20Permissions%20to%20Steal%20Data">GitHub</a> repository. Please review and integrate them into your <a href="https://cyble.com/knowledge-hub/what-is-a-threat-intelligence-feed/" target="_blank" rel="noreferrer noopener">Threat Intelligence feed</a> to enhance protection and improve your overall security posture.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/ai-assisted-phishing-campaign/">AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data]]></title>
<description><![CDATA[Executive Summary




Cyble Research & Intelligence Labs (CRIL) has identified a widespread, highly active social engineering campaign hosted primarily on edgeone.app infrastructure.


The initial access vectors are diverse — ranging from “ID Scanner,” and “Telegram ID Freezing,” to “Health Fund ...]]></description>
<link>https://tsecurity.de/de/3351888/it-security-nachrichten/ai-assisted-phishing-campaign-exploits-browser-permissions-to-capture-victim-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3351888/it-security-nachrichten/ai-assisted-phishing-campaign-exploits-browser-permissions-to-capture-victim-data/</guid>
<pubDate>Mon, 16 Mar 2026 07:35:24 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1366" height="768" src="https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="AI-Assisted" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog.png 1366w, https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog-300x169.png 300w, https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog-1024x576.png 1024w, https://cyble.com/wp-content/uploads/2026/03/AI-assisted-blog-768x432.png 768w" sizes="(max-width: 1366px) 100vw, 1366px" title="AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) has identified a widespread, highly active social engineering campaign hosted primarily on <strong>edgeone.app</strong> infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The initial access vectors are diverse — ranging from <strong>“ID Scanner,” </strong>and<strong> “Telegram ID Freezing,” </strong>to<strong> “Health Fund AI”</strong>—to trick users into granting browser-level hardware permissions such as camera and microphone access under the pretext of verification or service recovery.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Upon gaining permissions, the underlying JavaScript workflow attempts to capture <strong>live images, video recordings, microphone audio, device information, contact details, and approximate geographic location</strong> from affected devices. This data is subsequently transmitted to attacker-controlled infrastructure, enabling operators to obtain Personally Identifiable Information (PII) and contextually sensitive information. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Further analysis revealed indicators of potential AI-assisted code generation, including structured annotations and emoji-based message formatting embedded within the operational logic. These characteristics reflect a growing trend where <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/cyber-threat-actor-and-types/" target="_blank" rel="noopener" title="What is a Cyber Threat Actor? Types of Threat Actors" data-wpil-keyword-link="linked" data-wpil-monitor-id="29405">threat actors</a> leverage generative AI tools to accelerate the development of phishing frameworks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The breadth of data collected in this campaign extends beyond traditional credential phishing and raises significant security concerns. Harvested multimedia and device telemetry could be leveraged for <strong>identity theft, targeted social engineering, account compromise attempts, or extortion</strong>, posing risks to both individuals and organizations. (Figure 1)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114781,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-1-1024x605.png" alt="Figure 1 – Malicious Web Interfaces Used for Data Collection, AI-Assisted" class="wp-image-114781"><figcaption class="wp-element-caption">Figure 1 – Malicious Web Interfaces Used for Data Collection</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Infrastructure: Extensive use of edgeone.app (EdgeOne Pages) for hosting low-cost, scalable, and highly available phishing landing pages.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Biometric Harvesting: The operation abuses legitimate browser APIs to access cameras, microphones, and device information after user consent.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>C2 Mechanism: Utilization of the Telegram Bot API (api.telegram.org) as a streamlined C2 and data exfiltration channel.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Diverse Lures: Attackers rotate lures, including "ID Scanner" and "Health Fund AI", to target various demographics and bypass regional security filters.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The phishing pages impersonate popular platforms and services, including TikTok, Telegram, Instagram, Chrome/Google Drive, and game-themed lures such as Flappy Bird, to increase victim trust.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Once interaction occurs, the campaign attempts to collect multiple forms of sensitive data, including photographs, video recordings, microphone audio, device information, contact details, and approximate geographic location.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Campaign Start:</strong> Observed since early 2026</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Primary Objective:</strong> Harvesting victim multimedia data and device information</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Primary Infrastructure:</strong> edgeone.app (multiple subdomains)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Impersonated Brands:</strong> TikTok, Telegram, Instagram, Chrome/Google Drive, Flappy Bird</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Key Behavior:</strong> Browser permission prompts used to capture camera images, record audio/video, enumerate device metadata, retrieve geolocation information, and attempt contact list access through browser APIs.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign operates as a web-based phishing framework that captures photographs directly from victims’ devices. The infrastructure hosts multiple phishing templates that impersonate verification systems or service recovery portals. The goal is to socially engineer users into granting browser permission for camera access.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Unlike traditional credential phishing pages, these pages do not primarily collect typed input. Instead, they rely on browser hardware permissions, requesting access to the device’s camera. Once permission is granted, the page silently captures a frame from the live video stream and exfiltrates it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The use of Telegram as a data collection mechanism indicates that the operators prioritize low operational complexity and immediate access to stolen data. Since Telegram bots can receive file uploads through simple HTTP requests, attackers can directly integrate the API into client-side scripts.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Business Impact and Potential Abuse</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The data collected through this campaign provides attackers with <strong>multiple forms of sensitive personal information and contextual intelligence</strong>, thereby significantly increasing the effectiveness of follow-on attacks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>One potential abuse scenario involves <strong>identity fraud and account recovery manipulation</strong>. The campaign captures victim photographs, video recordings, and audio samples that could be used to bypass identity verification workflows used by financial platforms, social media services, or other online services that rely on biometric or video-based verification.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, the collection of device information, location data, and contact details allows attackers to build detailed victim profiles. This information may be used to perform <strong>targeted social engineering attacks</strong>, impersonate victims in communication platforms, or craft convincing fraud attempts against their contacts.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Another concerning use case involves <strong>extortion and intimidation</strong>. Because the campaign captures multimedia data, such as camera images, video recordings, and microphone audio, attackers may pressure victims by threatening to expose the collected material unless a payment is made.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For organizations, the broader business impact includes:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Increased risk of <strong>identity theft and account takeover attempts</strong></li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Potential abuse of stolen biometric and multimedia data in fraud schemes</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Targeted phishing or fraud campaigns against employees and customers</strong></li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Reputational damage if impersonated brand identities are used in malicious campaigns</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign's ability to collect multiple categories of sensitive information from a single interaction significantly amplifies the risk to both individuals and businesses.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Why does this matter?</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This campaign marks a significant evolution in phishing operations, shifting from credential theft to <strong>harvesting biometric and device-level data</strong>. By abusing browser permissions to capture victims' live images, audio, and contextual device information, threat actors can obtain high-quality identity data that is difficult to revoke or replace.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The stolen data can be leveraged to <strong>bypass video-KYC and remote identity verification processes</strong>, enabling fraudulent account creation, synthetic identity fraud, account takeover, and financial scams across banking, fintech, telecom, and digital service platforms. Additionally, high-resolution facial images and audio samples may be weaponized for <strong>AI-driven impersonation and deepfake attacks</strong>, increasing the effectiveness of business email compromise and targeted social engineering campaigns.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For organizations, the campaign introduces elevated risks, including <strong>financial losses, regulatory non-compliance, AML exposure, reputational damage, and erosion of trust in digital onboarding systems</strong>, highlighting the growing need for stronger verification controls and browser-permission abuse detection.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The infection chain, as outlined in Figure 2, shows the stages of the attack.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114782,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-2-723x1024.png" alt="Figure 2: Campaign Overview" class="wp-image-114782"><figcaption class="wp-element-caption">Figure 2: Campaign Overview</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Phishing Page Behaviour</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The phishing page contains embedded JavaScript that leverages browser media APIs to access the victim’s device camera after obtaining user permission. Once access is granted, the script initializes a live video stream and processes its frames.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A capture function then renders a frame from the video feed onto an HTML5 canvas using ctx.drawImage(), effectively converting the live camera input into a static image. (see Figure 3)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The canvas content is subsequently encoded into a JPEG blob via canvas.toBlob(), creating a binary image object that can be transmitted through HTTP requests to attacker-controlled infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114783,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-3.png" alt="Figure 3 – JavaScript Implementation Used for Browser-Based Photo Capture" class="wp-image-114783"><figcaption class="wp-element-caption">Figure 3 – JavaScript Implementation Used for Browser-Based Photo Capture</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Expanded Data Collection Capabilities</strong><strong></strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of the campaign script indicates that the phishing framework performs extensive device fingerprinting and environment enumeration before initiating camera-based verification workflows.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The script collects system metadata using the following browser APIs</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>navigator.userAgent</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.platform</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.deviceMemory</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.hardwareConcurrency</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.connection</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>navigator.getBattery</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This allows the attacker to gather detailed information such as operating system type and version, device model indicators, screen resolution and orientation, browser version, available RAM, CPU core count, network type, battery level, and language settings.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114784,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-4.png" alt="Figure 4 – Script Fetching Victim IP and Geolocation via External APIs" class="wp-image-114784"><figcaption class="wp-element-caption">Figure 4 – Script Fetching Victim IP and Geolocation via External APIs</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, the script retrieves the victim’s public IP address using services such as api.ipify.org, then enriches the geolocation using ipapi.co, enabling the collection of country, city, latitude, and longitude data. (see Figure 4)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This telemetry is aggregated and transmitted to the attacker via the Telegram Bot API, providing operators with contextual information about the victim’s device and location prior to further data harvesting.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114785,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-5.png" alt="Figure 5 – Audio Recording Logic Used to Capture Victim Microphone Input" class="wp-image-114785"><figcaption class="wp-element-caption">Figure 5 – Audio Recording Logic Used to Capture Victim Microphone Input</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Beyond system profiling, the script implements multiple routines for collecting multimedia and personal data via browser permission prompts. The campaign captures several still images from both the front-facing and rear-facing cameras, records short video clips using the MediaRecorder API, and performs microphone recordings.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These recordings are packaged as JPEG, WebM video, or WebM audio files and exfiltrated via Telegram API methods such as sendPhoto, sendVideo, and sendAudio. (see Figure 5)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114786,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-6.png" alt="" class="wp-image-114786"><figcaption class="wp-element-caption">Figure 6 – Code Requesting Access to Victim Contacts via the Contacts API</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, the script attempts to access the victim’s contact list through the Contacts Picker API (navigator.contacts.select), requesting attributes such as contact names, phone numbers, and email addresses. If granted, the selected contacts are formatted into structured messages and transmitted to the attacker. (see Figure 6)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>User Interface Manipulation</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The phishing pages include interface elements designed to convince victims that the image capture process is legitimate.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For example, status messages displayed during execution may include:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>“Capturing photo”</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>“Sending to server”</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>“Photo sent successfully”</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>These messages simulate the behavior of legitimate identity verification platforms and help maintain the illusion that the process is part of a valid verification workflow.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the image is successfully transmitted, the script terminates the camera stream and resets the interface after a short delay.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Infrastructure Observations</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of the campaign revealed that the phishing pages are primarily hosted under the edgeone.app domain. Multiple variations of phishing pages were observed using similar JavaScript logic and workflow patterns.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The consistent use of the same infrastructure suggests that attackers may be operating a templated phishing kit capable of generating different themed pages while maintaining the same underlying data-collection logic.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Because the image exfiltration occurs through Telegram infrastructure, the phishing pages themselves do not require backend servers, simplifying deployment and enabling rapid rotation of phishing URLs.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Indicators of Potential Generative AI Use in Script Development</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis of the phishing framework, researchers observed the use of emojis embedded directly within the script’s message formatting logic. These emojis appear in structured status messages that are assembled and transmitted during the data collection workflow. The use of decorative Unicode symbols within operational code is uncommon in manually written malicious scripts but has increasingly been observed in campaigns that use generative AI tools during development. (see Figure 7)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":114787,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/03/figure-7.png" alt="Figure 7 – Script Fragment Suggesting AI-Assisted Development" class="wp-image-114787"><figcaption class="wp-element-caption">Figure 7 – Script Fragment Suggesting AI-Assisted Development</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Targeted Countries and Impersonated Brands</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During infrastructure monitoring and phishing URL telemetry analysis, the campaign's infrastructure appears to be globally accessible. Analysis of the phishing templates used in this campaign reveals that the operators impersonate a range of widely recognized consumer platforms and applications. Observed brand impersonation themes include:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Impersonated Brand</strong><strong></strong></td>
<td><strong>Observed Theme</strong><strong></strong></td>
</tr>
<tr>
<td>TikTok</td>
<td>Free followers/engagement rewards</td>
</tr>
<tr>
<td>Flappy Bird</td>
<td>Game reward or verification workflows</td>
</tr>
<tr>
<td>Telegram</td>
<td>Account freezing or verification alerts</td>
</tr>
<tr>
<td>Instagram</td>
<td>Account recovery or follower reward systems</td>
</tr>
<tr>
<td>Google Chrome / Google Drive</td>
<td>Security verification prompts</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Our deep-dive analysis revealed a sophisticated phishing campaign that extends beyond traditional credential theft by harvesting <strong>multimedia and device-level data</strong> through browser permission abuse.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign attempts to collect <strong>photographs, video recordings, audio recordings from microphones, contact details, device information, and approximate location data</strong> directly from victims. This operation demonstrates a growing trend where attackers leverage <strong>client-side scripting and legitimate web services</strong> to collect and transmit sensitive data without relying on traditional command-and-control infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Indicators in the script also suggest AI-assisted development, reflecting how threat actors may be using generative AI tools to accelerate the creation of phishing frameworks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The breadth of information collected increases the potential for <strong>identity theft, targeted social engineering, account compromise attempts, and extortion</strong>. Organizations should remain cautious about phishing pages that request hardware permissions, such as camera, microphone, or contact access, particularly when originating from untrusted domains.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Cyble’s </strong><a href="https://cyble.com/products/cyble-vision/" target="_blank" rel="noreferrer noopener"><strong>Threat Intelligence Platforms </strong></a>continuously monitor emerging threats, attacker infrastructure, and malware activity across the <a href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noreferrer noopener">dark web</a>, <a href="https://cyble.com/knowledge-hub/what-is-the-deep-web/" target="_blank" rel="noreferrer noopener">deep web</a>, and open sources. This proactive intelligence empowers organizations with early detection, brand and domain protection, infrastructure mapping, and attribution insights. Altogether, these capabilities provide a critical head start in mitigating and responding to evolving <a href="https://cyble.com/knowledge-hub/what-are-cyber-threats/" target="_blank" rel="noreferrer noopener">cyber threats</a>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Restrict camera permissions for unknown websites</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Monitor outbound traffic to api.telegram.org when originating from browser sessions</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Deploy browser security extensions capable of identifying phishing pages</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Implement domain monitoring for suspicious infrastructure hosting phishing kits</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td><strong>Initial Access</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1566/">T1566 – Phishing</a></td>
<td>Phishing pages used to lure victims to malicious verification workflows.</td>
</tr>
<tr>
<td><strong>Execution</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1059/007/">T1059.007 – JavaScript</a></td>
<td>Malicious JavaScript executed in the victim’s browser.</td>
</tr>
<tr>
<td><strong>Collection</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1125/">T1125 – Video Capture</a></td>
<td>Camera access is used to capture photos and videos of victims.</td>
</tr>
<tr>
<td><strong>Collection</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1123/">T1123 – Audio Capture</a></td>
<td>Microphone access is used to record the victim's audio.</td>
</tr>
<tr>
<td><strong>Collection</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1005/">T1005 – Data from Local System</a></td>
<td>Device information is collected from the browser environment.</td>
</tr>
<tr>
<td><strong>Collection</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1213/">T1213 – Data from Information Repositories</a></td>
<td>Contact details retrieved from the device contact list.</td>
</tr>
<tr>
<td><strong>Discovery</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1082/">T1082 – System Information Discovery</a></td>
<td>Device and browser information enumeration.</td>
</tr>
<tr>
<td><strong>Discovery</strong></td>
<td><a href="https://attack.mitre.org/techniques/T1614/">T1614 – System Location Discovery</a></td>
<td>Victim IP and geographic location collected.</td>
</tr>
<tr>
<td><strong>Exfiltration</strong><strong></strong></td>
<td><a href="https://attack.mitre.org/techniques/T1567/">T1567 – Exfiltration Over Web Services</a></td>
<td>Collected data transmitted to the attacker's infrastructure.</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The IOCs have been added to this <a href="https://github.com/CRIL-ThreatIntelligence/IOCs/tree/main/AI-Assisted%20Phishing%20Uses%20Browser%20Permissions%20to%20Steal%20Data">GitHub</a> repository. Please review and integrate them into your <a href="https://cyble.com/knowledge-hub/what-is-a-threat-intelligence-feed/" target="_blank" rel="noreferrer noopener">Threat Intelligence feed</a> to enhance protection and improve your overall security posture.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/ai-assisted-phishing-campaign/">AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4596: Adding voice-over audio track created using text to speech on the movie subtitles]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.

We’ll explain why we’re doing it, what it is, and cover some useful tools along the way.

I’ve been watching movies recommended to me by my colleagues.

As I work for a global company, the recommendations are often “Foreign Language”, which b...]]></description>
<link>https://tsecurity.de/de/3351507/podcasts/hpr4596-adding-voice-over-audio-track-created-using-text-to-speech-on-the-movie-subtitles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3351507/podcasts/hpr4596-adding-voice-over-audio-track-created-using-text-to-speech-on-the-movie-subtitles/</guid>
<pubDate>Mon, 16 Mar 2026 01:01:58 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<h1>
We’ll explain why we’re doing it, what it is, and cover some useful tools along the way.</h1>
<p>
I’ve been watching movies recommended to me by my colleagues.</p>
<p>
As I work for a global company, the recommendations are often “Foreign Language”, which by definition is every movie to someone.</p>
<p>
It’s often difficult to read the subtitles, or they are distracting from the acting.</p>
<p>
So I thought of converting the subtitles to speech for inclusion as an audio track, to produce a Voice Over or Lectoring audio track.</p>
<h2>
Lectoring aka Voice Over Translations</h2>
<p>
First used is soviet countries to read the news and propaganda from a lectors - the first podcasts ?</p>
<blockquote>
In Polish, lektor is also used to mean “off-screen reader” or “voice-over artist”. A lektor is a (usually male) reader who provides the Polish voice-over on foreign-language programmes and films where the voice-over translation technique is used. This is the standard localization technique on Polish television and (as an option) on many DVDs; full dubbing is generally reserved for children’s material.</blockquote>
<ul>
<li>
<a href="https://en.wikipedia.org/wiki/Lector#Television" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/Lector#Television</a>
</li>
</ul>
<h2>
Example: Night of the Living Dead</h2>
<p>
To give you an idea of what this sounds like I’m going to play you an example of the out of copyright movie, <a href="https://en.wikipedia.org/wiki/Night_of_the_Living_Dead" rel="noopener noreferrer" target="_blank">
Night of the Living Dead</a>
.</p>
<blockquote>
In the United States, Night of the Living Dead was mistakenly released into the public domain because the original distributor failed to replace the copyright notice when changing the film’s name</blockquote>
<h3>
Original</h3>
<p>
First the original sound track, then the same clip with the voice over track.</p>
<audio controls="" preload="none">
  <source src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_1968_Night_of_the_Living_Dead_Original.mp3" type="audio/mpeg">
</audio>
<h3>
Voice Over</h3>
<audio controls="" preload="none">
  <source src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_1968_Night_of_the_Living_Dead_voice_over.mp3" type="audio/mpeg">
</audio>
<h1>
Proof of Concept</h1>
<p>
As a native English speaker I find it difficult to follow those Voice Over tracks as I am trying to focus on the underlying audio. In discussions with Polish friends, it seems that this is not a problem when Polish is your native language. To put that to the test I wanted to try it out on a movie to see if that were indeed the case.</p>
<p>
I asked on Mastodon for a non English movie that was Creative Commons but did have English Subtitles, and HPR host <a href="https://hackerpublicradio.org/correspondents/0196.html" rel="noopener noreferrer" target="_blank">
Windigo</a>
had the answer.</p>
<blockquote>
<a href="https://en.wikipedia.org/wiki/Nasty_Old_People" rel="noopener noreferrer" target="_blank">
2009 Nasty Old People</a>
is a 2009 Swedish film directed by Hanna Sköld, Tangram Film. It premiered on 10 October 2009 at Kontrapunkt in Malmö, and on file sharing site The Pirate Bay. The film is available as an authorized and legal download under the Creative Commons license CC BY-NC-SA.</blockquote>
<p>
So my idea was to take each bit of subtitle text, convert it to audio, then have the generated audio play at the same time the subtitle appears on the screen.</p>
<p>
We use <a href="https://github.com/OHF-Voice/piper1-gpl" rel="noopener noreferrer" target="_blank">
piper</a>
to process shows here on HPR, and we also generate <a href="https://en.wikipedia.org/wiki/SubRip" rel="noopener noreferrer" target="_blank">
srt, or SubRip subtitle files</a>
for each show.</p>
<p>
SRT or SubRip files are the easiest subtitle file to work with.</p>
<p>
From <a href="https://en.wikipedia.org/wiki/SubRip" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/SubRip</a>
</p>
<p>
The SubRip file format is described on the <a href="https://en.wikipedia.org/wiki/Matroska" rel="noopener noreferrer" target="_blank">
Matroska</a>
multimedia <a href="https://en.wikipedia.org/wiki/Container_format_(digital)" rel="noopener noreferrer" target="_blank">
container format</a>
website as “perhaps the most basic of all subtitle formats.”</p>
<p>
SubRip (SubRip Text) files are named with the <a href="https://en.wikipedia.org/wiki/Filename_extension" rel="noopener noreferrer" target="_blank">
extension</a>
<code>
.srt</code>
, and contain formatted lines of plain text in groups separated by a blank line.</p>
<p>
Subtitles are numbered sequentially, starting at 1. The <a href="https://en.wikipedia.org/wiki/Timecode" rel="noopener noreferrer" target="_blank">
timecode</a>
format used is hours:minutes:seconds,milliseconds with time units fixed to two zero-padded digits and fractions fixed to three zero-padded digits (00:00:00,000).</p>
<p>
The comma (,) is used for <a href="https://en.wikipedia.org/wiki/Decimal_separator#History" rel="noopener noreferrer" target="_blank">
fractional separator</a>
.</p>
<ol>
<li>
A numeric counter identifying each sequential subtitle</li>
<li>
The time that the subtitle should appear on the screen, followed by <code>
–&gt;</code>
and the time it should disappear</li>
<li>
Subtitle text itself on one or more lines</li>
<li>
A blank line containing no text, indicating the end of this subtitle</li>
</ol>
<p>
I downloaded <a href="https://archive.org/details/VisionOntv-NastyOldPeopleFeatureFilm625-3" rel="noopener noreferrer" target="_blank">
the movie from the Internet Archive</a>
, and then used <a href="https://github.com/OHF-Voice/piper1-gpl" rel="noopener noreferrer" target="_blank">
Piper voice</a>
to convert a minutes worth of subtitles.</p>
<blockquote>
piper_voice: A fast and local neural text-to-speech engine that embeds espeak-ng for phonemization. GPL-3.0 license</blockquote>
<p>
Once I had the audio prepared for a sample of the subtitles, it was over to audacity to create a new subtitle audio track.</p>
<blockquote>
Audacity is the world’s most popular audio editing and recording app GPL v2 or later,</blockquote>
<p>
Timing the segments would be a problem, if it were not for the fact that Audacity supports srt files as Labels.</p>
<p>
File &gt; Import &gt; Lables. Then select the srt file</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_1.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_1_tn.png">
</a>
</p>
<p>
</p>
<p>
The subtitle track with the text of the audio will be displayed. I could then Import each Audio segment and line them up with the subtitle track for to get the correct timing.</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_2.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_2_tn.png">
</a>
</p>
<p>
Each subtitles segment created a new separate audio file which I then exported.</p>
<p>
I then used <a href="https://kdenlive.org/" rel="noopener noreferrer" target="_blank">
Kdenlive</a>
to open the video and import the audio and subtitle tracks.</p>
<blockquote>
Kdenlive: is the acronym for KDE Non-Linear Video Editor. It works on Linux, Windows, macOS, and BSD. GPL-3.0-or-later</blockquote>
<p>
There is a good article on adding <a href="https://www.checksub.com/blog/subtitles-in-kdenlive" rel="noopener noreferrer" target="_blank">
by Jean-Marc on How to Add Subtitles Easily in Kdenlive</a>
</p>
<p>
Project &gt; Subtitles &gt; Add Subtitle Track</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_3.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_3_tn.png">
</a>
</p>
<p>
Select the Subtitle file</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_4.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_4_tn.png">
</a>
</p>
<p>
Align the subtitle and audio track.</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_5.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_5_tn.png">
</a>
</p>
<p>
After rendering the segment out I was satisfied that this was something worth doing.</p>
<h1>
The script</h1>
<p>
The <a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_srt2audio.bash" rel="noopener noreferrer" target="_blank">
script</a>
can be found on the episode page for this show on the HPR site, and I put it together as a proof of concept.</p>
<p>
It creates a new audio track for the subtitles, and merges this with the original sound track to create a new selectable sound track.</p>
<p>
It begins by creating a length of silent audio that is as long as up to the first subtitle time segment begin timestamp.</p>
<p>
The first subtitle segment is converted from text to speech using <a href="https://github.com/OHF-Voice/piper1-gpl" rel="noopener noreferrer" target="_blank">
Piper voice</a>
</p>
<p>
That segment of audio is added to the initial silence track.</p>
<p>
We check the total length so far, and then see if there is supposed to be silence between the last and next subtitle segment begin timestamp.</p>
<p>
If there is, then a filler piece of silence is added until the next subtitle should appear.</p>
<p>
If not then the audio for both subtitles play immediately after one another.</p>
<p>
I was worried that the subtitle audio would then lag behind the on screen dialogue but it works surprisingly well. Even long series of dialogue sort themselves out after a bit.</p>
<p>
We do this over and over again for each subtitle, right up to the very end of the movie.</p>
<p>
This new subtitle to speech audio track is then merged back into the media file as a new audio track.</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_6.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_6_tn.png">
</a>
</p>
<pre data-language="plain">
96
00:15:06,240 --&gt; 00:15:10,640
It will be two years before it's this big
</pre>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_7.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_7_tn.png">
</a>
</p>
<pre data-language="plain">
97
00:15:12,840 --&gt; 00:15:17,840
But don't you bother. By then I'll be long gone
</pre>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_8.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_8_tn.png">
</a>
</p>
<pre data-language="plain">
98
00:15:19,840 --&gt; 00:15:22,400
It was just a question
</pre>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_9.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_9_tn.png">
</a>
</p>
<pre data-language="plain">
99
00:15:22,880 --&gt; 00:15:25,480
Porridge?
</pre>
<p>
</p>
<h3>
Original</h3>
<p>
First the original sound track, then the same clip with the voice over track.</p>
<audio controls="" preload="none">
  <source src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_Nasty_Old_People_Original.mp3" type="audio/mpeg">
</audio>
<h3>
Voice Over</h3>
<audio controls="" preload="none">
  <source src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_Nasty_Old_People_voice_over.mp3" type="audio/mpeg">
</audio>
<h1>
Lessons learned</h1>
<p>
Now that I have done this for a lot of movies, there a few tips for getting the best output.</p>
<p>
The creation of the audio track usually goes well, but you can run into issues with the merging of the new track back into the movie.</p>
<h1>
Preparation</h1>
<p>
The first thing you need is a subtitle file which will be the basis of the voice you will be listening to. It should be good quality so that it matches when the actors speak.</p>
<p>
It’s important to clean up this before you use it, fixing spelling mistakes and removing html that will get rendered. Listening to three hours of “I L Zero ve y Zero u”, or “less than forward slash I, greater than”, or “L am from Lndia” can get a bit tedious.</p>
<p>
You should also try and get versions that translate the songs as well.</p>
<h3>
Getting a SRT file from the media.</h3>
<p>
As many Subtitles are taken from a DVDs they can often be poor <a href="https://en.wikipedia.org/wiki/Optical_character_recognition" rel="noopener noreferrer" target="_blank">
Optical character recognition</a>
versions of the bitmap-based streams. So a picture of string “Hello World” rather than the letters.</p>
<h3>
ffmpeg</h3>
<p>
By far the easiest and best way to get the subtitles is to extract it from the movie itself, provided it’s a separate track.</p>
<blockquote>
ffmpeg is a complete, cross-platform solution to record, convert and stream audio and video. LGPL-2.1-or-later, GPL-2.0-or-later</blockquote>
<ul>
<li>
<a href="https://ffmpeg.org/" rel="noopener noreferrer" target="_blank">
https://ffmpeg.org/</a>
</li>
</ul>
<p>
<code>
ffmpeg -y -hide_banner -loglevel error -txt_format text -i "${this_movie_file}" "${this_srt_file}"</code>
</p>
<h3>
Getting a SRT file from the web.</h3>
<p>
If that fails you can try to get the subtitle files from the Internet.</p>
<ul>
<li>
<a href="https://www.opensubtitles.org/" rel="noopener noreferrer" target="_blank">
https://www.opensubtitles.org</a>
</li>
</ul>
<p>
Select your language with the highest subtitle rating.</p>
<p>
You can check the media using the <em>
mpv</em>
media player.</p>
<blockquote>
mpv is a media player based on MPlayer and mplayer2. It supports a wide variety of video file formats, audio and video codecs, and subtitle types. GPLv2+, parts under LGPLv2.1+, some optional parts under GPLv3</blockquote>
<ul>
<li>
<a href="https://mpv.io/manual/master/" rel="noopener noreferrer" target="_blank">
https://mpv.io/manual/master/</a>
</li>
</ul>
<p>
Name the srt file with the same prefix as the movie and <code>
mpv</code>
will play it. You can also use the <code>
--sub-files=</code>
option as well.</p>
<p>
<code>
mpv "${this_movie_file}" --sub-files="${this_srt_file}"</code>
</p>
<p>
Scrub through the file to see if the timing is correct. The subtitles can be toggled using the <code>
j</code>
key.</p>
<h3>
Fixing Timing issues</h3>
<p>
It’s very important to get the subtitles to align, otherwise the voices will be out of sync.</p>
<p>
When the subtitles don’t match up, it’s usually that they need to have the start offset corrected.</p>
<p>
<em>
ffsubsync</em>
will automatically try and adjust the offset of the first subtitle to the first use of speech in a movie.</p>
<blockquote>
ffsubsync: Language-agnostic automatic synchronization of subtitles with video, so that subtitles are aligned to the correct starting point within the video. MIT license</blockquote>
<ul>
<li>
<a href="https://github.com/smacke/ffsubsync" rel="noopener noreferrer" target="_blank">
https://github.com/smacke/ffsubsync</a>
</li>
</ul>
<p>
<code>
pip install ffsubsync</code>
</p>
<pre data-language="plain">
ffs video.mp4 -i unsynchronized.srt -o synchronized.srt
</pre>
<p>
<em>
LosslessCut</em>
will allow you to quickly remove additional trailers, or ads, at the beginning, so that ffsubsync will have a better chance of working if they are trimmed away.</p>
<blockquote>
LosslessCut: aims to be the ultimate cross platform FFmpeg GUI for extremely fast and lossless operations on video, audio, subtitle and other related media files. GPL-2.0 license</blockquote>
<ul>
<li>
<a href="https://github.com/mifi/lossless-cut" rel="noopener noreferrer" target="_blank">
https://github.com/mifi/lossless-cut</a>
</li>
</ul>
<p>
If that fails to match up the subtitles, you can use <a href="https://gist.github.com/flatlinebb/07caa79fd3b9f3770788df21756a4611" rel="noopener noreferrer" target="_blank">
mpv keyboard shortcuts</a>
, move to the first speech segment an then press the <code>
Ctrl+Shift+Left</code>
and <code>
Ctrl+Shift+Right</code>
to adjust subtitle delay so that the next or previous subtitle is displayed. It will also show a number giving the miliseconds the delay is, eg <code>
-148416</code>
miliseconds or <code>
-148.416</code>
seconds.</p>
<p>
You can use many tools to adjust the subtitles, and I tried out <a href="https://github.com/zambrinf/srt-offset" rel="noopener noreferrer" target="_blank">
SRT Offset</a>
.</p>
<blockquote>
srt-offset: A simple command-line tool to offset SRT subtitle files. This tool allows you to adjust the timing of subtitles in SRT files, which can be useful when subtitles are out of sync with the video. MIT license</blockquote>
<p>
<code>
srt-offset -i input.srt -offset -148.416 -o output.srt</code>
</p>
<h2>
Manually adding the new subtitle to speech audio track</h2>
<p>
If that presents an issue then you can use <a href="https://avidemux.sourceforge.net/" rel="noopener noreferrer" target="_blank">
avidemux</a>
to just add the new audio track.</p>
<blockquote>
Avidemux: is a free video editor designed for simple cutting, filtering and encoding tasks. GPL V2</blockquote>
<p>
Open Avidemux, and select “File &gt; Open”, to select the movie.</p>
<p>
Then go to “Audio &gt; Select Track”</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_10.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_10_tn.png">
</a>
</p>
<p>
Select the next unselected track and tick “Enabled”, “Add Audio Track”</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_11.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_11_tn.png">
</a>
</p>
<p>
Then pick the new mixed track, in this example <code>
.~NastyOldPeople_mixed.mp3</code>
</p>
<p>
<a href="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_12.png">
<img src="https://hackerpublicradio.org/eps/hpr4596/hpr4596_image_12_tn.png">
</a>
</p>
<h1>
Conclusion</h1>
<p>
I now find it much easier to watch a movie with the voice over track. It gets to a point where I don’t even notice it is there and just hear the actors speak in their own language, and I just know what they are saying.</p>
<h3>
Links</h3>
<ul>
<li>
<a href="https://en.wikipedia.org/wiki/Nasty_Old_People" rel="noopener noreferrer" target="_blank">
2009 Nasty Old People</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/File:Wikimania_2015_-_Jimmy_Wales_-_es.webm" rel="noopener noreferrer" target="_blank">
A Spanish voice-over translation</a>
</li>
<li>
<a href="https://avidemux.sourceforge.net/" rel="noopener noreferrer" target="_blank">
avidemux</a>
</li>
<li>
<a href="https://www.checksub.com/blog/subtitles-in-kdenlive" rel="noopener noreferrer" target="_blank">
by Jean-Marc on How to Add Subtitles Easily in Kdenlive</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Container_format" rel="noopener noreferrer" target="_blank">
container format</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Decimal_separator#History" rel="noopener noreferrer" target="_blank">
Decimal separator</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Filename_extension" rel="noopener noreferrer" target="_blank">
extension</a>
</li>
<li>
<a href="https://ffmpeg.org/" rel="noopener noreferrer" target="_blank">
ffmpeg</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/FFmpeg" rel="noopener noreferrer" target="_blank">
ffmpeg on wikipedia</a>
</li>
<li>
<a href="https://github.com/smacke/ffsubsync" rel="noopener noreferrer" target="_blank">
ffsubsync</a>
</li>
<li>
<a href="https://www.gnu.org/licenses/gpl-3.0.en.html" rel="noopener noreferrer" target="_blank">
GPL-3.0 license</a>
</li>
<li>
<a href="https://www.gnu.org/licenses/old-licenses/gpl-2.0.html" rel="noopener noreferrer" target="_blank">
GPL v2 or later</a>
</li>
<li>
<a href="https://kdenlive.org/" rel="noopener noreferrer" target="_blank">
Kdenlive</a>
</li>
<li>
<a href="https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html" rel="noopener noreferrer" target="_blank">
LGPL-2.1</a>
</li>
<li>
<a href="https://github.com/mifi/lossless-cut" rel="noopener noreferrer" target="_blank">
LosslessCut</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Matroska" rel="noopener noreferrer" target="_blank">
Matroska</a>
</li>
<li>
<a href="https://mit-license.org/" rel="noopener noreferrer" target="_blank">
MIT license</a>
</li>
<li>
<a href="https://archive.org/details/night-of-the-living-dead-1968_202312" rel="noopener noreferrer" target="_blank">
Movie on Archive.org</a>
</li>
<li>
<a href="https://mpv.io/manual/master/" rel="noopener noreferrer" target="_blank">
mpv</a>
</li>
<li>
<a href="https://gist.github.com/flatlinebb/07caa79fd3b9f3770788df21756a4611" rel="noopener noreferrer" target="_blank">
mpv keyboard shortcuts</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Mpv_%28media_player%29" rel="noopener noreferrer" target="_blank">
mpv wikipedia</a>
</li>
<li>
<a href="https://archive.org/details/VisionOntv-NastyOldPeopleFeatureFilm625-3" rel="noopener noreferrer" target="_blank">
Nasty Old People from the Internet Archive</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Night_of_the_Living_Dead#Copyright_status_and_home_media" rel="noopener noreferrer" target="_blank">
Night of the Living Dead</a>
</li>
<li>
<a href="https://www.youtube.com/watch?v=zprG3AtrvOk" rel="noopener noreferrer" target="_blank">
Noc żywych trupów | Film grozy | Polski lektor</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/OpenSubtitles" rel="noopener noreferrer" target="_blank">
OpenSubtitles</a>
</li>
<li>
<a href="https://www.opensubtitles.org/" rel="noopener noreferrer" target="_blank">
opensubtitles.org</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Optical_character_recognition" rel="noopener noreferrer" target="_blank">
Optical character recognition</a>
</li>
<li>
<a href="https://github.com/OHF-Voice/piper1-gpl" rel="noopener noreferrer" target="_blank">
Piper voice</a>
</li>
<li>
<a href="https://github.com/zambrinf/srt-offset" rel="noopener noreferrer" target="_blank">
SRT Offset</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/SubRip" rel="noopener noreferrer" target="_blank">
srt, or SubRip subtitle files</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/SubRip" rel="noopener noreferrer" target="_blank">
SubRip</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Timecode" rel="noopener noreferrer" target="_blank">
Timecode</a>
</li>
<li>
<a href="https://en.wikipedia.org/wiki/Voice-over_translation" rel="noopener noreferrer" target="_blank">
Voice-over translation</a>
</li>
<li>
<a href="https://github.com/openai/whisper" rel="noopener noreferrer" target="_blank">
Whisper</a>
</li>
</ul>
<p>
</p><p><a href="https://hackerpublicradio.org/eps/hpr4596/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4593: Nuclear Reactor Technology - Ep 8 Generation Four Reactors]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


01 Introduction

This episode is the eighth and final one in an 8 part series on nuclear reactor technology. 




In this episode I will talk about future reactor technologies, particularly what are referred to as "Generation IV" reactors.

Some ...]]></description>
<link>https://tsecurity.de/de/3339862/podcasts/hpr4593-nuclear-reactor-technology-ep-8-generation-four-reactors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3339862/podcasts/hpr4593-nuclear-reactor-technology-ep-8-generation-four-reactors/</guid>
<pubDate>Wed, 11 Mar 2026 01:01:32 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
01 Introduction</p>
<p>
This episode is the eighth and final one in an 8 part series on nuclear reactor technology. </p>
<p>
<br>
</p>
<p>
In this episode I will talk about future reactor technologies, particularly what are referred to as "Generation IV" reactors.</p>
<p>
Some of these will be simply additional developments of reactors that have already been discussed in this series, but this will show what technologies are seen as most promising today.</p>
<p>
<br>
</p>
<p>
03 What is Generation IV</p>
<p>
Generation IV International Forum is an international organization whose membership is composed of many of the countries that are researching advanced fission reactors.</p>
<p>
Their goal is to conduct a number of joint research projects to advance the state of the art.</p>
<p>
The members agree to participate in and share research on advanced technologies.</p>
<p>
<br>
</p>
<p>
04 Research Subjects</p>
<p>
05 Lead Fast Reactors (LFR)</p>
<p>
08 Sodium Fast Reactor (SFR)</p>
<p>
10 Gas-Cooled Fast Reactor (GFR)</p>
<p>
13 Very High Temperature Reactor (VHTR)</p>
<p>
16 Molten Salt Reactors (MSR)</p>
<p>
19 Super Critical Water Reactors (SCWR)</p>
<p>
<br>
</p>
<p>
27 Episode Conclusion</p>
<p>
In this episode we looked at the reactor types being studied under an international organization called the "Generation IV International Forum".</p>
<p>
All of these reactor types except for supercritical water reactors are not new and we have looked at them previously.</p>
<p>
<br>
</p>
<p>
Supercritical water reactors themselves represent the natural evolution of water cooled reactors.</p>
<p>
I expect that many of these research projects will not result in commercially successful results. Such is the nature of R&amp;D.</p>
<p>
<br>
</p>
<p>
The supercritical water reactors would on the surface seem to have the most promise in terms of commercial use, as they focus on bringing two very well established technologies together, water cooled reactors and supercritical water.</p>
<p>
However, I'm not an expert in this field, so I'm just making an educated guess on that.</p>
<p>
<br>
</p>
<p>
30 Series Conclusion</p>
<p>
This is the end of the series on nuclear reactor technology.</p>
<p>
<br>
</p>
<p>
Episode 1 covered nuclear basics, including basic terminology and civil versus military nuclear material.</p>
<p>
Episode 2 covered nuclear fuel, including the different types, recycling of spent fuel, uranium and thorium resources, and medical isotopes. </p>
<p>
<br>
</p>
<p>
Episode 3 covered reactor basics, including slow versus fast reactors, moderators, coolants, steam generation, refuelling methods, and the three main commercial reactor types.</p>
<p>
Episode 4 covered the less common reactor types, including types which are no longer used, some historical developmental dead ends, and some types which may possibly be making a come back.</p>
<p>
<br>
</p>
<p>
Episode 5 covered fast reactors, including the different types, some of their history, why they were developed, and why they have so far only seen limited use.</p>
<p>
Episode 6 covered thorium reactors, including what is thorium and how it differs from uranium, why there is interest in thorium, what sorts of reactors can use thorium, and why thorium has not yet seen widespread use.</p>
<p>
<br>
</p>
<p>
Episode 7 covered small modular reactors or SMRs, what the reason is for developing them, what are the different ways they may be used, and where they are currently being built.</p>
<p>
Episode 8 covered "Generator IV" reactors which is a collection of future technologies.  </p>
<p>
<br>
</p>
<p>
I hope that this series has been useful and informative on how nuclear reactors work and what the different types of reactors and different types of fuel are. </p>
<p>
I have focused on the past and present without looking very much beyond what is already developed except in this final episode.</p>
<p>
<br>
</p>
<p>
I have focused on the reactors, fuel, and medical isotopes, without much discussion of mining, refining, converting, enrichment, fuel fabrication, or disposal. </p>
<p>
I also haven't talked much about the rest of a functioning power plant, which includes cooling, steam turbines, generators, transformers, control systems, refuelling systems, switch gear, transmission grid connections, grid coordination, and many, many other things.</p>
<p>
<br>
</p>
<p>
And of course there's the entire grid itself, a very complex thing when operated at scale. </p>
<p>
<br>
</p>
<p>
None the less we count on the lights going on when we turn on the light switch while seldom thinking about all the things that go on behind the scenes to make that happen. </p>
<p>
As the recent blackout in Spain shows, that is something that we can't take for granted. </p>
<p>
<br>
</p>
<p>
With plans for "Net Zero" amounting essentially to the further electrification of everything, we need reliable sources of electrical energy to make that happen. Without reliable energy available at the touch of a switch, we don't even have a stone age civilization, let alone a modern one. </p>
<p>
<br>
</p>
<p>
So think about that the next time you turn on the lights or listen to a podcast or do nearly anything else in your daily life. </p>
<p>
<br>
</p>
<p>
This concludes the eighth and final episode of an 8 part series on nuclear reactor technology. </p>
<p>
<br>
</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4593/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A strategic roadmap for the post-quantum CIO]]></title>
<description><![CDATA[The recent Palo Alto Networks Quantum Safe Summit assembled industry titans and cybersecurity leaders to deliver a sobering message to CIOs: the harvest now, decrypt later (HNDL) threat is real and active, and the window for cryptographic transition is closing.



For the modern CIO, quantum read...]]></description>
<link>https://tsecurity.de/de/3324741/it-security-nachrichten/a-strategic-roadmap-for-the-post-quantum-cio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324741/it-security-nachrichten/a-strategic-roadmap-for-the-post-quantum-cio/</guid>
<pubDate>Wed, 04 Mar 2026 11:06:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The recent <a href="https://www.paloaltonetworks.com/quantum-safe" rel="nofollow">Palo Alto Networks Quantum Safe Summit</a> assembled industry titans and cybersecurity leaders to deliver a sobering message to CIOs: the harvest now, decrypt later (HNDL) threat is real and active, and the window for cryptographic transition is closing.</p>



<p>For the modern CIO, quantum readiness is more than just a technical upgrade, it’s a fundamental requirement for long-term business resilience and public trust. And the consensus this year so far is quantum is no longer an if for CIOs, but a when. Customers, employees, shareholders, and other stakeholders need to trust that the data being fed into AI systems is protected, and quantum looms as a major threat to breaking this trust.</p>



<p>To navigate this shift, CIOs must move beyond theoretical awareness and into a structured operational framework. The following roadmap provides a strategic checklist necessary to transition from legacy encryption to quantum-safe resilience.</p>



<h2 class="wp-block-heading">The reality of the quantum clock</h2>



<p>There’s a common misconception that <a href="https://www.cio.com/article/4058026/quantum-computing-is-coming-for-your-data-heres-how-to-stay-secure.html?utm=hybrid_search">quantum threats</a> are decades away. But Jerry Chow, CTO of quantum-centric supercomputing at IBM, says the roadmap is accelerating. IBM targets its Starling processor, a 200-logical-qubit fault-tolerant system, for 2029, and the Blue Jay system, aiming for 1,000 logical qubits, by 2033. And while a million-qubit machine might be required to fully break RSA-2048 encryption, Nobel Laureate in physics John Martinis warns that the threat could arrive sooner via algorithmic breakthroughs.</p>



<p>“You have time to do this properly,” Martinis said during the summit, “but you don’t have an infinite amount of time.” Regarding algorithmic advances, most current encryption-breaking projections are based on quantum-classical hybrids — essentially running traditional logic on quantum hardware.</p>



<p>However, as fault-tolerant quantum systems become commercially accessible, we’ll see the rise of native quantum algorithms<strong>.</strong> These are mathematical models designed specifically for the unique properties of qubits, like superposition and entanglement, allowing them to solve problems that classical logic can’t even map. It’s the shift from doing old things on a new machine to doing things we once thought were impossible.</p>



<h2 class="wp-block-heading">The HNDL risk and navigating standards</h2>



<p>The most pressing reason for immediate action is HNDL. Adversaries currently intercept and store encrypted sensitive data like intellectual property, state secrets, and financial records with the intent to decrypt it once quantum hardware matures. If your data has a shelf life of over 10 years, it’s already at risk. <a href="https://www.iotworldtoday.com/security/deloitte-companies-face-harvest-now-decrypt-later-quantum-threat" rel="nofollow">IoT World Today</a> references a Deloitte poll that found over 50% of surveyed professionals believe their organizations are at risk from HNDL attacks, yet only a fraction has completed a full data sensitive-life inventory.</p>



<p>The transition to post-quantum cryptography (PQC) is being led by the National Institute of Standards and Technology (NIST). Dustin Moody, lead of the PQC project at NIST, says the standards are now ready for implementation.</p>



<p><strong>Key milestones for CIOs:</strong></p>



<ul class="wp-block-list">
<li><strong>The 2035 mandate:</strong> The US Federal Government has set this deadline for full migration to PQC standards. Private sector organizations, especially those in regulated industries like finance, healthcare, and defense are expected to follow this timeline to maintain compliance and interoperability.</li>



<li><strong>Cryptographic agility:</strong> NIST and CISA urge organizations to move away from hard-coded security. Crypto agility, the ability to swap encryption algorithms without overhauling entire systems, is the new gold standard for IT architecture, and is something CIOs need to ensure is part of their deployment strategy. Getting locked into a specific algorithm could create long-term pain, making optionality mandatory.</li>
</ul>



<h2 class="wp-block-heading">The CIO’s action plan: discover, protect, accelerate</h2>



<p>The summit outlined a three-pillar strategy for organizations to move from vulnerability to resilience.</p>



<p><strong>Phase I: Discovery and inventory</strong></p>



<p>You can’t secure what you can’t see. Most organizations lack a Cryptographic Bill of Materials (CBOM). The challenge is that cryptography is buried in everything from legacy OT to cloud-native microservices. So the goal is to use automated tools to map where RSA, ECC, and other vulnerable algorithms are used. Palo Alto Networks, for instance, leverages existing firewall telemetry to create quantum-aware discovery engines without needing new sensors.</p>



<p><strong>Phase II: Systemic protection</strong></p>



<p>Once a comprehensive cryptographic inventory is established, the CIO’s focus must shift to risk-based prioritization, where the shelf life of data dictates the urgency of remediation. But not all data carries equal quantum risk in that while a session token expires in minutes, corporate trade secrets or legal records must remain confidential for decades.</p>



<p>By segmenting assets into high-priority, long-lived data and lower-priority, short-lived data, organizations can ensure they’re securing the assets most vulnerable to retroactive decryption before the quantum clock runs out. The former would be long-term strategic data, such as IP and legal records, whereas the latter would be more short-lived information like one-time passwords and session tokens.</p>



<p>Some CIOs question the value of data after a few years. While not every byte of data retains its value over time, every enterprise possesses crown jewel information — intellectual property, long-term contracts, or sensitive PII — that remains high-value targets for retroactive decryption. The key is to understand what that data is and to protect it now. Today, that’s the minority of company data, although it’s still a healthy percentage. According to the <a href="https://ponemonsullivanreport.com/2025/" rel="nofollow">2025 Ponemon-Sullivan Privacy Report</a>, 36% of all data currently in storage is considered mission-critical to organizational survival, yet most of this remains protected by classical encryption vulnerable to future quantum attacks.</p>



<p><strong>Phase III: Solving the legacy anchor</strong></p>



<p>This refers to mission-critical systems like satellite systems, medical devices, or ancient mainframe apps that can’t be easily updated. Anand Oswal, EVP at Palo Alto Networks, spoke about cipher translation, which allows next-gen firewalls to act as a translator, converting vulnerable traffic into a quantum-secure session in real-time. This effectively future-proofs legacy hardware without a rip and replace project.</p>



<h2 class="wp-block-heading">Operationalizing quantum security</h2>



<p>Mike Duffy, US Federal CISO, highlighted that quantum readiness is central to responsible IT modernization since without it, considering PQC readiness is really just creating technical debt in the future, he said.</p>



<p>As most CIOs have experienced, technical debt remains one of the biggest inhibitors in modernizing systems, and among the many challenges is to understand the financial and risk implications through resource allocation. Quantum migration isn’t a side project for the IT team, it requires dedicated budget and executive sponsorship. Another is vendor management issues. CIOs must demand PQC roadmaps from their vendors, and every new procurement today should be evaluated for its cryptographic agility.</p>



<h2 class="wp-block-heading">The path forward</h2>



<p>While Q-Day, or the day a quantum computer breaks the internet, is in the future, the security preparation for it must happen today. To adequately prepare, CIOs should appoint a quantum lead by tasking a senior member of IT or security to oversee the transition, conduct a CBOM inventory beginning with the most sensitive data flows, and engage with the ecosystem by using platforms that offer closed-loop resilience — systems that can both identify and enforce the cure at the network level.</p>



<p>Manual cryptographic migration is mathematically impossible at enterprise scale. The shift to quantum-safe security must be automated, platform-based, and initiated now.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Illumio Insights brings agentless visibility and breach containment to hybrid environments]]></title>
<description><![CDATA[Illumio unveiled its solution to deliver agentless visibility and breach containment across both data center and cloud environments. Illumio Insights ingests real-time telemetry and policy data from Check Point and Fortinet firewalls, converting existing firewall information into real-time traffi...]]></description>
<link>https://tsecurity.de/de/3314387/it-security-nachrichten/illumio-insights-brings-agentless-visibility-and-breach-containment-to-hybrid-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3314387/it-security-nachrichten/illumio-insights-brings-agentless-visibility-and-breach-containment-to-hybrid-environments/</guid>
<pubDate>Fri, 27 Feb 2026 11:37:45 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Illumio unveiled its solution to deliver agentless visibility and breach containment across both data center and cloud environments. Illumio Insights ingests real-time telemetry and policy data from Check Point and Fortinet firewalls, converting existing firewall information into real-time traffic maps…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/illumio-insights-brings-agentless-visibility-and-breach-containment-to-hybrid-environments/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/illumio-insights-brings-agentless-visibility-and-breach-containment-to-hybrid-environments/">Illumio Insights brings agentless visibility and breach containment to hybrid environments</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Illumio Insights brings agentless visibility and breach containment to hybrid environments]]></title>
<description><![CDATA[Illumio unveiled its solution to deliver agentless visibility and breach containment across both data center and cloud environments. Illumio Insights ingests real-time telemetry and policy data from Check Point and Fortinet firewalls, converting existing firewall information into real-time traffi...]]></description>
<link>https://tsecurity.de/de/3314342/it-security-nachrichten/illumio-insights-brings-agentless-visibility-and-breach-containment-to-hybrid-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3314342/it-security-nachrichten/illumio-insights-brings-agentless-visibility-and-breach-containment-to-hybrid-environments/</guid>
<pubDate>Fri, 27 Feb 2026 11:23:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Illumio unveiled its solution to deliver agentless visibility and breach containment across both data center and cloud environments. Illumio Insights ingests real-time telemetry and policy data from Check Point and Fortinet firewalls, converting existing firewall information into real-time traffic maps to provide agentless visibility across the hybrid environment. This extends Illumio Insights into data center and endpoint estates, providing end-to-end view and analysis of network posture. By ingesting native firewall telemetry, Insights can map data … <a href="https://www.helpnetsecurity.com/2026/02/27/illumio-insights-agentless-visibility/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/02/27/illumio-insights-agentless-visibility/">Illumio Insights brings agentless visibility and breach containment to hybrid environments</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Before the Breach: When digital footprints become a strategic cyber risk]]></title>
<description><![CDATA[OverviewFor years, organizations have prioritized strengthening technical defenses, including hardening networks, accelerating patch management, and expanding endpoint detection and response capabilities. Defensive systems have become more adaptive, identity has moved to the center of security ar...]]></description>
<link>https://tsecurity.de/de/3312417/it-security-nachrichten/before-the-breach-when-digital-footprints-become-a-strategic-cyber-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3312417/it-security-nachrichten/before-the-breach-when-digital-footprints-become-a-strategic-cyber-risk/</guid>
<pubDate>Thu, 26 Feb 2026 14:50:55 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><span>Overview</span></h2><p><span>For years, organizations have prioritized strengthening technical defenses, including hardening networks, accelerating patch management, and expanding endpoint detection and response capabilities. Defensive systems have become more adaptive, identity has moved to the center of security architectures, and zero-trust has emerged as a foundational design principle. </span></p><p><span>Despite these advances, successful intrusions continue to occur in environments that appear technically mature. While traditional attack vectors like vulnerability exploitation, misconfigurations, and malware-based intrusions show no sign of decline, modern attacks are increasingly preceded or materially enabled by extensive reconnaissance conducted beyond the victim’s technical perimeter.</span></p><p><span>Organizations and their employees expose substantial volumes of data online, both intentionally and unintentionally. This includes professional and personal information shared through corporate websites, SaaS platforms, social media, developer repositories, marketing materials, and third-party services, as well as data exposed through breaches, misconfigured cloud assets, and shadow IT.</span></p><p><span>As seen in the following screenshots, vast amounts of historical information, credential leaks, personally identifiable information (PII) persist in exposed databases, as well as on dark web marketplaces and cybercrime forums.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt935226c625c75a2d/69a04867d5b2d260bc74fe1f/dark-web-marketplace-US-SSNs-sale.png" alt="dark-web-marketplace-US-SSNs-sale.png" caption="Figure 1: A dark web marketplace offering US SSNs for sale." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="dark-web-marketplace-US-SSNs-sale.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt935226c625c75a2d/69a04867d5b2d260bc74fe1f/dark-web-marketplace-US-SSNs-sale.png" data-sys-asset-uid="blt935226c625c75a2d" data-sys-asset-filename="dark-web-marketplace-US-SSNs-sale.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: A dark web marketplace offering US SSNs for sale." data-sys-asset-alt="dark-web-marketplace-US-SSNs-sale.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: A dark web marketplace offering US SSNs for sale.</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt211adc3b079d8f80/69a04867e8d8db5e94f1c3a9/compromised-database-search-engine-exposes-leaked-credentials.png" alt="compromised-database-search-engine-exposes-leaked-credentials.png" caption="Figure 2: A compromised database search engine exposes leaked credentials." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="compromised-database-search-engine-exposes-leaked-credentials.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt211adc3b079d8f80/69a04867e8d8db5e94f1c3a9/compromised-database-search-engine-exposes-leaked-credentials.png" data-sys-asset-uid="blt211adc3b079d8f80" data-sys-asset-filename="compromised-database-search-engine-exposes-leaked-credentials.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: A compromised database search engine exposes leaked credentials." data-sys-asset-alt="compromised-database-search-engine-exposes-leaked-credentials.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: A compromised database search engine exposes leaked credentials.</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt76972e94eebe876e/69a04867d5b2d205c974fe23/citizenship-databases-exposed-on-cybercriminal-forum.png" height="796" alt="citizenship-databases-exposed-on-cybercriminal-forum.png" caption="Figure 3: Multiple citizenship databases exposed on a cybercriminal forum" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="citizenship-databases-exposed-on-cybercriminal-forum.png" width="1553" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt76972e94eebe876e/69a04867d5b2d205c974fe23/citizenship-databases-exposed-on-cybercriminal-forum.png" data-sys-asset-uid="blt76972e94eebe876e" data-sys-asset-filename="citizenship-databases-exposed-on-cybercriminal-forum.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Multiple citizenship databases exposed on a cybercriminal forum" data-sys-asset-alt="citizenship-databases-exposed-on-cybercriminal-forum.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Multiple citizenship databases exposed on a cybercriminal forum</figcaption></div></figure><p>⠀</p><p><span>Threat actors increasingly leverage this layered digital footprint as a core component of their operational planning. While such exposure may not always constitute the initial access vector itself, it significantly influences attacker decision-making, targeting precision, and the likelihood of success. </span></p><p><span>Breach data and open-source intelligence are utilized to map organizational structures, identify privileged or high-value identities, correlate reused credentials, infer security controls, and tailor phishing or social engineering campaigns with high contextual credibility. In many cases, this intelligence determines which vulnerability, account, or trust relationship is exploited, rather than whether exploitable weaknesses exist. As a result, the boundary between “technical” and “human” attack vectors continues to erode. Infrastructure security remains necessary, but it is no longer sufficient in isolation. The effective attack surface now extends beyond networks and endpoints to encompass identity exposure, employee digital behavior, third-party data ecosystems, and long-lived data traces that persist outside traditional security tooling and governance models. </span></p><h2>What is digital footprint exposure?</h2><p><span>A digital footprint refers to all the information about an organization and/or an individual that is publicly, semi-publicly, or commercially available online. This information is often scattered across numerous platforms, but aggregating it enables the creation of detailed, actionable profiles of individuals and institutions.</span></p><p><span>Typical elements of a digital footprint include:</span></p><ul><li><p><span>Corporate and personal email addresses</span></p></li><li><p><span>Passwords and authentication data leaked through breaches</span></p></li><li><p><span>Public social media profiles and historical activity</span></p></li><li><p><span>Personally Identifiable Information (e.g., name, SSN, phone number, email address).</span></p></li><li><p><span>Employment history, job titles, role descriptions, and annual reports</span></p></li><li><p><span>Online behavior, interests, affiliations, and routines</span></p></li><li><p><span>Metadata collected and sold by third-party data brokers</span></p></li></ul><p><span>The acquisition of this data does not require hacking, system intrusion, or the deployment of malware. Instead, attackers collect, correlate, and exploit information that exists beyond the organization’s security perimeter, making it inherently unreachable by conventional security controls such as firewalls, EDR, or internal monitoring systems. Because these digital assets reside outside direct organizational ownership and technical control, they cannot be effectively protected by traditional defensive mechanisms. In this context, threat intelligence monitoring plays a critical role by providing visibility into external data exposure, tracking adversarial collection and misuse of such information, and enabling organizations to detect, assess, and respond to risks that would otherwise remain invisible to perimeter-based security architectures.</span></p><h2>Digital footprint exposure: A growing security threat</h2><p><span>The modern threat landscape no longer rewards attackers who are simply skilled at exploiting systems; it rewards those who are best at understanding people, relationships, and behavior. Publicly accessible data, semi-private platforms, and commercially available datasets collectively form a digital footprint that can be mapped, enriched, and weaponized well before any technical intrusion attempt. This exposure shifts the initial battleground away from firewalls and endpoints toward employees’ online presence and the organization’s external data shadow.</span></p><p><span>Organizations that continue to define their perimeter in terms of IP ranges, devices, or cloud assets are defending yesterday’s battlefield. In many cases, the first stage of compromise occurs months before an alert is raised, within public forums, social networks, breached datasets, and data broker platforms, entirely outside traditional security monitoring and response processes. Adversaries use this information to identify key personnel, ascertain internal structures, map trusted relationships, and assess security maturity without ever touching corporate infrastructure.</span></p><p><span>Attackers collect specific external data to identify valid users, authentication systems, and internal dependencies. They extract employee names, roles, and corporate email formats from LinkedIn, conference materials, and public breach datasets. They identify authentication portals, VPN gateways, and cloud services using passive DNS records, Certificate Transparency logs, and internet scanning platforms such as Shodan or Censys. Public GitHub repositories and technical documentation may reveal internal domain names, API endpoints, identity providers, and technology stacks. </span></p><p><span>These elements allow attackers to identify valid corporate accounts, target employees with privileged access, register impersonation domains that match internal naming conventions, and send phishing emails that reference real vendors, systems, or workflows. This preparation increases the likelihood of credential theft and unauthorized access because the attacker is targeting real users and real systems rather than relying on generic phishing or random scanning.</span></p><p><span>For employees, digital footprint exposure translates into personal risk that directly impacts corporate security. Leaked credentials, reused passwords, overshared professional information, or historical data breaches can be exploited to impersonate staff, coerce access, or establish credibility during pretexting operations. Senior leaders, IT staff, and individuals with privileged access are particularly vulnerable, as attackers can leverage publicly available information to craft convincing narratives that exploit trust and authority.</span></p><p><span>Uncontrolled exposure of employee information allows attackers to move from targeting individuals to compromising the organization. This enables them to identify employees with access to key systems, administrative privileges, or sensitive organizational platforms through public work profiles and data obtained from data breaches. They then test exposed credentials on corporate login portals, send phishing emails impersonating trusted internal or external entities, or attempt to intercept authentication codes by targeting exposed phone numbers. Once a single employee account is compromised, attackers can gain access to internal systems, escalate their privileges, and move laterally within the organization.</span></p><h2>Threat actor exploitation of digital footprints</h2><p><span>Threat actors, whether cybercriminal groups or state-sponsored operators, have always relied heavily on digital footprints in their operations. Publicly available information, leaked data, social media activity, and professional networks provide valuable insight into people, organizations, technologies, and trust relationships, making attacks more targeted and believable. </span></p><p><span>With the rise of AI-powered tools, this exploitation has intensified. What once required time-consuming manual research can now be automated, enriched, and scaled almost instantly. AI enables adversaries to turn fragmented online traces into compelling narratives, lures, and impersonations, significantly increasing the speed, precision, and overall impact of attack vectors driven by digital footprints.</span></p><h3><span>Cybercriminals</span></h3><p><span>Cybercriminals typically exploit online exposure to establish rapid, monetizable intrusion paths without requiring deep internal access. Public profiles, leaked credentials, exposed servers, misconfigured cloud resources, and operational metadata are aggregated to identify where access already exists or can be obtained with minimal resistance. The focus is on converting exposed data directly into usable access, validating it quickly, and either exploiting or reselling it.</span></p><p><span>Tactical attack vectors derived from exposed digital footprints include:</span></p><ul><li><p><span><strong>Leaked credential exploitation: </strong></span><span>Abuse of credentials harvested from data breaches, stealer logs, and infostealer marketplaces, correlated with corporate email domains to gain unauthorized access to VPNs, SSO portals, cloud consoles, SaaS platforms, and legacy authentication endpoints</span></p></li><li><p><span><strong>Identity and account surface expansion: </strong></span><span>Leveraging open professional and social network profiles to enumerate valid usernames, email address formats, job roles, seniority levels, and likely privilege tiers, enabling targeted credential testing and account takeover attempts</span></p></li><li><p><span><strong>Email signature and metadata harvesting: </strong></span><span>Exploitation of email signatures, contact blocks, and publicly shared correspondence to identify internal naming conventions, phone extensions, third-party services, and technology stack indicators useful for impersonation and lateral access</span></p></li><li><p><span><strong>Document-driven reconnaissance:</strong></span><span> Mining publicly exposed or leaked company documents (policies, PDFs, presentations, contracts, org. charts, etc.) to infer internal systems, authentication workflows, directory structures, cloud providers, and security controls</span></p></li><li><p><span><strong>Infrastructure targeting via exposure leakage: </strong></span><span>Identification and exploitation of externally exposed servers, admin panels, APIs, and management interfaces through search engines, passive DNS, certificate transparency logs, and open indexing platforms</span></p></li><li><p><span><strong>Banner, certificate, and service fingerprinting: </strong></span><span>Abuse of SSL/TLS certificates, HTTP headers, API responses, and service banners to fingerprint software versions, cloud services, authentication mechanisms, and unpatched or end-of-life systems</span></p></li><li><p><span><strong>Cloud asset exploitation: </strong></span><span>Targeting publicly exposed storage buckets, orphaned cloud tenants, misconfigured IAM roles, stale API keys, and secrets discovered via open repositories, leaked configuration files, or documentation artifacts</span></p></li><li><p><span><strong>Access brokerage: </strong></span><span>Enabling the validation, packaging, and resale of footprint-derived access (credentials, VPN sessions, cloud console access, shells) within cybercriminal marketplaces, based on assessed business impact and network reach</span></p></li><li><p><span><strong>Low-noise privilege escalation and lateral movement: </strong></span><span>Exploitation of weak segmentation, excessive trust relationships, and overexposed directory or identity services inferred from public documentation, leaked internal diagrams, or misconfigured federation endpoints</span></p></li></ul><h3><span>State-Sponsored Actors</span></h3><p><span>State-sponsored actors treat exposed digital footprints as long-term intelligence and access-enabling infrastructure. Voluntarily shared information, institutional transparency, technical disclosures, and accidental leaks are fused to build high-fidelity models of people, systems, and dependencies. These actors exploit exposure selectively, prioritizing vectors that support persistent access, intelligence collection, and operational survivability.</span></p><p><span>Tactical attack vectors derived from exposed digital footprints include:</span></p><ul><li><p><span><strong>Identity and role mapping: </strong></span><span>Use of social networks, publications, and organizational disclosures to identify privileged users, trust relationships, and lateral movement paths</span></p></li><li><p><span><strong>Credential and token reuse:</strong></span><span> Reuse of leaked credentials, API keys, and tokens over long periods to regain access without new exploits or tooling</span></p></li><li><p><span><strong>Perimeter exploitation via transparency: </strong></span><span>Targeting of publicly documented architectures, exposed technologies, and known integration points</span></p></li><li><p><span><strong>Exposed service exploitation:</strong></span><span> Compromise of internet-facing edge devices, management planes, update services, and CI/CD endpoints</span></p></li><li><p><span><strong>Supply-chain leverage: </strong></span><span>Exploitation of disclosed vendors, SaaS platforms, and cloud dependencies as indirect access paths</span></p></li><li><p><span><strong>Persistence through legacy exposure: </strong></span><span>Abuse of forgotten accounts, test systems, and undercommissioned services still reachable externally</span></p></li><li><p><span><strong>Defensive evasion through disclosure awareness: </strong></span><span>Tailoring operations based on publicly revealed security controls, tooling, and incident history</span></p></li></ul><h2>Advice for reducing digital footprint risk</h2><p><span>A structured technical approach is imperative to effectively reduce the risk of employees’ digital footprint exposure. It must aim to close identity security gaps, eliminate unknown external resources, and proactively monitor for leaks of sensitive data. First, organizations must strengthen their identity infrastructure by implementing phishing-resistant multi-factor authentication (MFA) for all privileged accounts and by integrating credential exposure monitoring directly at the identity provider (IdP) level to detect and block authentication attempts using compromised credentials.</span></p><p><span>In addition, </span><a href="https://www.rapid7.com/fundamentals/external-attack-surface-management-easm/" target="_blank"><span>external attack surface management (EASM)</span></a><span> must be implemented to identify and remediate internet-exposed, unknown, overlooked, or misconfigured resources, including servers, API endpoints, and storage resources that could expose configuration or sensitive organizational data. Digital risk protection (DRP) programs must prioritize monitoring the personally identifiable information (PII) of executives and board members, privileged credentials, and sensitive intellectual property on dark web forums, data breach datasets, and social media platforms to detect and disrupt adversary reconnaissance and targeting activities in the early stages of an attack lifecycle.</span></p><p><span>To reduce the risk of credential exposure, organizations should also continuously monitor for leaked or compromised credentials associated with corporate domains, limit the public disclosure of internal technical information, implement strong authentication methods resistant to credential theft, and respond rapidly when exposed accounts or infrastructure are identified.</span></p><p><span>It is equally important to consider employees as an integral part of the extended security perimeter. Technical controls must remain the primary means of mitigation. Measures such as strict access restrictions, centralized logging and analysis, and automated detection and response mechanisms should form the core of the defense. At the same time, it is critical to raise employee awareness about how their personal online activities and digital presence can directly affect the organization’s security posture.</span></p><p><span>Organizations that implement these measures will see their digital footprint exposure transformed from a silent risk into a managed, measurable security domain, significantly reducing the likelihood of identity theft, targeted intrusions, and the leakage of critical intelligence.</span></p><h2>Conclusion<strong> </strong></h2><p><span>Today’s threat actors are no longer limited to exploiting technical vulnerabilities; they increasingly weaponize digital footprints as a primary enabler of their operations. For organizations, this means the attack surface extends well beyond networks and endpoints to include all externally exposed information. Any data available online about systems, infrastructure, or employees can be collected, correlated, and exploited to support reconnaissance, targeting, and intrusion planning, often without generating a single security alert or triggering traditional detection mechanisms. As a result, organizations that actively identify, monitor, and manage their external assets and digital footprint are better positioned to detect exposure early, reduce opportunities for adversaries, and strengthen their overall security posture before threats materialize.</span></p><p><span><strong>Read the Rapid7 Labs threat report “</strong></span><a href="https://www.rapid7.com/lp/executive-digital-footprints-threat-report/" target="_blank"><span><strong>Executives’ Digital Footprints: The Overlooked Corporate Vulnerability</strong></span></a><span><strong>” for more insights and detailed recommendations.</strong></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Falcon for IT: Built-In Response Playbooks for Enterprise-Scale Automation]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:0 Adversaries are accelerating their tradecraft, exploiting configuration drift and operational blind spots before teams can respond.

Falcon for IT transforms the CrowdStrike Falcon Platform into the unified operational engine of the enterprise, turnin...]]></description>
<link>https://tsecurity.de/de/3311112/it-security-video/falcon-for-it-built-in-response-playbooks-for-enterprise-scale-automation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3311112/it-security-video/falcon-for-it-built-in-response-playbooks-for-enterprise-scale-automation/</guid>
<pubDate>Thu, 26 Feb 2026 00:16:51 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/hnRuYQuLImw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Adversaries are accelerating their tradecraft, exploiting configuration drift and operational blind spots before teams can respond.<br />
<br />
Falcon for IT transforms the CrowdStrike Falcon Platform into the unified operational engine of the enterprise, turning visibility into governed, enterprise-scale action.<br />
<br />
In this video, you will see how teams can:<br />
🔹 Import ready-to-use content packs directly within the Falcon console<br />
🔹 Automatically enforce application health and expected configuration state<br />
🔹 Gain enterprise-wide file visibility without disruptive live scans<br />
🔹 Execute automation safely at scale using built-in scheduling and performance guardrails<br />
<br />
Using the existing Falcon sensor, operators move from insight to enforcement without deploying new agents, writing custom scripts, or managing separate tools.<br />
<br />
Falcon for IT establishes continuous control across the enterprise, converting policy into enforced state and eliminating the gaps adversaries exploit. Security and IT teams move from reactive correction to proactive enforcement.<br />
<br />
Explore Falcon for IT and unlock the next level of enterprise-wide control.<br />
<br />
Learn More About Falcon for IT:<br />
► https://cs.link/ulVqY<br />
► https://cs.link/ulVqX<br />
<br />
📣 Connect With Us:<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
► Twitter:<br />
https://twitter.com/CrowdStrike<br />
► Facebook:<br />
https://www.facebook.com/crowdstrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
<br />
🔔 Subscribe and Stay Updated!<br />
Subscribe for more real-world attack walkthroughs and insights into modern cyber defense. Turn on notifications to stay ahead of evolving threats.<br />
<br />
#CrowdStrike #FalconForIT #CharlotteAI #Built-InResponse #EndpointManagement #Cybersecurity #SecOps<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Secure AI Transcription: Converting Audio Files Into Text Without Compromising Data]]></title>
<description><![CDATA[In this post, I will talk about secure AI transcription. Also, I will reveal how to convert audio files into text without compromising data. Audio used to stay in the background. Recorded calls, saved interviews, internal discussions — they lived quietly in folders until someone needed to replay ...]]></description>
<link>https://tsecurity.de/de/3310881/it-security-nachrichten/secure-ai-transcription-converting-audio-files-into-text-without-compromising-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3310881/it-security-nachrichten/secure-ai-transcription-converting-audio-files-into-text-without-compromising-data/</guid>
<pubDate>Wed, 25 Feb 2026 20:49:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will talk about secure AI transcription. Also, I will reveal how to convert audio files into text without compromising data. Audio used to stay in the background. Recorded calls, saved interviews, internal discussions — they lived quietly in folders until someone needed to replay them. Now they’re routinely converted into text. […]</p>
<p>The post <a href="https://secureblitz.com/secure-ai-transcription/">Secure AI Transcription: Converting Audio Files Into Text Without Compromising Data</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From digital transformation to intelligent transformation]]></title>
<description><![CDATA[Over the past decade, digital transformation has focused on converting manual processes to digital ones, migrating infrastructure to the cloud, updating applications and creating new channels for customer and employee engagement. These efforts have resulted in tangible benefits such as accelerate...]]></description>
<link>https://tsecurity.de/de/3309597/it-security-nachrichten/from-digital-transformation-to-intelligent-transformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3309597/it-security-nachrichten/from-digital-transformation-to-intelligent-transformation/</guid>
<pubDate>Wed, 25 Feb 2026 13:05:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Over the past decade, digital transformation has focused on converting manual processes to digital ones, migrating infrastructure to the cloud, updating applications and creating new channels for customer and employee engagement. These efforts have resulted in tangible benefits such as accelerated cycle times, increased transparency and reduced costs. However, these initiatives have also revealed limitations: Simply digitizing a flawed process does not resolve its underlying issues; it only makes the inefficiencies operate at a faster pace.</p>



<h2 class="wp-block-heading">The shift to intelligent transformation</h2>



<p>A new shift is underway. The next phase moves beyond digital — it is intelligent. Intelligent transformation is about evolving enterprises into systems that can sense, reason, make decisions and take action with minimal friction. This evolution is driven by the emergence of AI agents: Autonomous software systems capable of achieving goals by orchestrating workflows and leveraging tools such as APIs, applications, databases and automation technologies.</p>



<h2 class="wp-block-heading">From apps and dashboards to agents and actions</h2>



<p>In the digital era, organizational value was derived from systems of record like ERP and CRM, as well as systems of insight such as business intelligence and analytics. In the intelligent era, a new dimension is added: Systems of action, defined by agentic capabilities that execute tasks across diverse functions.</p>



<p>AI agents don’t merely answer questions; they are capable of planning steps, invoking tools, retrieving relevant information and completing end-to-end workflows. Modern agent architectures employ tool calling or function calling, where a model determines the next action, the application executes it and the model continues based on the outcome. This approach effectively bridges language models and enterprise systems, transforming agents into practical operational levers rather than mere demonstrations.</p>



<h2 class="wp-block-heading">Cross-industry value: Where agents compound outcomes</h2>



<h3 class="wp-block-heading">Manufacturing: From connected factories to learning factories</h3>



<p>Industry 4.0 connected machines and visualised data through dashboards. Intelligent transformation advances this by converting signals into actions: Agents detect abnormal patterns, recommend parameter adjustments, initiate maintenance requests and coordinate the availability of parts. The cumulative benefits extend beyond uptime to faster root-cause analysis, reduced quality deviations and more predictable throughput. Even minor improvements in planning stability can lead to significant gains in service and inventory management across complex networks.</p>



<h3 class="wp-block-heading">Healthcare &amp; life sciences: From documentation burden to decision support</h3>



<p>Clinicians and scientists often navigate context overload due to guidelines, patient histories, research literature, protocols and regulatory requirements. Agents can collate relevant context, draft structured notes, suggest trial eligibility matches or summarise evidence, all while ensuring human oversight in decision-making. Responsible implementations integrate retrieval from trusted sources, audit trails and strict permissions, as accuracy, privacy and traceability remain essential.</p>



<h3 class="wp-block-heading">Retail &amp; consumer: From personaliziation to orchestration</h3>



<p>Personalised recommendations marked the initial stage. Now, agents can orchestrate the entire customer journey — resolving issues, amending orders, offering suitable alternatives and updating inventory systems. Internally, agents produce assortment insights, conduct promotion analyses and automate supplier communication, reducing turnaround times from weeks to hours.</p>



<h2 class="wp-block-heading">The new enterprise stack: Agentic workflows built on trust</h2>



<p>As agents advance in capability, the critical question will shift from “Can the model write?” to “Can the enterprise operate safely with agentic systems?”</p>



<p>A pragmatic stack is emerging:</p>



<ul class="wp-block-list">
<li><strong>Experience layer:</strong> Copilots within work tools (email, CRM, service desk) and role-based agent interfaces.</li>



<li><strong>Reasoning &amp; orchestration:</strong> Policies, routing, human-in-the-loop approvals and monitoring.</li>



<li><strong>Knowledge layer:</strong> Retrieval from curated internal content with permissions and provenance.</li>



<li><strong>Tool layer:</strong> APIs, RPA, workflow engines and systems of record enabling agent actions.</li>



<li><strong>Governance &amp; risk:</strong> Evaluation, security, compliance and auditability by design.</li>
</ul>



<p>Consequently, AI risk management has become a board-level concern. Frameworks such as NIST’s AI Risk Management Framework stress the importance of embedding trustworthiness across the AI lifecycle and managing risks to individuals, organizations and society.</p>



<h2 class="wp-block-heading">The uncomfortable truth: Agents amplify both productivity and risk</h2>



<p>Agents have the potential to deliver substantial productivity gains, but they also introduce new vulnerabilities: Prompt injection, data leakage, unsafe actions and excessive reliance on generated outputs. Leading platforms are continuously enhancing agent safety and implementing robust controls.</p>



<p>Enterprises that succeed will treat agents like other critical systems — establishing guardrails, enforcing least-privilege access, mandating approvals for sensitive actions, continually evaluating performance and maintaining traceability of data and actions.</p>



<h2 class="wp-block-heading">The operating model shift: Product thinking, not project thinking</h2>



<p>Intelligent transformation does not succeed as a one-time rollout. Agents are never static; they learn, adapt and evolve as business needs and risks change. This calls for a shift from project-based delivery to a product-oriented operating model:</p>



<ul class="wp-block-list">
<li><strong>Business-led outcomes:</strong> Each agent is linked to a measurable business KPI (cycle time, NPS, yield, cash conversion).</li>



<li><strong>Fusion teams:</strong> Domain experts, engineers, data specialists and risk/compliance professionals collaborate as a unified team.</li>



<li><strong>Evaluation as a discipline:</strong> Ongoing test suites for accuracy, safety, robustness and cost.</li>



<li><strong>Change management at the edge:</strong> Successful adoption is achieved through daily workflow integration, not just on launch day.</li>
</ul>



<h2 class="wp-block-heading">Measuring value: 3 horizons that executives can govern</h2>



<p>To effectively scale enterprise value, leaders should consider three horizons:</p>



<ol start="1" class="wp-block-list">
<li><strong>Horizon 1: Assist.</strong> Copilots that draft, summarise, search and explain, delivering rapid adoption and immediate time savings.</li>



<li><strong>Horizon 2: Augment.</strong> Agents that complete defined workflows with approvals, offering greater ROI and governance.</li>



<li><strong>Horizon 3: Automate.</strong> New operating models that reinvent customer and enterprise value chains, presenting the largest opportunities but requiring significant change.</li>
</ol>



<p>The common mistake is attempting to leap directly to Horizon 3. The most effective strategy is to build progressively: Use Horizon 1 to establish fluency and trust, Horizon 2 to standardise platforms and guardrails and Horizon 3 to transform the enterprise after developing confidence and capability.</p>



<h2 class="wp-block-heading">Conclusion: Intelligent transformation is a leadership agenda</h2>



<p>Digital transformation modernised technology, while intelligent transformation modernises the enterprise itself — how work is discovered, decided and delivered. AI agents serve as force multipliers, converting knowledge into action and action into learning.</p>



<p>Ultimately, success will not be determined by who can showcase the most impressive agent, but by who can develop the most trustworthy agentic ecosystem — one that is secure by design, outcome-oriented and embraced by employees who feel empowered rather than displaced.</p>



<p>In the age of AI agents, scaling enterprise value transcends traditional transformation. It requires building an organization capable of continuous self-transformation, with intelligence embedded in every decision and action.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Texas Is About To Overtake California In Battery Storage]]></title>
<description><![CDATA[U.S. battery storage installations hit a record 57.6 GWh in 2025, and Texas is now poised to surpass California as the nationâ(TM)s largest storage market in 2026. Electrek reports: According to the US Energy Storage Market Outlook Q1 2026 from the Solar Energy Industries Association (SEIA) and B...]]></description>
<link>https://tsecurity.de/de/3306477/it-security-nachrichten/texas-is-about-to-overtake-california-in-battery-storage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3306477/it-security-nachrichten/texas-is-about-to-overtake-california-in-battery-storage/</guid>
<pubDate>Tue, 24 Feb 2026 08:20:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. battery storage installations hit a record 57.6 GWh in 2025, and Texas is now poised to surpass California as the nationâ(TM)s largest storage market in 2026. Electrek reports: According to the US Energy Storage Market Outlook Q1 2026 from the Solar Energy Industries Association (SEIA) and Benchmark Mineral Intelligence, installations are now four times higher than totals from just three years ago. The US had a total of 137 GWh of utility-scale storage installed as of 2025, plus 19 GWh of commercial and industrial systems and 9 GWh of residential storage. Analysts expect the growth streak to continue. More than 600 GWh of energy storage is projected to be deployed nationwide by 2030, even as the Trump administration targets clean energy industries.
 
Two-thirds of utility-scale storage installed in 2025 was built in red states, including nine of the top 15 states for new installations. Texas is projected to surpass California as the countryâ(TM)s largest battery storage market in 2026. Standalone battery projects accounted for nearly 30 GWh of new capacity in 2025, while solar-plus-storage installations made up about 20 GWh. Residential storage deployments reached 3.1 GWh last year, a 51% increase year-over-year. Analysts say virtual power plant programs in states such as Massachusetts, Texas, Arizona, and Illinois are helping drive adoption by reducing costs and easing strain during peak demand periods.
 
The supply chain is shifting to support the boom. In 2025, some battery cell manufacturers pivoted production from EV batteries to dedicated stationary storage cells, converting existing lines and adjusting future plans. Lithium-ion cell manufacturing for stationary storage reached more than 21 GWh in 2025, enough to power Houston overnight, according to SEIAâ(TM)s Solar and Storage Supply Chain Dashboard. Meanwhile, US factories now have the capacity to manufacture 69.4 GWh of battery energy storage systems annually.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Texas+Is+About+To+Overtake+California+In+Battery+Storage%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F02%2F24%2F0043228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F02%2F24%2F0043228%2Ftexas-is-about-to-overtake-california-in-battery-storage%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/02/24/0043228/texas-is-about-to-overtake-california-in-battery-storage?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Salesforce to acquire Momentum to boost Agentforce 360, Slack for sales teams]]></title>
<description><![CDATA[Salesforce has signed a definitive agreement to acquire San Francisco-based startup Momentum to boost the capabilities of Agentforce 360 and Slack for enterprise sales teams.



The acquisition will allow Salesforce to extend Agentforce 360 and Slackbot’s ability to ingest and analyze unstructure...]]></description>
<link>https://tsecurity.de/de/3304992/it-security-nachrichten/salesforce-to-acquire-momentum-to-boost-agentforce-360-slack-for-sales-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3304992/it-security-nachrichten/salesforce-to-acquire-momentum-to-boost-agentforce-360-slack-for-sales-teams/</guid>
<pubDate>Mon, 23 Feb 2026 14:05:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Salesforce has signed a definitive agreement to acquire San Francisco-based startup Momentum to boost the capabilities of Agentforce 360 and Slack for enterprise sales teams.</p>



<p>The acquisition will allow Salesforce to extend <a href="https://www.cio.com/article/4102862/salesforces-agentforce-360-gets-an-enterprise-data-backbone-with-informaticas-metadata-and-lineage-engine.html" target="_blank">Agentforce 360</a> and Slackbot’s ability to ingest and analyze unstructured data from third-party voice and video channels, such as Zoom and Google Meet, and apply those insights directly to agentic workflows so that sales teams can be armed with actionable revenue insights, the company said in a statement.</p>



<p>The integration of Momentum, analysts say, fills a longstanding gap in traditional customer relationship management (<a href="https://www.cio.com/article/272365/what-is-crm-software-for-managing-customer-data.html">CRM</a>) systems or processes, which rely on sales executives to manually fill critical signals such as buying intent, objections, pricing discussions, and next steps post calls with customers.</p>



<p>“By embedding Momentum’s capabilities, Salesforce reduces reliance on manual updates and external systems,” said <a href="https://www.linkedin.com/in/gaurav-dewan-pmp-8644a19/?originalSubdomain=in" target="_blank" rel="nofollow">Gaurav Dewan</a>, research director at Avasant.</p>



<p>Momentum’s integration should also help enterprises get cleaner pipeline data, better forecasting, and AI agents grounded in real customer context, not just manual notes, echoed <a href="https://pareekh.com/about/" target="_blank" rel="nofollow">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>“In practical terms, this means automated execution of complex workflows, accelerating revenue execution and reducing friction across go-to-market processes,” Jain added.</p>



<p>Beyond tightening sales workflows, analysts said the payoff from Momentum’s integration will be uneven across industries, with the biggest gains accruing to sectors where high-value deals hinge on long, conversation-heavy buying cycles.</p>



<p>Vertical software, B2B SaaS, professional services, financial services, and enterprise technology vendors are likely to see the earliest returns, as sales teams in these segments depend heavily on nuanced signals from discovery calls, demos, and negotiations, Dewan said.</p>



<p>Regulated industries such as healthcare and insurance could also benefit from better capture of intent and objections, Jain noted, as long as compliance and data governance guardrails are maintained.</p>



<h2 class="wp-block-heading">Salesforce vs standalone vendors</h2>



<p>Analysts say that the deal hints at Salesforce’s strategy to redraw the competitive lines in revenue intelligence and orchestration.</p>



<p>“Traditionally, CRM platforms focused on storing customer and pipeline data, while <a href="https://www.forrester.com/blogs/a-new-supergroup-for-revenue-technology-emerges-revenue-orchestration-platforms/" rel="nofollow">revenue orchestration</a>, intelligence tools sat on top to interpret signals, guide sellers, and trigger actions. Momentum’s integration into Agentforce 360 shows that this separation is breaking down,” Dewan said.</p>



<p>“Salesforce is explicitly embedding conversational insights and orchestration logic directly into its CRM and workflow layer so that insights can immediately trigger actions, not just populate dashboards,” Dewan added.</p>



<p>There are also other examples of consolidation in the same segment — the <a href="https://www.salesloft.com/company/newsroom/clari-and-salesloft-announce-merger-agreement" target="_blank" rel="nofollow">Clari–Salesloft merger in 2025</a> and <a href="https://www.sap.com/investors/en/resources/acquisitions.html" target="_blank" rel="nofollow">SAP’s acquisition of CallidusCloud</a> in 2018, both of which, according to Dewan, were aimed at boosting revenue orchestration capabilities.</p>



<p>In fact, Momentum’s acquisition is not Salesforce’s first deal to attempt to boost how revenue is generated, interpreted, and executed inside its Agentforce 360 offering.</p>



<p>“The agreement to acquire <a href="https://www.salesforce.com/news/stories/salesforce-signs-definitive-agreement-to-acquire-qualified/" target="_blank" rel="nofollow">Qualified in December</a> added automated, conversational buyer engagement at the top of the funnel, enabling AI‑driven inbound qualification and pipeline creation within Salesforce and Slack,” Dewan said.</p>



<p>“The Momentum acquisition extends this strategy into the mid‑funnel by converting customer conversations from calls and meetings into structured intelligence that can directly drive workflows inside Agentforce 360,” Dewan added.</p>



<p>All this consolidation, analysts say, also reflects a deeper shift in how buying conversations are changing for CIOs: from “which conversation intelligence tool is best?” to “which platform do we want to anchor our revenue execution on for the next 5–7 years?”</p>



<p>“Enterprises must now decide whether they want a suite‑led model, where engagement, insight, and execution live inside one platform, or a best‑of‑breed model, where these functions are sourced from multiple vendors and stitched together,” Dewan said.</p>



<p>Either way, buyers face a trade-off between stitching together a complex, multi-vendor stack or leaning more heavily on a single platform, with the risk of deeper lock-in, Dewan added. The acquisition is expected to close by April.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Growing Threat of DNS Powered Email and Web Attacks]]></title>
<description><![CDATA[  As an important component of the internet architecture, the Domain Name System has historically played the role of an invisible intermediary converting human intent into machine-readable destinations without much scrutiny or suspicion. However, this quiet confidence has now been…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3297855/it-security-nachrichten/the-growing-threat-of-dns-powered-email-and-web-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3297855/it-security-nachrichten/the-growing-threat-of-dns-powered-email-and-web-attacks/</guid>
<pubDate>Thu, 19 Feb 2026 14:34:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  As an important component of the internet architecture, the Domain Name System has historically played the role of an invisible intermediary converting human intent into machine-readable destinations without much scrutiny or suspicion. However, this quiet confidence has now been…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-growing-threat-of-dns-powered-email-and-web-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-growing-threat-of-dns-powered-email-and-web-attacks/">The Growing Threat of DNS Powered Email and Web Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shell script for converting JPG/JPEG to WebP and scaling to 1440 pixels.]]></title>
<description><![CDATA[I wanted to save some space on my hard-drives (i have a lot of photos that are up to 4000x3000 pixels, and are several Megabytes each. I learnt about WebP image type recently and with the help of Grok i was able to make a Shell command that:-  Creates a sub-folder called "converted". Checks if sh...]]></description>
<link>https://tsecurity.de/de/3296096/linux-tipps/shell-script-for-converting-jpgjpeg-to-webp-and-scaling-to-1440-pixels/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3296096/linux-tipps/shell-script-for-converting-jpgjpeg-to-webp-and-scaling-to-1440-pixels/</guid>
<pubDate>Wed, 18 Feb 2026 17:52:18 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I wanted to save some space on my hard-drives (i have a lot of photos that are up to 4000x3000 pixels, and are several Megabytes each.</p> <p>I learnt about WebP image type recently and with the help of Grok i was able to make a Shell command that:-</p> <ul> <li>Creates a sub-folder called "converted".</li> <li>Checks if shortest image dimension is over 1440 pixels and scales down to as close as 1440 as possible.</li> <li>If under 1440 pixels it doesn't adjust scale.</li> <li>Then it converts any JPG/JPEG to WebP with 82 Quality.</li> </ul> <p>One example is on a folder of about 1500 photos, it reduced the size from 5.3GB to 900MB.</p> <p>I had been using "Converseen GUI" for converting to WebP before but it couldn't handle checking dimensions before scaling, so i found this way in terminal to do it instead.</p> <p>This shell command works on Alacritty (fish shell), i'm using CachyOS.</p> <p>I had to install "perl-image-exiftool" beforehand for getting the dimensions.</p> <p>Thought i'd share it in-case someone else finds it useful. :-)</p> <p>(I just copy/paste it into my terminal but you could probably make it into a script if you wanted).</p> <pre><code>mkdir -p converted for f in *.jpg *.jpeg *JPG *JPEG if not test -f "$f" continue end # Get dimensions using exiftool (avoids ImageMagick policy issues) set width_out (exiftool -s3 -ImageWidth "$f" 2&gt;/dev/null) set height_out (exiftool -s3 -ImageHeight "$f" 2&gt;/dev/null) if test -z "$width_out" -o -z "$height_out" echo "Skip $f: failed to get dimensions with exiftool" continue end # Extract just the number (format: "Image Width : 4000") set w (string trim (string replace -r '.*: ' '' "$width_out")) set h (string trim (string replace -r '.*: ' '' "$height_out")) # Basic validation if not string match -qr '^[0-9]+$' -- $w $h echo "Skip $f: invalid dimensions from exiftool ($w × $h)" continue end set output "converted/$(path change-extension .webp (basename "$f"))" set min_dim (math "min($w, $h)") if test $min_dim -gt 1440 # Resize so shortest side = 1440 px exactly if test $w -lt $h # Portrait: width is short side → resize to 1440 width magick "$f" -auto-orient -resize 1440x -quality 82 "$output" else # Landscape or square: height is short side → resize to 1440 height magick "$f" -auto-orient -resize x1440 -quality 82 "$output" end echo "Resized $f → $(basename "$output") (short side → 1440 px, original $w × $h)" else # Just convert to WebP magick "$f" -auto-orient -quality 82 "$output" echo "Converted $f → $(basename "$output") (unchanged $w × $h)" end end </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/__Paradox___"> /u/__Paradox___ </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1r87y1b/shell_script_for_converting_jpgjpeg_to_webp_and/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1r87y1b/shell_script_for_converting_jpgjpeg_to_webp_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[tvOS 26.4 Public Beta Released With Audio Changes and App Removal]]></title>
<description><![CDATA[The tvOS 26.4 beta cycle is now underway. Apple shipped the first developer beta on February 16, 2026, and the tvOS 26.4 public beta followed on February 17, 2026.



This update looks like a focused refresh rather than a big redesign. Even so, it brings a few visible changes that will matter if ...]]></description>
<link>https://tsecurity.de/de/3295354/ios-mac-os/tvos-264-public-beta-released-with-audio-changes-and-app-removal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3295354/ios-mac-os/tvos-264-public-beta-released-with-audio-changes-and-app-removal/</guid>
<pubDate>Wed, 18 Feb 2026 13:07:21 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The tvOS 26.4 beta cycle is now underway. Apple shipped the first developer beta on February 16, 2026, and the tvOS 26.4 public beta followed on February 17, 2026.



This update looks like a focused refresh rather than a big redesign. Even so, it brings a few visible changes that will matter if you buy movies and shows on your Apple TV, or if you care about HDMI audio stability.



How to install tvOS 26.4 public beta




Join the Apple Beta Software Program using your Apple Account.



On Apple TV, open Settings.



Go to System &gt; Software Updates.



Open Get Beta Updates (or Beta Updates) and pick tvOS 26 Public Beta.



Go back, then select Update Software to download and install.




All the changes in tvOS 26.4 public beta



iTunes Movies and iTunes TV Shows apps are gonetvOS 26.4 removes the standalone iTunes Movies and iTunes TV Shows apps. You now buy and manage that content through the TV app instead.



Audio Format settings got a rethinkApple updated the Audio Format section, including a label change where Dolby Atmos in the settings is now shown as Spatial Audio. You also get clearer choices like Auto, Stereo-only, and converting to Dolby Digital 5.1.



New HDMI option: Continuous Audio ConnectionA new Continuous Audio Connection toggle appears for HDMI output. Reports say it aims to reduce audio dropouts and HDMI re-sync events when the Apple TV switches between formats like stereo, 5.1, and Atmos-style output.



That’s everything that’s clearly surfaced so far in the first public beta. If you spot another change on your setup, share it in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Detroit Automakers Take $50 Billion Hit]]></title>
<description><![CDATA[The Detroit Big Three -- General Motors, Ford and Stellantis -- have collectively announced more than $50 billion in write-downs on their electric-vehicle businesses after years of aggressive investment into a transition that, even before Republican lawmakers abolished a $7,500 federal tax credit...]]></description>
<link>https://tsecurity.de/de/3287414/it-security-nachrichten/detroit-automakers-take-50-billion-hit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3287414/it-security-nachrichten/detroit-automakers-take-50-billion-hit/</guid>
<pubDate>Sat, 14 Feb 2026 00:49:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Detroit Big Three -- General Motors, Ford and Stellantis -- have collectively announced more than $50 billion in write-downs on their electric-vehicle businesses after years of aggressive investment into a transition that, even before Republican lawmakers abolished a $7,500 federal tax credit last fall, was already running below expectations. 

U.S. EV sales fell more than 30% in the fourth quarter of 2025 once the credit expired in September, and Congress also eliminated federal fuel-efficiency mandates. More than $20 billion in previously announced investments in EV and battery facilities were canceled last year -- the first net annual decrease in years, according to Atlas Public Policy. 

GM has laid off thousands of workers and is converting plants once earmarked for EV trucks and motors to produce gas-powered trucks and V-8 engines. Ford dissolved a joint venture with a South Korean conglomerate to make batteries and now plans to build just one low-cost electric pickup by 2027. Stellantis is unloading its stake in a battery-making business after booking the largest EV-related charge of any automaker so far. Outside the U.S., the trajectory looks different: China's BYD recently overtook Tesla as the world's largest EV seller.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Detroit+Automakers+Take+%2450+Billion+Hit%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F02%2F13%2F191242%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F02%2F13%2F191242%2Fdetroit-automakers-take-50-billion-hit%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/02/13/191242/detroit-automakers-take-50-billion-hit?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SINEC OS]]></title>
<description><![CDATA[View CSAF
Summary
SINEC OS before V3.3 contains third-party components with multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens SINEC OS are affected:

RUGGEDCOM RST2428P (6GK6242-...]]></description>
<link>https://tsecurity.de/de/3284835/it-security-nachrichten/siemens-sinec-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3284835/it-security-nachrichten/siemens-sinec-os/</guid>
<pubDate>Thu, 12 Feb 2026 19:06:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-043-06.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>SINEC OS before V3.3 contains third-party components with multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.</strong></p>
<p>The following versions of Siemens SINEC OS are affected:</p>
<ul>
<li>RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XCH328 (6GK5328-4TS01-2EC2) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XCM324 (6GK5324-8TS01-2AC2) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XCM328 (6GK5328-4TS01-2AC2) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XCM332 (6GK5332-0GA01-2AC2) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
<li>SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) vers:intdot/&lt;3.3 (CVE-2022-48174, CVE-2023-7256, CVE-2023-39810, CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264, CVE-2024-8006, CVE-2024-8096, CVE-2024-9681, CVE-2024-11053, CVE-2024-12718, CVE-2024-41996, CVE-2024-47619, CVE-2024-52533, CVE-2025-0167, CVE-2025-0665, CVE-2025-0725, CVE-2025-1390, CVE-2025-3360, CVE-2025-4138, CVE-2025-4330, CVE-2025-4373, CVE-2025-4435, CVE-2025-4516, CVE-2025-4517, CVE-2025-6141, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232, CVE-2025-10148, CVE-2025-27587, CVE-2025-32433, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38345, CVE-2025-38350, CVE-2025-38498, CVE-2025-39839, CVE-2025-39841, CVE-2025-39846, CVE-2025-39853, CVE-2025-39860, CVE-2025-39864, CVE-2025-39865, CVE-2025-59375)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 10</td>
<td>Siemens</td>
<td>Siemens SINEC OS</td>
<td>Out-of-bounds Write, Double Free, Improper Input Validation, Use After Free, Improper Restriction of Operations within the Bounds of a Memory Buffer, Free of Memory not on the Heap, Buffer Over-read, Out-of-bounds Read, NULL Pointer Dereference, Improper Certificate Validation, Incorrect Comparison, Exposure of Sensitive Information to an Unauthorized Actor, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Multiple Releases of Same Resource or Handle, Integer Overflow to Buffer Overflow, Improper Access Control, Integer Overflow or Wraparound, Buffer Underwrite ('Buffer Underflow'), Incorrect Calculation, Stack-based Buffer Overflow, Covert Timing Channel, Generation of Predictable Numbers or Identifiers, Missing Authentication for Critical Function, Allocation of Resources Without Limits or Throttling</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Energy, Critical Manufacturing, Transportation Systems, Water and Wastewater</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2022-48174</a></h3>
<div class="csaf-accordion-content">
<p>There is a stack overflow vulnerability in ash.c:6030 in BusyBox versions prior to 1.35. In the environment of internet of vehicles, this vulnerability can be exploited via crafted commands, potentially leading to arbitrary code execution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48174">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-7256</a></h3>
<div class="csaf-accordion-content">
<p>In affected libpcap versions, during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller whether freeaddrinfo() needs to be called after the function returns. This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block. A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7256">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/415.html">CWE-415 Double Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-39810</a></h3>
<div class="csaf-accordion-content">
<p>An issue in the CPIO command of Busybox v1.33.2 may allow an attacker to perform a directory traversal attack.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39810">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-42363</a></h3>
<div class="csaf-accordion-content">
<p>A use-after-free vulnerability was discovered in the xasprintf function located in xfuncs_printf.c:344 in BusyBox v.1.36.1.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42363">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-42364</a></h3>
<div class="csaf-accordion-content">
<p>A use-after-free vulnerability in BusyBox v.1.36.1 may lead to denial of service through a crafted awk pattern processed by the evaluate function in awk.c.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42364">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-42365</a></h3>
<div class="csaf-accordion-content">
<p>A use-after-free vulnerability was identified in BusyBox v.1.36.1 through a crafted awk pattern processed by the copyvar function in awk.c</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42365">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-42366</a></h3>
<div class="csaf-accordion-content">
<p>A heap buffer overflow was discovered in BusyBox version 1.36.1 in the next_token function at awk.c:1159.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42366">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/119.html">CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-6197</a></h3>
<div class="csaf-accordion-content">
<p>libcurl's ASN1 parser includes the utf8asn1str() function, which is used for parsing an ASN.1 UTF-8 string. It can detect an invalid field and return an error. Unfortunately, when doing so it also invokes free() on a 4-byte local stack buffer. Most modern malloc implementations detect this error and immediately abort. Some, however, accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the free() implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploiting this flaw is a crash, although it cannot be ruled out that more serious results may occur under special circumstances.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6197">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/590.html">CWE-590 Free of Memory not on the Heap</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-6874</a></h3>
<div class="csaf-accordion-content">
<p>libcurl's URL API function curl_url_get() offers punycode conversions to and from IDN. When converting a name that is exactly 256 bytes, libcurl may read outside of a stack-based buffer when built to use the macidn IDN backend. The conversion function then fills up the provided buffer exactly - but does not null-terminate the string. This flaw can lead to stack contents accidentally getting returned as part of the converted string.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6874">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/126.html">CWE-126 Buffer Over-read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.1</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-7264</a></h3>
<div class="csaf-accordion-content">
<p>libcurl's ASN.1 parser code includes the GTime2str() function, which is used for parsing an ASN.1 generalized time field. If given a syntactically incorrect field, the parser might end up using -1 for the length of the time fraction, leading to a strlen() being performed on a pointer to a heap buffer area that is not intentionally not null-terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when CURLINFO_CERTINFO is used.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7264">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-8006</a></h3>
<div class="csaf-accordion-content">
<p>Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that becomes available is pcap_findalldevs_ex(). One of the function arguments can accept a filesystem path, which typically refers to a directory containing input data files. When the specified path cannot be used as a directory, the function receives NULL from opendir(). It does not check the return value and passes the NULL value to readdir(), which causes a NULL pointer dereference.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8006">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-8096</a></h3>
<div class="csaf-accordion-content">
<p>When curl is configured to use the certificate status request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and may incorrectly consider the response valid. If the returned status reports an error other than 'revoked' (such as 'unauthorized') it is not treated as a bad certificate.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8096">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/295.html">CWE-295 Improper Certificate Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-9681</a></h3>
<div class="csaf-accordion-content">
<p>When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, causing it to expire earlier or later than intended. This affects curl-using applications that enable HSTS and use URLs with the insecure http:// scheme and perform transfers with hosts like x.example.com as well as example.com where the first host is a subdomain of the second host. (The HSTS cache must either have been populated manually or through previous HTTPS requests, as entries for the domains involved are required to trigger this issue.) When x.example.com responds with Strict-Transport-Security: headers, this bug can make the subdomain's expiry timeout bleed over and get set for the parent domain example.com in curl's HSTS cache. The result of a triggered bug is that HTTP accesses to example.com get converted to HTTPS for a different period of time than what was asked for by the origin server. If example.com for example stops supporting HTTPS at its expiry time, curl might then fail to access http://example.com until the (wrongly set) timeout expires. This bug can also expire the parent's entry earlier, thus making curl inadvertently switch back to insecure HTTP earlier than otherwise intended.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9681">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/697.html">CWE-697 Incorrect Comparison</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-11053</a></h3>
<div class="csaf-accordion-content">
<p>When configured to use a .netrc file for credentials and follow HTTP redirects, curl could leak the password from the first host to the redirect target host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits the password or both the login and password.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11053">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200 Exposure of Sensitive Information to an Unauthorized Actor</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-12718</a></h3>
<div class="csaf-accordion-content">
<p>This vulnerability allows modifying some file metadata (e.g., last modified) with filter="data" or file permissions (chmod) with filter="tar" for files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives when extracting untrusted tar archives with TarFile.extractall() or TarFile.extract() and specifying the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions do not include the extraction filter feature. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to "data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However, when evaluating source distributions it is important to avoid installing source distributions that contain suspicious links.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12718">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-41996</a></h3>
<div class="csaf-accordion-content">
<p>Validating the order of public keys in the Diffie-Hellman Key Agreement Protocol—when an approved safe prime is used—can allow remote attackers (from the client side) to trigger computationally expensive server-side DHE modular-exponentiation calculations. This can result in asymmetric resource consumption. In the basic attack scenario, the client claims that it can only communicate using DHE, and the server must be configured to allow DHE and validate the order of the public keys.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41996">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/295.html">CWE-295 Improper Certificate Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-47619</a></h3>
<div class="csaf-accordion-content">
<p>syslog-ng is an enhanced log daemon. Prior to version 4.8.2, `tls_wildcard_match()` matches certificates such as foo.*.bar, which is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided or invalidated. This issue could impact TLS connections and potentially enable man-in-the-middle attacks. Version 4.8.2 contains a fix for the issue.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47619">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/295.html">CWE-295 Improper Certificate Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-52533</a></h3>
<div class="csaf-accordion-content">
<p>gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 is affected by an off-by-one error resulting in a buffer overflow because SOCKS4_CONN_MSG_LEN is insufficient to accommodate a trailing '\0' character.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52533">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-0167</a></h3>
<div class="csaf-accordion-content">
<p>When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password from the first host to the redirect target host under certain circumstances. This flaw occurs only if the netrc file contains a default entry that omits both the login and password which is a rare circumstance.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0167">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200 Exposure of Sensitive Information to an Unauthorized Actor</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.4</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-0665</a></h3>
<div class="csaf-accordion-content">
<p>libcurl could incorrectly close the same eventfd file descriptor twice when closing a connection channel after completing a threaded name resolution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0665">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1341.html">CWE-1341 Multiple Releases of Same Resource or Handle</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-0725</a></h3>
<div class="csaf-accordion-content">
<p>When libcurl is configured to perform automatic gzip decompression of content-encoded HTTP responses using the CURLOPT_ACCEPT_ENCODING option with zlib version 1.2.0.3 or older, an attacker-controlled integer overflow could lead to a buffer overflow in libcurl</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0725">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/680.html">CWE-680 Integer Overflow to Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-1390</a></h3>
<div class="csaf-accordion-content">
<p>The PAM module pam_cap.so in libcap configuration supports group names starting with "@". During parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in unintended users being granted unintended inherited capabilities, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by creating specially crafted usernames.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1390">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/284.html">CWE-284 Improper Access Control</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-3360</a></h3>
<div class="csaf-accordion-content">
<p>An integer overflow and buffer under-read in GLib occurs when parsing an excessively long or malformed ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3360">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-4138</a></h3>
<div class="csaf-accordion-content">
<p>This vulnerability allows the extraction filter to be ignored, which enables symlink targets to point outside the destination directory and permits modification of some file metadata. You are affected by this vulnerability if you use the tarfile module to extract untrusted tar archives with TarFile.extractall() or TarFile.extract() and specify the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later, the default value of filter= changed from "no filtering" to "data," so if you rely on this new default behavior, your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions, which are tar archives, as source distributions already allow arbitrary code execution during the build process. However, when evaluating source distributions, it is important to avoid installing those with suspicious links.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4138">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-4330</a></h3>
<div class="csaf-accordion-content">
<p>This vulnerability allows the extraction filter to be ignored, enabling symlink targets to point outside the destination directory and permitting modification of some file metadata. You are affected by this vulnerability if you use the tarfile module to extract untrusted tar archives with TarFile.extractall() or TarFile.extract() and specify the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation (https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter) for more information. Note that for Python 3.14 or later, the default value of filter= changed from "no filtering" to "data," so if you rely on this new default behavior, your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions, which are tar archives, as source distributions already allow arbitrary code execution during the build process. However, when evaluating source distributions, it is important to avoid installing those with suspicious links.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4330">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-4373</a></h3>
<div class="csaf-accordion-content">
<p>GLib contains an integer overflow vulnerability in the g_string_insert_unichar() function. If the specified insertion position is excessively large, it may overflow, resulting in a buffer underwrite.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4373">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/124.html">CWE-124 Buffer Underwrite ('Buffer Underflow')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-4435</a></h3>
<div class="csaf-accordion-content">
<p>When using TarFile.errorlevel = 0 and extracting with a filter, the documented behavior is that any filtered members should be skipped and not extracted. However, in affected versions, the actual behavior is that the member is still extracted and not skipped.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4435">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/682.html">CWE-682 Incorrect Calculation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-4516</a></h3>
<div class="csaf-accordion-content">
<p>An issue exists in CPython when using bytes.decode("unicode_escape", errors="ignore|replace"). If you are not using the "unicode_escape" encoding or an error handler, your usage is not affected. To work around this issue, you may stop using the errors parameter and instead wrap the bytes.decode() call in a try-except block catching UnicodeDecodeError.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4516">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-4517</a></h3>
<div class="csaf-accordion-content">
<p>This vulnerability allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if you use the tarfile module to extract untrusted tar archives with TarFile.extractall() or TarFile.extract() and specify the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation (https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter) for more information. Note that for Python 3.14 or later, the default value of filter= changed from "no filtering" to "data," so if you rely on this new default behavior, your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions, which are tar archives, as source distributions already allow arbitrary code execution during the build process. However, when evaluating source distributions, it is important to avoid installing those with suspicious links.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4517">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.4</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-6141</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability was discovered in GNU ncurses versions up to 6.5-20250322 and classified as a security issue. This vulnerability affects the postprocess_termcap function in the file tinfo/parse_entry.c. The manipulation leads to a stack-based buffer overflow. Exploitation of this vulnerability requires local access. Upgrading to version 6.5-20250329 addresses this issue. It is recommended to upgrade the affected component.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6141">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9086</a></h3>
<div class="csaf-accordion-content">
<p>First, a cookie is set using the secure keyword for https://target. Second, curl is redirected to, or otherwise made to communicate with, http://target (same hostname, but using clear-text HTTP) using the same cookie. Third, the same cookie name is set, but with just a slash as the path (path='/'). Since this site is not secure, the cookie should be ignored. Fourth, a bug in the path comparison logic causes curl to read outside a heap buffer boundary. The bug may cause a crash or lead to an incorrect comparison, allowing the clear-text site to override the contents of the secure cookie. This behavior depends on the memory contents immediately following the single-byte allocation that holds the path. The expected behavior is to ignore the second cookie, as it was already set as secure on a secure host; overriding it on an insecure host should not be permitted.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9230</a></h3>
<div class="csaf-accordion-content">
<p>An application attempting to decrypt CMS messages encrypted using password-based encryption can trigger an out-of-bounds read and write. This out-of-bounds read may trigger a crash, leading to an application denial of service. The out-of-bounds write can cause memory corruption, which may lead to various consequences, including a denial of service or execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that an attacker would be able to perform it is low. Additionally, password-based (PWRI) encryption support in CMS messages is very rarely used. For that reason, the issue was assessed as moderate severity. The FIPS modules in versions 3.5, 3.4, 3.3, 3.2, 3.1, and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9230">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9231</a></h3>
<div class="csaf-accordion-content">
<p>A timing side-channel that could allow remote recovery of the private key exists in the SM2 algorithm implementation on 64-bit ARM platforms. A timing side-channel in SM2 signature computations on 64-bit ARM platforms could allow an attacker to recover the private key. While remote key recovery over a network was not attempted by the reporter, timing measurements revealed a signal that may enable such an attack. OpenSSL does not directly support certificates with SM2 keys in TLS; therefore, this CVE is not relevant in most TLS contexts. However, because it is possible to add support for such certificates via a custom provider, and given that the private key may be recoverable through remote timing measurements in that context, this is considered a moderate severity issue. The FIPS modules in versions 3.5, 3.4, 3.3, 3.2, 3.1, and 3.0 are not affected by this issue, as SM2 is not an approved algorithm.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/385.html">CWE-385 Covert Timing Channel</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-9232</a></h3>
<div class="csaf-accordion-content">
<p>An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set, and the host portion of the authority component of the HTTP URL is an IPv6 address. An out-of-bounds read can trigger a crash, leading to an application denial of service. The OpenSSL HTTP client API functions can be used directly by applications, but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However, the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code, the out-of-bounds read can only trigger a crash. Furthermore, the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function, and the user must have a 'no_proxy' environment variable set. For the aforementioned reasons, the issue was assessed as low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0, and 3.5.0. The FIPS modules in versions 3.5, 3.4, 3.3, 3.2, 3.1, and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9232">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-10148</a></h3>
<div class="csaf-accordion-content">
<p>curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as required by the specification. Instead, it used a fixed mask that persisted throughout the entire connection. A predictable mask pattern allows a malicious server to induce traffic between the two communicating parties. This traffic could be interpreted by an involved proxy (configured or transparent) as genuine HTTP traffic with content, thereby poisoning its cache. The poisoned cache content could then be served to all users of that proxy.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10148">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/340.html">CWE-340 Generation of Predictable Numbers or Identifiers</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-27587</a></h3>
<div class="csaf-accordion-content">
<p>OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, an attacker can compare signing times of full-sized nonces to those of signatures using smaller nonces through statistical tests. There is a side-channel in the P-364 curve that allows private key extraction. Additionally, there is a dependency between the bit size of K and the size of the side channel. This CVE is disputed because the OpenSSL security policy explicitly states that any side channels requiring the same physical system to be detected are outside the software’s threat model. The timing signal is so small that it cannot be detected without the attacking process running on the same physical system.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27587">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/385.html">CWE-385 Covert Timing Channel</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-32433</a></h3>
<div class="csaf-accordion-content">
<p>Erlang/OTP is a collection of libraries and tools for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, an SSH server could allow an attacker to perform unauthenticated remote code execution. By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access and execute arbitrary commands without valid credentials. This issue is resolved in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or preventing access via firewall rules.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32433">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/306.html">CWE-306 Missing Authentication for Critical Function</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>10</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38084</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "mm/hugetlb: unshare page tables during VMA split, not before. " Currently, __split_vma() triggers hugetlb page table unsharing through vm_ops-&gt;may_split(). This happens before the VMA lock and rmap locks are taken, which is too early. It allows racing VMA-locked page faults in the process and racing rmap walks from other processes to cause page tables to be shared again before the split occurs. This is fixed by explicitly calling the hugetlb unshare logic from __split_vma() in the same place where THP splitting also occurs. At that point, both the VMA and the rmap(s) are write-locked. A notable detail is that the helper hugetlb_unshare_pmds() can be called from two different locking contexts: First, from hugetlb_split(), holding: mmap lock (exclusively), VMA lock, file rmap lock (exclusively). Second, from hugetlb_unshare_all_pmds(), which appears to be designed to call with only the mmap lock held (in shared mode), but currently only runs while holding the mmap lock and VMA lock. This commit fixes a race condition introduced in commit b30c14cd6102 (“hugetlb: unshare some PMDs when splitting VMAs”). That commit claimed to fix an issue introduced in 5.13, but the fix should also apply to earlier versions.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38084">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38085</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race." huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes. This can potentially turn it into a normal page table used in another process, where unrelated VMAs can later be installed. If this occurs during a concurrent gup_fast() operation, the function could end up walking the page tables of another process. Although this does not appear to immediately lead to kernel memory corruption, it is highly unusual and unexpected. This is resolved by using an explicit broadcast IPI through tlb_remove_table_sync_one(), similar to the approach used in khugepaged when removing page tables for a THP collapse.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38085">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38086</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "net: ch9200: fix uninitialised access during mii_nway_restart." In mii_nway_restart(), the code attempts to call mii-&gt;mdio_read, which is ch9200_mdio_read(). ch9200_mdio_read() uses a local buffer called buff, which is initialized with control_read(). However, buff is conditionally initialized inside control_read(). If the condition err == size is not met, then buff remains uninitialized. Once this happens, the uninitialized buff is accessed and returned during ch9200_mdio_read(). The problem stems from the fact that ch9200_mdio_read() ignores the return value of control_read(), leading to uninitialized access of buff. To fix this, the return value of control_read() should be checked and return early on error.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38345</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "ACPICA: fix ACPI operand cache leak in dswstate.c." An ACPI cache leak was identified during early termination and continued boot scenarios. When early termination occurs due to a malicious ACPI table, the Linux kernel terminates the ACPI function and continues the boot process. While the kernel terminates the ACPI function, kmem_cache_destroy() reports an Acpi-Operand cache leak. Analysis revealed that the acpi_ds_obj_stack_pop_and_delete() function miscalculated the top of the stack. The acpi_ds_obj_stack_push() function uses walk_state-&gt;operand_index for the start position of the top, but acpi_ds_obj_stack_pop_and_delete() considers index 0. Therefore, this causes acpi operand memory leak. This cache leak poses a security risk because older kernels (&lt;= 4.9) display memory locations of kernel functions in stack dumps. Malicious users could exploit this information to bypass kernel ASLR. A patch was developed to fix the ACPI operand cache leak.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38345">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38350</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "net/sched: Always pass notifications when child class becomes empty." Certain classful qdiscs may invoke their classes' dequeue handler during an enqueue operation. This may unexpectedly empty the child qdisc, causing an in-flight class to become passive via qlen_notify(). Most qdiscs do not expect such behavior at this point and may eventually re-activate the class anyway, which can lead to a use-after-free. The referenced fix commit attempted to address this behavior for the HFSC case by adjusting backlog accounting. However, this proved incomplete because the parent's parent may also encounter the issue. Because backlog accounting issues causing use-after-free on stale class pointers have become a recurring problem, this patch takes a different approach. Instead of attempting to fix the accounting, the patch ensures that qdisc_tree_reduce_backlog() always calls qlen_notify() when the child qdisc is empty. This solves the problem because deletion of qdiscs always involves a call to qdisc_reset() and / or qdisc_purge_queue() which ultimately resets its qlen to 0 thus causing the following qdisc_tree_reduce_backlog() to report to the parent. Note that this may call qlen_notify() on passive classes multiple times. This is not an issue after the recent patch series that made all classful qdiscs' qlen_notify() handlers idempotent.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38350">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38498</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "do_change_type(): refuse to operate on unmounted or non-owned mounts." This change ensures that propagation settings can only be modified for mounts located in the caller's mount namespace. This change aligns permission checking with the behavior of other mount(2) system calls.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38498">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39839</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "batman-adv: fix out-of-bounds read/write in network-coding decode." atadv_nc_skb_decode_packet() trusts coded_len and checks only against skb-&gt;len. XOR starts at sizeof(struct batadv_unicast_packet), reducing payload headroom. Additionally, the source skb length is not verified, allowing an out-of-bounds read and a small out-of-bounds write. Ensure that coded_len fits within the payload area of both destination and source sk_buff structures before performing XOR operations.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39839">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39841</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "scsi: lpfc: Fix buffer free/clear order in deferred receive path." This change addresses a use-after-free vulnerability by correcting the buffer release sequence in the deferred receive path. The code freed the RQ buffer first and only then cleared the context pointer under the lock. Concurrent paths (e.g., ABTS and the repost path) also inspect and release the same pointer under the lock, so the previous order could lead to a double-free or use-after-free condition. Note that the repost path already uses the correct pattern: detach the pointer under the lock, then free it after dropping the lock. The deferred path now follows the same pattern.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39841">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39846</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()." In __iodyn_find_io_region(), pcmcia_make_resource() is assigned to res and used in pci_bus_alloc_resource(). res is dereferenced in pci_bus_alloc_resource(), which could lead to a NULL pointer dereference if pcmcia_make_resource() fails. This issue is resolved by adding a check for res.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39846">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39853</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "i40e: Fix potential invalid access when MAC list is empty." list_first_entry() never returns NULL—if the list is empty, it still returns a pointer to an invalid object, which can lead to invalid memory access when dereferenced. This issue is resolved by using list_first_entry_or_null() instead of list_first_entry().</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39853">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39860</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()." In the crash report, a single thread calling bt_accept_dequeue() freed sk and accessed it afterward. The root cause appears to be the racy l2cap_sock_cleanup_listen() call introduced by the cited commit. bt_accept_dequeue() is called under lock_sock() except when invoked by l2cap_sock_release(). Two threads could see the same socket during the list iteration in bt_accept_dequeue(). Depending on timing, the other thread could appear in the "Freed by task" section. The fix ensures that l2cap_sock_cleanup_listen() is called under lock_sock() in l2cap_sock_release().</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39860">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39864</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "wifi: cfg80211: fix use-after-free in cmp_bss()." Following the bss_free() quirk introduced in commit 776b3580178f ("cfg80211: track hidden SSID networks properly"), update cfg80211_update_known_bss() to free the last beacon frame elements only if they are not shared via the corresponding hidden_beacon_bss pointer.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39864">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39865</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: "tee: fix NULL pointer dereference in tee_shm_put()." tee_shm_put() has a NULL pointer dereference. Add a NULL check in tee_shm_put() to resolve the issue.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39865">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-59375</a></h3>
<div class="csaf-accordion-content">
<p>Expat versions prior to 2.7.2 allow attackers to trigger large dynamic memory allocations via a small document submitted for parsing.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59375">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SINEC OS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>RUGGEDCOM RST2428P (6GK6242-6PA00), SCALANCE XCH328 (6GK5328-4TS01-2EC2), SCALANCE XCM324 (6GK5324-8TS01-2AC2), SCALANCE XCM328 (6GK5328-4TS01-2AC2), SCALANCE XCM332 (6GK5332-0GA01-2AC2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
<p><strong>Vendor fix</strong><br>Update to V3.3 or later version</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/770.html">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Siemens reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>General Recommendations</h2>
<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>
<hr>
<h2>Additional Resources</h2>
<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>
<hr>
<h2>Terms of Use</h2>
<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-089022 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-01-28</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-01-28</td>
<td>1</td>
<td>Publication Date</td>
</tr>
<tr>
<td>2026-02-12</td>
<td>2</td>
<td>Initial CISA Republication of Siemens SSA-089022 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[VideoProc Converter AI: The All‑in‑One Mac Toolkit to Download, Convert, and AI‑Enhance Your Videos]]></title>
<description><![CDATA[If you regularly edit video on Mac, you know the real work often starts before you even open DaVinci Resolve: noisy audio, soft footage, clips that don’t want to cooperate during import, or old videos that don’t look their best on a 4K display. Today, I’m taking a look at VideoProc Converter AI, ...]]></description>
<link>https://tsecurity.de/de/3280786/ios-mac-os/videoproc-converter-ai-the-allinone-mac-toolkit-to-download-convert-and-aienhance-your-videos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3280786/ios-mac-os/videoproc-converter-ai-the-allinone-mac-toolkit-to-download-convert-and-aienhance-your-videos/</guid>
<pubDate>Wed, 11 Feb 2026 06:50:58 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you regularly edit video on Mac, you know the real work often starts before you even open DaVinci Resolve: noisy audio, soft footage, clips that don’t want to cooperate during import, or old videos that don’t look their best on a 4K display. Today, I’m taking a look at VideoProc Converter AI, a program that acts as the bridge between raw media and a smooth editing experience, helping creators optimize their files before they ever hit the timeline.



By combining AI video enhancement, format conversion, compression, and recording tools, Videoproc Converter AI aims to streamline the entire pre‑production stage — making your editing workflow faster and more efficient.



At the time of writing, the lifetime version is available at 55% off, and the purchase includes a Buy 1 Get 4 offer featuring Aiarty Image Matting, iPhone Manager, 5KPlayer, and VideoProc Vlogger — expanding the toolkit beyond video processing into image editing, device management, media playback, and video creation.



Learn more about VideoProc Converter AI and download the free trial &gt;



See the 55% lifetime deal and Buy 1 Get 4 Offer details &gt; 



AI Video Enhancement on macOS: Fixing Low-Res and Low-Light Footage







VideoProc Converter AI for macOS serves as an all-in-one media processing app that combines AI-powered video and image enhancement with conversion, downloading, compression, and screen recording. While it may sound like it’s tackling a lot, working with the app gives it a streamlined feel that’s built with purpose. Rather than replacing your editor, VideoProc Converter AI focuses on solving those problems early — preparing media so it’s clean, optimized, and ready for Final Cut Pro, DaVinci Resolve, or Adobe Premiere.



See how VideoProc Converter AI upscales footage to 4K and smooths your video editing workflow. 



Working with the program, one of the first things I wanted to try was testing low-resolution footage -- something AI programs can struggle with delivering convincingly. Working with some compressed mobile video and old 1080p clips I shot long ago, I first tested the app’s Super Resolution tool for video to upscale them. The results were impressive. Rather than over-sharpening, results were subtle, yet prominent. Facial features look clear, compression artifacts appear reduced, and the footage looked good on my M4 MacBook Air’s display. 



However, I also wanted to see how the program handled video shot in low light. Even novice editors know that dim or grainy footage can be painful to work with, yet VideoPro Converter AI’s denoising and enhancement tools kept textures intact while cleaning up the selected clips -- making it highly suitable for editors. The program also features AI Frame Interpolation, which can help increase frame rates. The tool can help make video smoother without producing artifacts, which is nice. Good for those who want to produce slow motion clips or improve the fluidity of a video during playback. 



AI Image Enhancement to Upscale and Restore Photos







VideoProc Converter AI isn’t limited to video. It also includes a powerful AI Image Enhancement feature designed to upscale and restore photos in just a few clicks. Whether you're working with old family pictures, compressed web images, product shots, or low-resolution thumbnails, the AI models intelligently increase resolution while preserving natural detail — avoiding the over-sharpened, artificial look common with basic upscaling tools.



In my testing, images gained noticeable clarity and improved texture definition without introducing halos or noise. The process is refreshingly simple: import your image, choose the enhancement model, preview the result, and export. No complicated sliders or technical adjustments required. For anyone looking to improve their photos — from beginners to hobbyists to more experienced users — this tool adds real value. It’s ideal for social media posts, personal albums, presentations, or website visuals, and it’s especially convenient since it’s included alongside VideoProc’s video workflow features in one streamlined app.



Format Compatibility and Mobile Video Optimization for Mac







Looking at mobile camera footage -- which can often be super compressed -- it also benefited from these tools. Once processing finished, mobile video clips looked more balanced and cleaner, which made it easier to combine with footage from my iPhone 17 Pro. What’s really cool about these tools is that they didn’t try and flip the footage on its head, rather, it simply made the footage more usable. 



It’s not just a matter of cleaning up video, I also wanted to ensure the results played well with Mac video editors. Featuring support for over 1,000 audio and video formats, VideoProc Converter AI is primed for dealing with mixed source. Whether it's converting clips into optimized HEVC or ProRes, the process is straightforward, and I was able to import the results into my editor of choice with ease. I was also a big fan of the program’s compression features, as they shine for the everyday workflow of Mac users. Large files can be time consuming and eat up storage, but VideoProc Converter AI’s ability to reduce file sizes while keeping image quality was rather impressive. 



Built-In Screen Recorder, Audio Cleanup, and Editing Tools







As someone that records a lot of videos containing live music, I appreciated the app’s audio cleanup tool. The noise suppression capabilities were super helpful for me, as recording live music gets noisy, and quick. I was able to eliminate weird room echoes and excess audience noise with ease, while still keeping my original audio sounding natural. 



An additional plus for VideoProc Converter AI is its inclusion of a built-in camera and screen recorder, with capabilities of recording 4K and 60 fps -- it worked smoothly with my M4. It also includes support for green-screen effects, system audio, webcam overalls, and microphone inputs for those that like streaming or producing online content. The app also includes some basic one-click editing tools: including options for merging, trimming, cropping, adding subtitles, and applying watermarks. They won’t necessarily replace a full-fledged video editor, but they’re good for quick fixes before exporting. 



In terms of performance, there’s full support for Apple Silicon, making batch processing fast and responsive. Even when you’re working with multiple clips or large libraries, it’s got the goods. Supporting macOS 10.13 or newer with its standard features and macOS 10.15 or newer with AI enhancements, it's super accessible for Mac users. 



The Final Word







In the end, VideoProc Converter AI feels like a practical utility rather than something relying on the popularity of AI. It’s good for fixing early problems, smoothing footage, and cleaning up audio, ensuring your media is ready to go before editing. For content creators, influencers, video editors, marketers, educators, hobbyists, and everyday users seeking media enhancement, it can be downright indispensable.



Right now, there’s a 55% discount on the lifetime version, and it even comes with four additional tools -- Aiarty Image Matting, iPhone Manager, 5KPlayer, and VideoProc Vlogger -- a $128.59 present. It’s a practical choice for anyone on Mac who wants a smoother, more efficient workflow for videos, images, and media projects.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Remove Background in Mac Preview]]></title>
<description><![CDATA[We have all been there. You have a perfect photo for a presentation, a profile picture, or a fun sticker, but the background is cluttered or just plain boring. You might think you need expensive software like Photoshop to fix it, but you actually do not!



Your Mac comes with a powerful hidden g...]]></description>
<link>https://tsecurity.de/de/3279355/ios-mac-os/how-to-remove-background-in-mac-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3279355/ios-mac-os/how-to-remove-background-in-mac-preview/</guid>
<pubDate>Tue, 10 Feb 2026 14:22:43 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We have all been there. You have a perfect photo for a presentation, a profile picture, or a fun sticker, but the background is cluttered or just plain boring. You might think you need expensive software like Photoshop to fix it, but you actually do not!



Your Mac comes with a powerful hidden gem called Preview. While mobile users are still exploring what Preview offers on iOS 26, the desktop version remains a mature powerhouse. It is not just for viewing PDFs or helping you print selected pages; it is a surprisingly capable image editor. Whether you are running the latest macOS or rocking an older version, Preview can help you isolate your subject and banish that background in seconds.



Ready to make your images pop? Let’s dive in.



Table of contentsWhat you’ll need to Get StartedHere’s How to Remove the Background1. Method 1: The One-Click Magic (macOS Ventura and newer)2. Method 2: The Instant Alpha Tool (Older macOS or detailed work)3. Method 3: The Smart Lasso (For complex edges)Additional TipsFinal ThoughtsFAQs



What you’ll need to Get Started



Before we start editing, ensure you have the following ready. The good news is that you likely have everything you need already installed on your computer.




A Mac Computer: Any MacBook, iMac, or Mac mini will work.



The Image File: Have your photo saved on your Desktop or in a folder where you can easily find it. High-contrast images (where the subject stands out clearly from the background) work best.



Preview App: This comes pre-installed on every Mac.




Here’s How to Remove the Background



There are a few ways to tackle this, depending on which version of macOS you are using and how complex your image is. We will start with the easiest method available on modern Macs.



1. Method 1: The One-Click Magic (macOS Ventura and newer)



If you have updated your Mac recently (macOS Ventura, Sonoma, or Sequoia), Apple has included a feature that uses machine learning to detect your subject automatically. It is incredibly fast.




Open your image: Double-click your image file to open it in Preview.



Select the Tool: Go to the top menu bar and click Tools.



Click Remove Background: Select Remove Background from the dropdown menu. Alternatively, you can use the keyboard shortcut Command + Shift + K.



Convert to PNG: If your image is a JPG or HEIC, Preview might ask to convert it to a PNG. Click Convert. Transparency only works with PNG files, so this step is crucial. (If you have a whole folder of these to process, you might want to batch convert your images to PNG format before you start).



Admire the result: The background should disappear instantly, leaving your subject surrounded by a transparent area.




2. Method 2: The Instant Alpha Tool (Older macOS or detailed work)



If you are on an older version of macOS (like Monterey or Big Sur) or if the automatic tool missed a spot, the Instant Alpha tool is your best friend. This works like a magic wand that selects colors.




Open the Markup Toolbar: Open your image in Preview. Click the Markup Toolbar icon (it looks like a pen tip in a circle) near the top right of the window.



Select Instant Alpha: Click the icon that looks like a magic wand (usually the second icon from the left in the toolbar).



Click and Drag: Click on the background area you want to remove and strictly hold the click. Slowly drag your mouse pointer away from the click point.



Watch the Red Overlay: You will see a red overlay spread across the background. This indicates what will be deleted.

Drag further to select more similar colors.



Drag back if it starts selecting your subject.





Delete: Once the background is highlighted in red, release the mouse button. You will see "marching ants" (a dotted line) around the selection. Press the Delete key on your keyboard.



Repeat if necessary: You may need to repeat this process for different sections of the background.




3. Method 3: The Smart Lasso (For complex edges)



Sometimes the background is too messy for Instant Alpha. The Smart Lasso lets you trace the object you want to keep.




Open Selection Tools: In the Markup Toolbar, click the Selection Tools menu (usually the first icon, a dotted rectangle). Choose Smart Lasso.



Trace your subject: Click and drag to draw a heavy outline around the edge of your subject. You do not need to be perfect; just ensure the thick line covers the border between the subject and the background.



Connect the loop: Finish your tracing by connecting back to the starting point.



Invert Selection: By default, you have selected the subject. To delete the background, go to the top menu bar, click Edit, and select Invert Selection.



Delete: Press the Delete key to remove everything except your traced subject.




Additional Tips




Check for Transparency: If the background turns white instead of checkerboard (transparent) after you press delete, you are likely still working with a JPG file. Go to File &gt; Export, select PNG as the format, and ensure the Alpha checkbox is ticked.



Zoom In for Details: For tricky areas like hair or fur, use the Command + Plus (+) shortcut to zoom in. This gives you much better control with the Instant Alpha or Lasso tools.



Duplicate First: It is always a safe bet to duplicate your image before editing. In Finder, right-click the image and select Duplicate so you keep the original safe.



Finder Quick Action: For an even faster method on newer Macs, simply right-click the image file in a Finder window, scroll down to Quick Actions, and select Remove Background. You do not even need to open the app! If this option is missing or fails to launch, you might need to troubleshoot why Preview is not working in Finder.




Final Thoughts



Removing image backgrounds used to be a tedious chore reserved for graphic designers. Now, Preview makes it accessible to everyone right on the desktop. Whether you use the modern AI-powered tool or the trusty Instant Alpha wand, you can create professional-looking cutouts in seconds.



So go ahead and clean up those product photos or make that funny meme of your cat. You have the tools right at your fingertips.



FAQs



Why is the "Remove Background" option greyed out? This usually happens if the subject is not clearly defined or if the image format is unsupported. Try converting the image to a standard PNG or JPG first, or ensure the subject has good contrast against the background.  Can I undo the background removal if I made a mistake?  Yes! As long as you have not closed the file, you can press Command + Z to undo your last action. You can press it multiple times to go back several steps.  Why did the file size get larger after removing the background? When you switch from a compressed format like JPG to a PNG (which supports transparency), the file size often increases because PNG is a lossless format that preserves higher quality.]]></content:encoded>
</item>
<item>
<title><![CDATA[I made an open source image and video converter]]></title>
<description><![CDATA[i made a simple file converter for batch processing images and videos. it's built on ffmpeg and imagemagick with a pyside6 interface. you can drag and drop files or folders, convert between different formats, adjust quality settings like bitrate and resolution for videos, resize and convert image...]]></description>
<link>https://tsecurity.de/de/3273169/linux-tipps/i-made-an-open-source-image-and-video-converter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3273169/linux-tipps/i-made-an-open-source-image-and-video-converter/</guid>
<pubDate>Fri, 06 Feb 2026 18:22:58 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>i made a simple file converter for batch processing images and videos. it's built on ffmpeg and imagemagick with a pyside6 interface. you can drag and drop files or folders, convert between different formats, adjust quality settings like bitrate and resolution for videos, resize and convert images to different formats. it also treats gifs as videos to compress them better and shows you how much space you saved. works on linux and windows, available as appimage or exe. wrote it because i was tired of converting files one by one and wanted something straightforward. it's open source under mit license.</p> <p><a href="https://github.com/cenullum/Yet-Another-Open-File-Converter">https://github.com/cenullum/Yet-Another-Open-File-Converter</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/cenkerc"> /u/cenkerc </a> <br> <span><a href="https://i.redd.it/15gokk28xvhg1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1qxj8uw/i_made_an_open_source_image_and_video_converter/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[SystemBC Botnet Hijacked 10,000 Devices Worldwide to Use for DDoS Attacks]]></title>
<description><![CDATA[The SystemBC malware family, a persistent threat first documented in 2019, has evolved into a massive botnet infrastructure controlling over 10,000 hijacked devices globally. Functioning primarily as a SOCKS5 proxy and a backdoor, this malware enables threat actors to mask their malicious traffic...]]></description>
<link>https://tsecurity.de/de/3253449/it-security-nachrichten/systembc-botnet-hijacked-10000-devices-worldwide-to-use-for-ddos-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3253449/it-security-nachrichten/systembc-botnet-hijacked-10000-devices-worldwide-to-use-for-ddos-attacks/</guid>
<pubDate>Wed, 04 Feb 2026 19:05:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The SystemBC malware family, a persistent threat first documented in 2019, has evolved into a massive botnet infrastructure controlling over 10,000 hijacked devices globally. Functioning primarily as a SOCKS5 proxy and a backdoor, this malware enables threat actors to mask their malicious traffic and maintain long-term access to compromised networks. By converting infected systems into […]</p>
<p>The post <a href="https://cybersecuritynews.com/systembc-botnet-hijacked-10000-devices/">SystemBC Botnet Hijacked 10,000 Devices Worldwide to Use for DDoS Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8007-1: ImageMagick vulnerabilities]]></title>
<description><![CDATA[It was discovered that ImageMagick incorrectly handled image depth values
when processing MIFF image files. An attacker could use this issue to cause
a denial of service or possibly execute arbitrary code. (CVE-2025-43965)

It was discovered that ImageMagick incorrectly processed SVG images and
M...]]></description>
<link>https://tsecurity.de/de/3251985/unix-server/usn-8007-1-imagemagick-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3251985/unix-server/usn-8007-1-imagemagick-vulnerabilities/</guid>
<pubDate>Wed, 04 Feb 2026 08:31:04 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that ImageMagick incorrectly handled image depth values
when processing MIFF image files. An attacker could use this issue to cause
a denial of service or possibly execute arbitrary code. (CVE-2025-43965)

It was discovered that ImageMagick incorrectly processed SVG images and
MSL files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-68618)

It was discovered that ImageMagick incorrectly handled memory when
converting MVG files. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-69204)]]></content:encoded>
</item>
<item>
<title><![CDATA[If your AI strategy still looks like 2024, you’re already too late]]></title>
<description><![CDATA[The global economy has already moved past the great AI experiment of 2023–2024. Until 2022, AI was just a buzzword and was limited to individual adoption. But by 2025, AI tools will have become an integrated part of our daily lives in some form. We are using AI to polish our emails, suggestions o...]]></description>
<link>https://tsecurity.de/de/3250580/it-security-nachrichten/if-your-ai-strategy-still-looks-like-2024-youre-already-too-late/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3250580/it-security-nachrichten/if-your-ai-strategy-still-looks-like-2024-youre-already-too-late/</guid>
<pubDate>Tue, 03 Feb 2026 14:50:29 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The global economy has already moved past the great AI experiment of 2023–2024. Until 2022, AI was just a buzzword and was limited to individual adoption. But by 2025, AI tools will have become an integrated part of our daily lives in some form. We are using AI to polish our emails, suggestions on social platforms, to develop images, summaries of meetings, etc. Adoption of AI among companies has grown even stronger. Most enterprises have pivoted their transformation journey to accommodate AI in their processes.</p>



<p>By 2026, the cost of raw intelligence is expected to drop significantly. Research says that <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="nofollow">90% of a company’s tech value won’t come from the software it owns but from the proprietary data it uses to train AI</a>. Within the next two years, a single SME will be equipped with AI workflows that will eliminate the need for traditional departments of specialists at the back end.</p>



<p>As we progress in 2026, I am predicting some of the following AI trends. Sources of these predictions are work experience, market research and data from research firms and quotes made by industry legends.</p>



<h2 class="wp-block-heading">Foundational-level performance of all models will be the same</h2>



<p>Two years ago, when the score and quality output of ChatGPT, Llama, Gemini and Claude were distinctly apart. But as we are getting further in <a href="https://www.swfte.com/blog/open-source-ai-models-frontier-2026" rel="nofollow">our AI journey, this gap has narrowed</a>. The cost of running models is getting cheaper due to advancements in technology.  <a href="https://hai.stanford.edu/ai-index/2025-ai-index-report" rel="nofollow">While all models are getting smarter in absolute terms, models have started generating similar and adequate performance for all basic tasks.</a> As we go down further, what will differentiate those open or closed models now would be their parity of comparison in their specialized area.</p>



<p>In a nutshell, models won’t look distinct anymore; they are more of a commodity from the perspective of usability, performance and elementary tasks. Battle has gone to the next level, “point of comparison” (PoC) between the models. The likes of Gemini are likely to leverage their reach and tight integration across their ecosystem, and OpenAI will still enjoy a mindshare advantage in the minds of consumers. Claude and Anthropic will have a different fanbase of developers due to their specialized ability in code productivity.</p>



<p>So which model will win? Well, no one in all areas. While all AI tools will provide fundamental features of everyday AI, each AI tool will accelerate in its own territory. Advantage, however, lies with those who will have tight integration across various ecosystems with ease.</p>



<h2 class="wp-block-heading">AI workflow &gt;&gt; AI agents</h2>



<p>In the year 2025, agentic AI was perhaps the most celebrated topic in tech communities. Organizations lined up to embed autonomous agents in their everyday processes, even tried to force-fit where there was absolutely no need. The ideas were conceptualized around agentic AI, PoC happened and then “death by PoC.” Projects were not scaled to production. The reason? AI agents are costly to scale, unpredictable and require niche skills to implement, not to mention the pain of integration with other agents.</p>



<p>The massive leap from AI chatbots to agentic AI skipped a crucial middle step in between – “AI workflow.” AI workflows are not totally autonomous, but instead of unthinkingly fully automating entire processes that may result in unexpected outputs, AI workflows rely on step-by-step automation and use human-in-the-loop to ensure AI processes carefully execute every step. According to McKinsey, <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="nofollow">“No more than 10% of organizations report scaling AI agents in any individual function.”</a></p>



<p>ChatGPT reports that 20% of enterprise workflow is happening through custom or project. While fad chased agent AI in social media, the development was happening with AI workflows. The phrase “fully autonomous agent” creates unrealistic expectations, and we have still not fully solved the problem of data security. This looks like we are not exactly staring at “Year of the Agents,” but with the advancement we are making toward it, it will for sure become “The Decade of Agents.”</p>



<p>At the same time, integrating AI workflows is still fetching more impactful results in a shorter time than developing agents. While this may not remove the requirement of a human in between, it still saves 50-70% of person-hours at the back office.</p>



<h2 class="wp-block-heading">Erasure of the technical barrier</h2>



<p>Being a consultant, I had to depend on the marketing team to templatize my proposals in the correct format. Being an author, I must wait until the media team designs images that fit for my articles. These back-office jobs require specialized skills. It takes time to do that kind of work and requires a lot of back-and-forth communication.</p>



<p>The arrival of AI is shifting this trend. We are already witnessing the automation of many such jobs. With the proper context and prompt, GenAI tools are generating media, slides, documents, music, etc. Technical workers are no longer waiting for back offices to execute their tasks like reviewing spreadsheets, writing scripts, creating dashboards, grammar correction and programming support. User-friendly AI tools are enabling everyone to execute these specialized jobs by themselves.</p>



<p>This trend is only going to amplify in 2026. AI in the capacity of an equalizer is narrowing the skills gap between technical and non-technical users. In other words, if your value in an organization depends on only technical skills, your advantage is shrinking every day. The salesperson who used to rely upon an analyst for custom BI reports for his next sales pitch can do it himself.</p>



<h2 class="wp-block-heading">Context &gt;&gt; Prompt engineering</h2>



<p>Prompt engineering was a popular learning skill till 2024. There were videos, courses and experts specializing in this precise concept. The skill was mostly about what to give as input to AI and how to provide that input so that AI can respond most logically. It was around the time when ChatGPT was updated to upload external content and integrate with external providers. This was like giving mini reference material to AI. Even then, I didn’t think this would last forever. Of course, because if AI itself were so intelligent, then why do we need to provide context in a specific manner?</p>



<p>AI has now grown to a level where it can learn vague instructions, writing patterns, previous conversations, uploaded files, etc., with ease. This makes the precise science of prompt engineering less valuable today.</p>



<p>However, for AI to give more personalized answers, providing the right content is essential. Almost all AI tools now accept input files and media to perform tasks. Better file input would result in narrowing the fact gap. AI models can learn everything from the internet —  news, articles, website information, music library, sports box scores — but they know nothing about your personal requirements.</p>



<p>Models must be told the proper context, such as that you want your presentation for a board meeting, sheet-wise data for the technical head of department, or the email you are replying to, or what your manager requested yesterday. This is where the likes of Google, Microsoft and Meta have an advantage. If your organization is operating entirely on Microsoft Workspace, Copilot has access to personalize context emails, documents and calendar. Hence, it can provide a much faster and more precise response to your request. On the downside, this is also where vendor lock-in becomes a significant concern.</p>



<h2 class="wp-block-heading">Sponsored content coming to AI</h2>



<p>It takes about 10 times more money to print a newspaper than the actual selling price. So, how do printing presses sustain? It’s no secret: Advertising. A very similar analogy can be framed here. At this point in time, despite running an average subscription at 20 USD per month, most AI tools are not making any profit. The AI companies created a paradox: If they increase the price of their models, very few people will have access to those models and the learning data for those models will also be low in quantity. So how will they eventually succeed?</p>



<p>In 2026, sponsored ads are expected to cover the cost of models. Yes, it’s true that, like newspapers, AI cannot promote products within the advice or output of an AI prompt, as incentive-motivated outcomes will significantly lower the trust level. But ads can still appear in some other format on the page without disrupting the original idea of intelligence.</p>



<p>So, if you happen to see a Nike sneaker promotion appearing while you’re checking ChatGPT about leg pain you’re experiencing, you may assume that it was inevitable. No one likes ads, but it is the only way for AI companies to offer costly models accessible to everyone, from students, developers, and non-profits, without breaking their wallets.</p>



<h2 class="wp-block-heading">Arrival of robotic AI</h2>



<p>So far, we have witnessed AI robots only in sci-fi movies. The version of AI that we mainly use today, however, is in the form of software or a chatbot. But 2026 can mark the arrival of AI-powered hardware devices specialized to perform specific tasks.</p>



<p>In particular, in small sections of industries, it’s already happening. <a href="https://waymo.com/safety/impact/" rel="nofollow">Waymo provides AI-enabled self-driving taxi services, and it has significantly reduced the accident rate by 96%.</a> As per Walmart, China has deployed more industrial robots than the rest of the world combined. Robots may not necessarily take the form of a humanoid, but other formats could be significantly more visible going forward. Another critical aspect of investing in such hardware would be that, in time, they become more intelligent. An automated car will become safer to drive as it learns more data, driving patterns and rules.</p>



<h2 class="wp-block-heading">AI governance officers as a job title</h2>



<p>AI is vast and massive, but it is also confusing when it comes to handling data. Security officers have always been on the edge when it comes to blind exposure of data that AI models demand. There are very limited instruments in place that can control granule-level access to data once exposed to an AI system. In addition to ever-changing and complex regulatory compliance, shadow AI proliferation, misconfigured resources, access control, model poisoning and a whole other array of threats are emerging to AI systems.</p>



<p>This will demand a new security profile in the IT department. AI governance officers will be responsible for data and models security. <a href="https://www.simmons-simmons.com/en/publications/cm7yowsvj00c4tfd4fe4syrgj/enforcement-of-the-eu-ai-act-when-can-it-start-" rel="nofollow">Following the full enforcement of the EU AI Act and similar other global frameworks, there is a demand for transparency over data being fed into AI</a>. Stanford’s HAI reports that “trust and safety” is now the fastest-growing department in Fortune 500 companies.</p>



<h2 class="wp-block-heading">The human-centric premium</h2>



<p>Technical expertise was born, grew, and advanced in last 50 years. The craftsmanship of software developers refined the world. However, we are at the juncture where expertise is being reset. And I already touched on how only core technical expertise will gradually become redundant as AI is likely to remove technical barriers. This should be a valid reason for resources to upgrade their skills.</p>



<p>When the technical barrier is removed, human-centric skills will take the stage. We are officially exiting the era of generalists. Those who can perform in multiple disciplines alongside technical expertise would be the most qualified resources. For example, someone who has the intuition to apply AI-produced output in a real-world system will become more valuable. In the world of infinite content and code, soft skills and the ability to build relationships, negotiate, the art of storytelling, problem solving, etc., will become a non-commoditized asset.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Year 2026 will take a significant leap into AI, and it won’t be defined by how fast technology moves but by how smartly individuals and organizations apply it to real-life requirements. The winner of the year 2026 won’t be a company with a brilliant 10-year plan, but those who are willing to learn, unlearn and relearn faster than machines. Here are my pointers for individuals and companies who are looking forward to embrace changes coming to AI this year.  </p>



<h3 class="wp-block-heading">Strategies for individuals</h3>



<ul class="wp-block-list">
<li>Select AI tools based on your specific task fit instead of model intelligence, benchmark score and model ranking.</li>



<li>Start your AI workflow journey now by converting your recurring AI prompts into AI workflow automation while keeping human judgment as a gatekeeper at various stages.</li>



<li>Grow beyond core technology by developing human-centric skills such as negotiation, storytelling, design thinking, and problem framing, as these will become differentiators post-shirking of the technology barrier.</li>



<li>Organize files, labels and permissions deliberately so AI systems can use a clean context to produce accurate output.</li>



<li>Validate AI inputs for possible commercial bias, especially in free and ad-funded AI tools.</li>



<li>Build skills in emerging AI domains such as AI security, governance and robotics, where sudden demand might arise.</li>
</ul>



<h3 class="wp-block-heading">Strategies for companies</h3>



<ul class="wp-block-list">
<li>Stop competing on AI models and focus on proprietary training, user experience and deep integration with your organization’s ecosystem.</li>



<li>Identify and leverage AI to automate execution-heavy back-office tasks so that the team can work on higher value outcomes.</li>



<li>Create your intelligence ecosystem to rightly balance fragmented AI adoption and portability to avoid vendor lock-in.</li>



<li>Prepare marketing strategies to include AI platform optimization for potential sponsored discovery models.</li>



<li>Invest early in AI robotics as a future service line and operational differentiator in your industry.</li>



<li>Establish AI service, governance and ethics practices as part of your security team. </li>
</ul>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit]]></title>
<description><![CDATA[Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom. Active since 2009, the group is known for its targeted espionage campaigns primarily impacting organizations across Southeast Asia and more recently Central Am...]]></description>
<link>https://tsecurity.de/de/3248725/it-security-nachrichten/the-chrysalis-backdoor-a-deep-dive-into-lotus-blossoms-toolkit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3248725/it-security-nachrichten/the-chrysalis-backdoor-a-deep-dive-into-lotus-blossoms-toolkit/</guid>
<pubDate>Mon, 02 Feb 2026 17:05:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom. Active since 2009, the group is known for its targeted espionage campaigns primarily impacting organizations across Southeast Asia and more recently Central America, focusing on government, telecom, aviation, critical infrastructure, and media sectors.</span></p><p><span>Our investigation identified a security incident stemming from a sophisticated compromise of the infrastructure hosting Notepad++, which was subsequently used to deliver a previously undocumented custom backdoor</span><span>, which we have dubbed </span><span><span data-type="inlineCode">Chrysalis</span></span><span>.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt78d5255e4bec3077/6980bb18831fe853231a96c6/lotus-blossom-telemetry.jpg" alt="lotus-blossom-telemetry.jpg" caption="Figure 1: Telemetry on the custom backdoor samples" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-telemetry.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt78d5255e4bec3077/6980bb18831fe853231a96c6/lotus-blossom-telemetry.jpg" data-sys-asset-uid="blt78d5255e4bec3077" data-sys-asset-filename="lotus-blossom-telemetry.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 1: Telemetry on the custom backdoor samples" data-sys-asset-alt="lotus-blossom-telemetry.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Telemetry on the custom backdoor samples</figcaption></div></figure><p>⠀</p><p><span>Beyond the discovery of the new implant, forensic evidence led us to uncover several custom loaders in the wild. One sample, </span><span><em>“ConsoleApplication2.exe”</em></span><span>, stands out for its use of Microsoft Warbird, a complex code protection framework, to hide shellcode execution. This blog provides a deep technical analysis of Chrysalis, the Warbird loader, and the broader tactic of mixing straightforward loaders with obscure, undocumented system calls.</span></p><h2>Initial access vector</h2><p>Forensic analysis conducted by the MDR team suggests that the initial access vector aligns with publicly disclosed abuse of the Notepad++ distribution infrastructure. While <a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/"><span>reporting</span></a> references both plugin replacement and updater-related mechanisms, no definitive artifacts were identified to confirm exploitation of either. The only confirmed behavior is that execution of <em>“notepad++.exe”</em>  and subsequently <em>“GUP.exe”</em> preceded the execution of a suspicious process <em>“update.exe”</em> which was downloaded from 95.179.213.0.</p><h2>Analysis of update.exe</h2><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4fbd1b5b4e1bd25/6980bb9d090b8315c274c37c/lotus-blossom-execution-diagram-of-update-exe.png" alt="lotus-blossom-execution-diagram-of-update-exe.png" caption="Figure 2: Execution diagram of update.exe" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4fbd1b5b4e1bd25/6980bb9d090b8315c274c37c/lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-uid="bltd4fbd1b5b4e1bd25" data-sys-asset-filename="lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Execution diagram of update.exe" data-sys-asset-alt="lotus-blossom-execution-diagram-of-update-exe.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Execution diagram of update.exe</figcaption></div></figure><p>⠀</p><p><span>Analysis of</span><span><em> “update.exe”</em></span><span> shows the file is actually an NSIS installer, a tool commonly used  by </span><a href="https://www.rapid7.com/blog/post/2025/05/22/nsis-abuse-and-srdi-shellcode-anatomy-of-the-winos-4-0-campaign/"><span>Chinese APT</span></a><span> to deliver initial payload.</span></p><p><span>The following (Table 1) are the extracted NSIS installer files:</span></p><table><colgroup data-width="750"><col><col><col></colgroup><tbody><tr><td><p><span><strong>File name</strong></span></p></td><td><p><span><strong>Description</strong></span></p></td><td><p><span><strong>SHA-256 </strong></span></p></td></tr><tr><td><p><span>[NSIS].nsi</span></p></td><td><p><span>NSIS </span><span>Installation script</span></p></td><td><p><span>8ea8b83645fba6e23d48075a0d3fc73ad2ba515b4536710cda4f1f232718f53e</span></p></td></tr><tr><td><p><span>BluetoothService.exe</span></p></td><td><p><span>Renamed Bitdefender Submission Wizard used for DLL sideloading</span></p></td><td><p><span>2da00de67720f5f13b17e9d985fe70f10f153da60c9ab1086fe58f069a156924</span></p></td></tr><tr><td><p><span>BluetoothService</span></p></td><td><p><span>Encrypted shellcode</span></p><p></p></td><td><p><span>77bfea78def679aa1117f569a35e8fd1542df21f7e00e27f192c907e61d63a2e</span></p></td></tr><tr><td><p><span>log.dll</span></p></td><td><p><span>Malicious DLL sideloaded by BluetoothService.exe</span></p></td><td><p><span>3bdc4c0637591533f1d4198a72a33426c01f69bd2e15ceee547866f65e26b7ad</span></p></td></tr></tbody></table><p>⠀</p><p><span>Installation script is instructed to create a new directory </span><span><em>“Bluetooth”</em></span><span><strong> </strong></span><span>in </span><span><em>“%AppData%”</em></span><span><strong> </strong></span><span>folder, copy the remaining files there, change the attribute of the directory to </span><span><span data-type="inlineCode"><strong>HIDDEN</strong></span></span><span><strong> </strong></span><span>and execute </span><span><span data-type="inlineCode"><em>BluetoothService.exe</em></span></span><span><em>.</em></span></p><h3>DLL sideloading</h3><p><span>Shortly after the execution of </span><span><span data-type="inlineCode"><em>BluetoothService.exe</em></span></span><span><em> </em></span><span>which is actually a renamed legitimate </span><span><span data-type="inlineCode"><em>Bitdefender Submission Wizard</em></span></span><span> that was abused for </span><span><span data-type="inlineCode"><strong>DLL sideloading</strong></span></span><span>, where a malicious </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span> was placed alongside the executable, causing it to be loaded instead of the legitimate library. Two exported functions from </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span> are called by </span><span><span data-type="inlineCode"><em>Bitdefender Submission Wizard</em></span></span><span>: </span><span><span data-type="inlineCode"><strong>LogInit</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>LogWrite</strong></span></span><span>.</span></p><h3>LogInit and LogWrite - Shellcode load, decrypt, execute</h3><p><span><span data-type="inlineCode"><strong>LogInit</strong></span></span><span><strong>  </strong></span><span>just loads </span><span><span data-type="inlineCode"><em>BluetoothService</em></span></span><span><em> </em></span><span>into the memory of the running process.</span></p><p><span><span data-type="inlineCode"><strong>LogWrite</strong></span></span><span><strong> </strong></span><span>has a more sophisticated goal – to decrypt and execute the shellcode.</span></p><p><span>The decryption routine implements a custom runtime decryption mechanism used to unpack encrypted data in memory. It derives key material from previously calculated hash value and applies a stream‑cipher–like algorithm rather than standard cryptographic APIs. At a high level, the decryption routine relies on a linear congruential generator, with the standard constants </span><span><span data-type="inlineCode"><strong>0x19660D</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>0x3C6EF35F</strong></span></span><span>, combined with several basic data transformation steps to recover the plaintext payload.</span></p><p><span>Once decrypted, the payload replaces the original buffer and all temporary memory is released. Execution is then transferred to this newly decrypted stage, which is treated as executable code and invoked with a predefined set of arguments, including runtime context and resolved API information.</span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt17e6d0b98986647a/6980bcf7c302595bc9cb786f/lotus-blossom-LogWrite-internals.png" alt="lotus-blossom-LogWrite-internals.png" caption="Figure 3: LogWrite internals" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-LogWrite-internals.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt17e6d0b98986647a/6980bcf7c302595bc9cb786f/lotus-blossom-LogWrite-internals.png" data-sys-asset-uid="blt17e6d0b98986647a" data-sys-asset-filename="lotus-blossom-LogWrite-internals.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: LogWrite internals" data-sys-asset-alt="lotus-blossom-LogWrite-internals.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: LogWrite internals</figcaption></div></figure><h3>IAT resolution</h3><p><span><span data-type="inlineCode"><strong>Log.dll</strong></span></span><span><strong> </strong></span><span>implements an API hashing subroutine to resolve required APIs during execution, reducing the likelihood of detection by antivirus and other security solutions.</span></p><h3>API hashing subroutine</h3><p><span>The hashing algorithm will hash export names using </span><span><span data-type="inlineCode"><strong>FNV‑1a</strong></span></span><span><strong> </strong></span><span>(fnv-1a hash 0x811C9DC5, fnv-1a prime 0x1000193 observed), then apply a </span><span><span data-type="inlineCode"><strong>MurmurHash‑style avalanche finalizer</strong></span></span><span><strong> </strong></span><span>(murmur constant 0x85EBCA6B observed), and comparing the result to a salted target hash.</span></p><h2>Analysis of the Chrysalis backdoor</h2><p><span>The shellcode, once decrypted by </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span><em>,</em></span><span> is a custom, feature-rich backdoor we've named “</span><span><em>Chrysalis</em></span><span>”. Its wide array of capabilities indicates it is a sophisticated and permanent tool, not a simple throwaway utility. It uses legitimate binaries to sideload a crafted DLL with a generic name, which makes simple filename-based detection unreliable. It relies on custom API hashing in both the loader and the main module, each with its own resolution logic. This is paired with layered obfuscation and a fairly structured approach to C2 communication. Overall, the sample looks like something that has been actively developed over time, and we’ll be keeping an eye on this family and any future variants that show up.</span></p><h3>Decryption of the main module</h3><p><span>Once the execution is passed to decrypted shellcode from </span><span><span data-type="inlineCode"><em>log.dll</em></span></span><span><em>,</em></span><span> malware starts with decryption of the main module via a simple combination of XOR, addition and subtraction operations, with a hardcoded key </span><span><span data-type="inlineCode"><strong>gQ2JR&amp;9;</strong></span></span><span>. See below the p</span>seudocode of decryption routine:</p><p>⠀</p><pre language="cpp">char XORKey[8] = "gQ2JR&amp;9;";
DWORD counter = 0;
DWORD pos = BufferPosition;

while (counter &lt; size) {
    BYTE k = XORKey[counter &amp; 7];
    BYTE x = encrypted[pos];

    x = x + k;
    x = x ^ k;
    x = x - k;

    decrypted[pos] = x;

    pos++;
    counter++;
}</pre><p>⠀</p><p><span>XOR operation is performed 5 times in total, suggesting a section layout similar to PE format. Following the decryption, malware will proceed to yet another dynamic IAT resolution using </span><span><span data-type="inlineCode"><strong>LoadLibraryA</strong></span></span><span><strong> </strong></span><span>to acquire a handle to </span><span><span data-type="inlineCode"><strong>Kernel32.dll</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>GetProcAddress</strong></span></span><span>. Once exports are resolved, the jump is taken to the main module.</span></p><h3>Main module</h3><p><span>The decrypted module is a reflective </span><span><span data-type="inlineCode"><strong>PE-like</strong></span></span><span> module that executes the </span><span><span data-type="inlineCode"><strong>MSVC CRT</strong></span></span><span><strong> </strong></span><span>initialization sequence before transferring control to the program’s main entry point. Once in the Main function, the malware will dynamically load DLLs in the following order : </span><span><span data-type="inlineCode"><strong>oleaut32.dll</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>advapi32.dll</strong></span></span><span>,  </span><span><span data-type="inlineCode"><strong>shlwapi.dll</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>user32.dll</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>wininet.dll</strong></span></span><span>,</span><span><strong> </strong></span><span><span data-type="inlineCode"><strong>ole32.dll</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>shell32.dll</strong></span></span><span>.</span></p><p><span>Names of targeted DLLs are constructed on the run, using two separate subroutines. These two subroutines implement a custom, position-dependent character obfuscation scheme. Each character is transformed using a combination of bit rotations, conditional XOR operations, and index-based arithmetic, ensuring that identical characters encrypt differently depending on their position. The second routine reverses this process at runtime, reconstructing the original plaintext string just before it is used. The purpose of these two functions is not only to conceal strings, but also to intentionally complicate static analysis and hinder signature-based detection.</span></p><p><span>After the DLL name is reconstructed, the Main module implements another, more sophisticated API hashing routine.</span></p><h3>API hashing subroutine</h3><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt47a4d3aa70f2644b/6980beba4551a4a087ba56d2/lotus-blossom-API-hashing-diagram.jpg" alt="lotus-blossom-API-hashing-diagram.jpg" caption="Figure 4: API hashing diagram" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt47a4d3aa70f2644b/6980beba4551a4a087ba56d2/lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-uid="blt47a4d3aa70f2644b" data-sys-asset-filename="lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 4: API hashing diagram" data-sys-asset-alt="lotus-blossom-API-hashing-diagram.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: API hashing diagram</figcaption></div></figure><p>⠀</p><p><span>The first difference between this and the API hashing routine used by the loader is that this subroutine accepts only a single argument: the hash of the target API. To obtain the DLL handle, the malware walks the PEB to reach the </span><span><span data-type="inlineCode"><strong>InMemoryOrderModuleList</strong></span></span><span>, then parses each module’s export table, skipping the main executable, until it resolves the desired API. Instead of relying on common hashing algorithms, the routine employs multi-stage arithmetic mixing with constants of </span><span><span data-type="inlineCode"><strong>MurmurHash-style finalization</strong></span></span><span>. API names are processed in 4-byte blocks using multiple rotation and multiplication steps, followed by a final diffusion phase before comparison with the supplied hash. This design significantly complicates static recovery of resolved APIs and reduces the effectiveness of traditional signature-based detection. As a fallback, the resolver supports direct resolution via </span><span><span data-type="inlineCode"><strong>GetProcAddress</strong></span></span><span> if the target hash is not found through the hashing method. The pointer to </span><span><span data-type="inlineCode"><strong>GetProcAddress</strong></span></span><span> is obtained earlier during the “main module preparation” stage.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta01bac2b11922a6f/6980bf0473b29a313cc2cac2/lotus-blossom-API-hashing-internals.png" alt="lotus-blossom-API-hashing-internals.png" caption="Figure 5: API hashing internals " class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-API-hashing-internals.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta01bac2b11922a6f/6980bf0473b29a313cc2cac2/lotus-blossom-API-hashing-internals.png" data-sys-asset-uid="blta01bac2b11922a6f" data-sys-asset-filename="lotus-blossom-API-hashing-internals.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 5: API hashing internals" data-sys-asset-alt="lotus-blossom-API-hashing-internals.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5: API hashing internals</figcaption></div></figure><h3>Config decryption</h3><p><span>The next step in the malware’s execution is to decrypt the configuration. Encrypted configuration is stored in the </span><span><em>BluetoothService</em></span><span> file at offset 0x30808 with the size of 0x980. Algorithm for the decryption is </span><span><span data-type="inlineCode"><strong>RC4</strong></span></span><span><strong> </strong></span><span>with the key </span><span><span data-type="inlineCode"><strong>qwhvb^435h&amp;*7</strong></span></span><span>. This revealed the following information:</span></p><ul><li><span><span data-type="inlineCode"><strong>Command and Control (C2) url</strong></span></span><span>: </span><span><span data-type="inlineCode"><strong>https://api.skycloudcenter.com/a/chat/s/70521ddf-a2ef-4adf-9cf0-6d8e24aaa821</strong></span></span></li><li><span><span data-type="inlineCode"><strong>Name of the module</strong></span></span><span>: </span><span><span data-type="inlineCode"><strong>BluetoothService</strong></span></span></li><li><span><span data-type="inlineCode"><strong>User agent</strong></span></span><span>: </span><span><span data-type="inlineCode"><strong>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36</strong></span></span></li></ul><p><span>Decrypted configuration doesn’t give much useful information besides the C2. The name of the module is too generic and the user agent belongs to Google Chrome browser. The URL resolves to </span><span><span data-type="inlineCode"><strong>61.4.102.97</strong></span></span><span>, IP address based in</span><span><strong> </strong></span><span><span data-type="inlineCode"><strong>Malaysia</strong></span></span><span>. At the time of the writing of this blog, no other file has been seen to communicate with this IP and URL.</span></p><h4>Persistence and Command-Line Arguments</h4><p><span>To determine the next course of action, malware checks command line arguments highlighted in Table 1 and chooses one of four potential paths - if the amount of the command-line arguments is greater than two, the process will exit. If there is no additional argument, persistence is set up primarily via service creation or registry as a fall back mechanism.</span></p><p><span>See Table 2 below:</span></p><table><colgroup data-width="750"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Argument</strong></span></p></td><td><p><span><strong>Mode</strong></span></p></td><td><p><span><strong>Action</strong></span></p></td></tr><tr><td><p><span><strong>(None)</strong></span></p></td><td><p><span>Installation</span></p></td><td><p><span>Installs persistence (Service or Registry) pointing to binary with </span><span data-type="inlineCode">-i</span><span> flag, then terminates.</span></p></td></tr><tr><td><p><span data-type="inlineCode"><strong>-i</strong></span></p></td><td><p><span>Launcher</span></p></td><td><p><span>Spawns a new instance of itself with the </span><span data-type="inlineCode">-k</span><span> flag via </span><span data-type="inlineCode">ShellExecuteA</span><span>, then terminates.</span></p></td></tr><tr><td><p><span data-type="inlineCode"><strong>-k</strong></span></p></td><td><p><span>Payload</span></p></td><td><p><span>Skips installation checks and executes the main malicious logic (C2 &amp; Shellcode).</span></p></td></tr></tbody></table><p>⠀</p><p><span>With the expected arguments present, the malware proceeds to its primary functionality - to gather information about the infected asset and initiate the communication with C2.</span></p><h3>Information gathering and C2 communication</h3><p><span>A mutex </span><span><span data-type="inlineCode"><strong>Global\\Jdhfv_1.0.1 </strong></span></span><span>is registered to enforce single instance execution on the host. If it already exists, malware is terminated. If the check is clear, information gathering begins by querying for the following : current time, installed AVs, OS version, user name and computer name. Next, computer name, user name, OS version and string </span><span><span data-type="inlineCode"><strong>1.01</strong></span></span><span><strong> </strong></span><span>are concatenated and the data are hashed using </span><span><span data-type="inlineCode"><strong>FNV-1A</strong></span></span><span>. This value is later turned into its decimal ascii representation and used most likely as a unique identifier of the infected host. </span></p><p><span>Final buffer uses a dot as delimiter and follows this pattern: </span></p><p>⠀</p><pre language="cpp">&lt;UniqueID&gt;.&lt;ComputerName&gt;.&lt;UserName&gt;.&lt;OSVersion&gt;.&lt;127.0.0.1&gt;.&lt;AVs&gt;.&lt;DateAndTime&gt;</pre><p>⠀</p><p><span>The last piece of information added to the beginning of the buffer is a string </span><span><span data-type="inlineCode"><strong>4Q</strong></span></span><span>. The buffer is then </span><span><span data-type="inlineCode"><strong>RC4</strong></span></span><span> encrypted with the key </span><span><span data-type="inlineCode"><strong>vAuig34%^325hGV</strong></span></span><span>.</span></p><p><span>Following data encryption, the malware establishes an internet connection using previously mentioned user agent and C2 </span><span><strong>api.skycloudcenter.com </strong></span><span>over port </span><span><strong>443</strong></span><span>. Data is then transferred via </span><span><span data-type="inlineCode"><strong>HttpSendRequestA</strong></span></span><span><strong> </strong></span><span>using the </span><span><span data-type="inlineCode"><strong>POST</strong></span></span><span><strong> </strong></span><span>method. Response from the server is then read to a temporary buffer which is later decrypted using the same key </span><span><span data-type="inlineCode"><strong>vAuig34%^325hGV</strong></span></span><span>.</span></p><h4>Response and command processing</h4><p><span><em><strong>Note:</strong></em></span><span> C2  server was already offline during the initial analysis, preventing recovery of any network data. As a result, and due to the complexity of the malware, parts of the following analysis may contain minor inaccuracies.</span></p><p><span>The response from the C2 undergoes multiple checks before further processing. First, the HTTP response code is compared against the hardcoded value </span><span><span data-type="inlineCode"><strong>200</strong></span></span><span><strong> </strong></span><span>(0xC8),</span><span><strong> </strong></span><span>indicating a successful request, followed by a validation of the associated WinInet handle to ensure no error occurred. The malware then verifies the integrity of the received payload and execution proceeds only if at least one valid structure is detected. Next, malware looks into the response data for a small tag to determine what to do next. Tag is used as a condition for a switch statement with 16 possible cases. The default case will simply set up a flag to </span><span><span data-type="inlineCode"><strong>TRUE</strong></span></span><span>. Setting up this flag will result in completely jumping out of the switch. Other switch cases includes following options:</span></p><p>⠀</p><table><tbody><tr><td><p><span><strong>Char representation</strong></span></p></td><td><p><span><strong>Hex representation</strong></span></p></td><td><p><span><strong>Purpose</strong></span></p></td></tr><tr><td><p><span><strong>4T</strong></span></p></td><td><p><span><strong>0x3454</strong></span></p></td><td><p><span>Spawn interactive shell</span></p></td></tr><tr><td><p><span><strong>4U</strong></span></p></td><td><p><span><strong>0x3455</strong></span></p></td><td><p><span>Send ‘OK’ to C2</span></p></td></tr><tr><td><p><span><strong>4V</strong></span></p></td><td><p><span><strong>0x3456</strong></span></p></td><td><p><span>Create process</span></p></td></tr><tr><td><p><span><strong>4W</strong></span></p></td><td><p><span><strong>0x3457</strong></span></p></td><td><p><span>Write file to disk</span></p></td></tr><tr><td><p><span><strong>4X</strong></span></p></td><td><p><span><strong>0x3458</strong></span></p></td><td><p><span>Write chunk to open file</span></p></td></tr><tr><td><p><span><strong>4Y</strong></span></p></td><td><p><span><strong>0x3459</strong></span></p></td><td><p><span>Read &amp; send data</span></p></td></tr><tr><td><p><span><strong>4Z</strong></span></p></td><td><p><span><strong>0x345A</strong></span></p></td><td><p><span>Break from switch</span></p></td></tr><tr><td><p><span><strong>4\\</strong></span></p></td><td><p><span><strong>0x345C</strong></span></p></td><td><p><span>Uninstall / Clean up</span></p></td></tr><tr><td><p><span><strong>4]</strong></span></p></td><td><p><span><strong>0x345D</strong></span></p></td><td><p><span>Sleep</span></p></td></tr><tr><td><p><span><strong>4_</strong></span></p></td><td><p><span><strong>0x345F</strong></span></p></td><td><p><span>Get info about logical drives</span></p></td></tr><tr><td><p><span><strong>4`</strong></span></p></td><td><p><span><strong>0x3460</strong></span></p></td><td><p><span>Enumerate files information</span></p></td></tr><tr><td><p><span><strong>4a</strong></span></p></td><td><p><span><strong>0x3661</strong></span></p></td><td><p><span>Delete file </span></p></td></tr><tr><td><p><span><strong>4b</strong></span></p></td><td><p><span><strong>0x3662</strong></span></p></td><td><p><span>Create directory</span></p></td></tr><tr><td><p><span><strong>4c</strong></span></p></td><td><p><span><strong>0x3463</strong></span></p></td><td><p><span>Get file from C2</span></p></td></tr><tr><td><p><span><strong>4d</strong></span></p></td><td><p><span><strong>0x3464</strong></span></p></td><td><p><span>Send file to C2</span></p></td></tr></tbody></table><p>⠀</p><p><span><span data-type="inlineCode"><strong>4T</strong></span></span><span> - The malware implements a fully interactive </span><span><span data-type="inlineCode"><strong>cmd.exe reverse shell</strong></span></span><span> using redirected pipes. Incoming commands from the C2 are converted from </span><span><span data-type="inlineCode"><strong>UTF‑8</strong></span></span><span> to the system </span><span><span data-type="inlineCode"><strong>OEM</strong></span></span><span> code page before being written to the shell’s standard input, while a dedicated thread continuously reads shell output, converts it from OEM encoding to UTF‑8 using </span><span><span data-type="inlineCode"><strong>GetOEMCP</strong></span></span><span> API, and forwards the result back to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4V</strong></span></span><span><strong> </strong></span><span>- This option allows remote process execution by invoking </span><span><span data-type="inlineCode"><strong>CreateProcessW</strong></span></span><span> on a C2-supplied command line and relaying execution status back to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4W</strong></span></span><span><strong> </strong></span><span>- This option implements a remote file write capability, parsing a structured response containing a destination path and file contents, converting encodings as necessary, </span><span><span data-type="inlineCode"><strong>writing the data to disk</strong></span></span><span>, and </span><span><span data-type="inlineCode"><strong>returning a formatted status message</strong></span></span><span> to the command-and-control server.</span></p><p><span><span data-type="inlineCode"><strong>4X</strong></span></span><span><strong> </strong></span><span>- Similar to the previous switch, it supports a remote file-write capability, allowing the C2 to drop arbitrary files on the victim system by supplying a </span><span><span data-type="inlineCode"><strong>UTF-8 filename and associated data blob</strong></span></span><span>.</span></p><p><span><span data-type="inlineCode"><strong>4Y</strong></span></span><span> - Switch implements a remote file-read capability. It opens a specified file with, retrieves its size, reads the entire contents into memory, and </span><span><span data-type="inlineCode"><strong>transmits the data back to the C2</strong></span></span><span>. </span></p><p><span><span data-type="inlineCode"><strong>4\\</strong></span></span><span><strong> </strong></span><span>- The option implements a full </span><span><span data-type="inlineCode"><strong>self-removal mechanism</strong></span></span><span>. It deletes auxiliary payload files, removes persistence artifacts from both the </span><span><span data-type="inlineCode"><strong>Windows Service registry hive</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>the Run key</strong></span></span><span>, generates and executes a temporary batch file </span><span><span data-type="inlineCode"><strong>u.bat</strong></span></span><span><strong> </strong></span><span>to delete the running executable after termination, and finally removes the batch script itself. </span></p><p><span><span data-type="inlineCode"><strong>4_</strong></span></span><span><strong> </strong></span><span>- Here malware enumerates information about logical drivers using </span><span><span data-type="inlineCode"><strong>GetLogicalDriveStringsA</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>GetDriveTypeA</strong></span></span><span><strong> </strong></span><span>APIs and sends the information back to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4`</strong></span></span><span><strong> </strong></span><span>- This switch option shares similarities with previously analyzed data exfiltration function - </span><span><span data-type="inlineCode"><strong>4Y</strong></span></span><span>. However, its primary purpose differs. Instead of transmitting preexisting data, it </span><span><span data-type="inlineCode"><strong>enumerates files</strong></span></span><span> within a specified directory, </span><span><span data-type="inlineCode"><strong>collects per-file metadata</strong></span></span><span> (timestamps, size, and filename), serializes the results into a custom buffer format, and sends the aggregated listing to the C2.</span></p><p><span><span data-type="inlineCode"><strong>4a - 4b - 4c - 4d</strong></span></span><span><strong> </strong></span><span>- In the last 4 cases, malware implements a custom file transfer protocol over its C2 channel. Commands </span><span><span data-type="inlineCode"><strong>4a</strong></span></span><span> and </span><span><span data-type="inlineCode"><strong>4b</strong></span></span><span> act as control messages used to initialize file </span><span><span data-type="inlineCode"><strong>download</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>upload operations</strong></span></span><span> respectively, including file paths, offsets, and size validation. Once initialized, the actual data transfer occurs in a chunked fashion using commands </span><span><span data-type="inlineCode"><strong>4c (download)</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>4d (upload)</strong></span></span><span><strong>.</strong></span><span> Each chunk is wrapped in a fixed-size 40-byte response structure, validated for successful HTTP status and correct structure count before processing. Transfers continue until the C2 signals completion via a non-zero termination flag, at which point file handles and buffers are released.</span></p><h3>Additional artifacts discovered on the infected host</h3><p><span>During the initial forensics analysis of the affected asset, Rapid7’s MDR team observed execution of following command:</span></p><p>⠀</p><pre language="cpp">C:\ProgramData\USOShared\svchost.exe-nostdlib -run
C:\ProgramData\USOShared\conf.c</pre><p>⠀</p><p><span>The retrieved folder </span><span><em>“USOShared”</em></span><span><strong> </strong></span><span>from the infected asset didn’t contain svchost.exe but it contained </span><span><em>“libtcc.dll” </em></span><span>and </span><span><em>“conf.c”</em></span><span>. The hash of the binary didn’t match any known legitimate version but the command line arguments and associated </span><span><em>“libtcc.dll”</em></span><span> suggested that svchost.exe is in fact renamed </span><a href="https://github.com/phoenixthrush/Tiny-C-Compiler"><span>Tiny-C-Compiler</span></a><span>. To confirm this, we replicated the steps of the attacker successfully loaded </span><span><span data-type="inlineCode"><strong>shellcode</strong></span></span><span> from </span><span><em>“conf.c” </em></span><span>into the memory of </span><span><em>“tcc.exe”</em></span><span>, confirming our previous hypothesis.  </span><span><strong> </strong></span></p><h4><strong>Analysis of conf.c</strong></h4><p><span>The C source file contains a fixed size (836) char buffer containing shellcode bytes which is later casted to a function pointer and invoked. The shellcode is consistent with 32-bit version of </span><a href="https://github.com/rapid7/metasploit-framework/blob/master/external/source/shellcode/windows/x86/src/block/block_api.asm"><span>Metasploit’s block API.</span></a></p><p><span>The shellcode loads </span><span><span data-type="inlineCode"><strong>Wininet.dll</strong></span></span><span> using </span><span><span data-type="inlineCode"><strong>LoadLibraryA</strong></span></span><span>, resolves Internet-related APIs such as </span><span><span data-type="inlineCode"><strong>InternetConnectA</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>HttpSendRequestA</strong></span></span><span>, and downloads a file from </span><span><span data-type="inlineCode"><strong>api.wiresguard.com/users/admin</strong></span></span><span>. The file is read into a newly allocated and execution is then transferred to the start of the 2000-byte second-stage shellcode. </span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7e5771a2056ea7bb/6980c2dca49b287b588e2770/lotus-blossom-hellcode-decryption-stub.png" alt="lotus-blossom-hellcode-decryption-stub.png" caption="Figure 6: Shellcode decryption stub" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7e5771a2056ea7bb/6980c2dca49b287b588e2770/lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-uid="blt7e5771a2056ea7bb" data-sys-asset-filename="lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 6: Shellcode decryption stub" data-sys-asset-alt="lotus-blossom-hellcode-decryption-stub.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6: Shellcode decryption stub</figcaption></div></figure><p>⠀</p><p><span>This stub is responsible for decrypting the next payload layer and transferring execution to it. It uses a </span><span><span data-type="inlineCode"><strong>rolling XOR-based</strong></span></span><span><strong> </strong></span><span>decryption loop before jumping directly to the decrypted code.</span></p><p><span>A quick look into the decrypted buffer revealed an interesting blob with a repeated string </span><span><span data-type="inlineCode"><strong>CRAZY</strong></span></span><span>, hinting additional XORed layer, later confirmed by a quick test.  </span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltfba70f268e1aa776/6980c33229b277724c63dd5f/lotus-blossom-repeated-XOR-key-CRAZY.png" alt="lotus-blossom-repeated-XOR-key-CRAZY.png" caption="Figure 7: Repeated XOR key “CRAZY”" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltfba70f268e1aa776/6980c33229b277724c63dd5f/lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-uid="bltfba70f268e1aa776" data-sys-asset-filename="lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 7: Repeated XOR key “CRAZY”" data-sys-asset-alt="lotus-blossom-repeated-XOR-key-CRAZY.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 7: Repeated XOR key “CRAZY”</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7fdc600725c456fa/6980c35fe313c672d8909c1a/lotus-blossom-decrypted-configuration.png" alt="lotus-blossom-decrypted-configuration.png" caption="Figure 8: Decrypted configuration" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-decrypted-configuration.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7fdc600725c456fa/6980c35fe313c672d8909c1a/lotus-blossom-decrypted-configuration.png" data-sys-asset-uid="blt7fdc600725c456fa" data-sys-asset-filename="lotus-blossom-decrypted-configuration.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Decrypted configuration" data-sys-asset-alt="lotus-blossom-decrypted-configuration.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8: Decrypted configuration</figcaption></div></figure><p>⠀</p><p><span>Parsing of the decrypted configuration data confirms that retrieved shellcode is </span><span><span data-type="inlineCode"><strong>Cobalt Strike (CS) HTTPS beacon</strong></span></span><span><strong> </strong></span><span>with http-get </span><span><span data-type="inlineCode"><strong>api.wiresguard.com/update/v1</strong></span></span><span><strong> </strong></span><span>and http-post </span><span><span data-type="inlineCode"><strong>api.wiresguard.com/api/FileUpload/submit</strong></span></span><span> urls.</span></p><p><span>Analysis of the initial evidence revealed a consistent execution chain: a loader embedding </span><span><span data-type="inlineCode"><strong>Metasploit block_api</strong></span></span><span> shellcode that downloads a </span><span><span data-type="inlineCode"><strong>Cobalt Strike beacon</strong></span></span><span>. The unique decryption stub and configuration XOR key </span><span><span data-type="inlineCode"><strong>CRAZY</strong></span></span><span> allowed us to pivot into an external hunt, uncovering additional loader variants.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt989ba6e7f4c51324/6980c3e773b29add1cc2cb00/lotus-blossom-Execution-flow.png" alt="lotus-blossom-Execution-flow.png" caption="Figure 9: Execution flow followed by conf.c and other loaders" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-Execution-flow.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt989ba6e7f4c51324/6980c3e773b29add1cc2cb00/lotus-blossom-Execution-flow.png" data-sys-asset-uid="blt989ba6e7f4c51324" data-sys-asset-filename="lotus-blossom-Execution-flow.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Execution flow followed by conf.c and other loaders" data-sys-asset-alt="lotus-blossom-Execution-flow.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9: Execution flow followed by conf.c and other loaders</figcaption></div></figure><h4>Variation of loaders and shellcode</h4><p><span>In the last year, four similar files were uploaded to public repositories.</span></p><p>⠀</p><table><tbody><tr><td><p><br></p></td><td><p><span><strong>Loader 1</strong></span></p></td><td><p><span><strong>Loader 2</strong></span></p></td><td><p><span><strong>Loader 3</strong></span></p></td><td><p><span><strong>Loader 4 </strong></span></p></td></tr><tr><td><p><span><strong>Loader </strong></span></p><p><span><strong>SHA-256</strong></span></p></td><td><p><span>0a9b8df968df41920b6ff07785cbfebe8bda29e6b512c94a3b2a83d10014d2fd</span></p></td><td><p><span>e7cd605568c38bd6e0aba31045e1633205d0598c607a855e2e1bca4cca1c6eda</span></p></td><td><p><span>b4169a831292e245ebdffedd5820584d73b129411546e7d3eccf4663d5fc5be3</span></p></td><td><p><span>fcc2765305bcd213b7558025b2039df2265c3e0b6401e4833123c461df2de51a</span></p></td></tr><tr><td><p><span><strong>Shellcode SHA-256</strong></span></p></td><td><p><span>4c2ea8193f4a5db63b897a2d3ce127cc5d89687f380b97a1d91e0c8db542e4f8</span></p></td><td><p><span>078a9e5c6c787e5532a7e728720cbafee9021bfec4a30e3c2be110748d7c43c5</span></p></td><td><p><span>7add554a98d3a99b319f2127688356c1283ed073a084805f14e33b4f6a6126fd</span></p></td><td><p><span>7add554a98d3a99b319f2127688356c1283ed073a084805f14e33b4f6a6126fd</span></p></td></tr><tr><td><p><span><strong>User Agent</strong></span></p></td><td><p><span>Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4472.114 Safari/537.36</span></p><p></p></td><td><p><span>Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4472.114 Safari/537.36</span></p><p></p></td><td><p><span> Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36</span></p><p></p></td><td><p><span> Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36</span></p></td></tr><tr><td><p><span><strong>URL hosting CS beacon</strong></span></p></td><td><p><span>http://59.110.7.32:8880/uffhxpSy</span></p></td><td><p><span>http://124.222.137.114:9999/3yZR31VK</span></p></td><td><p><span>https://api.wiresguard.com/users/system</span></p></td><td><p><span>https://api.wiresguard.com/users/system</span></p></td></tr><tr><td><p><span><strong>CS http-get URL</strong></span></p></td><td><p><span>http:// 59.110.7.32:8880/api/getBasicInfo/v1</span></p></td><td><p><span>http://124.222.137.114:9999/api/updateStatus/v1</span></p></td><td><p><span>https://api.wiresguard.com/api/getInfo/v1</span></p></td><td><p><span>https://api.wiresguard.com/api/getInfo/v1</span></p></td></tr><tr><td><p><span><strong>CS http-post URL</strong></span></p></td><td><p><span>http:// 59.110.7.32:8880/api/Metadata/submit</span></p></td><td><p><span>http://124.222.137.114:9999/api/Info/submit</span></p></td><td><p><span>https://api.wiresguard.com/api/Info/submit</span></p></td><td><p><span>https://api.wiresguard.com/api/Info/submit</span></p></td></tr></tbody></table><p>⠀</p><p><span>From all the loaders we analyzed, </span><span><span data-type="inlineCode"><strong>Loader 3</strong></span></span><span><strong> </strong></span><span>piqued our interest for three reasons - shellcode </span><span><span data-type="inlineCode"><strong>encryption</strong></span></span><span> technique, </span><span><span data-type="inlineCode"><strong>execution</strong></span></span><span><strong> </strong></span><span>and </span><span><span data-type="inlineCode"><strong>almost identical C2</strong></span></span><span><strong> </strong></span><span>to beacon that was found on the infected asset . All the previous samples used a pretty common technique to execute the shellcode - decrypt embedded shellcode in user space, change the protection of memory region  to executable state and invoke decrypted code via </span><span><span data-type="inlineCode"><strong>CreateThread</strong></span></span><span><strong> </strong></span><span>/ </span><span><span data-type="inlineCode"><strong>CreateRemoteThread</strong></span></span><span>, Loader 3 (original name </span><span><em>“ConsoleApplication2.exe”</em></span><span>) violates this approach. </span></p><h4>Analysis of Loader 3 - ConsoleApplication2.exe </h4><p><span>At the first glance, the logic of the sample is straightforward Load the DLL </span><span><span data-type="inlineCode"><strong>clipc.dll</strong></span></span><span>, overwrite first 0x490 bytes, change the protection to </span><span><span data-type="inlineCode"><strong>PAGE_EXECUTE_READ</strong></span></span><span> (0x20), and then invoke </span><span><span data-type="inlineCode"><strong>NtQuerySystemInformation</strong></span></span><span><strong>. </strong></span><span>Two interesting notes to highlight here - bytes copied into the memory region of clipc.dll are not valid shellcode and </span><span><span data-type="inlineCode"><strong>NtquerySystemInformation</strong></span></span><span> is used to “</span><a href="https://learn.microsoft.com/en-us/windows/win32/api/winternl/nf-winternl-ntquerysysteminformation"><span>Retrieve the specified system information</span></a><span>”, not to execute code.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad7ccddfd03069d8/6980c4cca05d7d5b4d9ac74d/lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" alt="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" caption="Figure 10: Snippet from ConsoleApplication2.exe" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltad7ccddfd03069d8/6980c4cca05d7d5b4d9ac74d/lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-uid="bltad7ccddfd03069d8" data-sys-asset-filename="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: Snippet from ConsoleApplication2.exe" data-sys-asset-alt="lotus-blossom-Snippet-from-ConsoleApplication2-exe.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10: Snippet from ConsoleApplication2.exe</figcaption></div></figure><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5dfccfc7e3596d19/6980c4cccaf3ac7371ce0c06/lotus-blossom-data-copied-clipc-dll.png" alt="lotus-blossom-data-copied-clipc-dll.png" caption="Figure 11: Data copied into clipc.dll" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5dfccfc7e3596d19/6980c4cccaf3ac7371ce0c06/lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-uid="blt5dfccfc7e3596d19" data-sys-asset-filename="lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 11: Data copied into clipc.dll" data-sys-asset-alt="lotus-blossom-data-copied-clipc-dll.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 11: Data copied into clipc.dll</figcaption></div></figure><p>⠀</p><p><span>According to the official documentation, the first parameter of NtQuerySystemInformation is of type </span><span><span data-type="inlineCode"><strong>SYSTEM_INFORMATION_CLASS</strong></span></span><span><strong> </strong></span><span>which specifies the category of system information to be queried.  During static analysis in </span><span><strong>IDA Pro</strong></span><span>, this parameter was initially identified as </span><span><span data-type="inlineCode"><strong>SystemExtendedProcessInformation|0x80</strong></span></span><span><strong> </strong></span><span>but looking for this value in MSDN and other public references didn’t provide any explanation on how the execution was achieved. But, searching for the original value passed to the function </span><span><span data-type="inlineCode"><strong>(0xB9)</strong></span></span><span><strong> </strong></span><span>uncovered something interesting. The following </span><a href="https://downwithup.github.io/blog/post/2023/04/23/post9.html"><span>blog</span></a><span> by DownWithUp covers Microsoft Warbird, which could be described as an internal </span><a href="https://cirosec.de/en/news/abusing-microsoft-warbird-for-shellcode-execution/"><span>code protection and obfuscation framework </span></a><span><strong>. </strong></span><span>These resources confirm IDA misinterpretation of the argument which should be </span><span><span data-type="inlineCode"><strong>SystemCodeFlowTransition</strong></span></span><span>, a necessary argument to invoke Warbird functionality. Additionally, DownWithUp’s blog post mentioned the possible operations:</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc3eb7e9c08aca2f0/6980c55fef7b8950faaca1b2/lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" alt="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" caption="Figure 12: Warbird operations documented by DownWithUp" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc3eb7e9c08aca2f0/6980c55fef7b8950faaca1b2/lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-uid="bltc3eb7e9c08aca2f0" data-sys-asset-filename="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: Warbird operations documented by DownWithUp" data-sys-asset-alt="lotus-blossom-Warbird-operations-documented-by-DownWithUp.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 12: Warbird operations documented by DownWithUp</figcaption></div></figure><p>⠀</p><p><span>Referring to the snippet we saw  from </span><span><em>“ConsoleApplication2.exe”</em></span><span>, the operation is equal to </span><span><span data-type="inlineCode"><strong>WbHeapExecuteCall</strong></span></span><span><strong> </strong></span><span>which gives us the answer on how the shellcode gained execution. Thanks to work of other researchers, we also know that this technique only works if the code resides inside of memory of Microsoft signed binary, thus revealing why </span><span><span data-type="inlineCode"><strong>clipc.dll</strong></span></span><span><strong> </strong></span><span>has been used.</span><span><strong> </strong></span><span>The blog post from </span><span><span data-type="inlineCode"><strong>cirosec</strong></span></span><span><strong> </strong></span><span>also contains a link for their </span><a href="https://github.com/cirosec/warbird-demos/blob/main/Loader/Loader.cpp"><span>POC</span></a><span> of this technique which is almost the same replica of </span><span><em>“ConsoleApplication2.exe”</em></span><span>, hinting that author of </span><span><em>“ConsoleApplication2.exe”</em></span><span> simply copied it and modified to execute </span><span><span data-type="inlineCode"><strong>Metasploit block_api</strong></span></span><span> shellcode instead of the benign calc from POC. The comparison of the Cobalt Strike beacon configuration delivered via </span><span><em><strong>“</strong></em></span><span><em>conf.c</em></span><span><em><strong>”</strong></em></span><span><em> </em></span><span>and </span><span><em>“ConsoleApplication2.exe”</em></span><span> revealed shared trades between these two, most notably </span><span><span data-type="inlineCode"><strong>domain</strong></span></span><span>, </span><span><span data-type="inlineCode"><strong>public key</strong></span></span><span><strong>,</strong></span><span> and </span><span><span data-type="inlineCode"><strong>process injection technique</strong></span></span><span>.</span></p><h2>Attribution</h2><p><span>Attribution is primarily based on strong similarities between the initial loader observed in this intrusion and previously published </span><a href="https://sed-cms.broadcom.com/system/files/threat-hunter-whitepaper/2025-04/2025_04_ChinaLinked_Espionage_Actors.pdf"><span>Symantec</span></a><span> research. Particularly the use of a renamed </span><span><em>“Bitdefender Submission Wizard”</em></span><span> to side-load </span><span><em>“log.dll”</em></span><span> for decrypting and executing an additional payload.</span><br><span>In addition, similarities of the execution chain of </span><span><em>“conf.c”</em></span><span> retrieved from the infected asset and other loaders that we found, supported by the same </span><span><span data-type="inlineCode"><strong>public key</strong></span></span><span> extracted from CS beacons delivered through </span><span><em>“conf.c”</em></span><span> and </span><span><em>“ConsoleApplication2.exe”</em></span><span> suggests with moderate confidence, that the threat actor behind this campaign is likely Lotus Blossom.</span></p><h2>Conclusion</h2><p>The discovery of the <span data-type="inlineCode">Chrysalis</span> backdoor and the <span data-type="inlineCode">Warbird</span> loader highlights an evolution in Billbug’s capabilities. While the group continues to rely on proven techniques like DLL sideloading and service persistence, their multi layered shellcode loader and integration of undocumented system calls (NtQuerySystemInformation) marks a clear shift toward more resilient and stealth tradecraft.</p><p>What stands out is the mix of tools: the deployment of custom malware (Chrysalis) alongside commodity frameworks like Metasploit and Cobalt Strike, together with the rapid adaptation of public research (specifically the abuse of Microsoft Warbird). This demonstrates that Billbug is actively updating their playbook to stay ahead of modern detection.</p><h2>Rapid7 Customers</h2><h3>Intelligence Hub</h3><p><span>Customers using Rapid7’s Intelligence Hub gain direct access to Chrysalis backdoor, Metasploit loaders and Cobalt Strike IOCs, including any future indicators as they are identified.</span></p><h2>Indicators of compromise (IoCs)</h2><h3>File indicators</h3><table><tbody><tr><td><p>update.exe</p></td><td><p>a511be5164dc1122fb5a7daa3eef9467e43d8458425b15a640235796006590c9</p></td></tr><tr><td><p>[NSIS.nsi]</p></td><td><p>8ea8b83645fba6e23d48075a0d3fc73ad2ba515b4536710cda4f1f232718f53e</p></td></tr><tr><td><p>BluetoothService.exe</p></td><td><p>2da00de67720f5f13b17e9d985fe70f10f153da60c9ab1086fe58f069a156924</p></td></tr><tr><td><p>BluetoothService</p></td><td><p>77bfea78def679aa1117f569a35e8fd1542df21f7e00e27f192c907e61d63a2e</p></td></tr><tr><td><p>log.dll</p></td><td><p>3bdc4c0637591533f1d4198a72a33426c01f69bd2e15ceee547866f65e26b7ad</p></td></tr><tr><td><p>u.bat</p></td><td><p>9276594e73cda1c69b7d265b3f08dc8fa84bf2d6599086b9acc0bb3745146600</p></td></tr><tr><td><p>conf.c</p></td><td><p>f4d829739f2d6ba7e3ede83dad428a0ced1a703ec582fc73a4eee3df3704629a</p></td></tr><tr><td><p>libtcc.dll</p></td><td><p>4a52570eeaf9d27722377865df312e295a7a23c3b6eb991944c2ecd707cc9906</p></td></tr><tr><td><p>admin</p></td><td><p>831e1ea13a1bd405f5bda2b9d8f2265f7b1db6c668dd2165ccc8a9c4c15ea7dd</p></td></tr><tr><td><p>loader1</p></td><td><p>0a9b8df968df41920b6ff07785cbfebe8bda29e6b512c94a3b2a83d10014d2fd</p></td></tr><tr><td><p>uffhxpSy</p></td><td><p>4c2ea8193f4a5db63b897a2d3ce127cc5d89687f380b97a1d91e0c8db542e4f8</p></td></tr><tr><td><p>loader2</p></td><td><p>e7cd605568c38bd6e0aba31045e1633205d0598c607a855e2e1bca4cca1c6eda</p></td></tr><tr><td><p>3yzr31vk</p></td><td><p>078a9e5c6c787e5532a7e728720cbafee9021bfec4a30e3c2be110748d7c43c5</p></td></tr><tr><td><p>ConsoleApplication2.exe</p></td><td><p>b4169a831292e245ebdffedd5820584d73b129411546e7d3eccf4663d5fc5be3</p></td></tr><tr><td><p>system</p></td><td><p>7add554a98d3a99b319f2127688356c1283ed073a084805f14e33b4f6a6126fd</p></td></tr><tr><td><p>s047t5g.exe</p></td><td><p>fcc2765305bcd213b7558025b2039df2265c3e0b6401e4833123c461df2de51a</p></td></tr></tbody></table><h3>Network indicators</h3><table><tbody><tr><td><p>95.179.213.0</p></td></tr><tr><td><a href="http://api.skycloudcenter.com/">api.skycloudcenter.com</a></td></tr><tr><td><a href="http://api.wiresguard.com/">api.wiresguard.com</a></td></tr><tr><td><p>61.4.102.97</p></td></tr><tr><td><p>59.110.7.32</p></td></tr><tr><td><p>124.222.137.114</p></td></tr></tbody></table><h3>MITRE TTPs</h3><table><tbody><tr><td><p><strong>ATT&amp;CK ID</strong></p></td><td><p><strong>Name</strong></p></td></tr><tr><td><p>T1204.002</p></td><td><p>User Execution: Malicious File</p></td></tr><tr><td><p>T1036</p></td><td><p>Masquerading</p></td></tr><tr><td><p>T1027</p></td><td><p>Obfuscated Files or Information</p></td></tr><tr><td><p>T1027.007</p></td><td><p>Obfuscated Files or Information: Dynamic API Resolution</p></td></tr><tr><td><p>T1140</p></td><td><p>Deobfuscate/Decode Files or Information</p></td></tr><tr><td><p>T1574.002</p></td><td><p>DLL Side-Loading</p></td></tr><tr><td><p>T1106</p></td><td><p>Native API</p></td></tr><tr><td><p>T1055</p></td><td><p>Process Injection</p></td></tr><tr><td><p>T1620</p></td><td><p>Reflective Code Loading</p></td></tr><tr><td><p>T1059.003</p></td><td><p>Command and Scripting Interpreter: Windows Command Shell</p></td></tr><tr><td><p>T1083</p></td><td><p>File and Directory Discovery</p></td></tr><tr><td><p>T1005</p></td><td><p>Data from Local System</p></td></tr><tr><td><p>T1105</p></td><td><p>Ingress Tool Transfer</p></td></tr><tr><td><p>T1041</p></td><td><p>Exfiltration Over C2 Channel</p></td></tr><tr><td><p>T1071.001</p></td><td><p>Application Layer Protocol: Web Protocols (HTTP/HTTPS)</p></td></tr><tr><td><p>T1573</p></td><td><p>Encrypted Channel</p></td></tr><tr><td><p>T1547.001</p></td><td><p>Boot or Logon Autostart Execution: Registry Run Keys</p></td></tr><tr><td><p>T1543.003</p></td><td><p>Create or Modify System Process: Windows Service</p></td></tr><tr><td><p>T1480.002</p></td><td><p>Execution Guardrails: Mutual Exclusion</p></td></tr><tr><td><p>T1070.004</p></td><td><p>Indicator Removal on Host: File Deletion</p></td></tr></tbody></table><p><span></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[39C3 - Greenhouse Gas Emission Data: Public, difficult to access, and not always correct]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 4x - Views:75 Data about greenhouse gas emissions, both from countries and individual factories, is
often publicly available. However, the data sources are often not as accessible and
reliable as they should be. EU emission databases contain obvious flaws, and no...]]></description>
<link>https://tsecurity.de/de/3247820/it-security-video/39c3-greenhouse-gas-emission-data-public-difficult-to-access-and-not-always-correct/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3247820/it-security-video/39c3-greenhouse-gas-emission-data-public-difficult-to-access-and-not-always-correct/</guid>
<pubDate>Mon, 02 Feb 2026 10:34:22 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 4x - Views:75 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/n38O_8oneh8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Data about greenhouse gas emissions, both from countries and individual factories, is<br />
often publicly available. However, the data sources are often not as accessible and<br />
reliable as they should be. EU emission databases contain obvious flaws, and nobody<br />
wants to be responsible.<br />
<br />
Which factory in my city is the largest emitter of CO2? Which industrial sector is<br />
responsible for the largest share of a country's contribution to climate change? It<br />
should not be difficult to answer these questions. Public databases and reporting<br />
required by international agreements usually allow us to access this data.<br />
<br />
However, trying to access and work with these datasets — or, shall we say, Excel tables<br />
— can be frustrating. UN web pages that prevent easy downloads with a "security<br />
firewall", barely usable frontends, and other issues make it needlessly difficult to<br />
gain transparency about the sources of climate pollution.<br />
<br />
While working with official EU datasets, the speaker observed data points that could not<br />
possibly be true. Factories suddenly dropped their emissions by orders of magnitude<br />
without any explanation, different official sources report diverging numbers for the<br />
same emission source, and responsible European and National authorities appear not to<br />
care that much.<br />
<br />
The talk will show how to work with relevant greenhouse gas emission data sources and<br />
how we can access them more easily by converting them to standard SQL tables. Furthermore, we will dig into some of the<br />
strange issues one may find while investigating emission datasets.<br />
<br />
# Background / Links<br />
<br />
* Why is it needlessly difficult to access UNFCCC Emission Data? <br />
* UNFCCC Emission Data Downloads: <br />
* Code (Docker, MariaDB/MySQL, phpMyAdmin) to easily access EU emisison data: <br />
<br />
Hanno Böck<br />
<br />
https://events.ccc.de/congress/2025/hub/event/detail/greenhouse-gas-emission-data-public-difficult-to-access-and-not-always-correct<br />
<br />
#39c3 #Science<br />
<br />
Licensed to the public under http://creativecommons.org/licenses/by/4.0<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Compiling Rust to readable C with Eurydice]]></title>
<description><![CDATA[A few years ago, the only way to compile Rust code was using the rustc compiler
with LLVM as a backend. Since then, several projects, including

Mutabah's Rust Compiler (mrustc), GCC's Rust
support (gccrs),

rust_codegen_gcc, and

Cranelift have made enormous progress
on diversifying Rust's compi...]]></description>
<link>https://tsecurity.de/de/3244481/linux-tipps/compiling-rust-to-readable-c-with-eurydice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3244481/linux-tipps/compiling-rust-to-readable-c-with-eurydice/</guid>
<pubDate>Fri, 30 Jan 2026 17:22:29 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>
A few years ago, the only way to compile Rust code was using the rustc compiler
with LLVM as a backend. Since then, several projects, including
<a href="https://github.com/thepowersgang/mrustc?tab=readme-ov-file#mutabahs-rust-compiler">
Mutabah's Rust Compiler</a> (mrustc), <a href="https://lwn.net/Articles/1040197/">GCC's Rust
support</a> (gccrs),
<a href="https://lwn.net/Articles/907405/#rust_codegen_gcc">
rust_codegen_gcc</a>, and
<a href="https://lwn.net/Articles/964735/">
Cranelift</a> have made enormous progress
on diversifying Rust's compiler implementations. The most recent such project,
<a href="https://github.com/AeneasVerif/eurydice?tab=readme-ov-file#eurydice">
Eurydice</a>, has a
more ambitious goal: converting Rust code to clean C code. This is especially
useful in high-assurance software, where existing verification and compliance
tools expect C. Until such tools can be updated to work with Rust, Eurydice could
provide a smoother transition for these projects, as well as a stepping-stone
for environments that have a C compiler but no working Rust compiler. Eurydice
has been used to compile some post-quantum-cryptography routines from Rust to C,
for example.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tesla Prepares to Retire Model S, Model X to Build More Humanoid Robots]]></title>
<description><![CDATA[Tesla will end Model S and Model X production, converting its Fremont factory to build Optimus humanoid robots and expand robotaxi ambitions.
The post Tesla Prepares to Retire Model S, Model X to Build More Humanoid Robots appeared first on eWEEK.]]></description>
<link>https://tsecurity.de/de/3244293/it-nachrichten/tesla-prepares-to-retire-model-s-model-x-to-build-more-humanoid-robots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3244293/it-nachrichten/tesla-prepares-to-retire-model-s-model-x-to-build-more-humanoid-robots/</guid>
<pubDate>Fri, 30 Jan 2026 16:01:49 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tesla will end Model S and Model X production, converting its Fremont factory to build Optimus humanoid robots and expand robotaxi ambitions.</p>
<p>The post <a href="https://www.eweek.com/news/tesla-ends-model-s-x-production-optimus-robots-robotaxis/">Tesla Prepares to Retire Model S, Model X to Build More Humanoid Robots</a> appeared first on <a href="https://www.eweek.com/">eWEEK</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Get a Geocoding API Key: Step-by-Step Guide for Developers]]></title>
<description><![CDATA[Geocoding API keys enable applications converting addresses into coordinates and vice versa. Understanding how to Get a geocoding API key learned at https://distancematrix.ai/guides/get-geocoding-api-key quickly and properly helps developers in integrating location services into apps.  
API key a...]]></description>
<link>https://tsecurity.de/de/3243570/it-security-nachrichten/how-to-get-a-geocoding-api-key-step-by-step-guide-for-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3243570/it-security-nachrichten/how-to-get-a-geocoding-api-key-step-by-step-guide-for-developers/</guid>
<pubDate>Fri, 30 Jan 2026 10:21:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/how-to-get-a-geocoding-api-key-step-by-step-guide-for-developers" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/geocoding_api_with_bgc.webp" alt="Geocoding API Key" class="hs-featured-image"> </a> 
</div> 
<p><span>Geocoding API keys enable applications converting addresses into coordinates and vice versa. Understanding how to Get a geocoding API key learned at <a href="https://distancematrix.ai/guides/get-geocoding-api-key"><u><span>https://distancematrix.ai/guides/get-geocoding-api-key</span></u></a> quickly and properly helps developers in integrating location services into apps. </span></p> 
<p><span>API key acquisition, configuration, security best practices, usage monitoring all affect successful geocoding implementation. Different providers offer varying signup processes, pricing structures, rate limits requiring evaluation before committing to specific service.<br></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MiniTool Partition Wizard Review: All in One Tool [ 2026 ]]]></title>
<description><![CDATA[Looking for MiniTool Partition Wizard Review?



If yes, then you are in the right place.



I know that there are lots of partition managers out there but in my opinion, this is the best one and most effective.



And if you are a Windows user then this tool is a boon for you.



But how? Like i...]]></description>
<link>https://tsecurity.de/de/3241509/windows-tipps/minitool-partition-wizard-review-all-in-one-tool-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3241509/windows-tipps/minitool-partition-wizard-review-all-in-one-tool-2026/</guid>
<pubDate>Thu, 29 Jan 2026 12:05:58 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Looking for <strong>MiniTool Partition Wizard Review</strong>?</p>



<p>If yes, then you are in the right place.</p>



<p>I know that there are lots of partition managers out there but in my opinion, this is the best one and most effective.</p>



<p>And if you are a <strong>Windows</strong> user then this tool is a boon for you.</p>



<p>But how? Like in the previous post on <strong><a href="https://www.buildsometech.com/how-to-enable-secure-boot-for-windows-11/">how to enable secure boot for Windows 11</a></strong>, we badly needed software to convert MBR to GPT disk partition.</p>



<p>And in that case, this tool can fix this issue. Not only this but using this software you can also fix other issues, which we will be covering later.</p>



<p>In this article, I will give you a detailed review of the MiniTool Partition Wizard including its <strong>Pros and Cons</strong>,<strong> Features</strong>, and <strong>Pricing</strong>.</p>



<p>So without further ado, let’s get started…</p>



<h2 class="wp-block-heading">What is Minitool Partition Wizard?</h2>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14591" src="https://www.buildsometech.com/wp-content/uploads/2022/03/What-is-Minitool-Partition-Wizard.png" alt="What is Minitool Partition Wizard" width="938" height="500" title="What is Minitool Partition Wizard" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/What-is-Minitool-Partition-Wizard.png 938w, https://www.buildsometech.com/wp-content/uploads/2022/03/What-is-Minitool-Partition-Wizard-768x409.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/What-is-Minitool-Partition-Wizard-150x80.png 150w" sizes="auto, (max-width: 938px) 100vw, 938px"></p>


<p><strong><a href="https://www.partitionwizard.com/free-partition-manager.html" target="_blank" rel="noopener">Minitool Partition Wizard</a></strong> is one of the best disk partition management software. It is very easy to use and helps you to manage, update, reformat and clone your hard drive. This tool is developed by a specialized software development firm known as <strong>Minitool</strong>, been providing services for more than <strong>15 years</strong>.</p>



<p>Moreover, this tool benefits both personal and business users and there have been more than <strong>40 million downloads</strong> of this application around the world. And the best part is that the majority of reviews for Minitool Partition Wizard are positive. In a nutshell, this is the best program which gives you lots of functions and can help you in simplifying the process of managing hard disc.</p>



<h2 class="wp-block-heading">MiniTool Partition Wizard Features</h2>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14588" src="https://www.buildsometech.com/wp-content/uploads/2022/03/MiniTool-Partition-Wizard-Features.png" alt="MiniTool Partition Wizard Features" width="709" height="496" title="MiniTool Partition Wizard Features" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/MiniTool-Partition-Wizard-Features.png 709w, https://www.buildsometech.com/wp-content/uploads/2022/03/MiniTool-Partition-Wizard-Features-150x105.png 150w" sizes="auto, (max-width: 709px) 100vw, 709px"></p>


<p>However, it’s easy to do partition-related activities with Windows 10’s <strong>Disc Management Utility</strong>. For example, building new volumes or expanding existing ones, adding mirrors, identifying active partitions, and creating or attaching virtual hard drives.</p>



<p>In spite of this, the default tool has always had a restricted set of options. And if you want more control over your partition management tasks then <strong>Minitool Partition Wizard</strong> is a good choice for you. With its simple wizards and clear interface, this Windows program makes managing drives, partitions, and volume a breeze.</p>



<p>All Image Credits:- partitionwizard.com</p>



<p>Now let’s get right to the features part…</p>



<h3 class="wp-block-heading">Create/Delete/Format Partition</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14564" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Create-Delete-Format-Partition.png" alt="Create Delete Format Partition" width="800" height="200" title="Create Delete Format Partition" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Create-Delete-Format-Partition.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Create-Delete-Format-Partition-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Create-Delete-Format-Partition-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>With this tool, creating and deleting partitions is very easy, just you have to select the <strong>drive letter</strong> and <strong>partition type,</strong> and it’s done. And using the format partition option, you can easily convert <strong>RAW to NTFS</strong> which means all the unallocated space on your hard drive can be revived.</p>



<p><strong>Note:-</strong> Please make sure not to choose <strong>Local Disk C:</strong> ( OS partition )while using the delete or format partition options.</p>



<h3 class="wp-block-heading">Move/Resize Partition</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14565" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Move-Resize-Partition.png" alt="Move Resize Partition" width="800" height="200" title="Move Resize Partition" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Move-Resize-Partition.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Move-Resize-Partition-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Move-Resize-Partition-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>This option is a lifesaver if you just want to adjust the dynamic disk’s volume size. Most of the users face <strong>low disk space warnings</strong> on their Windows PC which can be easily fixed using this option. Two important procedures can be performed using this tool.</p>



<ul class="wp-block-list">
<li>Shrink dynamic volumes into <strong>plain</strong>, <strong>mirrored</strong>, <strong>striped</strong>, or <strong>spanned</strong> volumes to free up capacity for new volumes.</li>



<li>Extend a mirrored, spanned, striped, or <strong>RAID 5</strong> volume using unallocated space or the space you no longer needed.</li>
</ul>



<h3 class="wp-block-heading">Wipe Disk/Partition</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14566" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Wipe-Disk-Partition.png" alt="Wipe Disk Partition" width="800" height="200" title="Wipe Disk Partition" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Wipe-Disk-Partition.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Wipe-Disk-Partition-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Wipe-Disk-Partition-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>Do you know that anyone can easily <strong><a href="https://www.buildsometech.com/how-to-recover-deleted-photos-files/">recover your deleted photos</a></strong> or file from your external hard drive? If no, then start using the <strong>Wipe disk</strong> feature for deleting data from your devices. This feature allows you to securely and permanently delete all your sensitive data from your hard drives so that nothing can be recovered using any <strong><a href="https://www.buildsometech.com/best-free-data-recovery-software-tools/">data recovery software</a></strong>.</p>



<h3 class="wp-block-heading">Merge/Split Partition</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14567" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Merge-Split-Partition.png" alt="Merge Split Partition" width="800" height="200" title="Merge Split Partition" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Merge-Split-Partition.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Merge-Split-Partition-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Merge-Split-Partition-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>Using this feature, you can easily merge two or more partitions and can combine them in a single volume. Furthermore, you can also split a single large hard drive into multiple smaller ones. And the best part is that you can do all this without losing any of your data. But I would suggest you to be careful while using these options <strong>C: drive</strong> ( OS installation partition ).</p>



<h3 class="wp-block-heading">Convert FAT to NTFS</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14568" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Convert-FAT-to-NTFS.png" alt="Convert FAT to NTFS" width="800" height="200" title="Convert FAT to NTFS" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Convert-FAT-to-NTFS.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Convert-FAT-to-NTFS-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Convert-FAT-to-NTFS-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>While formatting the external or internal hard disk and flash drives, the <strong>File System</strong> automatically changes if it does not meet the necessary requirements. But in some cases like <strong><a href="https://www.buildsometech.com/convert-bootable-usb-to-normal/">converting bootable USB to normal</a></strong>, we need to change the file system from <strong>FAT to NTFS</strong> manually. Moreover, by doing this <strong>USB</strong> can also support files larger than <strong>4GB</strong>, and all this can be done without losing any data.</p>



<h3 class="wp-block-heading">Copy Disk/Partition</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14569" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Copy-Disk-Partition.png" alt="Copy Disk Partition" width="800" height="200" title="Copy Disk Partition" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Copy-Disk-Partition.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Copy-Disk-Partition-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Copy-Disk-Partition-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>When you need to clone a disc, this wizard can be a lifesaver. Using this tool, you can easily copy all your data or full partition to a new hard drive. And the best part is that the <strong>Pro Edition</strong> allows you to copy the <strong>OS disk/partition</strong> so that it can be used as a backup or for booting up. Also, please make sure to close all applications before starting the cloning process.</p>



<p> Now let’s see some specialized tools… </p>



<h2 class="wp-block-heading">Some Specialized Tools to Check Disk Partition</h2>



<p>Although, managing your Windows partition is a pleasure with Minitool Partition Wizard. All the above features are very helpful if you want to perform any type of operation on the disk partitions but what if they are damaged. In that case, you can use these specialized tools to check your disk partition health so that any data loss does not occur.</p>



<h3 class="wp-block-heading">Disk Benchmark</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14573" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Benchmark.png" alt="Disk Benchmark" width="800" height="200" title="Disk Benchmark" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Benchmark.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Benchmark-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Benchmark-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>One of the easiest ways to see how quickly your hard drive is running then <strong>benchmark test</strong> is a good choice. Various transfer situations, such as sequential and random are used to gauge the pace of the data transfer. And while using sequential read/write, your disc reads or writes huge continuous blocks of data at neighboring locations, which causes a heavy load on the system.</p>



<h3 class="wp-block-heading">Disk/Partition Surface Test</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14575" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Surface-Test.png" alt="Disk Partition Surface Test" width="800" height="200" title="Disk Partition Surface Test" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Surface-Test.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Surface-Test-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Surface-Test-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>If you observe that your computer is taking a long time to perform certain tasks, this could be a sign that your hard disc is malfunctioning. And in that case, checking your hard drive by using <strong>Disk/Partition Surface Test</strong> is a good choice. Basically, this test checks each and every sector and then highlights it in red if any disc blocks have a fault or malfunction.</p>



<h3 class="wp-block-heading">Disk/Partition Properties</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14576" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Properties.png" alt="Disk Partition Properties" width="800" height="200" title="Disk Partition Properties" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Properties.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Properties-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Disk-Partition-Properties-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>However, this tool is not that unique because Windows already has an inbuilt tool to check properties. But if you want to get more in-depth details like physical sectors, blocks, cylinders, file systems, partition usage, and many more.</p>



<h3 class="wp-block-heading">Space Analyzer</h3>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14577" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Space-Analyzer.png" alt="Space Analyzer" width="800" height="200" title="Space Analyzer" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Space-Analyzer.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Space-Analyzer-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Space-Analyzer-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>Like the previous one, this tool is also a very basic one to analyze which files are taking up the most space. Like in some cases, we have to manually check for the <strong><a href="https://www.buildsometech.com/how-big-is-windows-11/">space size of Windows 11</a></strong> but using this you can easily free up disk space and can remove any files that are no longer needed.</p>



<p> Now let’s see some comparisons… </p>



<h2 class="wp-block-heading">Some Comparison &amp; Impressive Minitool Partition Wizard Reviews</h2>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14580" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Some-Comparison-Impressive-Minitool-Partition-Wizard-Reviews.png" alt="Some Comparison &amp; Impressive Minitool Partition Wizard Reviews" width="1000" height="256" title="Some Comparison Impressive Minitool Partition Wizard Reviews" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Some-Comparison-Impressive-Minitool-Partition-Wizard-Reviews.png 1000w, https://www.buildsometech.com/wp-content/uploads/2022/03/Some-Comparison-Impressive-Minitool-Partition-Wizard-Reviews-768x197.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Some-Comparison-Impressive-Minitool-Partition-Wizard-Reviews-150x38.png 150w" sizes="auto, (max-width: 1000px) 100vw, 1000px"></p>


<p>Here we will see a quick comparison and discuss the reviews given by the users. And according to them, Minitool Partition Wizard is more user-friendly, easier to set up, and easier to administrate. It is much better than other tools and is a better fit for business needs. The approach taken by <strong>Minitool</strong> or <strong>Partition Wizard</strong> in terms of product upgrades and roadmaps is much better. Furthermore, the technical support system is very good as it is handled by experienced ones. </p>



<p>Whereas <strong>EaseUS Partition Master</strong> does not offer much functionality and technical support is also limited.</p>



<h3 class="wp-block-heading">Minimum System Requirements</h3>



<p>Now let’s check if your system is compatible with this software:-</p>



<ul class="wp-block-list">
<li>Windows 10, 8, 7, Vista, XP are supported OS.</li>



<li>Windows Server ( 2003, 2008, 2012, 2016, 2019 ) versions are supported for Server, Enterprise and Technician editions only.</li>



<li>CPU of at least <strong>1-GHz</strong> processor.</li>



<li>Minimum memory required is <strong>512 MB</strong>.</li>



<li>Grpahics card at least <strong>128 MB</strong>.</li>
</ul>



<p>Now let’s move to the pros and cons part…</p>



<h2 class="wp-block-heading">Minitool Partition Wizard Pros and Cons</h2>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14578" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pros-and-Cons.png" alt="Minitool Partition Wizard Pros and Cons" width="800" height="200" title="Minitool Partition Wizard Pros and Cons" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pros-and-Cons.png 800w, https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pros-and-Cons-768x192.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pros-and-Cons-150x38.png 150w" sizes="auto, (max-width: 800px) 100vw, 800px"></p>


<p>Although, we have already talked much about the tools &amp; features but here we will try to highlight them in more detail.</p>



<h3 class="wp-block-heading">Pros</h3>



<ul class="wp-block-list">
<li>Extensive features for partition management.</li>



<li>All tasks can be completed using a simple interface.</li>



<li>Free Version is also provided with good features.</li>



<li>Variety of payment options are available.</li>
</ul>



<h3 class="wp-block-heading">Cons</h3>



<ul class="wp-block-list">
<li>Annoying offers at the time of free version installation.</li>



<li>Unable to handle dynamic disk management.</li>



<li>Most features can be accessed with upgraded version. </li>



<li>Attempts to install irrelevant apps during setup process.</li>
</ul>



<p>Apart from the pros and cons, here I would like to answer one more question which is asked by plenty of users.</p>



<p><strong>Is Minitool Partition Wizard Safe?</strong></p>



<p>Yes, Minitool Partition Wizard is totally safe to use as a disk management tool. It is developed by a well-known software company that has a proven track record of success for past years. It is easy to use and very secure if you want to tamper with your hard drives with advanced features.</p>



<h2 class="wp-block-heading">Minitool Partition Wizard Pricing Plans</h2>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14583" src="https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pricing-Plans.png" alt="Minitool Partition Wizard Pricing Plans" width="900" height="640" title="Minitool Partition Wizard Pricing Plans" srcset="https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pricing-Plans.png 900w, https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pricing-Plans-768x546.png 768w, https://www.buildsometech.com/wp-content/uploads/2022/03/Minitool-Partition-Wizard-Pricing-Plans-150x107.png 150w" sizes="auto, (max-width: 900px) 100vw, 900px"></p>


<p>Talking about the pricing plans, then this tool comes in three subscriptions with different features which we have already discussed in the above section.</p>



<ul class="wp-block-list">
<li><strong>Free Version</strong>: In this you get all basic features like <strong>create/Delete/Format/Move/Resize</strong> partition also including the convert FAT to NTFS feature.</li>



<li><strong>Pro for $59</strong>: This version includes all the features of Free Version and other additional features like Migrate OS to SSD/HDD, OS Disk from MBR to GPT, Convert Dynamic Disk to Basic and Copy OS Disk Convert.</li>



<li><strong>Pro-Platinum for $109</strong>: This version includes all the features of Pro Version and other additional features like Data Recovery, Partition Recovery and Bootable Media Builder.</li>
</ul>



<p>And in my opinion, the<strong> Pro version</strong> is much better in terms of both features and pricing.</p>



<p>That’s it for now…</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>So, that’s all about this partition wizard tool by Minitool. And here I would like to conclude why this program is widely used in disc management. Basically, it provides a wide range of options and makes it easy to manage your partitions. </p>



<p>Moreover, the user interface is simple, and there is a safety net in place to prevent accidental changes to your hard drives. And there’s nothing to worry about whether or not you’re an avid computer user.</p>



<p>Stay tuned for the next post…</p>



<p>Feel free to share your thoughts via comments and also tell us about this post on <em>MiniTool Partition Wizard Review: All in One Tool [ 2026 ]</em>.</p>



<p>If you liked this post, don’t forget to share it…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dropbox Direct Download Link: How to Create & Get [2026]]]></title>
<description><![CDATA[How do I create a direct download link in dropbox?



If you want to know how to create it, then keep reading this post.



In the previous posts, I have already talked about creating a direct download link to a google drive file.



And now I am publishing the same for Dropbox files.



Accordin...]]></description>
<link>https://tsecurity.de/de/3241506/windows-tipps/dropbox-direct-download-link-how-to-create-get-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3241506/windows-tipps/dropbox-direct-download-link-how-to-create-get-2026/</guid>
<pubDate>Thu, 29 Jan 2026 12:05:54 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>How do I create a direct download link in dropbox?</strong></p>



<p>If you want to know how to create it, then keep reading this post.</p>



<p>In the previous posts, I have already talked about <a href="https://www.buildsometech.com/google-drive-direct-download-link/" target="_blank" rel="noreferrer noopener"><strong>creating a direct download link to a google drive </strong><strong>file</strong></a>.</p>



<p>And now I am publishing the same for Dropbox files.</p>



<p>According to Wikipedia, <a href="https://en.wikipedia.org/wiki/Dropbox_(service)" target="_blank" rel="noreferrer noopener">Dropbox has 500 million active users</a>.</p>



<p>And its the second-largest cloud service after the Google Drive.</p>



<p>I know both provides the same functionality &amp; features like uploading &amp; storing files, accessing from anywhere &amp; <strong>shared URLs</strong>.</p>



<p>But in terms of creating direct links to files, it’s pretty different.</p>



<p>So in this post, I will show you how to create direct download links to files &amp; download them directly instead of opening them in a preview window.</p>



<p>Let’s see How it works…</p>



<h2 class="wp-block-heading">How to Create Dropbox Direct Download Link</h2>



<p>This tutorial is divided into two parts, first, we will be creating the shared links for differents files and then converting them to the direct download link.</p>



<p>So let’s get started…</p>



<h3 class="wp-block-heading">Generate or Get Shared Link for Dropbox Files</h3>



<p><strong>1. </strong>Open your Dropbox account through the <strong>Dropbox Login</strong> page. And upload the file for which you want to create a direct link.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-743 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2020/05/Dropbox-Login.png" alt="Dropbox Login" width="324" height="300" title="Dropbox Login"></p>


<p>2. Now Go to <strong>Files</strong> from the left-hand side section.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-744 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2020/05/Dropbox-Files.png" alt="Dropbox Files" width="227" height="300" title="Dropbox Files"></p>


<p>And Now hover the mouse to the dropbox file for which you want to create a direct download link. So, Click on <strong>Share</strong>.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-745 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2020/05/Dropbox-Share-Direct-Download-Link.png" alt="Dropbox Share Direct Download Link" width="1194" height="347" title="Dropbox Share Direct Download Link" srcset="https://www.buildsometech.com/wp-content/uploads/2020/05/Dropbox-Share-Direct-Download-Link.png 1194w, https://www.buildsometech.com/wp-content/uploads/2020/05/Dropbox-Share-Direct-Download-Link-768x223.png 768w" sizes="auto, (max-width: 1194px) 100vw, 1194px"></p>


<p><strong>3. </strong>Now Click on <strong>Create Link</strong> under the <strong>share a link instead</strong> section.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-746 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2020/05/Create-Link.png" alt="Create Link" width="453" height="450" title="Create Link"></p>


<p>Here you will see two options <strong>Link settings</strong> and <strong>Copy link</strong>.</p>



<p>Link settings are for configuring the sharing settings of files but it’s of no use. So, simply click on the <strong>Copy link</strong>.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-747 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2020/05/Copy-Link.png" alt="Copy Link" width="648" height="156" title="Copy Link"></p>


<p>And Done! You have successfully created a direct download link for sharing the file.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-748 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2020/05/Dropbox-Share-Link.png" alt="Dropbox Share Link" width="731" height="81" title="Dropbox Share Link"></p>


<p>Now let’s move to the next part…</p>



<h3 class="wp-block-heading">Convert Dropbox Share link to Direct Download link</h3>



<p>And for converting the normal shared Link/URL to the direct download link you need a third-party <strong>Link Generator</strong> like this.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-749 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2020/05/Link-Generator.png" alt="Link Generator" width="968" height="179" title="Link Generator" srcset="https://www.buildsometech.com/wp-content/uploads/2020/05/Link-Generator.png 968w, https://www.buildsometech.com/wp-content/uploads/2020/05/Link-Generator-768x142.png 768w" sizes="auto, (max-width: 968px) 100vw, 968px"></p>


<p>But you can also do this by simply following these simple <strong>Dropbox URL hacks</strong>.</p>



<p>So, the basic default format of the <strong>Dropbox Shared URL</strong> is like this.</p>



<p>https://www.dropbox.com/s/g4ygalz2my88c71/Get%20Started.pdf?dl=0</p>



<p>And if you change the <em>“www.dropbox.com”</em> part with <em>“http://dl.dropboxusercontent.com/”</em> you will get a link like this which is actually a direct download link.</p>



<p>https://dl.dropboxusercontent.com/s/g4ygalz2my88c71/Get%20Started.pdf?dl=0</p>



<p>Does it seems confusing, then Check this.</p>



<p>Simply change the end part of the link from <strong>dl=0</strong> to <strong>dl=1</strong>. And<strong> Copy the link</strong> &amp; <strong>paste</strong> it into the URL bar &amp; Press <strong>Enter</strong>. It will directly download the file.</p>



<p>That’s it for now…</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>So this is how by following these simple tricks you can easily generate dropbox sharing Url for files and can convert them into direct links.</p>



<p>So what are you waiting for? Go ahead and use these simple Url hacks for direct links to files &amp; share them on the internet freely.</p>



<p>Stay tuned for the next posts on <strong>Onedrive direct download link</strong>.</p>



<p>Feel free to share your thoughts and also tell us if you know any better way to <em>get or create a dropbox direct download link in 2026</em>.</p>



<p>If you liked this post, <strong>Don’t forget to share</strong> this with your friends.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Create Google Drive Direct Download Link 2026: How to Guide]]></title>
<description><![CDATA[Want to Create Google Drive Direct Download Link?



If yes then you are in the right place.



Google Drive is one of the best Cloud Storage service providers in the market.



According to theverge, Google Drive is about to hit 1 billion users & has more than 800 million daily users.



But why...]]></description>
<link>https://tsecurity.de/de/3241505/windows-tipps/create-google-drive-direct-download-link-2026-how-to-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3241505/windows-tipps/create-google-drive-direct-download-link-2026-how-to-guide/</guid>
<pubDate>Thu, 29 Jan 2026 12:05:52 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>Want to Create Google Drive Direct Download Link?</strong></p>



<p>If yes then you are in the right place.</p>



<p>Google Drive is one of the best <a href="https://en.wikipedia.org/wiki/Cloud_storage" target="_blank" rel="noreferrer noopener">Cloud Storage</a> service providers in the market.</p>



<p>According to theverge, <a href="https://www.theverge.com/2018/7/25/17613442/google-drive-one-billion-users" target="_blank" rel="noreferrer noopener">Google Drive is about to hit 1 billion users</a> &amp; has more than <strong>800 million</strong> daily users.</p>



<p>But why Google Drive is so much popular? As it provides <strong>15 GB</strong> of free storage space.</p>



<p>No. I think it’s because of its feature &amp; functionality. One feature which I really like is <strong>File Sharing</strong>.</p>



<p>Using this feature you can easily share your files or folders stored on your drive via shareable links.</p>



<p>But one thing is really bad about this is that whenever these links are shared on the web. And accessed by other people, these links are opened in a new preview window instead of downloading the files directly.</p>



<p>So in this post, I will show you how to convert google drive link to direct download links easily.</p>



<p>Let’s see How it works…</p>



<p><strong>Also Read: <a href="https://www.buildsometech.com/create-get-dropbox-direct-download-link/" target="_blank" rel="noreferrer noopener">How to Create Dropbox Direct Download Link 2026</a></strong></p>



<h2 class="wp-block-heading">How to Create Google Drive Direct Download Link</h2>



<p>In this tutorial, I will be using an online tool called <strong>WonderPlugin-Google Drive Direct Link Generator</strong> for Image, MP3 and Video Files.</p>



<p>But before that, we need a google drive <strong>shared URL</strong>.</p>



<p>Let’s see how to get it.</p>



<h3 class="wp-block-heading">Create or Get Google Drive File Shared URL</h3>



<p><strong>1.</strong> Open <strong>Google Drive</strong> &amp; Upload the desired file for which you want to create a direct downloadable link.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-1086 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2018/12/Google-Drive-Direct-Download-Link.png" alt="Google Drive Direct Download Link" width="320" height="156" title="Google Drive Direct Download Link"></p>


<p>And When the file is Uploaded, Right Click on it and then select <strong>Share</strong>.</p>



<p><strong>Tip:-</strong> You can also use the <strong>Backup and Sync</strong> app to upload files and folders.</p>



<p>2. Now here you will see two options <strong>Share with people and groups</strong> and <strong>Get link</strong>. So click on the <strong>Get link</strong>.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-1087 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2018/12/Get-Link.png" alt="Get Link" width="611" height="354" title="Get Link"></p>


<p>3. Now Click on the <strong>Copy link</strong> and your google drive file shareable link is ready. And you can further configure it also &amp; can change its permissions.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-1088 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2018/12/Google-Drive-File-Shareable-Link.png" alt="Google Drive File Shareable Link" width="600" height="283" title="Google Drive File Shareable Link"></p>


<p>And you can further configure it also &amp; can change its <strong>permissions</strong>.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-1089 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2018/12/Link-Public-on-the-Web.png" alt="Link Public on the Web" width="600" height="188" title="Link Public on the Web"></p>


<p>Like <strong>Anyone with the link</strong> means this file is <strong>public on the web</strong> and can access or viewed by anyone. Also, you can change its editing permission by clicking on <strong>Viewer</strong> and changing to the <strong>Commenter</strong> or <strong>Editor</strong>.</p>



<p>4. And Now Click on <strong>Done</strong>.</p>


<p><img loading="lazy" decoding="async" class="size-full wp-image-1090 aligncenter" src="https://www.buildsometech.com/wp-content/uploads/2018/12/Shared-URL-Created.png" alt="Shared URL Created" width="600" height="175" title="Shared URL Created"></p>


<p><strong>Note:-</strong> It works with the files of any type like Google Docs, Spreadsheets, Video &amp; Audio files and not with the <strong>Folders</strong> but for that you can convert a folder into a <strong>.Zip</strong> file.</p>



<p>Now the next part of converting it to direct link.</p>



<h3 class="wp-block-heading">Convert Google Drive Link to Direct Download Link</h3>



<p>Now Open the <strong>WonderPlugin</strong> Link Generator tool and <strong>Paste</strong> the copied google drive file link &amp; then Click on <strong>Generate Google Drive Direct Link</strong>.</p>


<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-1091" src="https://www.buildsometech.com/wp-content/uploads/2018/12/WonderPlugin-Google-Drive-Direct-Link-Generator.png" alt="WonderPlugin-Google Drive Direct Link Generator" width="879" height="323" title="WonderPlugin Google Drive Direct Link Generator" srcset="https://www.buildsometech.com/wp-content/uploads/2018/12/WonderPlugin-Google-Drive-Direct-Link-Generator.png 879w, https://www.buildsometech.com/wp-content/uploads/2018/12/WonderPlugin-Google-Drive-Direct-Link-Generator-768x282.png 768w" sizes="auto, (max-width: 879px) 100vw, 879px"></p>


<p>And Done! You have successfully converted a normal google drive shareable link into a direct download link.</p>



<p>Now the bonus part…</p>



<h3 class="wp-block-heading">Google drive URL Format for Direct Links</h3>



<p>So basically when you create a shared URL for Google drive file. Its default format looks like this:</p>



<pre class="wp-block-code"><code>https://drive.google.com/open?id=FILE_ID</code></pre>



<p>And <strong>FILE_ID</strong> is unique for every file present in Google drive. And if you Copy the <strong>FILE_ID</strong> and the use this in the below code, then you will get a direct download link of a google drive file.</p>



<pre class="wp-block-code"><code>https://drive.google.com/uc?export=download&amp;id=FILE_ID</code></pre>



<p>And if you only want to view the file viewer mode, then paste the FILE_ID in the below code.</p>



<pre class="wp-block-code"><code>https://drive.google.com/file/d/FILE_ID/view</code></pre>



<p>That’s it for now…</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>This is how by using these two simple steps you can easily generate a Google drive sharing Url and can convert it into a direct download link using a link generator.</p>



<p>So what are you waiting for? Go ahead and use this awesome tool to generate direct download links for free and share them on the internet.</p>



<p>Stay tuned for the next posts on <strong>Onedrive direct download link</strong>.</p>



<p>Feel free to share your thoughts and also tell us if you know any better way to <em>create or make google drive direct download link in 2026.</em></p>



<p>If you liked this post, <strong>Don’t forget to share</strong> this with your friends.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4563: Nuclear Reactor Technology - Ep 5 Fast Reactors]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


Fast Reactors




03 Fast versus Slow Neutrons

"Fast neutron" reactors are ones which use the "fast neutron" reaction.

This is as opposed to "slow" or "thermal" neutron reactors which use a slow neutron reaction.

Nearly all reactors in use tod...]]></description>
<link>https://tsecurity.de/de/3238230/podcasts/hpr4563-nuclear-reactor-technology-ep-5-fast-reactors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3238230/podcasts/hpr4563-nuclear-reactor-technology-ep-5-fast-reactors/</guid>
<pubDate>Wed, 28 Jan 2026 01:02:16 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
Fast Reactors</p>
<p>
<br>
</p>
<p>
03 Fast versus Slow Neutrons</p>
<p>
"Fast neutron" reactors are ones which use the "fast neutron" reaction.</p>
<p>
This is as opposed to "slow" or "thermal" neutron reactors which use a slow neutron reaction.</p>
<p>
Nearly all reactors in use today use a slow neutron reaction.</p>
<p>
<br>
</p>
<p>
04 Moderators</p>
<p>
06 No Moderator in Fast Neutron Reactors</p>
<p>
<br>
</p>
<p>
07 Burners versus Breeders</p>
<p>
<br>
</p>
<p>
08 Fast Fission Fuel Cycle</p>
<p>
08 "Typical" Fuel</p>
<p>
09 Other Methods</p>
<p>
10 Reprocessing</p>
<p>
<br>
</p>
<p>
11 Fuel Types</p>
<p>
11 Oxide</p>
<p>
12 Metal</p>
<p>
13 Nitride</p>
<p>
14 Carbide</p>
<p>
<br>
</p>
<p>
15 Coolant</p>
<p>
16 Liquid Sodium</p>
<p>
18 Liquid Lead or Lead-Bismuth</p>
<p>
19 Helium Gas</p>
<p>
20 Molten Salt</p>
<p>
<br>
</p>
<p>
21 History of Fast Neutron Reactors</p>
<p>
21 Origins</p>
<p>
22 Reasons for Developing Them</p>
<p>
23 Reasons They are Still Being Developed</p>
<p>
24 This is a Proven Technology</p>
<p>
25 Plutonium Stockpiles</p>
<p>
<br>
</p>
<p>
26 Pros and Cons of Fast Reactors</p>
<p>
If fast reactors are more expensive and difficult to operate than slow reactors, why is there any interest in them?</p>
<p>
<br>
</p>
<p>
27 Pros</p>
<p>
Fast neutron reactors can use all of the uranium supply by converting the U-238 to plutonium as well as using the U-235.</p>
<p>
Slow neutron reactors can only use the U-235 plus converting a very small proportion of the U-238 to plutonium.</p>
<p>
This means that a given amount of fuel will go much further when used with a fast neutron reactor than a slow one.</p>
<p>
28</p>
<p>
Some (but not all) fast neutron reactors can produce more plutonium than they use.</p>
<p>
This extra plutonium can be used to make uranium-plutonium mixed oxide (or MOX) fuel to be used in slow reactors, or it can be used to power a thorium fuel cycle. </p>
<p>
So the higher cost of the fast neutron reactors can be offset by having it produce fuel for several slow neutron or thorium reactors.</p>
<p>
29</p>
<p>
They can also use up or "burn" radioactive waste. That is, highly radioactive elements which are a byproduct of fuel use but not usable as fuel by themselves can be separated from the spent fuel and fed back into the reactor where the additional radiation will convert them into elements or isotopes which are either not radioactive or which are otherwise easier to dispose of.</p>
<p>
<br>
</p>
<p>
30 Cons</p>
<p>
There are a number of cons however, as otherwise there would be a lot more fast neutron reactors in the world.</p>
<p>
Since water, even "light" water, is a moderator, fast neutron reactors cannot use water as a coolant.</p>
<p>
Other alternative coolants must be used, and these complicate the design of the reactor and make it more difficult to operate.</p>
<p>
31</p>
<p>
Alternative compatible coolants may be corrosive, and so new materials may need to be developed for both the reactor vessel and the fuel cladding.</p>
<p>
Alternative coolants are often opaque, making it difficult to inspect the reactor.</p>
<p>
The fuel cycle requires reprocessing spent fuel, which means that reprocessing facilities have to be set up, which is an additional expense.</p>
<p>
32</p>
<p>
Fast neutron reactors were primarily developed on the premise that uranium supplies were limited and would soon become very expensive. However new very large and very high grade uranium deposits were discovered in Canada, Australia, and Kazakhstan, causing uranium prices to fall rather than rise. As a result it is much cheaper to operate a once-through fuel cycle than to build fast neutron reactors.</p>
<p>
<br>
</p>
<p>
33 Future Prospects</p>
<p>
Currently fast neutron reactors are not economically competitive with slow neutron reactors for electric power generation so there isn't a lot of interest from prospective customers.</p>
<p>
Originally interest in them was driven by a belief that the world would run short of uranium.</p>
<p>
However, higher uranium prices sparked increased mineral exploration which resulted in finding large high grade reserves of low cost uranium, undercutting the need for economizing on its use.</p>
<p>
34</p>
<p>
There is still ongoing R&amp;D though as they offer several other use cases.</p>
<p>
One is to get rid of radioactive waste elements by turning them into non-radioactive or less radioactive isotopes or elements.</p>
<p>
The other is to provide a supply of plutonium for fuelling thorium reactors.</p>
<p>
<br>
</p>
<p>
35 Conclusion</p>
<p>
This has been a short overview of fast neutron reactors, including their history, uses, and underlying design features.</p>
<p>
<br>
</p>
<p>
In the next episode we will describe the use of thorium in nuclear power, including what thorium is, how it differs from uranium, and what sort of reactors can use it.</p>
<p>
<br>
</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4563/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon shutters all of its physical Go and Fresh stores]]></title>
<description><![CDATA[Amazon Go and Fresh physical store locations will soon be no more, with Amazon announcing on Tuesday that it's closing up the majority of the stores and converting others into Whole Foods Market locations. Customers will still be able to order from Amazon Fresh online, but won't be able to shop a...]]></description>
<link>https://tsecurity.de/de/3237910/it-nachrichten/amazon-shutters-all-of-its-physical-go-and-fresh-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3237910/it-nachrichten/amazon-shutters-all-of-its-physical-go-and-fresh-stores/</guid>
<pubDate>Tue, 27 Jan 2026 20:01:42 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon Go and Fresh physical store locations will soon be no more, with Amazon announcing on Tuesday that it's closing up the majority of the stores and converting others into Whole Foods Market locations. Customers will still be able to order from Amazon Fresh online, but won't be able to shop at physical stores with […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Using AWS WorkMail in Phishing Campaigns]]></title>
<description><![CDATA[IntroductionAt Rapid7, we track a wide range of threats targeting cloud environments, where a frequent objective is hijacking victim infrastructure to host phishing or spam campaigns. Beyond the obvious security risks, this approach allows threat actors to offload their operational costs onto the...]]></description>
<link>https://tsecurity.de/de/3237832/it-security-nachrichten/threat-actors-using-aws-workmail-in-phishing-campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3237832/it-security-nachrichten/threat-actors-using-aws-workmail-in-phishing-campaigns/</guid>
<pubDate>Tue, 27 Jan 2026 19:21:25 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Introduction</h2><p><span>At Rapid7, we track a wide range of threats targeting cloud environments, where a frequent objective is hijacking victim infrastructure to host phishing or spam campaigns. Beyond the obvious security risks, this approach allows threat actors to offload their operational costs onto the target company, often resulting in significant, unwanted bills for services the victim never intended to use.</span></p><p><span>Rapid7 recently investigated a cloud abuse incident in which threat actors leveraged compromised AWS credentials to deploy phishing and spam infrastructure using AWS WorkMail, bypassing the anti-abuse controls normally enforced by AWS Simple Email Service (SES). AWS SES is a general-purpose, API-driven email platform intended for application-generated email such as transactional notifications and marketing messages. This allows the threat actor to leverage Amazon’s high sender reputation to masquerade as a valid business entity, with the ability to send email directly from victim-owned AWS infrastructure. Generating minimal service-attributed telemetry also makes threat actor activity difficult to distinguish from routine activity. Any organization with exposed AWS credentials and permissive Identity and Access Management (IAM) policies are potentially at risk, particularly those without guardrails or monitoring around WorkMail and SES configuration.</span></p><p><span>In this post, we analyzed a real-world incident observed by our MDR team in which threat actors abused native AWS email services to build phishing and spam infrastructure inside a compromised cloud environment. We will reconstruct the attacker’s progression from credential validation and IAM reconnaissance to bypassing Amazon SES safeguards by pivoting to AWS WorkMail. Along the way, we highlight how legitimate service abstractions can be leveraged to evade detection, examine the resulting logging and attribution gaps, and outline practical detection and prevention strategies defenders can use to identify and disrupt similar cloud-native abuse.</span></p><h2>Background: AWS WorkMail and its key components</h2><p><span>AWS WorkMail is a fully managed business email and calendaring service that allows organizations to operate corporate mailboxes without deploying or maintaining their own mail servers. It supports standard email protocols such as IMAP and SMTP, as well as common desktop and mobile clients, making it a lightweight, pay-as-you-go alternative for teams already operating within AWS.</span></p><p><span>To understand the activities performed by threat actors in the incident, it’s important to first introduce several core concepts within AWS WorkMail.</span></p><h3><span>Organization</span></h3><p><span>An Organization is the top-level container in WorkMail. It represents an isolated email environment that holds all users, groups, and domains. Each WorkMail organization is region-specific and operates independently, which allows attackers to create disposable, self-contained email infrastructures with minimal setup.</span></p><h3><span>Users</span></h3><p><span>Users represent individual mail-enabled identities within a WorkMail organization. After a user is created using the “</span><span><em>workmail:CreateUser”</em></span><span> API call, a mailbox can be assigned via a “</span><span><em>workmail:RegisterToWorkMail</em></span><span>”API call. Once registered, the user can authenticate to the AWS WorkMail web client or connect via standard email protocols and immediately begin sending and receiving email.</span></p><h3><span>Groups</span></h3><p><span>Groups are collections of users that can receive email on behalf of multiple members. They are typically used for distribution lists or shared inboxes and can simplify bulk message delivery or internal coordination within a WorkMail organization.</span></p><h3><span>Domains</span></h3><p><span>Domains define the email address namespace used by a WorkMail organization (e.g.@example.com). Before a domain can be used, ownership must be verified. This verification process leverages the standard domain verification mechanism of Amazon Simple Email Service, typically via DNS records. Once verified, the domain can be actively used for sending and receiving email, enabling threat actors to operate from attacker-controlled, but seemingly legitimate, domains.</span></p><h2>Attack analysis</h2><p><span>The diagram below contains a graphical representation of the key events carried out by the attackers throughout the attack, starting with initial access actions, continuing through privilege escalation, and ending with the achievement of objectives.</span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt50e68a576abf9851/6978f840a00c217afa58604f/Graphical-visualization-of-AWS-workmail-phishing-attack.png" alt="Graphical-visualization-of-AWS-workmail-phishing-attack.png" caption="Figure 1: Graphical visualization of the attack" height="353" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Graphical-visualization-of-AWS-workmail-phishing-attack.png" width="1261" max-width="1261" max-height="353" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt50e68a576abf9851/6978f840a00c217afa58604f/Graphical-visualization-of-AWS-workmail-phishing-attack.png" data-sys-asset-uid="blt50e68a576abf9851" data-sys-asset-filename="Graphical-visualization-of-AWS-workmail-phishing-attack.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Graphical visualization of the attack" data-sys-asset-alt="Graphical-visualization-of-AWS-workmail-phishing-attack.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Graphical visualization of the attack</figcaption></div></figure><p></p><h3><span>Initial access</span></h3><p>The compromise began with the exposure of long-term AWS access keys. The first indication of malicious activity was an <em>“sts:GetCallerIdentity”</em> API call with the User-Agent set to <strong>“</strong>TruffleHog Firefox.<strong>”</strong> This strongly suggests the use of TruffleHog, a tool commonly leveraged by adversaries to discover and validate leaked credentials from sources such as GitHub, GitLab, and public S3 buckets. Rapid7 has frequently observed TruffleHog usage in active campaigns, including activity attributed to groups such as the <a href="https://www.rapid7.com/blog/post/tr-crimson-collective-a-new-threat-group-observed-operating-in-the-cloud/" target="_blank">Crimson Collective</a>.</p><p>Several days after this initial credential validation, we observed suspicious activity involving a second IAM user authenticated via long-term access keys. While we cannot conclusively prove that both users were accessed by the same operator, multiple factors suggest they were part of the same intrusion activity. Notably, both authentications originated from the same geographic region, which was anomalous for the victim’s normal operating patterns. Throughout the incident window, access to both accounts was conducted through a rotating set of IP addresses associated primarily with cloud service providers such as Amazon and DigitalOcean. This infrastructure choice is consistent with common adversary tradecraft used to obfuscate true origin and blend into legitimate cloud-to-cloud traffic.</p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7cd104aa41140df3/6978f8fefaf6ac6d8573f3b7/TruffleHog-output-discovered-credentials-for-Google-Cloud-Platform.png" alt="TruffleHog-output-discovered-credentials-for-Google-Cloud-Platform.png" caption="Figure 2: Example TruffleHog output showing discovered credentials for Google Cloud Platform (GCP)" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="TruffleHog-output-discovered-credentials-for-Google-Cloud-Platform.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7cd104aa41140df3/6978f8fefaf6ac6d8573f3b7/TruffleHog-output-discovered-credentials-for-Google-Cloud-Platform.png" data-sys-asset-uid="blt7cd104aa41140df3" data-sys-asset-filename="TruffleHog-output-discovered-credentials-for-Google-Cloud-Platform.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Example TruffleHog output showing discovered credentials for Google Cloud Platform (GCP)" data-sys-asset-alt="TruffleHog-output-discovered-credentials-for-Google-Cloud-Platform.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Example TruffleHog output showing discovered credentials for Google Cloud Platform (GCP)</figcaption></div></figure><h3><span>Discovery phase and privilege escalation</span></h3><p><span>Following initial access, the first compromised user was used to perform basic environment discovery via native AWS APIs. These attempts repeatedly resulted in AccessDenied errors, indicating that the exposed credentials were constrained by limited permissions. The activity was conducted using the AWS command-line interface (CLI), suggesting hands-on, interactive exploration by the threat actor rather than automated tooling.</span></p><p><span>After encountering these limitations, the adversary shifted activity to the second set of compromised credentials, which possessed significantly broader permissions. With this user, enumeration became more deliberate and structured. The actor began with </span><span><span data-type="inlineCode"><em>iam:ListUsers</em></span></span><span> API calls to understand the identity landscape and then used a technique of intentionally triggering API errors to confirm specific permissions without making persistent changes.</span></p><p><span>As part of this broader discovery effort, the actor also queried Amazon SES to assess its current configuration and readiness for abuse. Specifically, they executed </span><span><span data-type="inlineCode"><em>ses:GetAccount</em></span></span><span><em> </em></span><span>and </span><span><span data-type="inlineCode"><em>ses:ListIdentities</em></span></span><span>. These calls allowed the adversary to quickly map the operational status of SES within the account. The </span><span><span data-type="inlineCode"><em>ses:ListIdentities</em></span></span><span> API call was used to determine whether any verified identities (domains or email addresses) already existed that could be immediately leveraged for sending mail; none were present at the time. In parallel, </span><span><span data-type="inlineCode"><em>ses:GetAccount</em></span></span><span><em> </em></span><span>was used to identify whether the account was operating in the SES sandbox, which would impose strict sending limits and require additional steps before large-scale email campaigns could be launched.</span></p><p><span>This SES-focused reconnaissance indicates early intent to abuse email-sending capabilities and demonstrates how attackers can efficiently evaluate service readiness using only a small number of low-noise management API calls.</span></p><p><span>For example, the actor attempted to create an IAM user that already existed. The resulting error response confirmed possession of </span><span><span data-type="inlineCode"><em>iam:CreateUser</em></span></span><span><em> </em></span><span>permissions without successfully creating a new entity:</span></p><p>⠀</p><pre language="json">{
"userAgent": "aws-cli/1.22.34 Python/3.10.12 Linux/5.15.0-113-generic botocore/1.23.34",
"errorCode": "EntityAlreadyExistsException",
"errorMessage": "User with name xxxx already exists."
}</pre><p><span><em>Listing 1: Part of the </em></span><span><span data-type="inlineCode"><em>iam:CreateUser</em></span></span><span><em> CloudTrail log</em></span></p><p>⠀</p><p><span>A similar validation was performed using </span><span><span data-type="inlineCode"><em>iam:CreateLoginProfile</em></span></span><span><em>.</em></span><span> By supplying a password that violated the account’s password policy, the actor received a </span><span><span data-type="inlineCode"><em>PasswordPolicyViolationException</em></span></span><span>, confirming their ability to create console login profiles:</span></p><p>⠀</p><pre language="json">{
"userAgent": "aws-cli/1.22.34 Python/3.10.12 Linux/5.15.0-113-generic botocore/1.23.34",
"errorCode": "PasswordPolicyViolationException",
"errorMessage": "Password should have at least one uppercase letter"
}</pre><p><span><em>Listing 2: Part of the </em></span><span><span data-type="inlineCode"><em>iam:CreateLoginProfile</em></span></span><span><em> CloudTrail log</em></span></p><p>⠀</p><p><span>After validating the scope of their privileges, the adversary created a new IAM user, attached the AWS managed policy “</span><span><em>AdministratorAccess”</em></span><span>, and established a login profile to enable AWS Management Console access. This marked a transition from CLI-based reconnaissance to full GUI-based control, providing unrestricted access and setting the stage for subsequent operational activity.</span></p><h3><span>Action on objectives: Preparing email infrastructure for abuse</span></h3><p><span>By the end of the discovery phase, the threat actor had established two critical facts:</span></p><ol><li><p><span>No verified identities existed in Amazon Simple Email Service (SES).</span></p></li><li><p><span>The account remained restricted by the SES sandbox.</span></p></li></ol><p><span>The SES sandbox is explicitly designed to limit fraud and abuse, and its restrictions effectively prevent meaningful phishing or spam campaigns. While an account remains in the sandbox, the following controls apply:</span></p><ul><li><p><span>Emails can only be sent to verified identities (email addresses or domains) or the SES mailbox simulator.</span></p></li><li><p><span>A maximum of </span><span><strong>200 messages per 24-hour period</strong></span><span>.</span></p></li><li><p><span>A maximum sending rate of </span><span><strong>1 message per second</strong></span><span>.</span></p></li></ul><p><span>These constraints made SES unsuitable for immediate abuse at scale. Rather than abandoning the service, the attacker initiated a process to legitimize higher-volume email sending.</span></p><p><span>First, they opened a support case with AWS requesting removal from the SES sandbox. In parallel, they requested a substantial increase to the daily sending quota— setting it to </span><span><strong>100,000 emails per day</strong></span><span> —using the </span><span><span data-type="inlineCode"><em>servicequotas:RequestServiceQuotaIncrease</em></span></span><span><em> </em></span><span>API call.</span></p><p>⠀</p><pre language="json">{
    "requestParameters": {
"serviceCode": "ses",
"quotaCode": "L-XXXXXX",
"desiredValue": 100000
	
}</pre><p><span><em>Listing 3: Request parameters from </em></span><span><span data-type="inlineCode"><em>RequestServiceQuotaIncrease</em></span></span><span><em> API call</em></span></p><p>⠀</p><p><span>During this waiting period, the actor focused on persistence and stealth. Multiple IAM users were created.. These usernames were deliberately chosen to resemble region- or service-scoped automation accounts rather than human operators. To further reduce suspicion during IAM audits, the attacker attached narrowly scoped, SES-only policies to these users instead of broad administrative permissions. This approach allowed them to preserve operational access while minimizing obvious indicators of compromise such as over-privileged identities.</span></p><p><span>At this stage, the attacker had effectively prepared the account for large-scale email abuse-but they did not wait for AWS approval to proceed.</span></p><h3><span>Bypassing SES controls by abusing AWS WorkMail</span></h3><p><span>Rather than remaining idle while SES sandbox removal and quota increases were pending, the attacker pivoted to AWS WorkMail, which offers an alternative email-sending pathway with significantly fewer upfront restrictions.</span></p><p><span>Using the </span><span><span data-type="inlineCode"><em>workmail:CreateOrganization</em></span></span><span><em> </em></span><span>API, the threat actor created multiple WorkMail organizations. They then initiated domain verification workflows for domains designed to appear legitimate and business-like, including:</span></p><ul><li><p><span><span data-type="inlineCode">cloth-prelove[.]me</span></span></p></li><li><p><span><span data-type="inlineCode">ipad-service-london[.]com</span></span></p></li></ul><p><span>Domain verification was performed through </span><span><span data-type="inlineCode"><em>ses:VerifyDomainIdentity</em></span></span><span> and </span><span><span data-type="inlineCode"><em>ses:VerifyDomainDkim</em></span></span><span>, with the calls originating from </span><span><span data-type="inlineCode"><em>workmail.amazonaws.com</em></span></span><span>. This highlights an important nuance for defenders: although SES APIs are involved, the activity is driven by WorkMail provisioning rather than traditional SES email campaigns.</span></p><p><span>Once domain verification was completed, the actor created multiple mailbox users directly within WorkMail, such as:</span></p><ul><li><p><span><span data-type="inlineCode">service@ipad-service-london[.]com</span></span></p></li><li><p><span><span data-type="inlineCode">marketing@ipad-service-london[.]com</span></span></p></li></ul><p><span>These accounts served two purposes. First, they established persistence at the application layer, independent of IAM. Second, they provided credible sender identities for phishing and spam operations, closely resembling legitimate corporate email addresses.</span></p><p><span>There were also AWS directory service events logged by CloudTrail that show new aliases created for the new sender domains, using the victim’s directory tenant:</span></p><p><span><em><strong>CreateAlias</strong></em></span></p><p><span><em><strong>AuthorizeAppication</strong></em></span></p><p><span>This pivot is particularly impactful because </span><span><strong>AWS WorkMail does not implement a sandbox model</strong></span><span> comparable to SES. Emails can be sent immediately to external, unverified recipients. Additionally, WorkMail supports significantly higher sending volumes than SES sandbox limits. While Rapid7 has not empirically validated the maximum throughput, AWS documentation cites a default upper limit of </span><span><strong>100,000 external recipients per day per organization</strong></span><span>, aggregated across all users.</span></p><h4><span>Email sending methods and logging gaps</span></h4><p><span>The attacker had two viable options for sending email through WorkMail:</span></p><p><span><strong>1. Web interface</strong></span><br><span>Emails sent through the AWS WorkMail web client may surface indirectly in CloudTrail as “</span><span><em>ses:SendRawEmail”</em></span><span> events. These events are generated because WorkMail uses Amazon Simple Email Service (SES) as its underlying mail transport, even though the messages are composed and sent entirely through the WorkMail application.</span></p><p><span>While these events are not attributed to an IAM principal, they do expose several pieces of valuable metadata within the “</span><span><em>requestParameters”</em></span><span> field — most notably the sender’s email address and associated SES identity. This allows defenders to link outbound email activity to specific WorkMail users and recently verified domains, even in the absence of traditional application or message-level logs.</span></p><p><span>One notable limitation of these “</span><span><em>ses:SendRawEmail”</em></span><span> events is the absence of a true client source IP address. Because emails sent via the WorkMail web interface are executed by an AWS-managed service on behalf of the mailbox user, CloudTrail records the “</span><span><em>sourceIPAddress”</em></span><span> as “</span><span><em>workmail.&lt;region&gt;.amazonaws.com”</em></span><span> rather than the originating IP address of the actor’s browser session. This effectively obscures the attacker’s true network origin and prevents defenders from correlating email-sending activity with suspicious IP ranges, TOR exit nodes, or previously observed intrusion infrastructure.</span></p><p>⠀</p><pre language="json">{
"eventVersion": "1.11",
"userIdentity": {
"type": "AWSService",
"invokedBy": "workmail.us-east-1.amazonaws.com"
    },
"eventTime": "2025-12-20T11:26:59Z",
"eventSource": "ses.amazonaws.com",
"eventName": "SendRawEmail",
"awsRegion": "us-east-1",
"sourceIPAddress": "workmail.us-east-1.amazonaws.com",
"userAgent": "workmail.us-east-1.amazonaws.com",
"requestParameters": {
"sourceArn": "arn:aws:ses:us-east-1:123456789012:identity/malicious-organiation[.]com",
"destinations": [
"HIDDEN_DUE_TO_SECURITY_REASONS"
        ],
"source": "=?UTF-8?Q?Malicious_User?= &lt;marketing@malicious-organiation[.]com&gt;",
"fromArn": "arn:aws:ses:us-east-1:123456789012:identity/malicious-organiation[.]com",
"configurationSetName": "gcp-iad-prod-workmail-default-configuration-set",
"rawMessage": {
"data": "HIDDEN_DUE_TO_SECURITY_REASONS"
        }
    },
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "4",
"sesMessageId": "0100019b3c4a8bb7-50af951c-fbd4-4610-bc94-c7fc35733699-000000"
    },
"requestID": "aff61405-04bd-4969-802a-7ce4d5946949",
"eventID": "c34ed12d-5bec-3fdd-aef9-57ae4313ca88",
"readOnly": true,
"resources": [
        {
"accountId": "123456789012",
"type": "AWS::SES::ConfigurationSet",
"ARN": "arn:aws:ses:us-east-1:123456789012:configuration-set/gcp-iad-prod-workmail-default-configuration-set"
        },
        {
"accountId": "123456789012",
"type": "AWS::SES::EmailIdentity",
"ARN": "arn:aws:ses:us-east-1:123456789012:identity/malicious-organiation[.]com"
        }
    ],
"eventType": "AwsApiCall",
"managementEvent": false,
"recipientAccountId": "123456789012",
"sharedEventID": "xxx",
"eventCategory": "xxx"}</pre><p><span><em>Listing 4: </em></span><span><span data-type="inlineCode"><em>SendRawEmail</em></span></span><span><em> event logged after an email is sent via AWS WorkMail web interface</em></span><em>⠀</em></p><p>⠀</p><p><span>While limited, this telemetry can still be valuable for correlating suspicious sending behavior with recently created WorkMail users or newly verified domains.</span></p><p><span><strong>2. SMTP access</strong></span><br><span>Alternatively, the attacker can authenticate directly to WorkMail’s SMTP endpoint and send messages programmatically. Emails sent via SMTP</span><span><strong> </strong></span><span>do not generate CloudTrail events, even when SES data events are enabled, creating a significant blind spot for defenders.</span></p><p><span>An example Python script used to send email through WorkMail SMTP is shown below:</span></p><p>⠀</p><pre language="python">import smtplib
from email.message import EmailMessage

# Configuration
SMTP_SERVER = "smtp.mail.us-east-1.awsapps.com"
SMTP_PORT = 465
EMAIL_ADDRESS = "email@example.com"
EMAIL_PASSWORD = "****"

# Create the message
msg = EmailMessage()
msg["Subject"] = "WorkMail SMTP"
msg["From"] = EMAIL_ADDRESS
msg["To"] = "&lt;unverified_email&gt;"
msg.set_content("Email Delivered to an Unverified Email via AWS WorkMail")

# Send the email
try:
with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT) as smtp:
smtp.login(EMAIL_ADDRESS, EMAIL_PASSWORD)
smtp.send_message(msg)
print("Email sent successfully!")
except Exception as e:
print(f"Error: {e}")</pre><p><span><em>Listing 5: Example script sending messages via AWS WorkMail via SMTP</em></span></p><p>⠀</p><p><span>From an attacker’s perspective, this method is ideal: higher volume, immediate external reach, and minimal centralized logging. From a defender’s perspective, it underscores the importance of monitoring WorkMail organization creation, domain verification events, and mailbox provisioning, as these actions often precede phishing activity that will never be visible in CloudTrail.</span></p><h2>Conclusion</h2><p><span>This incident illustrates how threat actors can abuse higher-level AWS services to deploy phishing and spam infrastructure closely resembling legitimate enterprise usage. While AWS WorkMail is not designed to support bulk email operations, attackers can still leverage it as an interim capability alongside Amazon SES. By abusing WorkMail’s authenticated mailboxes and relaxed upfront controls, adversaries can begin sending lower volumes of email immediately — well before SES is moved out of the sandbox and higher sending quotas are approved. This staged approach allows attackers to establish sender reputation, validate infrastructure, and maintain operational momentum while bypassing many of the friction points intentionally built into SES.</span></p><p><span>To mitigate this class of abuse, organizations should combine preventive guardrails with focused detection. Where AWS WorkMail is not required, its use should be explicitly blocked using AWS Organizations Service Control Policies (SCPs) to prevent organization creation and mailbox provisioning. In environments where WorkMail is needed, IAM policies should enforce strict least-privilege access and treat WorkMail and SES administration as privileged operations subject to monitoring and approval. Finally, organizations should reduce the likelihood of initial access by implementing secure development and operational practices — such as secret scanning in code repositories, regular key rotation, and minimizing long-term access keys — to limit the impact of credential leakage and prevent attackers from converting compromised credentials into scalable email abuse.</span></p><h2>MITRE ATT&amp;CK techniques</h2><table><tbody><tr><td><p><strong>Tactic</strong></p></td><td><p><strong>Technique</strong></p></td><td><p><strong>Details</strong></p></td></tr><tr><td><p>Initial Access</p></td><td><p>Valid Accounts: Cloud Accounts (T1078.004)</p></td><td><p>The attacker authenticated to AWS using exposed long-term access keys validated with sts:GetCallerIdentity</p></td></tr><tr><td><p>Persistence</p></td><td><p>Create Account: Cloud Account (T1136.003)</p></td><td><p>The attacker created multiple IAM users and AWS WorkMail mailbox users to maintain persistent access</p></td></tr><tr><td><p>Privilege Escalation</p></td><td><p>Account Manipulation: Additional Cloud Roles (T1098.003)</p></td><td><p>The attacker attached the AdministratorAccess managed policy to a newly created IAM user</p></td></tr><tr><td><p>Discovery</p></td><td><p>Cloud Infrastructure Discovery (T1580)</p></td><td><p>The attacker enumerated IAM users and assessed Amazon SES configuration and sandbox status via API calls</p></td></tr><tr><td><p>Impact</p></td><td><p>Resource Hijacking: Cloud Service Hijacking (T1496.004)</p></td><td><p>The attacker abused AWS WorkMail and SES to send high-volume phishing and spam emails from the victim account</p></td></tr></tbody></table><h2>Indicators of compromise (IOCs)</h2><p><span>139.59.117[.]125</span></p><p><span>3.0.205[.]202</span></p><p><span>54.151.176[.]0</span></p><p><span><strong>Note: </strong></span><span>IP addresses </span><span><em>3.0.205[.]202</em></span><span> and </span><span><em>54.151.176[.]0 </em></span><span>are Amazon owned IP addresses so care should be taken when applying IP blocks.</span></p><h2>Rapid7 customers</h2><p><span>InsightIDR and Managed Detection and Response (MDR) customers have existing detection coverage through Rapid7’s expansive library of detection rules. These detections are deployed and will alert on the behaviors described in this technical analysis.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Acquires Human Native to Strengthen AI Data Security]]></title>
<description><![CDATA[Cloudflare, the San Francisco-based cybersecurity and internet infrastructure giant, has acquired Human Native, a UK-based AI data marketplace. The deal aims to empower content creators with control over their data in the generative AI era, addressing rising tensions around web scraping and bot t...]]></description>
<link>https://tsecurity.de/de/3215561/it-security-nachrichten/cloudflare-acquires-human-native-to-strengthen-ai-data-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3215561/it-security-nachrichten/cloudflare-acquires-human-native-to-strengthen-ai-data-security/</guid>
<pubDate>Thu, 15 Jan 2026 18:35:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cloudflare, the San Francisco-based cybersecurity and internet infrastructure giant, has acquired Human Native, a UK-based AI data marketplace. The deal aims to empower content creators with control over their data in the generative AI era, addressing rising tensions around web scraping and bot traffic. Human Native specializes in converting unstructured multimedia videos, articles, and more […]</p>
<p>The post <a href="https://cybersecuritynews.com/cloudflare-acquires-human-native/">Cloudflare Acquires Human Native to Strengthen AI Data Security</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quantizing LLMs Step-by-Step: Converting FP16 Models to GGUF]]></title>
<description><![CDATA[Large language models like LLaMA, Mistral, and Qwen have billions of parameters that demand a lot of memory and compute power.]]></description>
<link>https://tsecurity.de/de/3213848/ai-nachrichten/quantizing-llms-step-by-step-converting-fp16-models-to-gguf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3213848/ai-nachrichten/quantizing-llms-step-by-step-converting-fp16-models-to-gguf/</guid>
<pubDate>Thu, 15 Jan 2026 02:46:57 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Large language models like LLaMA, Mistral, and Qwen have billions of parameters that demand a lot of memory and compute power.]]></content:encoded>
</item>
<item>
<title><![CDATA[Can retired naval power plants solve the data center power crunch?]]></title>
<description><![CDATA[Addressing the critical power shortage for AI data centers has made nuclear energy fresh and new again years after it fell out of favor. There is considerable activity among established players like Constellation Energy and startups like Oklo alike. However, a Texas power developer has found an u...]]></description>
<link>https://tsecurity.de/de/3210918/it-security-nachrichten/can-retired-naval-power-plants-solve-the-data-center-power-crunch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3210918/it-security-nachrichten/can-retired-naval-power-plants-solve-the-data-center-power-crunch/</guid>
<pubDate>Tue, 13 Jan 2026 18:49:27 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Addressing the <a href="https://www.networkworld.com/article/4058123/power-shortages-are-the-only-thing-slowing-the-data-center-market.html">critical power shortage</a> for AI data centers has <a href="https://www.networkworld.com/article/3613868/data-centers-go-nuclear-for-power-hungry-ai-workloads.html">made nuclear energy</a> fresh and new again years after it fell out of favor. There is considerable activity among established players like Constellation Energy and startups like <a href="https://www.networkworld.com/article/3564290/google-bets-on-nuclear-power-to-drive-ai-expansion.html">Oklo</a> alike. However, a Texas power developer has found an unlikely source for nuclear power plants: retired naval vessels.</p>



<p>Bloomberg <a href="https://www.bloomberg.com/news/articles/2025-12-24/nuclear-developer-proposes-using-navy-reactors-for-data-centers">reported</a> late last year that <a href="https://www.hgpenergy.com/">HGP Intelligent Energy LLC</a> is proposing to repurpose nuclear reactors from Navy warships, starting with the soon-to-be retired carrier USS Nimitz.</p>



<p>In its application to the Department of Energy, HGP proposes to redirect two retired reactors to a data center project proposed at Oak Ridge, Tennessee.</p>



<p>The plan is projected to produce about 450-520 mW of steady power, enough to power roughly 360,000 homes. Or one data center. The reactors would come from the USS Nimitz, which is headed toward retirement, to be replaced by a newer Gerald R Ford class carrier.</p>



<p>The Nimitz isn’t the only carrier headed to the boneyard; 10 <a href="https://en.wikipedia.org/wiki/Nimitz-class_aircraft_carrier">Nimitz class carriers</a> in total are due for retirement as they are replaced by Ford class carriers. Also, the aging Los Angeles class of nuclear submarines are being retired and replaced with Virginia class submarines, and those subs also have nuclear power plants, albeit not as powerful as the ones in the carriers.</p>



<p>Rewiring the reactors would cost about $1 million to $4 million per megawatt, a fraction of building new reactor, according to the proposal. The project is not a quick one; it requires 5 stages and is estimated to take a decade.</p>



<p>HGP’s plan includes a revenue share with the government, and the company would create a decommissioning fund, according to Bloomberg.</p>



<p>The alternative? After a lengthy decommissioning process, the reactors are shipped to a remote storage facility in Washington state together dust along with dozens of other retired nuclear reactors.</p>



<p>So the carrier itself isn’t going to be turned into a data center, but its power plants are being proposed for a data center on land. And even with the lengthening decommissioning process, that’s still faster than building a nuclear power plant from scratch.</p>



<p>Don’t hold your breath, says <a href="https://www.linkedin.com/in/kristen-vosmaer-0580131/">Kristen Vosmaer, managing director, JLL Work Dynamics Data</a> Center team. The idea of converting USS Nimitz’s nuclear reactors to power AI data centers sounds compelling but faces insurmountable obstacles, he argues.</p>



<p>“Naval reactors use weapons-grade uranium that civilian entities cannot legally possess, and the Nuclear Regulatory Commission has no pathway to license such facilities. Even setting aside the fuel issue, these military-designed systems would require complete reconstruction to meet civilian safety standards, eliminating any cost advantages over purpose-built nuclear plants,” Vosmaer said.</p>



<p>The maritime concept itself, however, does have some merit, said Vosmaer. “Ocean cooling can reduce energy consumption compared to land-based data centers, and floating platforms offer positioning flexibility that fixed facilities cannot match,” Vosmaer said.</p>



<p>Instead of pursuing nuclear, we are seeing floating natural gas turbine barges present a viable alternative. These proven systems operate within established regulatory frameworks and can deploy in 12-24 months rather than the unclear timeline around nuclear licensing.</p>



<p>“Natural gas barges combine reliable power generation with efficient seawater cooling, creating an energy solution that can scale incrementally and relocate as needed,” said Vosmaer.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[You Can Now Reserve a Hotel Room On the Moon For $250,000]]></title>
<description><![CDATA[A newly founded startup called GRU Space is taking deposits of up to $1 million to eventually build inflatable hotels on the Moon. The bet is that space needs destinations, not just rockets, even if the first customers are essentially early adopters of sci-fi optimism. Ars Technica reports: It so...]]></description>
<link>https://tsecurity.de/de/3209496/it-security-nachrichten/you-can-now-reserve-a-hotel-room-on-the-moon-for-250000/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3209496/it-security-nachrichten/you-can-now-reserve-a-hotel-room-on-the-moon-for-250000/</guid>
<pubDate>Tue, 13 Jan 2026 08:20:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A newly founded startup called GRU Space is taking deposits of up to $1 million to eventually build inflatable hotels on the Moon. The bet is that space needs destinations, not just rockets, even if the first customers are essentially early adopters of sci-fi optimism. Ars Technica reports: It sounds crazy, doesn't it? After all, GRU Space had, as of late December when I spoke to founder Skyler Chan, a single full-time employee aside from himself. And Chan, in fact, only recently graduated from the University of California, Berkeley. [...] The GRU in the company's name, by the way, stands for Galactic Resource Utilization. The long-term vision is to derive resources from the Moon, Mars, asteroids, and beyond to fuel human expansion into space.
 
If all that sounds audacious and unrealistic, well, it kind of is. But it is not without foundation. GRU Space has already received seed funding from Y Combinator, and it will go through the organization's three-month program early this year. This will help Chan refine his company's product and give him more options to raise money. Regarding his vision, you can read GRU Space's white paper here.
 
Presently, the company plans to fly its initial "mission" in 2029 as a 10-kg payload on a commercial lunar lander, demonstrating an inflatable structure capability and converting lunar regolith into Moon bricks using geopolymers. With its second mission, the company plans to launch a larger inflatable structure into a "lunar pit" to test a scaled-up version of its resource development capabilities.
 
The first hotel, an inflatable structure, would be launched in 2032 and would be capable of supporting up to four guests at a time. The next iteration beyond this would be the fancier structure, built from Moon bricks, in the style of the Palace of the Fine Arts. "SpaceX is building the FedEx to get us there, right?" Chan said. "But there has to be a destination worthy to stay in. Obviously, there is all kinds of debate around this, and what the future is going to be like. But our conviction is that the fundamental problem we have to solve, to advance humans toward the Moon and Mars, is off-world habitation. We can't keep everyone living on that first ship that sailed to North America, right? We have to build the roads and structures and offices that we live in today."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=You+Can+Now+Reserve+a+Hotel+Room+On+the+Moon+For+%24250%2C000%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F01%2F13%2F0358216%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F01%2F13%2F0358216%2Fyou-can-now-reserve-a-hotel-room-on-the-moon-for-250000%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/01/13/0358216/you-can-now-reserve-a-hotel-room-on-the-moon-for-250000?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Breaking Down the Attack Surface of the Kenwood DNR1007XR – Part Two]]></title>
<description><![CDATA[In our previous Kenwood DNR1007XR blog, we detailed the internals of the Kenwood in-vehicle infotainment (IVI) head unit and provided annotated pictures of the main PCB. In this post, we aim to outline the attack surface of the DNR1007XR in the hopes of providing inspiration for vulnerability res...]]></description>
<link>https://tsecurity.de/de/3204245/hacking/breaking-down-the-attack-surface-of-the-kenwood-dnr1007xr-part-two/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3204245/hacking/breaking-down-the-attack-surface-of-the-kenwood-dnr1007xr-part-two/</guid>
<pubDate>Fri, 09 Jan 2026 16:07:18 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">In our previous Kenwood DNR1007XR <a href="https://www.zerodayinitiative.com/blog/2026/1/6/breaking-down-the-attack-surface-of-the-kenwood-dnr1007xr-part-one">blog</a>, we detailed the internals of the Kenwood in-vehicle infotainment (IVI) head unit and provided annotated pictures of the main PCB. In this post, we aim to outline the attack surface of the DNR1007XR in the hopes of providing inspiration for vulnerability research.</p><p class="">We will cover the main supported technologies that present potential attack surfaces, such as USB, Bluetooth, Android Auto, Apple CarPlay, Kenwood apps, and more.</p><p class="">All information has been obtained through reverse engineering, experimenting, and combing through the following resources:</p><p class="">·      DNR1007XR <a href="https://www.kenwood.com/usa/car/excelon_reference/dnr1007xr/">product page</a><br>·      DNR1007XR <a href="https://manuals.jvckenwood.com/download/files/IM403_ref_K_En_00.pdf">instruction manual</a><br>·      DNR1007XR <a href="https://manuals.jvckenwood.com/download/files/B5K-0760-00_K.pdf">quick start guide</a><br>·      Kenwood <a href="https://www.kenwood.com/car/app/kenwood_portal_app/eng/">Portal</a> app<br>·      Kenwood <a href="https://www.kenwood.com/car/app/kenwood_remote_s/eng/">Remote S</a> app</p><p class=""><strong>USB</strong></p><p class="">The DNR1007XR is equipped with a single USB-A port that operates at USB 2.0 speeds, providing the necessary interface for wired Android Auto and Apple CarPlay. </p><p class="">The USB port also supports playback of audio files from a USB flash drive. The supported audio filetypes and their associated extensions are:</p><p class="">·      MP3 (.mp3)<br>·      WMA (.wma)<br>·      AAC-LC (.m4a)<br>·      WAV (.wav)<br>·      FLAC (.flac, .fla)<br>·      Vorbis (.ogg)<br>·      DSD (.dsf, .dff)</p><p class="">As well as audio, a USB flash drive can also be used to play back video files. The supported video filetypes and their associated extensions are:</p><p class="">·      MPEG-1 (.mpg, .mpeg)<br>·      MPEG-2 (.mpg, .mpeg)<br>·      H.264 / MPEG-4 (.mp4, .m4v, .avi, .flv, .f4v)<br>·      WMV (.wmv)<br>·      MKV (.mkv)</p><p class="">Robustly parsing and decoding these file formats is notoriously complicated and error-prone, which makes for a potentially rewarding attack surface. </p><p class="">USB flash drives must be formatted as either FAT16, FAT32, exFAT, or NTFS for the head unit to be able to read them.</p><p class=""><strong>SD Card</strong></p><p class="">A full-sized SD card slot is tucked away behind the screen and is used for audio/video playback as well as updating map data. As previously mentioned, a large attack surface is exposed when parsing audio and video files. Map updates are likely a good research target, too.</p><p class="">SD cards must be formatted as either FAT16, FAT32, exFAT, or NTFS for the head unit to be able to read them.</p><p class=""><strong>Bluetooth</strong></p><p class="">Bluetooth version 5 is supported by the head unit and is used for making and receiving phone calls, as well as playing audio from a paired mobile phone. The following Bluetooth profiles are officially documented in the user manual:</p><p class="">·      Hands Free Profile v1.7<br>·      Serial Port Profile<br>·      Phonebook Access Profile<br>·      Audio/Video Remote Control Profile (AVRCP) v1.6<br>·      Advanced Audio Distribution Profile (A2DP)<br>        o   Supporting codecs: SBC, AAC, or LDAC</p><p class="">Android Auto, Apple CarPlay, and the Kenwood apps also utilise Bluetooth in varying capacities. </p><p class="">Interrogating the unit shows a few more Bluetooth services that are not documented; these could be a great area to research. Judging by the service names, they may all be related to Kenwood apps.</p>





















  
  



<pre><code class="language-Service">Service RecHandle: 0x10003
Service Class ID List:
  UUID 128: 00001101-0000-1000-8000-00805f9b34fb
Protocol Descriptor List:
  "L2CAP" (0x0100)
  "RFCOMM" (0x0003)
    Channel: 2

Service Name: App1
Service RecHandle: 0x10004
Service Class ID List:
  UUID 128: 00000000-deca-fade-deca-deafdecacaff
Protocol Descriptor List:
  "L2CAP" (0x0100)
  "RFCOMM" (0x0003)
    Channel: 3

Service Name: App2
Service RecHandle: 0x10005
Service Class ID List:
  UUID 128: 4de17a00-52cb-11e6-bdf4-0800200c9a66
Protocol Descriptor List:
  "L2CAP" (0x0100)
  "RFCOMM" (0x0003)
    Channel: 4

Service Name: App3
Service RecHandle: 0x10006
Service Class ID List:
  UUID 128: 4de17a00-52cb-11e6-bdf4-0800200c9a66
Protocol Descriptor List:
  "L2CAP" (0x0100)
  "RFCOMM" (0x0003)
    Channel: 5

Service Name: App4
Service RecHandle: 0x10007
Service Class ID List:
  UUID 128: 4de17a00-52cb-11e6-bdf4-0800200c9a66
Protocol Descriptor List:
  "L2CAP" (0x0100)
  "RFCOMM" (0x0003)
    Channel: 6

Service Name: App5
Service RecHandle: 0x10008
Service Class ID List:
  UUID 128: 4de17a00-52cb-11e6-bdf4-0800200c9a66
Protocol Descriptor List:
  "L2CAP" (0x0100)
  "RFCOMM" (0x0003)
    Channel: 7</code></pre>




  <p class=""><strong>Wi-Fi</strong></p><p class="">The head unit provides a WiFi access point that is primarily used for wireless Android Auto and Apple CarPlay. There is no intention for the end user to directly connect to this network and there is no officially documented way of acquiring the password. However, internal research has discovered multiple methods to obtain the password.</p><p class="">Once connected to the access point, the following ports are open:</p><p class="">·      TCP: 7000, 8086, 8888, 5355, 22<br>·      UDP: 67, 5353, 5355, 34613, 50842</p><p class="">TCP 22 is an SSH server and can be logged into. As per the <a href="https://www.zerodayinitiative.com/Pwn2OwnAuto2026Rules.html">competition rules</a>, "If the entry leverages hardcoded credentials and/or exposed encryption keys, the entry must leverage an additional vulnerability to gain code execution to be in scope."</p><p class="">TCP 7000, 8086, and 8888 are all running non-standard services and are likely great places to research further.</p><p class=""><strong>Android Auto and Apple CarPlay</strong></p><p class="">Both wired and wireless Android Auto and Apple CarPlay are supported without the need for a 3rd party app to be installed on the paired mobile phone. When using the wireless versions, the paired phone connects to the aforementioned secured WiFi network to establish a high-bandwidth channel for data to be sent and received.</p><p class="">When connecting using a USB cable, the WiFi network isn't used by Android Auto or Apple CarPlay, but it is still active.</p><p class=""><strong>Kenwood</strong></p><p class="">Kenwood offers 2 Android/iOS apps to interface with the DNR1007XR. The first app is the <a href="https://play.google.com/store/apps/details?id=com.jvckenwood.car_multimedia_app.kenwood">Kenwood Portal App</a><strong>,</strong> which allows users to transfer photos from a mobile phone to the head unit over Bluetooth. The transferred photos can then be viewed as a slideshow on the head unit or be used as the wallpaper.</p><p class="">This presents an interesting attack surface, especially if the DNR1007XR itself performs any complex image handling tasks on the received images, such as resizing or converting between different image formats. The user-supplied images also need to be persisted to the head unit's filesystem, further expanding the attack surface.</p><p class="">The second app is the <a href="https://play.google.com/store/apps/details?id=com.jvckenwood.kwdremotes">Kenwood Remote S app</a>, which connects to the head unit over Bluetooth and allows for multimedia control such as selecting a radio station, skipping a track, and more. The Bluetooth Audio/Video Remote Control Profile (AVRCP) is designed for this exact task; however, no research was performed to confirm if the Remote S app takes advantage of AVRCP.</p><p class="">There are a few other Kenwood apps available, but they are not listed as supported on the DNR1007XR product page and therefore have not been explored.</p><p class=""><strong>Open Source Software</strong></p><p class="">A list of open source licences can be viewed from the head unit by navigating to Settings -&gt; System -&gt; Open Source Licenses. There's no guarantee these open source projects are actually used by the unit.</p><p class=""><strong>Summary</strong></p><p class="">We hope that this blog post has provided enough information about the DNR1007XR threat landscape to guide vulnerability research. Not every attack surface has been mentioned, and we encourage researchers to investigate further.</p><p class="">We are looking forward to <a href="https://www.zerodayinitiative.com/blog/2024/9/23/announcing-pwn2own-automotive-for-2025">Automotive Pwn2Own</a> again in Tokyo in January 2026 at Automotive World, and we will see if IVI vendors have improved their product security. Don’t wait until the last minute to ask questions and register! We hope to see you there.</p><p class="">You can find me on Twitter <a href="https://www.x.com/ByteInsight">@ByteInsight</a>, and follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Black & Veatch is democratizing AI expertise across its employee owners]]></title>
<description><![CDATA[Black & Veatch’s AI strategy demonstrates how thoughtful implementation can drive rapid, meaningful adoption across a large organization. Rather than deploying AI tools companywide and hoping for results, it’s built a cohort-based program that’s driven active and specific AI work usage to nearly ...]]></description>
<link>https://tsecurity.de/de/3199233/it-security-nachrichten/how-black-veatch-is-democratizing-ai-expertise-across-its-employee-owners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3199233/it-security-nachrichten/how-black-veatch-is-democratizing-ai-expertise-across-its-employee-owners/</guid>
<pubDate>Wed, 07 Jan 2026 11:06:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Black &amp; Veatch’s AI strategy demonstrates how thoughtful implementation can drive rapid, <a href="https://www.cio.com/article/4107301/the-human-side-of-ai-adoption-why-executive-mindset-will-determine-its-success.html?utm=hybrid_search">meaningful adoption</a> across a large organization. Rather than deploying AI tools companywide and hoping for results, it’s built a cohort-based program that’s driven active and specific AI work usage to nearly half of its employee owners in just one year. The approach addresses the human factors that often derail AI initiatives by building champion networks, eliminating friction, and converting employee passion into tangible workplace and business benefits. By also combining partner-provided AI capabilities with proprietary tools trained on 110 years of engineering data, Black &amp; Veatch is creating a multiplier effect that enables safety improvement, profitability, and increased resource capacity.</p>



<p><strong>How is AI making its way into your business strategy?</strong></p>



<p>We anchor our AI opportunities to three areas: safety, resourcing improvements, and profitable returns for our employee owners. With market demand increasing, particularly the power needs of data centers, we’re using AI to democratize knowledge across our engineers so Black &amp; Veatch can deliver more strategic and accelerated solutions.</p>



<p><strong>How are you embedding this strategy?</strong></p>



<p>We’ve defined our AI capabilities continuum as foundational, differentiating, and enduring with a focus on four themes across gen AI, agentic AI, and MLOps.</p>



<p>The first theme is iterative innovation, which lowers the <a href="https://www.cio.com/article/4001333/it-leaders-top-5-barriers-to-ai-success.html?utm=hybrid_search">barriers to effective use of AI</a> for all by driving adoption of Microsoft’s integrated gen AI capabilities.</p>



<p>Second is placing strategic bets on platforms for engineering, construction, HR, sales, and marketing while leveraging our strategic partners’ platform-specific generative and agentic AI strategies. We want the big providers to bring the models to us, so when an employee asks to use Claude, Perplexity AI, or ChatGPT, it’s fine to use a governed user experience like Microsoft 365 Copilot to bring those models to the user.</p>



<p>Third is disruptive innovation, which focuses less on provider AI and more on our own data. We’re rich in unstructured, natural language data from 110 years of documentation to engineer and deliver critical infrastructure. Our new BV ASK platform applies generative models against data, democratizing and improving functional expertise across engineering disciplines. So we’re leveraging AI and our data to create that multiplier effect of expertise.</p>



<p>Our fourth theme is in the MLOps space, turning our project sites into trillions of <a href="https://www.cio.com/article/4110545/delivering-resilience-and-continuity-for-ai.html?utm=hybrid_search">data points</a> that train models to advance our work. We’re advancing plans to collect telemetry from job site equipment, employee wearables for safety monitoring, geofencing technology, and drones with computer vision to create multivariate models that can help predict the success and profitability of new projects. Rather than turn down good work, we’re creating an AI-driven feedback loop to increase our margins.</p>



<p><strong>The human factor is the sticking point in driving AI adoption. How are you changing minds and behaviors?</strong></p>



<p>I’ve seen CIOs give everybody Microsoft 365 Copilot and watch adoption hover at five to 10%. Instead, we started by using early successes with Copilot to build a champion network to influence more adoption. We picked a few powerful use cases, identified personas who’d benefit from those use cases, and created a cohort of early adopters. Then we found another set of use cases and created another cohort, so today, approximately 5,000 employee owners engage in AI cohorts at Black &amp; Veatch, with 97% active usage of our core AI capabilities.</p>



<p>Curriculum within each cohort includes hands-on training and spark sessions to encourage growth and engagement within the community itself. In a few months, we expect to have about 7,500 of our employee owners through a program cohort, and 75% of our employee base actively using generative AI to support their work.</p>



<p>We ask our cohorts for three things: to actively incorporate AI into your daily job, participate enthusiastically in the cohort community, and be a net producer for the community versus a net consumer. The cohorts not only increase AI skill development, but <a href="https://www.cio.com/article/4109190/cios-top-resolution-should-be-to-create-a-visions-rich-2026.html?utm=hybrid_search">drive a whole new level of collaboration</a> across departments.</p>



<p><strong>What’s your advice for CIOs who need to balance AI innovation and data security?</strong></p>



<p>Just as access to the internet and social media platforms took some time to govern in corporations, AI is bringing similar consumer-driven urgency that we need to understand and use to drive efficiencies. People see that AI provides a tangible way to improve their personal lives, so when our teams come into our offices, they expect to have the same access to AI platforms to improve their work efficiency.</p>



<p>My first piece of advice is to educate your teams about the need for innovation and guardrails. We set up an AI governance committee and launched several campaigns coupled with cybersecurity awareness month to outline what we’re doing to deliver experiences using BV data, but within secure and safe guardrails. We also have a technology showcase every year where we educate ourselves on the why and how: why we need the guardrails and how to use the tools. Rather than restricting access, the approach we’re taking is to eliminate friction and frustration while establishing clear guidance and data security controls.</p>



<p>Also, establish a formal process to increase the overall AI acumen across the entire company. AI is different from the innovations of Metaverse and blockchain. People understand AI because it’s so tangible. They can use natural language to create interesting things, so the barriers to innovation are low.</p>



<p>And of course, use every opportunity to shift mindsets. When people express interest in AI tools, I ask them to send me an email with the answer to two questions: Why is this new capability interesting to you, and how will it allow you to do your job better? If the response is thoughtful, we pull them into an earlier cohort immediately. This removes potential frustration by converting their passion into a benefit of a cohort where they can apply their ideas.</p>



<p><strong>What’s the key motivation behind this cohort program?</strong></p>



<p>The most critical factor in AI-driven transformation, and in society, is the human element. Our program helps build a level playing field to enable all Black &amp; Veatch creators to do what they do best — create! This new but foundational knowledge across the company allows us to pursue more advanced opportunities with AI. As collective knowledge increases, this opens even more to further advance AI enablement within engineering, and even out in the field. We’re beginning to see it already.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit 2025 Annual Wrap-Up]]></title>
<description><![CDATA[Hard to believe it's that time again, and that Metasploit Framework will see the dawn of another Annual Wrap-Up (and a New Year). All of the metrics and modules you see here would in large part not be possible without the dedicated community members who care about the Framework and its mission on...]]></description>
<link>https://tsecurity.de/de/3195989/it-security-nachrichten/metasploit-2025-annual-wrap-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3195989/it-security-nachrichten/metasploit-2025-annual-wrap-up/</guid>
<pubDate>Mon, 05 Jan 2026 22:53:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hard to believe it's that time again, and that Metasploit Framework will see the dawn of another Annual Wrap-Up (and a New Year). All of the metrics and modules you see here would in large part not be possible without the dedicated community members who care about the Framework and its mission on all the days of the year. It is their hard work and dedication that makes it look like magic, and sometimes, it feels like it too. A heartfelt thank you to all of our researchers and contributors, you're what makes Metasploit Framework so resilient.</p><p>This year brought its share of notable vulnerabilities, substantial framework improvements, and continued evolution of the project. Whether you submitted a module, filed an issue, or helped triage a bug, your contributions have kept Metasploit relevant and powerful. So without further ado, let's dive into the highlights from 2025.</p><h2>Persistence Overhaul</h2><p>One of the year's significant infrastructure improvements came from community contributor h00die, who spearheaded a massive refactor of Metasploit's persistence modules. The project, tracked in issue <a href="https://github.com/rapid7/metasploit-framework/issues/20374">#20374</a>, involved reorganizing dozens of persistence modules from their scattered locations across the framework into a dedicated persistence directory under exploits. This wasn't just housekeeping—h00die created a standardized persistence mixin that brought consistency to how modules handle installation, cleanup, and option handling. The refactor touched over 30 modules spanning Linux, Windows, OSX, and multi-platform techniques, modernizing each one with proper check methods, MITRE ATT&amp;CK references, and standardized options like WritableDir. The work also laid the groundwork for a persistence suggester module that can automatically recommend viable persistence techniques based on session characteristics.</p><p>The sheer scope of this effort can't be overstated. Breaking the work into manageable chunks, h00die systematically converted modules from the old post-exploitation style to proper exploit modules with the new persistence mixin, handling everything from cron jobs and SSH keys to Windows registry modifications and service installations. The standardization means that all persistence modules now share common behaviors, produce cleanup scripts in a consistent format, and integrate cleanly with the rest of the framework. It's the kind of unglamorous but essential work that improves the entire framework's usability and maintainability, and we're grateful to h00die for taking on such an ambitious project and seeing it through.</p><h2>AD CS Vulnerable Certificate Template Detection and Exploitation Additions</h2><p>This year, Metasploit expanded its Active Directory Certificate Services (AD CS) coverage by adding detection and exploitation support for certificate templates vulnerable to ESC9, ESC10, and ESC16. Checks for these misconfigured certificate templates were integrated into the existing ldap_esc_vulnerable_template module, allowing users to easily identify misconfigured templates during assessments.</p><p>To complement this detection capability, we introduced the new esc_update_ldap_object module, which enables reliable exploitation of these vulnerable templates to escalate privileges. ESC9, ESC10, and ESC16 share a common pattern: each requires control of a user account with write privileges over another user that is permitted to enroll in the vulnerable template. While exploiting these techniques with other tools typically involves multiple manual and error-prone steps, the new module streamlines the entire workflow. Users configure the required datastore options, run the module, and receive a certificate that can be used to escalate privileges within the domain.</p><p>As part of this effort, we also introduced the ldap_object_attribute module, which provides standard CRUD operations for manipulating LDAP objects in Active Directory. This module — along with existing functionality such as shadow_credentials and get_ticket — is used internally by esc_update_ldap_object to abstract away low-level LDAP interactions and simplify exploitation.</p><p>This work included comprehensive documentation covering the configuration of templates vulnerable to ESC9, ESC10, and ESC16, as well as detailed instructions for exploiting each technique using the new module.</p><h3>Active Directory Improvements</h3><p>Related to our AD CS improvements, came new low-level functionality for interacting with Active Directory (AD) Domain Controllers over LDAP. Over the past couple of years, Metasploit has seen multiple modules added that facilitate AD attack workflows including <a href="https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/auxiliary/admin/ldap/shadow_credentials.md">Shadow Credentials</a>, <a href="https://docs.metasploit.com/docs/pentesting/active-directory/kerberos/rbcd.html">RBCD</a>, <a href="https://docs.metasploit.com/docs/pentesting/active-directory/kerberos/unconstrained_delegation.html">Unconstrained Delegation</a>, etc. Like the AD CS attacks, many of these techniques are reliant on access control to some degree. Over the summer, Metasploit introduced <a href="https://github.com/rapid7/metasploit-framework/pull/20345">new functionality</a> to facilitate checking for these types of attacks. This new library provides Active Directory specific functionality, most notably, the ability to remotely evaluate security descriptors to determine whether a particular user or group has a specific access right. This has already been incorporated into the following modules to either enable or improve the existing detection capabilities.</p><ul><li>auxiliary/admin/ldap/shadow_credentials</li><li>auxiliary/admin/ldap/rbcd</li><li>auxiliary/admin/ldap/ad_cs_cert_template</li><li>auxiliary/gather/ldap_esc_vulnerable_cert_finder</li></ul><p>For module authors, the library provides a composable API for determining if an object grants a particular permission to an optional SID. The SID can be either a user or group, and when omitted is automatically set to the authenticating user, i.e. to check if the current connection has the permissions.</p><p>For example, check if the object grants the read and write property permissions with:</p>adds_obj_grants_permissions?(@ldap, obj, SecurityDescriptorMatcher::Allow.all(%i[RP WP]))<br><h2>Code Cleanup At Scale</h2><p>Beyond new features and modules, 2025 also saw substantial code quality improvements thanks to community contributor bcoles, who took on the often-thankless task of resolving RuboCop violations across the codebase. Throughout the year, bcoles systematically worked through older modules, cleaning up style inconsistencies, fixing syntax violations, and converting outdated property types to proper boolean values in auxiliary scanners and exploit modules. This kind of incremental maintenance work—fixing redundant parentheses here, resolving style violations there—doesn't make for flashy headlines, but it keeps the codebase maintainable and makes life easier for everyone working in the framework. Code quality matters, and we're grateful to bcoles for putting in the work to keep Metasploit's technical debt in check.</p><h2>Payload Improvements</h2><p>It may be a fun fact, or perhaps tribal knowledge that an “exploit” to Metasploit is a module that delivers a payload. All the great exploit content this year would be nothing without corresponding payloads to deliver and we make sure that those get plenty of our time as well. The following changes in particular are highly impactful and may have gone unnoticed while the flashier exploits received all the attention.</p><h3>Windows Meterpreter Improvements</h3><p>The biggest updates for the Windows Meterpreter revolve around two major improvements: the first is the upgrade to ReflectiveDLLInjection, made by Alex (xaitax) Hagenah, for which we express our gratitude for improving this area of the Metasploit Framework that requires a high level of attention to detail. This update introduces full, production-ready ARM64 support and a comprehensive architectural modernization of the whole library. These changes open the door to future support for a native ARM64 Meterpreter on Windows. Additionally, Metasploit split the standard API extension for Windows this year. This was actually the design used in the original Meterpreter implementation and we’ve reconsidered the monolithic approach. This improvement is one of the multiple steps we have in the pipeline to improve the evasion capabilities for our Windows Meterpreter. The standard API library now allows the user to load only specific subcomponents of the extension (for example, the component for network or file-system interaction), reducing the memory footprint for memory scanners. To leverage this new functionality, set AutoLoadStdapi to False, and then load one or more extensions manually, e.g. load stdapi_fs. To maintain backwards compatibility, a single stdapi extension is also still available and can be loaded with load stdapi.</p><h3>Fetch Payload Improvements</h3><p>The first milestone was the introduction of fileless execution for Linux fetch payloads, enabling payloads to run directly from memory using anonymous files. This advancement greatly enhances operational stealth by minimizing forensic traces and avoiding file-based detection, with careful attention to safe, opt-in behavior and collaborative code refinement. Following this, the FETCH_PIPE option streamlined payload deployment into a single, compact command. This improvement enhanced both usability and evasion, while also supporting larger, more complex command payloads (such as fileless execution) to be executed even with reduced command size. Additionally, fetch payload support has expanded to seven additional CPU architectures: aarch64, armbe, armle, mipsbe, mipsle, ppc, and ppc64le. This significantly broadens Metasploit's reach across embedded and legacy systems. Both features are thoroughly tested and future-proof, making the framework more versatile and powerful.</p><h3>New Architectures Basic Support</h3><p>This year, we have also updated the framework to support new basic payloads. We have introduced the exec payload for Windows ARM64 (provided by Alex (xaitax) Hagenah), reverse shell for RISC-V 32 and 64 bit, and Loongarch64 (both provided by bcoles).</p><h3>COMING SOON</h3><p>As much as we try, everything doesn’t always fit into one year. With that in mind, we wanted to highlight some upcoming features that we’re particularly excited to complete in the coming months.</p><h4>Malleable C2</h4><p>The malleable c2 will allow the user to specify with a .profile scribing how the HTTP requests between meterpreter and metasploit-framework should look like, allowing metasploit to hide the distinctive traffic generated by the session communication.</p><h4>Direct Syscall in Metsrv</h4><p>We have updated the Meterpreter core (metsrv) to remove common static signatures, such as specific strings and function imports, making it harder to detect.</p><h4>PoolParty for 32-bit systems</h4><p>Additional work to port the poolparty injection on native 32 bit system, Huge thanks to xHector1337 for taking over the research and extension of the code injection for the new architecture.</p><h2>SCCM Modules</h2><p>This year, Metasploit added two modules for targeting SCCM instances and recovering the Network Access Account credentials. These modules differ in how they perform the authentication. The first, auxiliary/admin/sccm/get_naa_credentials accepts credentials from the operator and will use them to authenticate and run the attack on demand. This pairs nicely with the auxiliary/admin/dcerpc/samr_account module when the operator can create a new machine account. However, when that’s not an option, Metasploit still has you covered with the auxiliary/server/relay/relay_get_naa_credentials variant that enables relaying NTLM authentication from an SMB server. These attack workflows were demonstrated at Black Hat and DEF CON over the summer and we anticipate they’ll remain useful in the future.</p><h2>Module Highlights</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20713">CVE-2025-9316, CVE-2025-11700 N-able N-Central XXE</a> – N-able N-Central is a popular Remote Monitoring and Management (RMM) platform. These two vulnerabilities, when combined, enable Metasploit to read local files without authenticating. This can be used to obtain a number of sensitive backup files from the application itself, or anything else on the host system. XXE attacks are a less common vulnerability, at least in Metasploit-land but this is a fantastic example of how impactful they can be.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20112">CVE-2025-22457 Ivanti Connect Secure Unauthenticated RCE</a> – Ivanti RCEs are always valuable and this module shows that memory corruption lives on in 2025. Not only is this exploit unauthenticated and reliable, it is a great example of how ROP chains can be used.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/19897">CVE-2024-55555 Invoice Ninja RCE</a> – This particular module leverages a PHP deserialization vulnerability within the application. While this vulnerability requires knowledge of the APP_KEY, successful exploitation could have significant financial implications. As an added bonus, this module came with a new library adding support for Laravel Framework-specific cryptography methods.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/19950">CVE-2024-55556 InvoiceShelf RCE</a> – Everyone loves a good pairing, and this module continues h00die-gr3y’s work on invoicing software, showing that they’re useful for receiving more than just payments.</li><li>LDAP Password Disclosure – This module has been around for a while, but received some new features in 2025 for targeting Active Directory Domain Controllers. The <a href="https://github.com/rapid7/metasploit-framework/pull/20017">first</a> added support for LAPSv1 and v2, enabling the module to recover the local admin account on systems. Later in the year, a <a href="https://github.com/rapid7/metasploit-framework/pull/20401">second</a> improvement added support for gMSA accounts. This module also pairs nicely with the new <a href="https://github.com/rapid7/metasploit-framework/pull/19832">SMB to LDAP NTLM Relay</a> module we added this year as well.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20409">Microsoft SharePoint ToolPane Unauthenticated RCE (CVE-2025-53770 and CVE-2025-53771)</a></li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20060">Exploit module for CVE-2025-32433 (Erlang/OTP)</a></li></ul><h3>SMB Relay Expansion</h3><p>This year, Metasploit significantly leveled up its relaying capabilities, transforming the framework’s only SMB to SMB relay capability into a powerful engine for lateral movement. Traditionally, SMB relaying was often the domain of standalone external tools, but through the dedicated work of the Metasploit team, these workflows are now seamlessly integrated into the framework</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/19832">SMB to LDAP relay module</a></li><li><a href="https://github.com/rapid7/metasploit-framework/pull/20637">SMB to MSSQL NTLM Relay module</a></li></ul><h2><span>Community Stats Recap</span></h2><p>A huge thank you from the entire Metasploit team to all 66 contributors in 2025. Your contributions and ideas are what continue to improve this tool every year. Notably, 41 of these were first-time contributors who added new code.</p><p>Here are some stats for 2025:</p><ul><li>Number of new modules: 139</li><li>Number of new bug fixes: 133</li><li>Number of new enhancements: 115</li><li>Number of new documentations: 19</li><li>Number of new payload enhancements: 18</li></ul><p>Contributors in 2025 (ordered by count)</p><ul><li>bcoles</li><li>h00die</li><li>Chocapikk</li><li>h00die-gr3y</li><li>Takahiro-Yoko</li><li>h4x-x0r</li><li>smashery</li><li>vognik (new in 2025)</li><li>jvoisin</li><li>xHector1337 (new in 2025)</li><li>jmartin-tech</li><li>mariomontecatine (new in 2025)</li><li>blue0x1 (new in 2025)</li><li>nakkouchtarek (new in 2025)</li><li>molecula2788</li><li>xaitax</li><li>happybear-21 (new in 2025)</li><li>e2002e</li><li>fabpiaf (new in 2025)</li><li>mekhalleh</li><li>JohannesLks (new in 2025)</li><li>BitTheByte (new in 2025)</li><li>todb</li><li>00nx (new in 2025)</li><li>DevBuiHieu (new in 2025)</li><li>SweilemCodes (new in 2025)</li><li>arpitjain099 (new in 2025)</li><li>L-codes</li><li>Zeecka (new in 2025)</li><li>aaryan-11-x</li><li>whotwagner</li><li>lafried (new in 2025)</li><li>sebaspf (new in 2025)</li><li>hantwister (new in 2025)</li><li>tastyrce (new in 2025)</li><li>easymoney322 (new in 2025)</li><li>gardnerapp</li><li>TheBigStonk (new in 2025)</li><li>0xAryan (new in 2025)</li><li>sempervictus</li><li>szymonj99</li><li>Mathiou04</li><li>vultza (new in 2025)</li><li>enty8080 (new in 2025)</li><li>SaiSakthidar (new in 2025)</li><li>Zedeldi (new in 2025)</li><li>stfnw (new in 2025)</li><li>mmacfadden (new in 2025)</li><li>daffainfo (new in 2025)</li><li>HamzaSahin61 (new in 2025)</li><li>survivant (new in 2025)</li><li>uhei</li><li>EchoSl0w (new in 2025)</li><li>jeffmcjunkin</li><li>BenoitDePaoli (new in 2025)</li><li>randomstr1ng</li><li>2tunnels (new in 2025)</li><li>rodolphopivetta (new in 2025)</li><li>RakRakGaming (new in 2025)</li><li>Desiree05 (new in 2025)</li><li>Wopseeion (new in 2025)</li><li>jphamgithub (new in 2025)</li><li>H4k1l (new in 2025)</li><li>fishBone000 (new in 2025)</li><li>xl4635 (new in 2025)</li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[WHILL Model C2 Electric Wheelchairs and Model F Power Chairs]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to take control over the product.
The following versions of WHILL Model C2 Electric Wheelchairs and Model F Power Chairs are affected:

Model C2 Electric WheelChair (CVE-2025-14346)
Mode...]]></description>
<link>https://tsecurity.de/de/3186637/it-security-nachrichten/whill-model-c2-electric-wheelchairs-and-model-f-power-chairs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3186637/it-security-nachrichten/whill-model-c2-electric-wheelchairs-and-model-f-power-chairs/</guid>
<pubDate>Tue, 30 Dec 2025 18:21:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsma-25-364-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to take control over the product.</strong></p>
<p>The following versions of WHILL Model C2 Electric Wheelchairs and Model F Power Chairs are affected:</p>
<ul>
<li>Model C2 Electric WheelChair (CVE-2025-14346)</li>
<li>Model F Power Chair (CVE-2025-14346)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>WHILL Inc.</td>
<td>WHILL Model C2 Electric Wheelchairs and Model F Power Chairs</td>
<td>Missing Authentication for Critical Function</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Japan</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-14346</a></h3>
<div class="csaf-accordion-content">
<p>WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-14346" data-entity-type="external">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>WHILL Model C2 Electric Wheelchairs and Model F Power Chairs</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>WHILL Inc.</div>
<div class="ics-version"><strong>Product Version:</strong><br>WHILL Inc. Model C2 Electric WheelChair: vers:all/*, WHILL Inc. Model F Power Chair: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>WHILL has deployed the following fixes on December 29th, 2025:</p>
<p><strong>Mitigation</strong><br>Device-Side Speed Profile Protection:</p>
<p><strong>Mitigation</strong><br>Implemented a safeguard in the wheelchair firmware to prevent unauthorized modification of speed profiles from the mobile application.</p>
<p><strong>Mitigation</strong><br>Unlock Command Restriction During Motion:</p>
<p><strong>Mitigation</strong><br>Block unlock commands issued from either the mobile app or the smart key while the wheelchair is in motion.</p>
<p><strong>Mitigation</strong><br>Application JSON File Obfuscation:</p>
<p><strong>Mitigation</strong><br>Obfuscate the configuration files used by the mobile application by converting JSON files into a binary format on both Android and iOS platforms.</p>
<p><strong>Mitigation</strong><br>For more information, contact WHILL Inc.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/306.html">CWE-306 Missing Authentication for Critical Function</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Billy Rios, Jesse Young, Brandon Rothel, Jonathan Butts, Henri Hein, Justin Boling, Nick Kulesza, Ken Natividad, and Carl Schuettthe of the Exploit Development Team - QED Secure Solutions reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>For more information, contact WHILL Inc.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2025-12-30</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2025-12-30</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shit for Future: turning human shit into a climate solution (39c3)]]></title>
<description><![CDATA[Humanity has already crossed the point where simply reducing emissions will no longer be enough to keep global warming below 2°C. According to the IPCC (AR6, WGIII), it is now essential to actively remove greenhouse gases from the atmosphere in order to meet global climate targets, maintain net-z...]]></description>
<link>https://tsecurity.de/de/3184603/it-security-video/shit-for-future-turning-human-shit-into-a-climate-solution-39c3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3184603/it-security-video/shit-for-future-turning-human-shit-into-a-climate-solution-39c3/</guid>
<pubDate>Mon, 29 Dec 2025 16:32:05 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Humanity has already crossed the point where simply reducing emissions will no longer be enough to keep global warming below 2°C. According to the IPCC (AR6, WGIII), it is now essential to actively remove greenhouse gases from the atmosphere in order to meet global climate targets, maintain net-zero (or even net-negative emissions), and address the burden of historical emissions. At the same time, degraded soils and the climate crisis are a threat to global food security.
Two years ago, I presented an overview of different methods available for carbon dioxide removal. Today, I want to show you an example of how CO₂ can be removed from the atmosphere while simultaneously improving the lives of local communities:

Human shit.

Human shit is a high abundant biomass, contains critical nutrients for global food security, and causes serious health and environmental issues from poor or non-existent treatment outside industrial countries. Converting shit into biochar presents a powerful solution: the process eliminates contaminants, stabilizes and locks away carbon, and can be used to improve agricultural soils. The challenge is that most nutrients in this biochar are not accessible to plants. To overcome this, I mixed human and chicken shit and produced a “Superchar” that releases far more nutrients. It’s not magic, it’s just some chemistry and putting aside your prejudices and disgust. I’ll show you how I did some shit experiments in Hamburg and Guatemala and how you can do it too.

Today’s science mostly follows worn-out pathways and lack big discoveries and innovations. Scientists often don’t want to take a risk because the competition for a permanent position in academia is so high, which pressures them into conservative research topics supported by their supervisors. Even when science provides helpful solutions for urgent problems, the knowledge mostly ends up in libraries, written in papers that nobody understands. I want to show that it is worthwhile to follow research ideas that are unconventional, upset your boss af and explore topics that are unpopular like working with shit. I hope that sharing stories of how a funny idea turned into a solution encourage others to start making impact in their environment.

Licensed to the public under http://creativecommons.org/licenses/by/4.0
about this event: https://events.ccc.de/congress/2025/hub/event/detail/shit-for-future-turning-human-shit-into-a-climate-solution]]></content:encoded>
</item>
<item>
<title><![CDATA[Greenhouse Gas Emission Data: Public, difficult to access, and not always correct (39c3)]]></title>
<description><![CDATA[Data about greenhouse gas emissions, both from countries and individual factories, is
often publicly available. However, the data sources are often not as accessible and
reliable as they should be. EU emission databases contain obvious flaws, and nobody
wants to be responsible.

Which factory in ...]]></description>
<link>https://tsecurity.de/de/3184246/it-security-video/greenhouse-gas-emission-data-public-difficult-to-access-and-not-always-correct-39c3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3184246/it-security-video/greenhouse-gas-emission-data-public-difficult-to-access-and-not-always-correct-39c3/</guid>
<pubDate>Mon, 29 Dec 2025 13:02:37 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Data about greenhouse gas emissions, both from countries and individual factories, is
often publicly available. However, the data sources are often not as accessible and
reliable as they should be. EU emission databases contain obvious flaws, and nobody
wants to be responsible.

Which factory in my city is the largest emitter of CO2? Which industrial sector is
responsible for the largest share of a country's contribution to climate change? It
should not be difficult to answer these questions. Public databases and reporting
required by international agreements usually allow us to access this data.

However, trying to access and work with these datasets — or, shall we say, Excel tables
— can be frustrating. UN web pages that prevent easy downloads with a &quot;security
firewall&quot;, barely usable frontends, and other issues make it needlessly difficult to
gain transparency about the sources of climate pollution.

While working with official EU datasets, the speaker observed data points that could not
possibly be true. Factories suddenly dropped their emissions by orders of magnitude
without any explanation, different official sources report diverging numbers for the
same emission source, and responsible European and National authorities appear not to
care that much.

The talk will show how to work with relevant greenhouse gas emission data sources and
how we can access them more easily by converting them to standard SQL tables. Furthermore, we will dig into some of the
strange issues one may find while investigating emission datasets.

# Background / Links

* Why is it needlessly difficult to access UNFCCC Emission Data? &lt;https://industrydecarbonization.com/news/why-is-it-needlessly-difficult-to-access-unfccc-emission-data.html&gt;
* UNFCCC Emission Data Downloads: &lt;https://industrydecarbonization.com/docs/unfccc/&gt;
* Code (Docker, MariaDB/MySQL, phpMyAdmin) to easily access EU emisison data: &lt;https://github.com/decarbonizenews/ghgsql&gt;

Licensed to the public under http://creativecommons.org/licenses/by/4.0
about this event: https://events.ccc.de/congress/2025/hub/event/detail/greenhouse-gas-emission-data-public-difficult-to-access-and-not-always-correct]]></content:encoded>
</item>
<item>
<title><![CDATA[Australia Poised for Desalination Boom as Water Shortages Loom]]></title>
<description><![CDATA[Australia is on track for a significant expansion of desalination capacity -- converting seawater to freshwater -- to meet the needs of a swelling population at a time of declining average rainfall. From a report: The world's driest inhabited continent is projected to build or expand 11 desalinat...]]></description>
<link>https://tsecurity.de/de/3176635/it-security-nachrichten/australia-poised-for-desalination-boom-as-water-shortages-loom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3176635/it-security-nachrichten/australia-poised-for-desalination-boom-as-water-shortages-loom/</guid>
<pubDate>Tue, 23 Dec 2025 19:34:40 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Australia is on track for a significant expansion of desalination capacity -- converting seawater to freshwater -- to meet the needs of a swelling population at a time of declining average rainfall. From a report: The world's driest inhabited continent is projected to build or expand 11 desalination plants worth more than A$23 billion ($15 billion) over the next 10 years, according to a research report by Dominic McNally at Oxford Economics. 

"Our population growth forecasts imply an additional 190GL/year in household water demand across major cities by 2035, while the booming data center industry also threatens to rapidly expand urban water use," he said. "This growing demand coincides with falling average rainfall in major population centers, increasing the vulnerability of existing infrastructure." Water construction activity slowed after 2010 as a severe drought receded. However, recent dry periods have reignited interest in water security and coincide with a new boom in water infrastructure investment, including desalination, McNally said.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Australia+Poised+for+Desalination+Boom+as+Water+Shortages+Loom%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F12%2F23%2F1816257%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F12%2F23%2F1816257%2Faustralia-poised-for-desalination-boom-as-water-shortages-loom%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/25/12/23/1816257/australia-poised-for-desalination-boom-as-water-shortages-loom?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Save a Sticker From iMessage]]></title>
<description><![CDATA[iMessage stickers provide a fun way to express emotions and add personality to your digital conversations. While sending them is simple, many users struggle to figure out how to keep a sticker sent by a friend. Saving these graphics allows you to reuse them in your own chats and build a personali...]]></description>
<link>https://tsecurity.de/de/3170669/ios-mac-os/how-to-save-a-sticker-from-imessage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3170669/ios-mac-os/how-to-save-a-sticker-from-imessage/</guid>
<pubDate>Sat, 20 Dec 2025 06:20:36 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[iMessage stickers provide a fun way to express emotions and add personality to your digital conversations. While sending them is simple, many users struggle to figure out how to keep a sticker sent by a friend. Saving these graphics allows you to reuse them in your own chats and build a personalized collection of favorite digital assets.



Table of contentsSimple Methods to Save iMessage Stickers1. Save Directly to Your Sticker Collection2. Add a Sticker From the Photos App3. How to Delete Stickers You SavedFAQManaging Your Personal Sticker Gallery



Simple Methods to Save iMessage Stickers



1. Save Directly to Your Sticker Collection



When a contact sends you a custom sticker, you can easily add it to your own library without downloading external files. This is the most efficient way to ensure you have quick access to the graphic for future conversations. If you find that your collection is becoming cluttered after adding too many, you should learn how to delete stickers on iPhone to keep your library organized and easy to navigate.




Open the iMessage conversation containing the sticker.



Long press on the specific sticker you want to keep.



Tap the Emoji Details option from the pop up menu.



Tap the Download icon to add it to your sticker drawer.



App the Blue Check mark in the top-right corner.




2. Add a Sticker From the Photos App



You can manually import images from your gallery to turn them into stickers directly within the iMessage interface. This method is perfect for quickly grabbing a photo and converting it into a digital asset without leaving your current conversation. If you run into technical hurdles during this process, you may find that you can't make stickers on iPhone without checking specific software compatibility settings first.




Open a conversation in Messages and tap the Plus sign.



Select the Stickers option from the app menu.



Tap the large Plus icon located inside the sticker drawer.



Choose a photo from your Photos app.



Tap the Plus icon in the bottom right corner to add it.




3. How to Delete Stickers You Saved



Managing your library is just as important as growing it, especially if you accidentally save duplicate graphics or outdated designs. Removing unnecessary items ensures that your most used stickers remain easy to find during active conversations. This process clears space in your selector and helps keep your messaging interface clean and efficient.




Open the Messages app and tap the Plus icon next to the text field.



Select the Stickers option to open your collection.



Long press on any sticker within the drawer until a menu appears.



Tap the Delete button to remove the sticker from your permanent library.




FAQ



Where are saved iMessage stickers stored? Saved stickers are stored in the sticker drawer within the iMessage keyboard. If you save them as images, they appear in the All Photos album in the Photos app.  Can I save stickers from Android users? No, stickers sent from Android users via RCS or SMS usually arrive as standard image files or stickers that cannot be added to the native iOS sticker drawer.  Why can I not see the Add to Stickers option? This usually occurs if the sticker is a live animation or if there is a temporary bug in the Messages app.  



Managing Your Personal Sticker Gallery



Mastering the art of saving digital graphics ensures your conversations remain engaging and unique. By using the methods outlined above, you can build an impressive library of custom reactions and artistic cutouts. If you experience technical glitches where your stickers are not working on iOS, a quick settings reset or app restart will typically restore your full sticker functionality. If you have the latest hardware and stickers are not working on iPhone 16, ensure your software is fully updated to the newest version.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026: The year of scale or fail in enterprise AI]]></title>
<description><![CDATA[If 2024 was the year of experimentation and 2025 the year of the proof of concept, then 2026 is shaping up to be the year of scale or fail.



Across industries, boards and CEOs are increasingly questioning whether incumbent technology leaders can lead them to the AI promised land. That uncertain...]]></description>
<link>https://tsecurity.de/de/3162656/it-security-nachrichten/2026-the-year-of-scale-or-fail-in-enterprise-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3162656/it-security-nachrichten/2026-the-year-of-scale-or-fail-in-enterprise-ai/</guid>
<pubDate>Tue, 16 Dec 2025 16:36:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If 2024 was the year of experimentation and 2025 the year of the proof of concept, then 2026 is shaping up to be the year of scale or fail.</p>



<p>Across industries, boards and CEOs are increasingly questioning whether incumbent technology leaders can lead them to the AI promised land. That uncertainty persists even as many CIOs have made heroic efforts to move the agenda forward, often with little reciprocation from the business. The result is a growing imbalance between expectation and execution.</p>



<p>So what do you do when AI pilots aren’t converting into enterprise outcomes, when your copilot rollout hasn’t delivered the spontaneous innovation you hoped for and when the conveyor belt of new use cases continues to outpace the limited capacity of your central AI team? For many CIOs, this imbalance has created an environment where business units are inevitably branching off on their own, often in ways that amplify risk and inefficiency.</p>



<p>Leading CIOs are breaking this cycle by tackling the 2026 agenda on two fronts, beginning with turning IT into a productivity engine and extending outward by federating AI delivery across the enterprise. Together, these two approaches define the blueprint for taking back the AI narrative and scaling AI responsibly and sustainably.</p>



<h2 class="wp-block-heading">Inside out: Turning IT into a productivity engine</h2>



<p>Every CEO is asking the same question right now: Where’s the productivity? Many have read the same reports promising double-digit efficiency gains through AI and automation. For CIOs, this is the moment to show what good looks like, to use IT as the proving ground for measurable, repeatable productivity improvements that the rest of the enterprise can emulate.</p>



<p>The journey starts by reimagining what your technology organization looks like when it’s operating at peak productivity with AI. Begin with a job family analysis that includes everyone: Architects, data engineers, infrastructure specialists, people managers and more. Catalog how many resources sit in each group and examine where their time is going across key activities such as development, support, analytics, technical design and project management. The focus should be on repeatable work, the kind of activities that occur within a standard quarterly cycle.</p>



<p>For one Fortune 500 client, this analysis revealed that nearly half of all IT time was being spent across five recurring activities: development, support, analytics, technical design and project delivery. With that data in hand, the CIO and their team began mapping where AI could deliver measurable improvements in each job family’s workload.</p>



<p>Consider the software engineering group. Analysis showed that 45% of their time was spent on development work, with the rest spread across peer review, refactoring and environment setup, debugging and other miscellaneous tasks. Introducing a generative AI solution, such as GitHub Copilot enabled the team to auto-generate and optimize code, reducing development effort by an estimated 34%. Translated into hard numbers, that equates to roughly six hours saved per engineer each week. Multiply that by 48 working weeks and 100 developers and the result is close to 29,000 hours, or about a million dollars in potential annual savings based on a blended hourly rate of $35. Over five years, when considering costs and a phased adoption curve, the ROI for this single use case reached roughly $2.4 million</p>



<p>Repeating this kind of analysis across all job families and activities produces a data-backed productivity roadmap: a list of AI use cases ranked by both impact and feasibility. In the case of the same Fortune 500 client, more than 100 potential use cases were identified, but focusing on the top five delivered between 50% and 70% of the total productivity potential. With this approach, CIOs don’t just have a target; they have a method. They can show exactly how to achieve 30% productivity gains in IT and provide a playbook that the rest of the organization can follow.</p>



<h2 class="wp-block-heading">Outside in: Federating for scale</h2>



<p>If the inside-out effort builds credibility, the outside-in effort lays the foundation to attack the supply-demand imbalance for AI and ultimately, build scale.</p>



<p>No previous technology has generated as much demand pull from the business as AI. Business units and functions want to move quickly and they will, with or without IT’s involvement. But few organizations have the centralized resources or funding needed to meet this demand directly. To close that gap, many are now designing a hub-and-spoke operating model that will federate AI delivery across the enterprise while maintaining a consistent foundation of platforms, standards and governance.</p>



<p>In this model, the central AI center of excellence serves as the hub for strategy, enablement and governance rather than as a gatekeeper for approvals. It provides infrastructure, reusable assets, training and guardrails, while the business units take ownership of delivery, funding and outcomes. The power of this model lies in the collaboration between the hub’s AI engineers and the business teams in the spokes. Together, they combine enterprise-grade standards and tools with deep domain context to drive adoption and accountability where it matters most.</p>



<p>One Fortune 500 client, for example, is in the process of implementing its vision for a federated AI operating model. Recognizing the limits of a centralized structure, the CIO and leadership team defined both an interim state and an end-state vision to guide the journey over the next several years. The interim state would establish domain-based AI centers of excellence within each major business area. These domain hubs would be staffed with platform experts, responsible AI advisors and data engineers to accelerate local delivery while maintaining alignment with enterprise standards and governance principles.</p>



<p>The longer-term end state would see these domain centers evolve into smaller, AI-empowered teams that can operate independently while leveraging enterprise platforms and policies. The organization has also mapped out how costs and productivity would shift along the way, anticipating a J-curve effect as investments ramp up in the early phases before productivity accelerates as the enterprise “learns to fish” on its own.</p>



<p>The value of this approach lies not in immediate execution but in intentional design. By clearly defining how the transition will unfold and by setting expectations for how the cost curve will behave, the CIO is positioning the organization to scale AI responsibly, in a timeframe that is realistic for the organization.</p>



<h2 class="wp-block-heading">2026: The year of execution</h2>



<p>After two years of experimentation and pilots, 2026 will be the year that separates organizations that can scale AI responsibly from those that cannot. For CIOs, the playbook is now clear. The path forward begins with proving the impact of AI on productivity within IT itself and then extends outward by federating AI capability to the rest of the enterprise in a controlled and scalable way.</p>



<p>Those who can execute on both fronts will win the confidence of their boards and the commitment of their businesses. Those who can’t may find themselves on the wrong side of the J-curve, investing heavily without ever realizing the return.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond lift-and-shift: Using agentic AI for continuous cloud modernization]]></title>
<description><![CDATA[The promise of cloud is agility, but the reality of cloud migration often looks more like a high-stakes, one-time project. When faced with sprawling, complex legacy applications — particularly in Java or .NET — the traditional “lift-and-shift” approach is only a halfway measure. It moves the comp...]]></description>
<link>https://tsecurity.de/de/3159915/it-security-nachrichten/beyond-lift-and-shift-using-agentic-ai-for-continuous-cloud-modernization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3159915/it-security-nachrichten/beyond-lift-and-shift-using-agentic-ai-for-continuous-cloud-modernization/</guid>
<pubDate>Mon, 15 Dec 2025 14:19:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The promise of cloud is agility, but the reality of cloud migration often looks more like a high-stakes, one-time project. When faced with sprawling, complex legacy applications — particularly in Java or .NET — the traditional “lift-and-shift” approach is only a halfway measure. It moves the complexity, but doesn’t solve it. The next strategic imperative for the CIO is to transition from periodic, costly overhauls to continuous modernization powered by autonomous agentic AI. This shift transforms migration from a finite, risk-laden project into an always-on optimization engine that continuously grooms your application portfolio, directly addressing complexity and accelerating speed-to-market.<strong></strong></p>



<h2 class="wp-block-heading">The autonomous engine: Agentic AI for systematic refactoring </h2>



<p>Agentic AI systems are fundamentally different from traditional scripts; they are goal-driven and capable of planning, acting and learning. When applied to application modernization, they can operate directly on legacy codebases to prepare them for a cloud-native future.</p>



<h3 class="wp-block-heading">Intelligent code refactoring</h3>



<p>The most significant bottleneck in modernization is refactoring — restructuring existing code without changing its external behavior to improve maintainability, efficiency and cloud-readiness. McKinsey estimates that <a href="https://www.mckinsey.com/industries/technology-media-and-telecommunications/our-insights/navigating-the-generative-ai-disruption-in-software" target="_blank" rel="nofollow">Generative AI can shave 20–30%</a> off refactoring time and can reduce migration costs by up to 40%. Agentic AI tools leverage large language models (LLMs) to ingest entire repositories, analyze cross-file dependencies and propose or even execute complex refactoring moves, such as breaking a monolith into microservices. For applications running on legacy Java or .NET frameworks, these agents can systematically:</p>



<ul class="wp-block-list">
<li>Identify and flag “<a href="https://martinfowler.com/bliki/CodeSmell.html#:~:text=The%20term%20was%20first%20coined,I've%20recently%20put%20it." target="_blank" rel="nofollow">code smells</a>” (duplicated logic, deeply nested code).</li>



<li>Automatically convert aging APIs to cloud-native or serverless patterns.</li>



<li>Draft and apply migration snippets to move core functions to managed cloud services.</li>
</ul>



<h3 class="wp-block-heading">Automated application dependency mapping</h3>



<p>Before any refactoring can begin, you need a complete and accurate map of application dependencies, which is nearly impossible to maintain manually in a large enterprise. Agentic AI excels at this through autonomous discovery. Agents analyze runtime telemetry, network traffic and static code to create a real-time, high-fidelity map of the application portfolio. As BCG highlights, applying AI to core platform processes helps to reduce human error and can <a href="https://www.bcg.com/publications/2025/how-agentic-ai-is-transforming-enterprise-platforms" target="_blank" rel="nofollow">accelerate business processes by 30% to 50%</a>. In this context, the agent is continuously identifying potential service boundaries, optimizing data flow and recommending the most logical containerization or serverless targets for each component.</p>



<h2 class="wp-block-heading">Practical use cases for continuous value </h2>



<p>This agentic approach delivers tangible business value by automating the most time-consuming and error-prone phases of modernization:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Use Case</strong></td><td><strong>AI Agent Action</strong></td><td><strong>Business Impact</strong></td></tr></thead><tbody><tr><td><strong>Dependency mapping</strong></td><td>Analyzes legacy code and runtime data to map component-to-component connections and external service calls.</td><td><strong>Reduced risk:</strong> Eliminates manual discovery errors that cause production outages during cutover. </td></tr><tr><td><strong>Intelligent code refactoring</strong></td><td>Systematically restructures code for cloud-native consumption (e.g., converting monolithic C# or Java code into microservices).</td><td><strong>Cost &amp; speed:</strong> Reduces developer toil and cuts transformation timelines by as much as 50%. </td></tr><tr><td><strong>Continuous security posture enforcement</strong></td><td>The agent autonomously scans for new vulnerabilities (CVEs), identifies affected code components and instantly applies security patches or configuration changes (e.g., updating a policy or library version) across the entire portfolio.</td><td><strong>Enhanced resilience:</strong> Drastically reduces the “time-to-remediation” from weeks to minutes, proactively preventing security breaches and enforcing a compliant posture 24/7. </td></tr><tr><td><strong>Real-time performance tuning</strong></td><td>Monitors live workload patterns (e.g., CPU, latency, concurrent users) and automatically adjusts cloud resources (e.g., rightsizing instances, optimizing database indices, adjusting serverless concurrency limits) to prevent performance degradation.</td><td><strong>Maximized ROI:</strong> Ensures applications are always running with the optimal balance of speed and cost, eliminating waste from over-provisioning and avoiding customer-impacting performance slowdowns. </td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Integrating human-in-the-loop (HITL) framework governance </h2>



<p>The transition to an agent-driven modernization model doesn’t seek to remove the human role; rather, it elevates it from manual, repetitive toil to strategic governance. The success of continuous modernization hinges on a robust <a href="https://www.permit.io/blog/human-in-the-loop-for-ai-agents-best-practices-frameworks-use-cases-and-demo" target="_blank" rel="nofollow">human-in-the-loop (HITL) framework</a>. This framework mandates that while the agent autonomously identifies optimization opportunities (e.g., a component generating high costs) and formulates a refactoring plan, the deployment is always gated by strict human oversight. The role of the developer shifts to defining the rules, validating the agent’s proposed changes through automated testing and ultimately approving the production deployment incrementally. This governance ensures that the self-optimizing environment remains resilient and adheres to crucial business objectives for performance and compliance.</p>



<h2 class="wp-block-heading">Transforming the modernization cost model </h2>



<p>The agentic approach fundamentally transforms the economic framework for managing IT assets. Traditional “lift-and-shift” and periodic overhauls are viewed as massive, high-stakes capital expenditure (CapEx) projects. By shifting to an autonomous, continuous modernization engine, the financial model transitions to a predictable, utility-like pperational expenditure (OpEx). This means costs are tied directly to the value delivered and consumption efficiency, as the agent continuously grooms the portfolio to optimize for cost. This allows IT to fund modernization as an always-on optimization function, making the management of the cloud estate a sustainable, predictable line item rather than a perpetual budget shock.</p>



<h2 class="wp-block-heading">Shifting the development paradigm: From coder to orchestrator </h2>



<p>The organizational impact of agentic AI is as critical as the technical one. By offloading the constant work of identifying technical debt, tracking dependencies and executing routine refactoring or patching, the agent frees engineers from being primarily coders and maintainers. The human role evolves into the AI orchestrator or System Architect. Developers become responsible for defining the high-level goals, reviewing the agent’s generated plans and code for architectural integrity and focusing their time on innovation, complex feature development and designing the governance framework itself. This strategic shift not only reduces developer burnout and increases overall productivity but is also key to attracting and retaining top-tier engineering talent, positioning IT as a center for strategic design rather than just a maintenance shop.</p>



<h2 class="wp-block-heading">The pilot mandate: Starting small, scaling quickly </h2>



<p>For CIOs facing pressure to demonstrate AI value responsibly, the adoption of agentic modernization must begin with a targeted, low-risk pilot. The objective is to select a high-value application—ideally, a non-critical helper application or an internal-facing microservice that has a quantifiable amount of technical debt and clear performance or cost metrics. The goal of this pilot is to prove the agent’s ability to execute the full modernization loop autonomously: <em>Discovery &gt; Refactoring &gt; Automated Testing &gt; Human Approval &gt; Incremental Deployment</em>. Once key success metrics (such as a 40% reduction in time-to-patch or a 15% improvement in cost efficiency) are validated in this controlled environment, the organization gains the confidence and blueprint needed to scale the agent framework horizontally across the rest of the application portfolio, minimizing enterprise risk.</p>



<h2 class="wp-block-heading">The strategic mandate: Self-optimizing resilience </h2>



<p>By adopting autonomous agents, the operational model shifts from reactive fixes to a resilient, self-optimizing environment. Gartner projects that autonomous AI agents will be one of the fastest transformations in enterprise technology, with a major emphasis on their ability to orchestrate entire workflows across the application migration and modernization lifecycle. These agents are not just tools; they are continuous improvement loops that proactively:</p>



<ul class="wp-block-list">
<li>Identify a component that is generating high cloud costs.</li>



<li>Formulate a refactoring plan for optimization (e.g., move to a managed serverless queue).</li>



<li>Execute the refactoring, run automated tests and deploy the change incrementally, all under strict human oversight.</li>
</ul>



<p>The CIO’s task is to define the strategic goals — cost, performance, resilience — and deploy the agents with the governance and human-in-the-loop controls necessary to allow them to act. This proactive, agent-driven model is the only path to truly continuous modernization, ensuring your cloud estate remains an agile asset, not a perpetual liability</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[UPDF Review: My Top Pick as the Best PDF Editor for 2025/2026]]></title>
<description><![CDATA[Read on for the UPDF review in this post. PDFs require more than a simple viewer. Over the years, I have experienced that managing PDF activities is often more complicated than it should be, such as editing text, converting to other formats, organizing pages, performing OCRs, or adding security. ...]]></description>
<link>https://tsecurity.de/de/3156218/it-security-nachrichten/updf-review-my-top-pick-as-the-best-pdf-editor-for-20252026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3156218/it-security-nachrichten/updf-review-my-top-pick-as-the-best-pdf-editor-for-20252026/</guid>
<pubDate>Fri, 12 Dec 2025 21:50:08 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Read on for the UPDF review in this post. PDFs require more than a simple viewer. Over the years, I have experienced that managing PDF activities is often more complicated than it should be, such as editing text, converting to other formats, organizing pages, performing OCRs, or adding security.  I have tried many PDF tools. Some […]</p>
<p>The post <a href="https://secureblitz.com/updf-review-best-pdf-editor/">UPDF Review: My Top Pick as the Best PDF Editor for 2025/2026</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution]]></title>
<description><![CDATA[Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe ColdFusion is a rapid web application development platform that uses the ColdFusion Markup Language (CFML).Adobe Experience Manager (AEM) is a content manageme...]]></description>
<link>https://tsecurity.de/de/3149622/sicherheitsluecken/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3149622/sicherheitsluecken/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution/</guid>
<pubDate>Wed, 10 Dec 2025 08:06:20 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. </p><ul><li>Adobe ColdFusion is a rapid web application development platform that uses the ColdFusion Markup Language (CFML).</li><li>Adobe Experience Manager (AEM) is a content management and experience management system that helps businesses build and manage their digital presence across various platforms.</li><li>The Adobe DNG Software Development Kit (SDK) is a free set of tools and code from Adobe that helps developers add support for Adobe's Digital Negative (DNG) universal RAW file format into their own applications and cameras, enabling them to read, write, and process DNG images, solving workflow issues and improving archiving for digital photos.</li><li>Adobe Acrobat is a suite of paid tools for creating, editing, converting, and managing PDF documents.</li><li>The Adobe Creative Cloud desktop app is the central hub for managing all Adobe creative applications, files, and assets.</li></ul><p>Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Services and Job Portals in The Real World Platform: Connecting Skills to Real Opportunities]]></title>
<description><![CDATA[In this post, I will talk about services and job portals in the real world platform. In today’s digital economy, learning a skill is only the beginning. The main challenge is converting those skills into income, experience, or career growth. Many complete courses or certifications but still strug...]]></description>
<link>https://tsecurity.de/de/3149582/it-security-nachrichten/services-and-job-portals-in-the-real-world-platform-connecting-skills-to-real-opportunities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3149582/it-security-nachrichten/services-and-job-portals-in-the-real-world-platform-connecting-skills-to-real-opportunities/</guid>
<pubDate>Wed, 10 Dec 2025 07:36:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will talk about services and job portals in the real world platform. In today’s digital economy, learning a skill is only the beginning. The main challenge is converting those skills into income, experience, or career growth. Many complete courses or certifications but still struggle to find opportunities to apply their knowledge. […]</p>
<p>The post <a href="https://secureblitz.com/services-and-job-portals-in-the-real-world-platform/">Services and Job Portals in The Real World Platform: Connecting Skills to Real Opportunities</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How a Cryptocurrency Helps Criminals Launder Money and Evade Sanctions]]></title>
<description><![CDATA[An investigation has revealed how stablecoins -- cryptocurrencies pegged to the US dollar that exist largely beyond traditional financial oversight -- have become a practical tool for criminals and sanctioned individuals to move funds across borders almost instantly and convert them back into spe...]]></description>
<link>https://tsecurity.de/de/3146028/it-security-nachrichten/how-a-cryptocurrency-helps-criminals-launder-money-and-evade-sanctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3146028/it-security-nachrichten/how-a-cryptocurrency-helps-criminals-launder-money-and-evade-sanctions/</guid>
<pubDate>Mon, 08 Dec 2025 17:22:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An investigation has revealed how stablecoins -- cryptocurrencies pegged to the US dollar that exist largely beyond traditional financial oversight -- have become a practical tool for criminals and sanctioned individuals to move funds across borders almost instantly and convert them back into spendable money, often without detection. 

A Chainalysis report from February estimated that up to $25 billion in illicit transactions involved stablecoins last year. A New York Times reporter tested the system by converting $40 cash at a crypto ATM in Weehawken, New Jersey, into stablecoins and then using a Telegram bot to generate a Visa payment card without any identity verification. The card-issuing service, WantToPay, is incorporated in Hong Kong and led by a Russian entrepreneur in Thailand; it advertises to Russians blocked by US sanctions. Britain last month arrested members of a billion-dollar money laundering network that had purchased a bank in Kyrgyzstan to convert proceeds from drug trafficking and human trafficking into Tether, the most popular stablecoin. 

Further reading: China's Central Bank Flags Money Laundering and Fraud Concerns With Stablecoins.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=How+a+Cryptocurrency+Helps+Criminals+Launder+Money+and+Evade+Sanctions%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F12%2F08%2F1545253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F12%2F08%2F1545253%2Fhow-a-cryptocurrency-helps-criminals-launder-money-and-evade-sanctions%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/25/12/08/1545253/how-a-cryptocurrency-helps-criminals-launder-money-and-evade-sanctions?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vertical AI development agents are the future of enterprise integrations]]></title>
<description><![CDATA[Enterprise Application Integration (EAI) and modern iPaaS platforms have become two of the most strategically important – and resource-constrained – functions inside today’s enterprises. As organizations scale SaaS adoption, modernize core systems, and automate cross-functional workflows, integra...]]></description>
<link>https://tsecurity.de/de/3141250/it-security-nachrichten/vertical-ai-development-agents-are-the-future-of-enterprise-integrations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3141250/it-security-nachrichten/vertical-ai-development-agents-are-the-future-of-enterprise-integrations/</guid>
<pubDate>Fri, 05 Dec 2025 17:09:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise Application Integration (EAI) and modern iPaaS platforms have become two of the most strategically important – and resource-constrained – functions inside today’s enterprises. As organizations scale SaaS adoption, modernize core systems, and automate cross-functional workflows, integration teams face mounting pressure to deliver faster while upholding strict architectural, data quality, and governance standards.</p>



<p>AI has entered this environment with the promise of acceleration. But CIOs are discovering a critical truth:</p>



<p><strong>Not all AI is built for the complexity of enterprise integrations – whether in traditional EAI stacks or modern iPaaS environments.</strong></p>



<p>Generic coding assistants such as Cursor or Claude Code can boost individual productivity, but they struggle with the pattern-heavy, compliance-driven reality of integration engineering. What looks impressive in a demo often breaks down under real-world EAI/iPaaS conditions.</p>



<p>This widening gap has led to the rise of a new category: <strong>Vertical AI Development Agents</strong> – domain-trained agents purpose-built for integration and middleware development. Companies like <a href="http://www.curietech.ai/" target="_blank" rel="sponsored">CurieTech AI</a> are demonstrating that specialized agents deliver not just speed, but materially higher accuracy, higher-quality outputs, and far better governance than general-purpose tools.</p>



<p>For CIOs running mission-critical integration programs, that difference directly affects reliability, delivery velocity, and ROI.</p>



<h2 class="wp-block-heading">Why EAI and iPaaS integrations are not a “Generic Coding” problem</h2>



<p>Integrations—whether built on legacy middleware or modern iPaaS platforms – operate within a rigid architectural framework:</p>



<ul class="wp-block-list">
<li>multi-step orchestration, sequencing, and idempotency</li>



<li>canonical data transformations and enrichment</li>



<li>platform-specific connectors and APIs</li>



<li>standardized error-handling frameworks</li>



<li>auditability and enterprise logging conventions</li>



<li>governance and compliance embedded at every step</li>
</ul>



<p>Generic coding models are not trained on this domain structure. They often produce code that <strong>looks correct</strong>, yet subtly breaks sequencing rules, omits required error handling, mishandles transformations, or violates enterprise logging and naming standards.</p>



<p>Vertical agents, by contrast, are trained specifically to understand <strong>flow logic</strong>, <strong>mappings</strong>, <strong>middleware orchestration</strong>, and <strong>integration patterns </strong>– across both EAI and iPaaS architectures. They don’t just generate code – they reason in the same structures architects and ICC teams use to design integrations.</p>



<p>This domain grounding is the critical distinction.</p>



<h2 class="wp-block-heading"><strong>The hidden drag: Context latency, expensive context managers, and prompt fatigue</strong></h2>



<p>Teams experimenting with generic AI encounter three consistent frictions:</p>



<h3 class="wp-block-heading"><strong>Context Latency</strong></h3>



<p>Generic models cannot retain complex platform context across prompts. Developers must repeatedly restate platform rules, logging standards, retry logic, authentication patterns, and canonical schemas.</p>



<h3 class="wp-block-heading"><strong>Developers become “expensive context managers”</strong></h3>



<p>A seemingly simple instruction—<em>“Transform XML to JSON and publish to Kafka”</em>—<br>quickly devolves into a series of corrective prompts:</p>



<ul class="wp-block-list">
<li>“Use the enterprise logging format.”</li>



<li>“Add retries with exponential backoff.”</li>



<li>“Fix the transformation rules.”</li>



<li>“Apply the standardized error-handling pattern.”</li>
</ul>



<p>Developers end up managing the model instead of building the solution.</p>



<h3 class="wp-block-heading"><strong>Prompt fatigue</strong></h3>



<p>The cycle of re-prompting, patching, and enforcing architectural rules consumes time and erodes confidence in outputs.</p>



<p>This is why generic tools rarely achieve the promised acceleration in integration environments.</p>



<h2 class="wp-block-heading"><strong>Benchmarks show vertical agents are about twice as accurate</strong></h2>



<p>CurieTech AI recently published comparative <a href="https://www.curietech.ai/blog/curietech-ai-vs-claude-code" target="_blank" rel="sponsored">benchmarks</a> evaluating its vertical integration agents against leading generic tools, including Claude Code.<br>The tests covered real-world tasks:</p>



<ul class="wp-block-list">
<li>generating complete, multi-step integration flows</li>



<li>building cross-system data transformations</li>



<li>producing platform-aligned retries and error chains</li>



<li>implementing enterprise-standard logging</li>



<li>converting business requirements into executable integration logic</li>
</ul>



<p><strong>The results were clear:</strong> generic tools performed at roughly <strong>half the accuracy</strong> of vertical agents.</p>



<p>Generic outputs often looked plausible but contained structural errors or governance violations that would cause failures in QA or production. Vertical agents produced platform-aligned, fully structured workflows on the first pass.</p>



<p>For integration engineering – where errors cascade – this accuracy gap directly impacts delivery predictability and long-term quality.</p>



<h2 class="wp-block-heading"><strong>The vertical agent advantage: Single-shot solutioning</strong></h2>



<p>The defining capability of vertical agents is <strong>single-shot task execution</strong>.</p>



<p>Generic tools force stepwise prompting and correction. But vertical agents—because they understand patterns, sequencing, and governance—can take a requirement like:</p>



<p><em>“Create an idempotent order-sync flow from NetSuite to SAP S/4HANA with canonical transformations, retries, and enterprise logging.”</em></p>



<p>…and return:</p>



<ul class="wp-block-list">
<li>the flow</li>



<li>transformations</li>



<li>error handling</li>



<li>retries</li>



<li>logging</li>



<li>and test scaffolding</li>
</ul>



<p>in one coherent output.</p>



<p>This shift – from <strong>instruction-oriented prompting</strong> to <strong>goal-oriented prompting</strong>—removes context latency and prompt fatigue while drastically reducing the need for developer oversight.</p>



<h2 class="wp-block-heading"><strong>Built-in governance: The most underrated benefit</strong></h2>



<p>Integrations live and die by adherence to standards. Vertical agents embed those standards directly into generation:</p>



<ul class="wp-block-list">
<li>naming and folder conventions</li>



<li>canonical data models</li>



<li>PII masking and sensitive-data controls</li>



<li>logging fields and formats</li>



<li>retry and exception handling patterns</li>



<li>platform-specific best practices</li>
</ul>



<p>Generic models cannot consistently maintain these rules across prompts or projects.</p>



<p>Vertical agents enforce them automatically, which leads to higher-quality integrations with far fewer QA defects and production issues.</p>



<h2 class="wp-block-heading"><strong>The real ROI: Quality, consistency, predictability</strong></h2>



<p>Organizations adopting vertical agents report three consistent benefits:</p>



<h3 class="wp-block-heading"><strong>1. Higher-Quality Integrations</strong></h3>



<p>Outputs follow correct patterns and platform rules—reducing defects and architectural drift.</p>



<h3 class="wp-block-heading"><strong>2. Greater Consistency Across Teams</strong></h3>



<p>Standardized logic and structures eliminate developer-to-developer variability.</p>



<h3 class="wp-block-heading"><strong>3. More Predictable Delivery Timelines</strong></h3>



<p>Less rework means smoother pipelines and faster delivery.</p>



<p>A recent enterprise using CurieTech AI summarized the impact succinctly:</p>



<p><strong>“For MuleSoft users, generic AI tools won’t cut it. But with domain-specific agents, the ROI is clear. Just start.”</strong></p>



<p>For CIOs, these outcomes translate to increased throughput and higher trust in integration delivery.</p>



<h2 class="wp-block-heading"><strong>Preparing for the agentic future</strong></h2>



<p>The industry is already moving beyond single responses toward <strong>agentic orchestration</strong>, where AI systems coordinate requirements gathering, design, mapping, development, testing, documentation, and deployment.</p>



<p>Vertical agents—because they understand multi-step integration workflows—are uniquely suited to lead this transition.</p>



<p>Generic coding agents lack the domain grounding to maintain coherence across these interconnected phases.</p>



<h2 class="wp-block-heading"><strong>The bottom line</strong></h2>



<p>Generic coding assistants provide breadth, <strong>but vertical AI development agents deliver the depth, structure, and governance enterprise integrations require.</strong></p>



<p>Vertical agents elevate both EAI and iPaaS programs by offering:</p>



<ul class="wp-block-list">
<li>significantly higher accuracy</li>



<li>higher-quality, production-ready outputs</li>



<li>built-in governance and compliance</li>



<li>consistent logic and transformations</li>



<li>predictable delivery cycles</li>
</ul>



<p>As integration workloads expand and become more central to digital transformation, organizations that adopt vertical AI agents early will deliver faster, with higher accuracy, and with far greater confidence.</p>



<p>In enterprise integrations, specialization isn’t optional—<strong>it is the foundation of the next decade of reliability and scale.</strong></p>



<p><strong>Learn more about CurieTech AI </strong><a href="https://www.curietech.ai/" target="_blank" rel="sponsored">here</a><strong>.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[On the Challenge of Converting TensorFlow Models to PyTorch]]></title>
<description><![CDATA[How to upgrade and optimize legacy AI/ML models
The post On the Challenge of Converting TensorFlow Models to PyTorch appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3140740/ai-nachrichten/on-the-challenge-of-converting-tensorflow-models-to-pytorch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3140740/ai-nachrichten/on-the-challenge-of-converting-tensorflow-models-to-pytorch/</guid>
<pubDate>Fri, 05 Dec 2025 13:32:42 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>How to upgrade and optimize legacy AI/ML models</p>
<p>The post <a href="https://towardsdatascience.com/on-the-challenge-of-converting-tensorflow-models-to-pytorch/">On the Challenge of Converting TensorFlow Models to PyTorch</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Convert an Apple Live Photo to Video]]></title>
<description><![CDATA[Apple's Live Photos capture a brief moment of motion and sound. This creates a small, dynamic clip. Live Photos are great for viewing on an iPhone or iPad. However, sharing them requires converting them to a standard video format. This format is also needed for video editing. Your iOS or iPadOS d...]]></description>
<link>https://tsecurity.de/de/3135241/ios-mac-os/how-to-convert-an-apple-live-photo-to-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135241/ios-mac-os/how-to-convert-an-apple-live-photo-to-video/</guid>
<pubDate>Wed, 03 Dec 2025 08:10:58 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's Live Photos capture a brief moment of motion and sound. This creates a small, dynamic clip. Live Photos are great for viewing on an iPhone or iPad. However, sharing them requires converting them to a standard video format. This format is also needed for video editing. Your iOS or iPadOS device offers simple solutions. You can easily transform these moments into compatible video files.



Table of contentsEffortlessly Transform Live Photos into Shareable Videos1. Using the Built-in 'Save as Video' Feature2. Merging Multiple Live Photos to Create a Longer Video3. Exporting with a Third-Party ApplicationFAQMaximizing the Versatility of Your Converted Clips



Effortlessly Transform Live Photos into Shareable Videos



Converting your Live Photo makes sharing easier. You can share with non-Apple users or on social media. The receiver will always see the movement. These methods use the Photos app and the latest iOS/iPadOS version. The process becomes very streamlined. You won't need any external software.



1. Using the Built-in 'Save as Video' Feature



This is the most direct and simplest method available. Modern iOS and iPadOS versions use this feature. It quickly generates a new, standard .MOV video file. The new video preserves the three seconds of motion and sound. This was originally captured.




Open the Photos app. Navigate to the Live Photo you wish to convert.



Tap the three-dot icon in the top-right corner.



Tap select Save as Video.



The system instantly creates a new video file. It saves the video in your Recents album. The original Live Photo remains intact.




2. Merging Multiple Live Photos to Create a Longer Video



Perhaps you have a sequence of related Live Photos. You may want a slightly longer, cohesive video clip. The Photos app offers a native feature for stitching them together. You can learn more about merging Live Photos seamlessly into a longer file. Use the Albums tab in the Photos app to start.




Open the Photos app. 



Select Collections &gt; Media Types &gt; Live Photos.



Tap Select in the top-right. Choose all the Live Photos you want to combine.



Next, tap the three-dot icon in the top-right corner.



Select Save as Video from the menu. The Photos app automatically combines the photos. It creates one sequential video file.




3. Exporting with a Third-Party Application



The native options are highly effective. Still, a specialized third-party app provides more advanced control. You can control resolution, frame rate, and compression. Apps dedicated to this task offer great flexibility. They often allow batch conversions and custom trimming.




Download a trusted Live Photo converter app. Find it in the App Store.



Grant the app access to your Photos library.



Select the Live Photo you wish to convert within the app.



Adjust any necessary settings. These include cropping or resolution. Then tap the Export or Save button. This creates the final video file.




FAQ



Does converting a Live Photo delete the original? No. All methods mentioned create a new, separate video file. The original Live Photo remains in your library. It keeps its unique format.  Can I use the converted video as a dynamic background? Yes. Once the file is a standard format, you can use it. This includes .MOV or .MP4. Use it for creative purposes. This includes setting it as a dynamic background. Check out some ideas for interactive wallpapers. You might want to create these from your clips.  



Maximizing the Versatility of Your Converted Clips



Converting your dynamic Live Photos is an essential step. It expands their use beyond simple viewing. Once the conversion is complete, use these clips widely. Upload them to platforms like Instagram or TikTok. Use them in more complex video editing projects. Furthermore, the converted video offers great personalization options. For example, learn how to set a video as your wallpaper on your iPhone's lock screen.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,19ms -->